tag:blogger.com,1999:blog-102594812009-03-03T21:45:25.622-05:00Random Thoughts from Joel's WorldHome of the 5 way fin shake.Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.comBlogger1005125tag:blogger.com,1999:blog-10259481.post-52392572619903086922008-10-26T20:42:00.003-05:002008-10-26T20:43:47.616-05:00Apple Store Photos<div>I moved my Gallery of Apple Store Photos to MobileMe. I travel to an Apple Store if I am in the city with one. Check out the gallery over there on the right, or click right <a href="http://gallery.me.com/joel.esler#100087">here</a>.</div><div><br /></div><div>Thanks.</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-5239257261990308692?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-71556070940287682422008-10-23T21:19:00.000-05:002008-10-23T21:20:10.360-05:00ISC Podcast Episode Eleven Posted<div>Hey everyone, sorry it has taken so long to get around to recording another podcast episode. Travel schedules have been very crazy between us lately. Anyway, enough excuses, here is episode eleven. Thanks for all the emails asking me where it is! :) It helps to remind me....<br /><br /><a href="http://isc.sans.org/podcast.xml">All the podcasts</a><br /><a href="http://isc.sans.org/mp3s/20081022.mp3">Just this podcast</a><br /><a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=276609412">Podcast through iTunes</a><br /></div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-7155607094028768242?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-64302125870609922062008-10-23T21:11:00.002-05:002008-10-23T21:13:23.401-05:00CRCError<div>Recorded CRCError podcast last night, I've edited some of it, but I thought I would post something about the website on here. Well.. it's down. So wtf right? </div><div><br /></div><div>Well something about the hosting company where the server is hosted is retarded or something, I don't know the whole drama or the issue, but we're working to get the server back up, and then punch the hosting provider in the face.</div><div><br /></div><div><br /></div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-6430212587060992206?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-63290578699112333922008-10-21T15:41:00.004-05:002008-10-21T15:43:36.354-05:00Mark Wahlberg Talks to Animals<div>This has been cracking me up for like the past 3 days. I love it.</div><div><br /></div><div><object width="512" height="296"><param name="movie" value="http://www.hulu.com/embed/5fp5MK3K9uUbXE_mj1iooA"><embed src="http://www.hulu.com/embed/5fp5MK3K9uUbXE_mj1iooA" type="application/x-shockwave-flash" width="512" height="296"></embed></object><br /></div><div><br /></div><div>Of course it has a sequel as well:</div><div><br /></div><div><br /></div><div><object width="512" height="296"><param name="movie" value="http://www.hulu.com/embed/xw8wKL9q2MpPbW0vZ2sgZg"><embed src="http://www.hulu.com/embed/xw8wKL9q2MpPbW0vZ2sgZg" type="application/x-shockwave-flash" width="512" height="296"></embed></object><br /></div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-6329057869911233392?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com1tag:blogger.com,1999:blog-10259481.post-47530422307023458662008-10-14T17:11:00.003-05:002008-10-14T17:20:01.308-05:00Google Calendar Syncing, MobileMe, and iCal<div>Recently I've had to start keeping my Calendar on Google Calendar. (For a really good reason, and, it's not the free version of Google Calendar either.) However, I didn't know how I was going to get my iCal to publish to Google Calendar, AND sync with MobileMe at the same time.</div><div><br /></div><div>Well I started trying to connect iCal to Google Calendar via CalDAV, which I wrote about in an earlier post. However, Google's implementation of CalDAV is still kinda broke. You can't really schedule people's time, you can't see their availability, you can't call people up from the address book, and you can't have To-Do's on the calendar that you are syncing, so that breaks a bunch of stuff for me. </div><div><br /></div><div>So I was going to try and just keep my calendar on iCal, and have it publish to Google Calendar, well, that wasn't going to work either for a couple reasons. I actually can't remember all the reasons right now, but it had to be something really big for me to abandon it right away.</div><div><br /></div><div>So I started looking into Apps that would sync my calendars for me. So I came up with BusySync.</div><div><br /></div><div>So I took the following steps, since my calendar was maintained in iCal, YMMV, but good luck:</div><div>1. I exported my iCal calendar and put it on my desktop. </div><div>2. Logged into Google Calendar and imported my iCal calendar into Google Calendar (took a few seconds, I have a rather large calendar).</div><div>3. Deleted my local calendar in iCal.</div><div>4. Fired up BusySync and told BusySync to Sync my Google Calendar to local iCal.</div><div>5. Viola.</div><div><br /></div><div>Since BusySync syncs a calendar to a "local" calendar (as opposed to a "subscribed" calendar) everything works fine, in fact, MobileMe will sync your calendar right down to your iPhone. </div><div><br /></div><div>Problem Solved.</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-4753042230702345866?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-36102889760617429452008-10-14T16:56:00.005-05:002008-10-15T20:44:11.476-05:00Okay, so Tim Cook has a mic on.