星期二, 4月 19, 2011

MC_topic10.pdf

MULTIPLE CHOICE. Choose the one alternative that best completes the statement or answers the question.

1) Which statement below regarding the development of an AIS is false?
A) A newly designed AIS always meets user needs for a time period.
B) Changes to the AIS are often difficult to make after requirements have been frozen into specifications.
C) Users are unable to specify their needs adequately.
D) The development process can take so long that the system no longer meets company needs.

2) In which approach to systems acquisition is "inexpensive updates" considered an advantage?
A) turnkey software and systems
B) custom software
C) canned software
D) modified software

3) When canned software is used for systems acquisition, the conceptual design phase of the SDLC
A) is the same.
B) involves a make-or-buy decision.
C) is combined with the physical design phase.
D) is eliminated.

4) When canned software is used for systems acquisition, the physical design phase of the SDLC
A) is the same.
B) is eliminated.
C) is combined with the conceptual design phase.
D) does not involve designing and coding although modifications may be made.

5) When canned software is used for systems acquisition, the implementation and conversion phase of the SDLC
A) does not involve the documentation step.
B) does not require the develop and test software step.
C) does not require the company to have trained IS personnel.
D) both A and C above

6) When canned software is used for systems acquisition, the maintenance aspect of the operations and maintenance phase of the SDLC
A) is not necessary and is eliminated.
B) is usually the responsibility of the vendor.
C) is more costly.
D) requires trained personnel.

7) Software development companies write commercial software that can be used by a variety of organizations. Sometimes these companies combine both software and hardware together to sell as one package. Such a package is commonly referred to as
A) an application service package.
B) canned software.
C) a value-added system.
D) a turnkey system.

8) What is a major problem with "canned software"?
A) Canned software is sold on the open market to a broad range of users with similar requirements.
B) Canned software may not meet all of a company's information or data processing needs.
C) Canned software may offer easy availability and lower costs.
D) A commercial software development company has developed it.

9) Which statement is true regarding canned software and the SDLC?
A) Canned software cannot be modified to meet unique user needs.
B) The SDLC process does not apply to canned software.
C) Most canned software meets all of a company's information or data processing needs.
D) Companies that buy rather than develop AIS software can still follow the SDLC process.

10) The reasons for ________ are to simplify the decision-making process, reduce errors, provide timesavings, and avoid potential disagreements.
A) leasing
B) outsourcing
C) sending out a request for a proposal
D) prototyping

11) Total costs are usually lower and less time is required for vendor preparation and company evaluation when requests for proposal are solicited based on
A) generalized software needs.
B) specific hardware and software specifications.
C) exact equipment needs.
D) None of the above are correct.

12) Information given to vendors should include
A) timeframe required for completion of the project.
B) detailed specifications for the AIS.
C) a budget for software and hardware.
D) None of the above are correct.

13) The approach that evaluates vendors' systems based on the weighted score of criteria and points totaled is called
A) requirements costing.
B) prototyping.
C) benchmark problem.
D) point scoring.

14) The approaches to evaluating proposals that do not incorporate dollar estimates of costs and benefits is known as
A) requirement costing and point scoring.
B) benchmark problem and point scoring.
C) All methods mentioned above include dollar estimates.
D) point scoring and requirement costing.

15) It is important for a company to be selective in choosing a software vendor. When a company buys a large or complex system, it may request that a software vendor submit a specific proposal for a system by a specified date. What acronym is used to identify such a request?
A) EIS
B) ISP
C) ASP
D) RFP

16) A request for proposal sent to software vendors is an important tool since it can reduce errors.
Which statement below supports this reason?
A) All responses are in the same format and based on the same information.
B) The same information is provided to all vendors.
C) The chances of overlooking important factors are reduced.
D) Both parties possess the same expectations and pertinent information is captured in writing.

17) A company should carefully evaluate proposals submitted by software vendors. What is the first step a company should take in the proposal evaluation process?
A) Carefully compare proposals against the proposed AIS requirements.
B) Invite vendors to demonstrate their systems.
C) Eliminate proposals that are missing important information or fail to meet minimum requirements.
D) Determine how much of a given proposal meets the desired AIS requirements.

18) Among the methods a company can use to help it evaluate software and hardware systems from vendors, one way is to calculate and compare the processing times of different AIS to compare system performance. This is the ________ method.
A) mandatory requirements
B) requirements costing
C) benchmark problem
D) point scoring

19) What is a drawback to using the requirements costing method of software and hardware evaluation?
A) The weights and points used are assigned subjectively.
B) Intangible factors such as reliability and vendor support are overlooked.
C) There is no drawback to using the requirements costing method.
D) Dollar estimates of costs and benefits are not included.

