<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Andrew Berges at myITforum.com&lt;br /&gt;</title><link>http://myitforum.com/cs2/blogs/aberges/default.aspx</link><description>Antivirus, Malware, SMS 2003, and assorted musings from a self-confessed IT geek.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/aberges" type="application/rss+xml" /><item><title>Links for 2009-07-07 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/3-zuym0QrN4/aberges</link><pubDate>Wed, 08 Jul 2009 00:00:00 PDT</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-07-07</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://iase.disa.mil/stigs/checklist/"&gt;IASE -DISA - Security Checklists&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/3-zuym0QrN4" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-07-07</feedburner:origLink></item><item><title>Links for 2009-07-01 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/rr3Am_ckfd8/aberges</link><pubDate>Thu, 02 Jul 2009 00:00:00 PDT</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-07-01</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.delltechcenter.com/page/Dell+Business+Client+Operating+System+Deployment+-+The+.CAB+Files"&gt;Dell Business Client Operating System Deployment - The .CAB Files - The Dell TechCenter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/rr3Am_ckfd8" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-07-01</feedburner:origLink></item><item><title>Links for 2009-05-19 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/pZytSu-tcMg/aberges</link><pubDate>Wed, 20 May 2009 00:00:00 PDT</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-05-19</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/erikr/archive/2007/08/29/A-Guide-to-Network-Monitor-3.1.aspx"&gt;A Guide to Network Monitor 3.1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/pZytSu-tcMg" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-05-19</feedburner:origLink></item><item><title>Links for 2009-04-24 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/ziOktTs2SIo/aberges</link><pubDate>Sat, 25 Apr 2009 00:00:00 PDT</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-04-24</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://myitforum.com/cs2/blogs/jsandys/archive/2009/04/24/osdappchooser-2-0-1-beta.aspx"&gt;OSDAppChooser 2.0.1 Beta - I Have a Blog, And I Must Scream&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/ziOktTs2SIo" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-04-24</feedburner:origLink></item><item><title>Links for 2009-03-19 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/JmNM1jXvTrs/aberges</link><pubDate>Fri, 20 Mar 2009 00:00:00 PDT</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-03-19</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blog.coretech.dk/confmgr07/tips-and-tricks/speed-up-performance-on-the-config-mgr-2007-mmc-console/"&gt;Speed up performance on the Config Mgr. 2007 MMC console | Coretech Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://support.microsoft.com/kb/832017/"&gt;Service overview and network port requirements for the Windows Server system&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/JmNM1jXvTrs" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-03-19</feedburner:origLink></item><item><title>Links for 2009-03-04 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/LKeOPvjeqes/aberges</link><pubDate>Thu, 05 Mar 2009 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-03-04</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb735865.aspx"&gt;Troubleshooting Software Distribution Using Custom Error Codes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/LKeOPvjeqes" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-03-04</feedburner:origLink></item><item><title>Links for 2009-03-03 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/RYT5Bc0FfIc/aberges</link><pubDate>Wed, 04 Mar 2009 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2009-03-03</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb932203.aspx"&gt;State Messages in Configuration Manager 2007&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/RYT5Bc0FfIc" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2009-03-03</feedburner:origLink></item><item><title>McAfee Agent 4.0 Patch 1 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/234VcGRhXl4/mcafee-agent-4-0-patch-1-released.aspx</link><pubDate>Wed, 17 Dec 2008 17:06:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:125397</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=125397</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-agent-4-0-patch-1-released.aspx#comments</comments><description>&lt;p&gt;&lt;a href="https://mysupport.mcafee.com" target="_blank"&gt;Download&lt;/a&gt; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB53808" target="_blank"&gt;McAfee KB&lt;/a&gt; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Resolved issues&lt;/i&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Issues that are resolved in this release are listed below. &lt;/p&gt;&lt;ol&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An update dialog box appeared in English rather than the non-English language running on the system. (Reference: 389523) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Update dialog boxes now appear in the language running on the system. &lt;/p&gt;&lt;ol start="2"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When using the �??