<div><span class="Apple-style-span" style="color:#FFFF00;">UPDATE2</span>: I stand corrected. It's a mic. Sorry Mr. Cook! </div><div><br /></div><div><span class="Apple-style-span" style="color:#FFFF00;">UPDATE</span>: Leon in the comments points out that I may be a tard, and this is actually his wireless mic. I think Leon has something here.. There is an antenna sticking out the top, but from the brief look you can get at it in the show video, I can't tell if it's a flexible antenna or a hard antenna. But the more I look at it, the more I think it is a Mic. Mr. Cook, sorry about that. Like I said, I'm not complaining even if it _was_ a blackberry.</div><div><br /></div><div>I'm just not used to seeing a mic on anyone in an Apple presentation. Steve's is built into his shirt (look for the vertical line in the center of his chest in his shirt), and everyone else tucks it underneath their clothes.</div><div><br /></div><div><a href="http://www.shure.com/ProAudio/Products/WirelessMicrophones/us_pro_U1_content">http://www.shure.com/ProAudio/Products/WirelessMicrophones/us_pro_U1_content</a><br /></div><div><br /></div><div><br /></div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_BpBcl5urwoc/SPUWCCxz5CI/AAAAAAAAAUA/-T836_70le4/s1600-h/Picture+2.png"><img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_BpBcl5urwoc/SPUWCCxz5CI/AAAAAAAAAUA/-T836_70le4/s320/Picture+2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5257132364386264098" /></a><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_BpBcl5urwoc/SPUWCXhGXgI/AAAAAAAAAUI/DfaUSwefgdw/s1600-h/Picture+3.png"><img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_BpBcl5urwoc/SPUWCXhGXgI/AAAAAAAAAUI/DfaUSwefgdw/s320/Picture+3.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5257132369953316354" /></a><br /><div>Sorry Mr. Cook, just noticed it. No complaint here, not bitching, just noticed it :)</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-3610288976061742945?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com3tag:blogger.com,1999:blog-10259481.post-75070553146333123172008-10-13T19:49:00.002-05:002008-10-13T19:58:50.524-05:001001<div>Some insight. </div><div><br /></div><div>So, here I am at 1,001 posts. What do I have to say? Absolutely nothing more than what I said at 900. Do what you do, say what you say, and people will be interested.</div><div><br /></div><div>Between my 900 and my 1000 posts, I've picked up about 200% more readers (rss subscribers) and average about 500% more hits a day. </div><div><br /></div><div>Recently I've picked up a bunch more readers through subscriptions, it's basically like a heartbeat diagram that keeps going up. When my name is mentioned somewhere, or I do a post on the ISC or something, I get a huge influx of readers, then it dies off a little bit, but a few stick around to see what nonsense I have to ramble about. It hasn't been much lately as I've been pretty busy with work and what not.</div><div><br /></div><div>I'll try and get more active in the future. I promise. <span class="Apple-tab-span" style="white-space:pre"> </span>I've just got alot going on right now, I'm lucky if I can get through my email.</div><div><br /></div><div>Speaking of which, I need to do another "processing" email post, as I've changed alot about that.</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-7507055314633312317?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-78450893466496759392008-10-10T08:35:00.002-05:002008-10-10T08:40:39.031-05:00Apple Security Update 2008-007<div>I wish my 1000th post on the blog was way more insightful than this, but it's not going to be. I'll have to write something that really reflects a 1000th post. But it will be 1001.</div><div><br /></div><div><br /></div><div>Introducing Apple Security Update 2008-007. Just released last night:</div><div><br /></div><div><b><a href="http://support.apple.com/kb/HT3216">Security Update 2008-007</a></b><br /><ul><li>Apache</li></ul><br />CVE-ID: CVE-2007-6420, CVE-2008-1678, CVE-2008-2364<br /><br />Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Multiple vulnerabilities in Apache 2.2.8<br /><br />Description: Apache is updated to version 2.2.9 to address several vulnerabilities, the most serious of which may lead to cross site request forgery. Apache version 2 is not bundled with Mac OS X Client systems prior to version 10.5. Apache version 2 is bundled with Mac OS X Server v10.4.x systems, but is not active by default. Further information is available via the Apache web site at http://httpd.apache.org/<br /><br /><ul><li>Certificates</li></ul><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Root certificates have been updated<br /><br />Description: Several trusted certificates were added to the list of system roots. Several existing certificates were updated to their most recent version. The complete list of recognized system roots may be viewed via the Keychain Access application.