20) The costly and labor-intensive approach to systems acquisition is
A) modified software.
B) custom software.
C) canned software.
D) turnkey software.


Answer Key
1) A
2) C
3) B
4) D
5) D
6) B
7) D
8) B
9) D
10) C
11) B
12) B
13) D
14) D
15) D
16) C
17) C
18) C
19) B
20) B

星期一, 4月 18, 2011

Further Update (A11-04-01a): Vulnerability in Adobe Flash Player and Adobe Reader/Acrobat

Further to the security alert A11-04-01 issued on 12.04.2011, we would like to draw your attention that Adobe has released updated versions of Adobe Flash Player for the platforms below to address the issue. However, related patches for Adobe Reader and Adobe Acrobat are still pending. The respective updates are available at:
- Flash Player 10.2.159.1 for Windows, Macintosh, Linux and Solaris
  • http://www.adobe.com/go/getflash
- Flash Player 10.2.159.1 - network distribution
  • http://www.adobe.com/licensing/distribution
- Flash Player 10.2.154.27 for Chrome

  • http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html
If you have multiple browsers, you are required to perform the upgrade for each browser.
To verify the Flash player version installed, you may visit the following URL:
  • http://www.adobe.com/products/flash/about/
Currently, the patch for Flash Player for Android and the patches for Adobe Reader and Acrobat are not yet available for download. Affected users should keep abreast of the vendor's web site for the availability of new versions of the affected software.
Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
DITSOs (or your delegates) are also requested to inform the relevant system administrators and end users as appropriate about this issue.
More Information:
More information about this update is available at:
  • http://www.adobe.com/support/security/advisories/apsa11-02.html
  • http://www.adobe.com/support/security/bulletins/apsb11-07.html
  • http://www.us-cert.gov/current/index.html#adobe_releases_security_advisory_for7
  • http://www.kb.cert.org/vuls/id/230057
  • http://secunia.com/advisories/44119/
  • http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0611

星期四, 4月 14, 2011

Microsoft Windows XP 變數

有時編寫執行檔時,可能會因為使用者名稱不同而不能執行成功。
假若遇到這個情況,系統變數便可以簡化問題了。
以下是 Ms Windows XP  Windows 7 的例子:


變數
Win XP 例子
Win 7例子
%LOGONSERVER%
\\127.0.0.1
\\127.0.0.1
%HOMEDRIVE%
C:\
C:\
%SystemDrive%
C:\
C:\
%AllUsersProfile%
C:\Documents and Settings\All Users
C:\ProgramData
%HOMEPATH%
C:\Documents and Settings\wfh
C:\Users\wfh
%USERPROFILE%
C:\Documents and Settings\wfh
C:\Users\wfh
%APPDATA%
C:\Documents and Settings\wfh\Application Data
C:\Users\wfh\AppData\Roaming
%Temp%
C:\Documents and Settings\wfh\Local Settings\Temp
C:\Users\Ben\AppData\Local\Temp
%Tmp%
C:\Documents and Settings\wfh\Local Settings\Temp
C:\Users\Ben\AppData\Local\Temp
%USERPROFILE%\My Documents\
C:\Documents and Settings\wfh\My Documents\
%ProgramFiles%
C:\Program Files
C:\Program Files
%commonprogramfiles%
C:\Program Files\Common Files
C:\Program Files\Common Files
%SystemRoot%
C:\WINDOWS
C:\Windows
%windir%
C:\WINDOWS
C:\Windows
%ComSpec%
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
%PSModulePath%
C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules
C:\Windows\system32\WindowsPowerShell\v1.0\Modules

===========================


batch file 應用例子:

@echo off
:: 設定變數 drive G:\Backup
set drive=G:\Backup
 :: 設定變數 backupcmd xcopy /s /c /d /e /h /i /r /y
set backupcmd=xcopy /s /c /d /e /h /i /r /y

echo 備份我的文件至 G:\Backup\My Documents ...
%backupcmd% "%USERPROFILE%\My Documents" "%drive%\My Documents"

echo 備份我的最愛至 G:\Backup\Favorites...
%backupcmd% "%USERPROFILE%\Favorites" "%drive%\Favorites"

echo 備份 Outlook Express...
%backupcmd% "%USERPROFILE%\Application Data\Microsoft\Address Book" "%drive%\Address Book"
%backupcmd% "%USERPROFILE%\Local Settings\Application Data\Identities" "%drive%\Outlook Express"

echo 備份 Ms Outlook...
%backupcmd% "%USERPROFILE%\Local Settings\Application Data\Microsoft\Outlook" "%drive%\Outlook"

echo 備份登錄檔...
if not exist "%drive%\Registry" mkdir "%drive%\Registry"
if exist "%drive%\Registry\regbackup.reg" del "%drive%\Registry\regbackup.reg"
regedit /e "%drive%\Registry\regbackup.reg"