/forceinstall�?? switch and only changing the data (/datadir=&amp;lt;new folder&amp;gt;) folder, the upgrade process did not remove the old data folder and used the new folder. (Reference: 393182) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now when using the �??/forceinstall�?? switch and changing the data (/datadir=&amp;lt;new folder&amp;gt;) folder, the upgrade process removes the old data folder and uses the new folder. &lt;/p&gt;&lt;ol start="3"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When the AgentEvents folder was missing, the upgrade process failed. (Reference: 393764) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now the upgrade process creates the AgentEvents folder when it is missing. &lt;/p&gt;&lt;ol start="4"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Managed product installation routines were executed each time a deployment task ran on systems that used a language other than English. (Reference: 399232) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Managed product installation routines now execute only when necessary. &lt;/p&gt;&lt;ol start="5"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; If the installation or data folder contained a double-byte character, the upgrade process failed. (Reference: 404111) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now the installation and data folders can contain non-English characters. &lt;/p&gt;&lt;ol start="6"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When executing the VirusScan update process (mcupdate.exe) with the �??/update�?? and �??/quiet�?? switches, an upgrade dialog box would still be displayed. (Reference: 405004) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The VirusScan update process now honors the �??/quiet�?? switch. &lt;/p&gt;&lt;ol start="7"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The upgrade process was checking for the existence of the �??My Favorites�?? and �??Fonts�?? folders. If they were not present, the upgrade failed. (Reference: 405314) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The upgrade process no longer requires the �??My Favorites�?? and �??Fonts�?? folders to be present. &lt;/p&gt;&lt;ol start="8"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When an error occurred during Host Intrusion Prevention policy enforcement, the system could be �??locked out of the network�??. (Reference: 406896) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now the ePolicy Orchestrator server connection information (server IP, name and port, and incoming agent wake-up port) is recorded. This allows Host Intrusion Prevention to create specific rules that allow communication to and from the ePolicy Orchestrator server, even in the absence of Host IPS policies. &lt;/p&gt;&lt;ol start="9"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The name of the ePO server the system last communicated with appears in the XML log file. The value is initially blank and remained blank for a period of time after the first communication. (Reference: 407154) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The name of the ePO server the system last communicated with now appears immediately after the last server communication. &lt;/p&gt;&lt;ol start="10"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The McAfee Agent deployed managed products to Microsoft Vista or Windows Server 2008 that were not supported on these platforms. (Reference: 408989) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Managed products are now deployed only to their supported platforms. &lt;/p&gt;&lt;ol start="11"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The Mirror task created a duplicate repository, but it failed to copy the sitestat.xml file. This caused the duplicate repository to remain disabled. (Reference: 409637) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The Mirror task now copies the sitestat.xml file to the duplicated repository. &lt;/p&gt;&lt;ol start="12"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; During a managed product update, a dialog box could be presented requesting a system reboot. The dialog box asked the user if they wanted to reboot now and rebooted the system even when the user selected �??No�??. (Reference: 410573) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The managed product update process now honors the user&amp;#39;s selected reboot response. &lt;/p&gt;&lt;ol start="13"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Certain dates, such as leap years, were recorded incorrectly in the agent_&amp;lt;machinename&amp;gt;.xml log file. (Reference: 413415) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; All dates are now recorded correctly in the agent_&amp;lt;machinename&amp;gt;.xml log file. &lt;/p&gt;&lt;ol start="14"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The McAfee Agent only updated the VirusScan engine if the minor version was newer than what was installed. This prevented the VirusScan engine from updating to a newer build of the same version. (Reference: 414065) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The McAfee Agent now supports build-to-build VirusScan engine updates. &lt;/p&gt;&lt;ol start="15"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The installation