<br /><br /><ul><li>ClamAV</li></ul><br />CVE-ID: CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914<br /><br />Available for: Mac OS X Server v10.4.11, Mac OS X Server v10.5.5<br /><br />Impact: Multiple vulnerabilities in ClamAV 0.93.3<br /><br />Description: Multiple vulnerabilities exist in ClamAV 0.93.3, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating to ClamAV 0.94. ClamAV is not bundled on Mac OS X Client systems. Further information is available via the ClamAV website at http://www.clamav.net/<br /><br /><ul><li>ColorSync</li></ul><br />CVE-ID: CVE-2008-3642<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Viewing a maliciously crafted image may lead to an unexpected application termination or arbitrary code execution<br /><br />Description: A buffer overflow exists in the handling of images with an embedded ICC profile. Opening a maliciously crafted image with an embedded ICC profile may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of ICC profiles in images. Credit: Apple.<br /><br /><ul><li>CUPS</li></ul><br />CVE-ID: CVE-2008-3641<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: A remote attacker may be able to cause arbitrary code execution with the privileges of the 'lp' user<br /><br />Description: A range checking issue exists in the Hewlett-Packard Graphics Language (HPGL) filter, which may cause arbitrary memory to be overwritten with controlled data. If Printer Sharing is enabled, a remote attacker may be able to cause arbitrary code execution with the privileges of the 'lp' user. If Printer Sharing is not enabled, a local user may be able to obtain elevated privileges. This update addresses the issue by performing additional bounds checking. Credit to regenrecht working with TippingPoint's Zero Day Initiative for reporting this issue.<br /><br /><ul><li>Finder</li></ul><br />CVE-ID: CVE-2008-3643<br /><br />Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: A file on the Desktop may lead to a denial of service<br /><br />Description: An error recovery issue exists in Finder. A maliciously crafted file on the Desktop which causes Finder to unexpectedly terminate when generating its icon will cause Finder to continually terminate and restart. Until the file is removed, the user account is not accessible via Finder's user interface. This update addresses the issue by generating icons in a separate process. This issue does not affect systems prior to Mac OS X v10.5. Credit to Sergio 'shadown' Alvarez of n.runs AG for reporting this issue.<br /><br /><ul><li>launchd</li></ul><br />Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Applications may fail to enter a sandbox when requested<br /><br />Description: This update addresses an issue introduced in Mac OS X v10.5.5. An implementation issue in launchd may cause an application's request to enter a sandbox to fail. This issue does not affect programs that use the documented sandbox_init API. This update addresses the issue by providing an updated version of launchd. This issue does not affect systems prior to Mac OS X v10.5.5.<br /><br /><ul><li>libxslt</li></ul><br />CVE-ID: CVE-2008-1767<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Processing an XML document may lead to an unexpected application termination or arbitrary code execution<br /><br />Description: A heap buffer overflow issue exists in the libxslt library. Viewing a maliciously crafted HTML page may lead to an unexpected application termination or arbitrary code execution. Further information on the patch applied is available via http://xmlsoft.org/XSLT/ Credit to Anthony de Almeida Lopes of Outpost24 AB, and Chris Evans of Google Security Team for reporting this issue.<br /><br /><ul><li>MySQL Server</li></ul><br />CVE-ID: CVE-2007-2691, CVE-2007-5969, CVE-2008-0226, CVE-2008-0227, CVE-2008-2079<br /><br />Available for: Mac OS X Server v10.5.5<br /><br />Impact: Multiple vulnerabilities in MySQL 5.0.45<br /><br />Description: MySQL is updated to version 5.0.67 to address several vulnerabilities, the most serious of which may lead to arbitrary code execution. These issues only affect Mac OS X Server systems. Further information is available via the MySQL web site at http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-67.html<br /><br /><ul><li>Networking</li></ul><br />CVE-ID: CVE-2008-3645<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: A local user may obtain system privileges<br /><br />Description: A heap buffer overflow exists in the local IPC component of configd's EAPOLController plugin, which may allow a local user to obtain system privileges. This update addresses the issue through improved bounds checking. Credit: Apple.<br /><br /><ul><li>PHP</li></ul><br />CVE-ID: CVE-2007-4850, CVE-2008-0674, CVE-2008-2371<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X Server v10.5.5<br /><br />Impact: Multiple vulnerabilities in PHP 4.4.8<br /><br />Description: PHP is updated to version 4.4.9 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution. Further information is available via the PHP website at http://www.php.net/ These issues only affect systems running Mac OS X v10.4.x, Mac OS X Server v10.4.x, or Mac OS X Server v10.5.x.<br /><br /><ul><li>Postfix</li></ul><br />CVE-ID: CVE-2008-3646<br /><br />Available for: Mac OS X v10.5.5<br /><br />Impact: A remote attacker may be able to send mail directly to local users<br /><br />Description: An issue exists in the Postfix configuration files. For a period of one minute after a local command-line tool sends mail, postfix is accessible from the network. During this time, a remote entity who could connect to the SMTP port may send mail to local users and otherwise use the SMTP protocol. This issue does not cause the system to be an open mail relay. This issue is addressed by modifying the Postfix configuration to prevent SMTP connections from remote machines. This issue does not affect systems prior to Mac OS X v10.5 and does not affect Mac OS X Server. Credit to Pelle Johansson for reporting this issue.