:: use below syntax to backup other directories...
:: %backupcmd% "...source directory..." "%drive%\...destination dir..."

echo 備份完成
pause

試想像,假若目標使用者的視窗安裝在 D:\ ,而且你不知道對方的使用者名稱,在不使用變數的情況下便十分麻煩了。

===========================

如果希望新增 / 修改 Win xp 的變數,你可以:

1. 在「我的電腦」的空白位置單擊右鍵,然後點選「內容」

2. 在「系統內容」的「進階」分頁,點選「環境變數」

3. 在下方的「系統變數」,你可以找到 「TMP」 等大部份變數了

===========================
如果希望新增 / 修改 Win 7 的變數,你可以:

1. 在「我的電腦」的空白位置單擊右鍵,然後點選「內容」


2. 點選「進階系統設定」

3. 在「系統內容」的「進階」分頁,點選「環境變數」


4. 在下方的「系統變數」,你可以找到 「TMP」 等大部份變數了


星期三, 4月 13, 2011

Security Alert (A11-04-02): Multiple Vulnerabilities in Microsoft Products (April 2011)

Affected Systems:
Various versions of the following Microsoft products are affected:
  • Microsoft .NET Framework
  • Microsoft C++ 2005, 2008, 2010
  • Microsoft Internet Explorer 6, 7, 8
  • Microsoft Office XP, 2003, 2007, 2010
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
  • Microsoft Office Excel Viewer, PowerPoint Viewer and Web Apps
  • Microsoft Office 2004, 2008, 2011 for Mac
  • Open XML File Format Converter for Mac
  • Microsoft Visual Studio .NET 2003, 2005, 2008, 2010
  • Microsoft Windows XP, Vista, 7
  • Microsoft Windows Server 2003, 2008
A complete list of the affected products can be found in the section "Affected Software and Download Locations" in the Microsoft security bulletin summary available at:
  • http://www.microsoft.com/technet/security/bulletin/ms11-apr.mspx
Summary:
Microsoft has released 17 security bulletins listed below addressing 64 vulnerabilities which affect several Microsoft products or components:
  • MS11-018 Cumulative Security Update for Internet Explorer
  • MS11-019 Vulnerabilities in SMB Client Could Allow Remote Code Execution
  • MS11-020 Vulnerability in SMB Server Could Allow Remote Code Execution
  • MS11-021 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
  • MS11-022 Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution
  • MS11-023 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
  • MS11-024 Vulnerability in Windows Fax Cover Page Editor Could Allow Remote Code Execution
  • MS11-025 Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution
  • MS11-026 Vulnerability in MHTML Could Allow Information Disclosure
  • MS11-027 Cumulative Security Update of ActiveX Kill Bits
  • MS11-028 Vulnerability in .NET Framework Could Allow Remote Code Execution
  • MS11-029 Vulnerability in GDI+ Could Allow Remote Code Execution
  • MS11-030 Vulnerability in DNS Resolution Could Allow Remote Code Execution
  • MS11-031 Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution
  • MS11-032 Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution
  • MS11-033 Vulnerability in WordPad Text Converters Could Allow Remote Code Execution
  • MS11-034 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege
To successfully exploit the vulnerabilities, an attacker could entice a targeted user to open a specially crafted webpage, Excel/PowerPoint/Office/WordPad file, image file, content rendered in OpenType CFF font or fax cover page file (.cov). The attacker could also send specially crafted SMB packet or LLMNR broadcast queries in DNS resolution to an affected system, or entice user to initiate an SMB connection to a specially crafted SMB server.
Moreover, there are also vulnerabilities in the MHTML protocol handler, Microsoft Foundation Class (MFC) libraries, Microsoft .NET framework, JScript and VBScript scripting engines, and kernel-mode drivers in various Windows applications.
We would like to update you that patches for the security bulletin MS11-026 fixed the vulnerability described in the security alert A11-01-05 for MHTML protocol handler in Microsoft Windows. For details of the alert, please visit our IT Security Theme page at:

  • http://itginfo.ccgo.hksarg/content/itsecure/secalert/2011/A11-01-05.htm

  • Impact:
    Depending on the vulnerability exploited, a successful attack could lead to elevation of privilege or remote arbitrary code execution.
    Recommendation:
    Patches for affected products are available from the Microsoft Update website. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
    Microsoft Update

    • http://update.microsoft.com/microsoftupdate
    If any problem is encountered during the patch installation via automated methods, patches for various affected systems can also be downloaded individually from the "Affected and Non-Affected Software" section of the corresponding Microsoft Security Bulletins which can be accessed from the URL(s) listed in the "More Information" section of this Security Alert.
    DITSOs (or your delegates) are also requested to inform the relevant system administrators and end users as appropriate about this issue.
    More Information:
    More information about this issue is available at:
    • http://www.microsoft.com/technet/security/bulletin/ms11-apr.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-018.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-019.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-020.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-021.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-022.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-023.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-024.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-025.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-026.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-027.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-028.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-029.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-030.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-031.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-032.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-033.mspx
    • http://www.microsoft.com/technet/security/bulletin/MS11-034.mspx
    • http://www.microsoft.com/technet/security/advisory/2269637.mspx
    • http://www.microsoft.com/technet/security/advisory/2501696.mspx
    • http://www.us-cert.gov/cas/techalerts/TA11-102A.html
    • https://www.hkcert.org/my_url/en/alert/11041305
    • https://www.hkcert.org/my_url/en/alert/11041306
    • https://www.hkcert.org/my_url/en/alert/11041307
    • https://www.hkcert.org/my_url/en/alert/11041308
    • https://www.hkcert.org/my_url/en/alert/11041309
    • https://www.hkcert.org/my_url/en/alert/11041310
    • https://www.hkcert.org/my_url/en/alert/11041311
    • https://www.hkcert.org/my_url/en/alert/11041312
    • https://www.hkcert.org/my_url/en/alert/11041313
    • https://www.hkcert.org/my_url/en/alert/11041314
    • https://www.hkcert.org/my_url/en/alert/11041315
    • https://www.hkcert.org/my_url/en/alert/11041316
    • https://www.hkcert.org/my_url/en/alert/11041317
    • https://www.hkcert.org/my_url/en/alert/11041318
    • https://www.hkcert.org/my_url/en/alert/11041319
    • https://www.hkcert.org/my_url/en/alert/11041320
    • https://www.hkcert.org/my_url/en/alert/11041321
    • http://xforce.iss.net/xforce/xfdb/64908
    • http://xforce.iss.net/xforce/xfdb/66411
    • http://xforce.iss.net/xforce/xfdb/66415
    • http://xforce.iss.net/xforce/xfdb/66418
    • http://xforce.iss.net/xforce/xfdb/66422
    • http://xforce.iss.net/xforce/xfdb/66426
    • http://xforce.iss.net/xforce/xfdb/66427
    • http://xforce.iss.net/xforce/xfdb/66431
    • http://www.vupen.com/english/advisories/2011/0937
    • http://www.vupen.com/english/advisories/2011/0938
    • http://www.vupen.com/english/advisories/2011/0939
    • http://www.vupen.com/english/advisories/2011/0940
    • http://www.vupen.com/english/advisories/2011/0941
    • http://www.vupen.com/english/advisories/2011/0942
    • http://www.vupen.com/english/advisories/2011/0943
    • http://www.vupen.com/english/advisories/2011/0944
    • http://www.vupen.com/english/advisories/2011/0945
    • http://www.vupen.com/english/advisories/2011/0946
    • http://www.vupen.com/english/advisories/2011/0947
    • http://www.vupen.com/english/advisories/2011/0948
    • http://www.vupen.com/english/advisories/2011/0949
    • http://www.vupen.com/english/advisories/2011/0950
    • http://www.vupen.com/english/advisories/2011/0951
    • http://www.vupen.com/english/advisories/2011/0952
    • http://secunia.com/advisories/39122/
    • http://secunia.com/advisories/39903/
    • http://secunia.com/advisories/41387/
    • http://secunia.com/advisories/43836/
    • http://secunia.com/advisories/44015/
    • http://secunia.com/advisories/44072/
    • http://secunia.com/advisories/44153/
    • http://secunia.com/advisories/44155/
    • http://secunia.com/advisories/44156/
    • http://secunia.com/advisories/44159/
    • http://secunia.com/advisories/44160/
    • http://secunia.com/advisories/44161/
    • http://secunia.com/advisories/44162/
    • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=900
    • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=901
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0811
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3190
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3958
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3973
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3974
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0028
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0034
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0041
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0094
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0096
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0097
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0098
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0101
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0103
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0104
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0105
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0107
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0346
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0654
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0655
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0656
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0657
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0660
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0661
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0662
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0663
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0665
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0666
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0667
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0670
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0671
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0672
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0673
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0674
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0675
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0676
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0677
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0976
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0977
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0978
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0979
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0980
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1225
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1226
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1227
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1228
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1229
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1230
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1231
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1232
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1233
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1234
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1235
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1236
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1237
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1238
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1239
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1240
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1241
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1242
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1243
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1244
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1245
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1345