<br /><br /><ul><li>PSNormalizer</li></ul><br />CVE-ID: CVE-2008-3647<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Viewing a maliciously crafted PostScript file may lead to an unexpected application termination or arbitrary code execution<br /><br />Description: A buffer overflow exists in PSNormalizer's handling of the bounding box comment in PostScript files. Viewing a maliciously crafted PostScript file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of PostScript files. Credit: Apple.<br /><br /><ul><li>QuickLook</li></ul><br />CVE-ID: CVE-2008-4211<br /><br />Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Downloading or viewing a maliciously crafted Microsoft Excel file may lead to an unexpected application termination or arbitrary code execution<br /><br />Description: A signedness issue exists in QuickLook's handling of columns in Microsoft Excel files may result in an out-of-bounds memory access. Downloading or viewing a maliciously crafted Microsoft Excel file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of Microsoft Excel files. This issue does not affect systems prior to Mac OS X v10.5. Credit: Apple.<br /><br /><ul><li>rlogin</li></ul><br />CVE-ID: CVE-2008-4212<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Systems that have been manually configured to use rlogin and host.equiv may unexpectedly permit root login<br /><br />Description: The manpage for the configuration file hosts.equiv indicates that entries do not apply to root. However, an implementation issue in rlogind causes these entries to also apply to root. This update addresses the issue by properly disallowing rlogin from the root user if the remote system is in hosts.equiv. The rlogin service is not enabled by default in Mac OS X, and must be manually configured in order to be enabled. Credit to Ralf Meyer for reporting this issue.<br /><br /><ul><li>Script Editor</li></ul><br />CVE-ID: CVE-2008-4214<br /><br />Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: A local user may gain the privileges of another user that is using Script Editor<br /><br />Description: An insecure file operation issue exists in the Script Editor application when opening application scripting dictionaries. A local user can cause the scripting dictionary to be written to an arbitrary path accessible by the user that is running the application. This update addresses the issue by creating the temporary file in a secure location. Credit: Apple.<br /><br /><ul><li>Single Sign-On</li></ul><br />Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: The sso_util command now accepts passwords from a file<br /><br />Description: The sso_util command now accepts passwords from a file named in the SSO_PASSWD_PATH environment variable. This enables automated scripts to use sso_util more securely.<br /><br /><ul><li>Tomcat</li></ul><br />CVE-ID: CVE-2007-6286, CVE-2008-0002, CVE-2008-1232, CVE-2008-1947, CVE-2008-2370, CVE-2008-2938, CVE-2007-5333, CVE-2007-5342, CVE-2007-5461<br /><br />Available for: Mac OS X Server v10.5.5<br /><br />Impact: Multiple vulnerabilities in Tomcat 6.0.14<br /><br />Description: Tomcat on Mac OS X v10.5 systems is updated to version 6.0.18 to address several vulnerabilities, the most serious of which may lead to a cross site scripting attack. These issues only affect Mac OS X Server systems. Further information is available via the Tomcat site at http://tomcat.apache.org/<br /><br /><ul><li>vim</li></ul><br />CVE-ID: CVE-2008-2712, CVE-2008-4101, CVE-2008-2712, CVE-2008-3432, CVE-2008-3294<br /><br />Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5<br /><br />Impact: Multiple vulnerabilities in vim 7.0<br /><br />Description: Multiple vulnerabilities exist in vim 7.0, the most serious of which may lead to arbitrary code execution when working with maliciously crafted files. This update addresses the issues by updating to vim 7.2.0.22. Further information is available via the vim website at http://www.vim.org/<br /><br /><ul><li>Weblog</li></ul><br />CVE-ID: CVE-2008-4215<br /><br />Available for: Mac OS X Server v10.4.11<br /><br />Impact: Access control on weblog postings may not be enforced<br /><br />Description: An unchecked error condition exists in the weblog server. Adding a user with multiple short names to the access control list for a weblog posting may cause the Weblog server to not enforce the access control. This issue is addressed by improving the way access control lists are saved. This issue only affects systems running Mac OS X Server v10.4. Credit: Apple.<br /></div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-7845089346649675939?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-60175069599597544532008-10-05T15:49:00.003-05:002008-10-05T15:52:43.647-05:00ROFL<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_BpBcl5urwoc/SOkpBh8E-0I/AAAAAAAAATg/bdjViH7AGyg/s1600-h/2912236527_229f9762e2_o.jpg"><img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_BpBcl5urwoc/SOkpBh8E-0I/AAAAAAAAATg/bdjViH7AGyg/s320/2912236527_229f9762e2_o.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5253775546571356994" /></a><br />Saw this today, had to post it. Man that's awesome.<div><br /></div><div>BTW -- Star Wars.<br /><br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a></div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-6017506959959754453?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com1tag:blogger.com,1999:blog-10259481.post-4411625710783977982008-10-02T14:31:00.003-05:002008-10-02T14:36:28.472-05:00An actual meeting held via iChatEarlier this week, me and three of my coworkers held a 4-way iChat Video Conference as a meeting. It worked great.<div><br /></div><div>Of course, as bandwidth decreases, the video codec is dynamically reduced, however, the 4 of us had a face to face video/audio chat for over an hour about some code testing. It worked great. I've been using iChat to do one-on-one meetings with one person for a couple years now, however, never had the opportunity to have a call with 4 people. (Never had the bandwidth to sustain it before), and now that I have FiOS... awesome.<br /><br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a></div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-441162571078397798?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com1tag:blogger.com,1999:blog-10259481.post-51038977950259380692008-09-29T21:04:00.002-05:002008-09-29T21:06:58.327-05:00Physical Fitness #2Oh yeah, I ran again. Except this time I got to mile 1, didn't hurt. So I decided to keep going.<br /><br />Got to mile 2, still didn't feel it. Got to Mile 3, still not tired, but I decided not to kill my legs, just in case, and cut it short at 3.25 miles. Felt pretty good, wasn't sore or anything, so good stuff. I'll just keep ramping it up just a little bit every time until I get back up to my comfortable distance.<br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-5103897795025938069?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-19453899414575240402008-09-21T07:33:00.003-05:002008-09-21T07:55:35.324-05:00A tale of Physical FitnessQuick background -- I used to be in the Army. I joined the Army in 1997, and got out in 2003. In the Army we used to have this thing called a PFT, or Physical Fitness Test.<br /><br />One of the events in the PFT was a 2 mile run. I was always pretty good at this event, as I am not a huge guy. My best time in the 2 mile run was 10 minutes 26 seconds. A pretty respectable time. But, that was about 8 years ago. I was pretty good at running and ran several 10k's, 5k's and even a marathon. (Honolulu Marathon 2000)<br /><br />I recently had a friend of mine, who is NOTORIOUS for making outrageous claims, say he could beat me at a marathon. Well, seeing as how this dude weighs about 100 more lbs than me, and is almost a foot taller than me, I KNOW I can beat him. 100 bucks says I can.<br /><br />So I went out yesterday, got me a new pair of running sneakers (which I haven't had in about 5 years -- not even a new pair, but a pair period) and a Nike+ module for my shoe. (You know, one of those things that goes in your shoe and connects to your iPod Nano and tracks your progress)<br /><br />I have to say, that's a pretty cool little thing. Now, please keep in mind that I haven't ran AT ALL in about 5 years. Not even to the mailbox. So this morning I woke up, and ran my first two miles.<br /><br />I'm happy to report that I am still alive. I am also happy to report that I can still pass the 2 mile run on the Army PT test. But I have a long way to go to build up to 26 miles again. (Seeing as how, before the Marathon I ran in 2000, I as 8 years younger and trained by running 10 miles every morning).<br /><br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-1945389941457524040?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com1tag:blogger.com,1999:blog-10259481.post-46338817141155426642008-09-19T11:57:00.003-05:002008-09-19T12:00:30.828-05:00Quicktime/iTunes DoSI've received several emails from readers and reporters asking me if I am going to post anything about this QT/iTunes DoS vulnerability, and my opinion..etc.<br /><br />I think it's a much ado about nothing. Okay, so QT or iTunes stops working. Uh. So? Really. So what. The programs stops. That's it. It's a media app.<br /><br />Call me when this vulnerability is remotely exploitable. THEN i'll be interested.<br /><br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-4633881714115542664?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-17896525688033982852008-09-15T16:50:00.002-05:002008-10-11T16:22:17.242-05:00OSX Update 10.5.5 and Security Update 2008-006Just hitting the streets, as we speak, Apple released OSX update 10.5.5. Built into 10.5.5 is Security Update 2008-006, marking the 6th major security update of the year. So aside from the ton of updates in 10.5.5 for OSX Leopard, check out the below updates included with it.<br /><br />Keep in mind that Security Update is not just for 10.5 (OSX Leopard), being that it is also available for 10.4, Desktop and Server releases.<br /><br />This update releases updates to the following items:<br /><br />ATS -- Apple Type Services -- CVE-2008-2305<br /><br />BIND --<br /><br />10.5 -- Updated to 9.4.2-P2<br /><br />10.4.11 -- Updated to 9.3.5-P2<br /><br />ClamAV -- Antivirus included with OSX Server<br /><br />Updated to version 0.93.3.