    Security Alert (A11-04-03): Vulnerabilities in RealPlayer

    Affected Systems:
    • RealPlayer 14.0.2 and prior
    Summary:
    Vulnerabilities have been identified in RealPlayer, one is due to a heap-based buffer overflow caused by improper bounds checking in the RealVideo Renderer plugin for RealMedia (rvrender.dll) when processing Internet Video Recording (IVR) files. Another vulnerability is due to a flaw in the OpenURLInDefaultBrowser() method when processing RNX (".rnx") file. There are multiple attack vectors, a remote attacker may entice a user to open a specially crafted file or web page with malicious content.
    Impact:
    Depending on the vulnerabilities exploited, a successful attack could lead to remote arbitrary code execution.
    Recommendation:
    The product vendor has released the following updated player to address the issues.
    • RealPlayer 14.0.3
    Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk. The update can be obtained by clicking "Check for Update" in the "Help->About RealPlayer" menu, or manually downloaded at the following URL:
    • http://hk.real.com/?mode=rp
    DITSOs (or your delegates) are also requested to inform the relevant system administrators and end users as appropriate about this issue.
    More Information:
    More information about this issue is available at:
    • http://service.real.com/realplayer/security/04122011_player/en/
    • http://xforce.iss.net/xforce/xfdb/66209
    • http://secunia.com/advisories/43847
    • http://www.vupen.com/english/advisories/2011/0723
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1426
    • http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1525

    星期二, 4月 12, 2011

    Security Alert (A11-04-01): Vulnerability in Adobe Flash Player and Adobe Reader/Acrobat

    Affected Systems:
    • Adobe Flash Player 10.2.153.1 and earlier versions for Windows, Macintosh, Linux and Solaris
    • Adobe Flash Player 10.2.154.25 and earlier for Chrome users
    • Adobe Flash Player 10.2.156.12 and earlier for Android
    • Adobe Reader X(10.0.2), Reader 9.x and earlier versions for Windows and Macintosh
    • Adobe Acrobat X(10.0.2), Acrobat 9.x and earlier versions for Windows and Macintosh
    Summary:
    A vulnerability is found in the Adobe Flash Player and the "authplay.dll" component that ships with Adobe Reader and Acrobat, which could cause a crash and potentially allow an attacker to take control of the system. To successfully exploit the vulnerability, a remote attacker could entice a targeted user to open a malicious website with Flash content, or a specially crafted Flash (.swf) embedded in a Microsoft Word (.doc) file or other Microsoft Office document and delivered as an email attachment.
    Reports indicate that the vulnerability is being actively exploited in the wild.
    Impact:
    Successful exploitation could allow a remote attacker to execute arbitrary code and taking complete control of an affected system.
    Recommendation:
    Currently, patches for the vulnerability are still pending from the product vendor. Since the vulnerability could be exploited by simply viewing a malicious website without user interaction, as an interim measure as well as security best practices, users are reminded not to visit suspicious websites, open PDF file and Microsoft Office documents from doubtful origins, nor follow URL links from un-trusted sources or emails such as spam, and to keep the virus signature as well as detection and repair engine up-to-date.
    To verify the Flash player version installed, you may visit the following URL:
    • http://www.adobe.com/products/flash/about/
    We shall update you once the patches are available and on the latest development of the issue in due course.
    More Information:
    More information about this issue is available at:
    • http://www.adobe.com/support/security/advisories/apsa11-02.html
    • http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0611

    星期五, 4月 08, 2011

    Default boot.ini for Microsoft Windows XP

    Directory boot.ini of Ms Win XP: C:\
    Path of boot.ini: C:\boot.ini

    Original setting of boot.ini:

    [boot loader]
    timeout=30
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

    推薦此文