<br /><br />CVE-2008-1100, CVE-2008-1387, CVE-2008-0314, CVE-2008-1833, CVE-2008-1835, CVE-2008-1836, CVE-2008-1837, CVE-2008-2713, CVE-2008-3215<br /><br />Directory Services x2 -- (Something I found interesting -- Vulnerability reported by the "IT Department of the West Seneca Central School District". Not your usual reporter. Very nice) -- CVE-2008-2329<br /><br />Finder x2 -- CVE-2008-2331, CVE-2008-3613<br /><br />ImageIO x4 -- CVE-2008-2327, CVE-2008-2332, CVE-2008-3608, CVE-2008-1382<br /><br />Kernel -- CVE-2008-3609<br /><br />libresolv -- CVE-2008-1447<br /><br />Login Windows x2 -- CVE-2008-3610, CVE-2008-3611<br /><br />mDNSResolver -- CVE-2008-1447<br /><br />OpenSSH -- CVE-2008-1483, CVE-2008-1657<br /><br />QuickDraw Manager -- CVE-2008-3614<br /><br />Ruby -- CVE-2008-2376<br /><br />SearchKit -- CVE-2008-3616<br /><br />System Configuration -- CVE-2008-2312 (For 10.4.11)<br /><br />System Preferences x2 -- CVE-2008-3617, CVE-2008-3618<br /><br />Time Machine -- CVE-2008-3619<br /><br />VideoConference -- CVE-2008-3621<br /><br />Wiki Server -- CVE-2008-3622<br /><br />So, all in all, quite a few updates here in this one.<br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-1789652568803398285?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-70064495594232062612008-09-12T08:45:00.002-05:002008-09-12T08:49:29.377-05:00iPhone 2.1 actually lists its updates?!<div>Very uncharacteristic for Apple, but the update screen for 2.1 actually lists its updates.</div><div><br /></div><div>Wow.</div><div><br /></div><div><ul><li>Decrease in call set-up failures and call drops</li><li>Significantly improved battery life for most useres</li><li>Dramatically reduced time to backup to iTunes</li><li>Improved email reliability, notably fetching email from POP and exchange accounts.</li><li>Faster installation of 3rd party applications.</li><li>Fixed bugs causing hangs and crashed if you have lots of 3rd party applications</li><li>Improved performance in text messaging</li><li>Faster loading and searching of contacts</li><li>Improved accuracy of the 3G signal strength display</li><li>Repeat alert up to two additional time for incoming text messages</li><li>Option to wipe data after ten failed passcode attempts</li><li>Genius playlist creation.</li></ul></div><div><br /></div><div>Thanks for letting us know all these things Apple, please keep up the straightforwardness in updates!</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-7006449559423206261?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com2tag:blogger.com,1999:blog-10259481.post-6696273226462019512008-09-12T08:44:00.000-05:002008-09-12T08:45:45.912-05:00iPhone 2.1 is out, and here it is<div>iPhone v2.1<br /><ul><li>Application Sandbox</li></ul>CVE-ID: CVE-2008-3631<br /><br />Available for: iPhone v2.0 through v2.0.2<br /><br />Impact: An application may be able to read another application's files<br /><br />Description: The Application Sandbox does not properly enforce access restrictions between third-party applications. This may allow a third-party application to read files in another third-party application's sandbox, and lead to the disclosure of sensitive information. This update addresses the issue by enforcing the proper access restrictions between application sandboxes. Credit to Nicolas Seriot of Sen:te and Bryce Cogswell for reporting this issue. This issue does not affect iPhone versions prior to v2.0.<br /><br /><ul><li>CoreGraphics</li></ul>CVE-ID: CVE-2008-1806, CVE-2008-1807, CVE-2008-1808<br /><br />Available for: iPhone v1.0 through v2.0.2<br /><br />Impact: Multiple vulnerabilities in FreeType v2.3.5<br /><br />Description: Multiple vulnerabilities exist in FreeType v2.3.5, the most serious of which may lead to arbitrary code execution when accessing maliciously crafted font data. This update addresses the issue by incorporating the security fixes from version 2.3.6 of FreeType. Further information is available via the FreeType site at http://www.freetype.org/<br /><br /><ul><li>mDNSResponder</li></ul>CVE-ID: CVE-2008-1447<br /><br />Available for: iPhone v1.0 through v2.0.2<br /><br />Impact: mDNSResponder is susceptible to DNS cache poisoning and may return forged information<br /><br />Description: mDNSResponder provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow a remote attacker to perform DNS cache poisoning attacks. As a result, applications that rely on mDNSResponder for DNS may receive forged information. This update addresses the issue by implementing source port and transaction ID randomization to improve resilience against cache poisoning attacks. Credit to Dan Kaminsky of IOActive for reporting this issue.<br /><br /><ul><li>Networking</li></ul>CVE-ID: CVE-2008-3612<br /><br />Available for: iPhone v2.0 through v2.0.2<br /><br />Impact: Predictable TCP initial sequence numbers generation may lead to TCP spoofing or session hijacking<br /><br />Description: TCP initial sequence numbers are sequentially generated. Predictable initial sequence numbers may allow a remote attacker to create a spoofed TCP connection or insert data into an existing TCP connection. This update addresses the issue by generating random TCP initial sequence numbers. This issue does not affect iPhone versions prior to v2.0.<br /><br /><ul><li>Passcode Lock</li></ul>CVE-ID: CVE-2008-3633<br /><br />Available for: iPhone v2.0 through v2.0.2<br /><br />Impact: An unauthorized user may bypass the Passcode Lock and launch iPhone applications<br /><br />Description: The Passcode Lock feature is designed to prevent applications from being launched unless the correct passcode is entered. An implementation issue in the handling of emergency calls allows users with physical access to an iPhone to launch an application without the passcode by double clicking the home button in emergency call. This update addresses the issue through improved handling of emergency calls. Credit to Matthew Yohe of The University of Iowa's Department of Electrical and Computer Engineering for reporting this issue. This issue does not affect iPhone versions prior to v2.0.<br /><br /><ul><li>WebKit</li></ul>CVE-ID: CVE-2008-3632<br /><br />Available for: iPhone v1.0 through v2.0.2<br /><br />Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution<br /><br />Description: A use-after-free issue exists in WebKit's handling of CSS import statements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of document references.<br /></div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-669627322646201951?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-14739448455231503462008-09-12T07:57:00.003-05:002008-09-12T08:06:16.590-05:00Wow, Um, So hey, how you doing?<div>Haven't Blogged in awhile, I've been working on some other stuff as well over at <a href="http://www.dearcupertino.com">dearcupertino.com</a>.</div><div><br /></div><div>For those of you that haven't seen, here's a bit of mac news, Apple released iTunes 8, a new set of iPod Nano's (going back to the more vertical shape), updated and dropped the price on the iPod Touch, as well as refreshing the iPod Classic line.</div><div><br /></div><div>Basically, for the holiday shopping season. Good stuff.</div><div><br /></div><div>They also released an update to the iPod Touch software (2.1), and it has some nifty features in it (like the Genius feature from iTunes 8.0). Reports are also, that it is faster. The iPhone update 2.1 is supposed to hit today, so I might blog again with some updates about that.</div><div><br /></div><div>Otherwise, for those who know me, and know that i have been on a single customer site for the past year+, I have 12 days left (including weekends.)</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-1473944845523150346?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-68584696226572555272008-08-29T12:47:00.003-05:002008-08-29T12:59:12.431-05:00CRC Error Episode 2 Posted<div>Right after we got done recording the serious podcast (ISC Podcast from my previous post), I switched gears and Podcasters to do Episode 2 of the <a href="http://www.crcerror.net">CRCError</a> Podcast.</div><div><br /></div><div>As before, this podcast is not for the feint of heart, it is Not safe for work, or children, or pretty much anyone else. Don't listen to it if you get offended, don't like swear words, or pretty much anything that may damage your psyche. </div><div><br /></div><div>The podcast is meant to be funny. And it is!</div><div><br /></div><div>iTunes subscribers, please go here to <a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=288704245">subscribe</a>.</div><div>Non iTunes users, go <a href="http://crcerror.net/Blog/Podcast/rss.xml">here</a>.</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-6858469622657255527?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-84278817225052335302008-08-29T12:43:00.002-05:002008-08-29T12:47:52.574-05:00Internet Storm Center Podcast Episode 10 postedJust a quick note to let everyone know that we put out Podcast Episode 10.<br /><br />iTunes users, go here to <a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=276609412">subscribe</a>.<br />Non-iTunes users, go here to <a href="http://isc.sans.org/mp3s/20080826.mp3">download</a>.<br /><br />As always we are looking for listener feedback, be sure and write in!<br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-8427881722505233530?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-1491250465765355042008-08-28T09:38:00.001-05:002008-08-28T09:39:53.009-05:00Mac Tablet Patents surface -- i want.<div>Appleinsider has a great post today about some interface patents that have been uncovered from Apple detailing how a tablet Mac would work. Very short blog post from me, cause I want you to go read <a href="http://www.appleinsider.com/articles/08/08/28/apple_details_next_gen_multi_touch_techniques_for_tablet_macs.html">theirs</a>.</div><div><br /></div><div>I could think of about 30 uses I would have for something like this.</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-149125046576535504?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com1tag:blogger.com,1999:blog-10259481.post-22309200683722072032008-08-25T22:19:00.002-05:002008-08-25T22:21:57.120-05:00Google Calendar goes CalDAVOkay, so in Apple fashion (read: Not Google fashion) Google Calendar rolled out a new feature of it's product. The ability to use your iCal (or other CalDAV supported Calendar) to use Google Calendar.<br /><br />Finally, two way sync for Google Calendar with iCal! And it's not really even a "sync". When you put events on Google Calendar in your iCal, you are actually putting the events on the Google Calendar ITSELF.<br /><br />It's syncs instantly. Anyway, for more information hit up <a href="http://www.google.com/support/calendar/bin/answer.py?answer=99358">this link</a>, and let's all give a hand for Google for helping us out!<br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-2230920068372207203?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-5777255957676491032008-08-25T22:05:00.001-05:002008-08-25T22:05:44.992-05:00Podcast Episode X Record NoticeTomorrow night at 7:30 EDT (Eastern Daylight Savings Time) Johannes, John, and I will be recording Episode X of the Internet Storm Center Podcast.<br /><br />We'll be broadcasting live at <a href="http://www.stickam.com/joelesler">http://www.stickam.com/joelesler</a><br /><br />Please come and join! We love live feedback, talk with us in the stickam interface or via IRC in #dshield on irc.freenode.net.<br /><br />Thanks!<br /><br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-577725595767649103?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-69130638492981449082008-08-24T13:51:00.003-05:002008-08-24T13:54:38.606-05:00This just in, someone steals another Apple ideaOkay, so could someone please rip Apple off? I mean, it hasn't been done in a couple days. Watch <a href="http://gizmodo.com/5041048/blackberry-bold-unboxed-with-barely+controlled-enthusiasm">this video</a>. Blackberry Bold unboxing. Tell me that's not almost the exact design of how the iPhone unboxing is? Please.<br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-6913063849298144908?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-48579837271594708352008-08-24T13:28:00.004-05:002008-08-24T13:35:36.291-05:00Spam funMy name is Sgt Jeff <span class="blsp-spelling-error" id="SPELLING_ERROR_0">Frawley</span> I am an American soldier in peace keeping force in Iraq,<br /><br /><span style="font-style: italic;">No you're not.</span><br /><br />I am serving in the military of the 1st Armored Division in Iraq, as you know insurgents everyday and car bombs are attacking us.<br /><br /><span style="font-style: italic;">You mean insurgents and car bombs are attacking us everyday? Do they teach grammar anymore?</span><br /><br />We managed to move funds belonging to Saddam Hussein's family.<br /><br /><span style="font-style: italic;">No, you didn't.</span><br /><br />The total amount is US$ 12 Million dollars in cash. We want to move this money to you, so that you may keep our share for us till when we will come over to meet you.<br /><br /><span style="font-style: italic;">No, you don't. You didn't find the money, you wouldn't just email someone out of the blue, you'd try and smuggle that stuff in your pants. Besides, sew it into the spaces in your ruck sack. Come on, get inventive.</span><br /><br />We will take 60%, my partner and I.You take 40%.<br /><br /><span style="font-style: italic;">Actually, if I am moving your money, I'll take 90, you take 10. How about that? Since I am pretty much taking all the risk, I'll take the majority of the money. And since you pretty much have no alternatives because you are apparently stupid and just email me out of the blue on the <span class="blsp-spelling-corrected" id="SPELLING_ERROR_1">Internet</span>, you have no alternatives!</span><br /><br />No strings attached, just help us move it out of Iraq, Iraq is a war zone.<br /><br /><span style="font-style: italic;">No kidding? I thought it was the McDonald's Play area.</span><br /><br />We plan on using diplomatic courier and shipping the money out in two large boxes, using diplomatic immunity.<br /><br /><span style="font-style: italic;">So what do you need me for?</span><br /><br /><br />If you are interested I will send you the full details, my job is to find a good partner that we can trust and that will assist us. Can I trust you?<br /><br /><span style="font-style: italic;">Sure, if your terms are in line with mine, above. 90-10.</span><br /><br />If you are capable of handling this with me, kindly send me an e-mail signifying your interest including your most confidential telephone/fax numbers for quick communication also your contact details. This business is risk free the boxes can be shipped out in 48hrs.<br /><br /><span style="font-style: italic;">My "Most" confidential telephone and fax numbers? Really? Is there such a thing? (oh yeah, because the NSA isn't monitoring communications...</span><br /><br /><span style="font-weight: bold; font-style: italic;">BTW -- don't believe scams like this. Come on! You KNOW this is false, and I know you probably are reading my website because you Googled this same email if you got it. Don't fall victim to this kind of thing, of course it's fake!</span><br /><br /><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="border: 0pt none ; vertical-align: middle;" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-4857983727159470835?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0tag:blogger.com,1999:blog-10259481.post-73842737510528195272008-08-23T08:29:00.002-05:002008-08-23T08:31:44.196-05:00VRT challenge<div>The guys and girls over in the VRT (Vulnerability Research Team) at Sourcefire want to give you a challenge. Read this post <a href="http://www.snort.org/pub-bin/snortnews.cgi#800">over here</a>, and get your reverse engineering skills up to par. Have fun!</div><div><br /></div><a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml"><img src="http://www.feedburner.com/fb/images/pub/feed-icon16x16.png" alt="" style="vertical-align:middle;border:0" /></a> <a href="http://feeds.feedburner.com/RandomThoughtsFromJoelsWorld" rel="alternate" type="application/rss+xml">Subscribe in a reader</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10259481-7384273751052819527?l=blog.joelesler.net'/></div>Joel Eslerhttp://www.blogger.com/profile/05018134738510159518noreply@blogger.com0