and upgrade processes failed if the data folder was located in the �??Windows�?? or �??WinNT�?? folders. (Reference: 415578) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now the installation and upgrade processes allow the data folder to be located in the �??Windows�?? or �??WinNT�?? folders with the exception of the system32 folder. The installation and upgrade processes prohibit the data folder from including the system32 folder. &lt;/p&gt;&lt;ol start="16"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Some non-McAfee product installation routines removed critical registry entries, such as the Windows IStream COM registration, causing the McAfee Agent to fail. (Reference: 416298) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The upgrade process now re-registers the ole32.dll file when it detects it is missing. &lt;/p&gt;&lt;ol start="17"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The installation and upgrade processes failed if the installation or data folders contained double-byte characters. (Reference: 416559) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The installation and upgrade processes now allow the installation and data folders to contain double-byte characters. &lt;/p&gt;&lt;ol start="18"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Several install and uninstall error messages made no sense when displayed on a Japanese language system. (Reference: 418729) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The upgrade process now displays meaningful install and uninstall error messages on a Japanese language system. &lt;/p&gt;&lt;ol start="19"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; On systems running VirusScan Enterprise version 8.0 the McAfee Agent did not remove the Temp files created during the execution of an �??Agent Update Task�??. (Reference: 419066) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The McAfee Agent now removes the Temp files created during the execution of an �??Agent Update Task�??. &lt;/p&gt;&lt;p&gt;Note: This change does not remove the Temp files created during the execution of an &amp;quot;Agent Update Task&amp;quot; prior to implementing this patch. &lt;/p&gt;&lt;ol start="20"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; During Policy Enforcement, when the McAfee Agent failed to compile the policy file, the policy enforcement failed and the agent crashed on the next Policy Enforcement. (Reference: 423070) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The McAfee Agent now detects failed Policy Enforcements and retries the policy compilation until it completes successfully. &lt;/p&gt;&lt;ol start="21"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; DAT updates were postponed indefinitely and the message �??Update will be retried after 3 mins because update is already in progress�?? appeared repeatedly in the agent log file. (Reference: 424203) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The DAT update process now terminates properly when it detects an error in an FTP transaction.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=125397" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/487818760" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/234VcGRhXl4" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-agent-4-0-patch-1-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/487818760/mcafee-agent-4-0-patch-1-released.aspx</feedburner:origLink></item><item><title>McAfee ePolicy Orchestrator Server 4.0 Patch 3 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/fcmVnGdbqYk/mcafee-epolicy-orchestrator-server-4-0-patch-3-released.aspx</link><pubDate>Wed, 17 Dec 2008 17:06:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:125398</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=125398</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-epolicy-orchestrator-server-4-0-patch-3-released.aspx#comments</comments><description>&lt;p&gt;&lt;a target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB53887" target="_blank"&gt;McAfee KB&lt;/a&gt; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Resolved issues&lt;/i&gt;&lt;/b&gt; &lt;/p&gt;&lt;p&gt;Issues that are resolved in this release are listed below. &lt;/p&gt;&lt;ol&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; SuperAgent Repositories on Windows Vista and Windows 2008 systems did not appear as Distributed Repositories in the ePolicy Orchestrator console. (Reference: 371932, 405958) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; SuperAgent Repositories on Windows Vista and Windows 2008 systems now appear as Distributed Repositories in the ePolicy Orchestrator console.  &lt;/p&gt;&lt;ol start="2"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; A synchronization point could not be created, edited, or deleted for the �??My Organization�?? group. (Reference: 384135) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; A synchronization point for the �??My Organization�?? group can now be created, edited, and deleted.  &lt;/p&gt;&lt;ol start="3"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Grouped Summary Table queries could not be ordered by label values when grouped by a version number column. For example, a group summary of managed systems grouped by group name and DAT version could not be ordered by the group name label and then by DAT version label. (Reference: 386121) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Grouped Summary Table queries can now be ordered by the label values when grouped by a version number column.  &lt;/p&gt;&lt;ol start="4"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When configuring an Active Directory synchronization group, the �??Browse�?? button for browsing and �??Add�?? button for exceptions were disabled unless the user first selected an NT domain synchronization type. (Reference: 391830) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The �??Browse�?? and �??Add�?? buttons are now enabled without having to first select an NT domain synchronization type.  &lt;/p&gt;&lt;ol start="5"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Active Directory synchronization failed when a synchronized folder name included a semicolon. (Reference: 392803) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Active Directory folder names can now contain a semicolon.  &lt;/p&gt;&lt;ol start="6"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When viewing the system properties of a system that has never communicated with the ePolicy Orchestrator server, clicking on the �??more�?? link resulted in a blank page. (Reference: 398952) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Selecting the �??more�?? link for a managed system that has never communicated with the ePolicy Orchestrator server no longer results in a blank page.  &lt;/p&gt;&lt;ol start="7"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Extra.DAT packages were not updated on Windows Vista or Windows 2008 Server managed systems. (Reference: 400563) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Extra.DAT packages are now updated on Windows Vista and Windows 2008 Server managed systems.  &lt;/p&gt;&lt;p&gt;Note: All Extra.DAT packages in the repository must be reinstalled before this change takes effect. &lt;/p&gt;&lt;ol start="8"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The McAfee Agent failed to enforce Host Intrusion Protection rule policies when the rule name contained an angled bracket character. (Reference: 400808) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The McAfee Agent now enforces Host Intrusion Protection rule policies regardless of the rule name.  &lt;/p&gt;&lt;ol start="9"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; A client task with a �??repeat starting at�?? schedule could have a repeat duration that was less than the repeat interval, resulting in the client task never running. (Reference: 401301) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; New or modified client tasks with a �??repeat starting at�?? schedule must now have a repeat duration that is greater than or equal to the repeat interval. &lt;/p&gt;&lt;ol start="10"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When viewing the results of a query for Events, the �??Show Related Systems�?? action is not available. (Reference: 402250) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The �??Show Related Systems�?? action is now available for Event queries.  &lt;/p&gt;&lt;ol start="11"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Importing managed systems into the System Tree from a Unicode text file created erroneous entries in the System Tree. (Reference: 402271) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; An error message is now displayed when non-UTF-8 encoded text files are imported, and the System Tree is unaffected.  &lt;/p&gt;&lt;ol start="12"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt;&amp;nbsp; An updated version of the System Compliance Profiler 2.0 extension is available. (Reference: 404381) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Version 2.0.2.191 of the System Compliance Profiler 2.0 extension is now installed during ePolicy Orchestrator 4.0 Patch 3.  &lt;/p&gt;&lt;ol start="13"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Running a previous upgrade a second time, after it had been successfully installed, failed. (Reference: 405288) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The upgrade can now be run multiple times.  &lt;/p&gt;&lt;ol start="14"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; VirusScan DAT and Engine version information was missing on Managed System Rollup queries. (Reference: 405383) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Managed System Rollup queries now include VirusScan DAT and Engine version information.  &lt;/p&gt;&lt;ol start="15"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; In the ePolicy Orchestrator console, the option that uninstalls the McAfee Agent from managed systems was not supported by non-Windows agents, but it was a selectable option. When this option was selected and the agents were manually uninstalled and later reinstalled, the managed systems never reappeared in the ePolicy Orchestrator System Tree. (Reference: 405859) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; A non-Windows managed system, which successfully reinstalls the McAfee Agent after a failed agent uninstall from the ePolicy Orchestrator console, now reappears in the ePolicy Orchestrator console System Tree. &lt;/p&gt;&lt;ol start="16"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An ePolicy Orchestrator 4.0 upgrade failed when the SQL Server UDP port was enabled for the initial ePolicy Orchestrator 4.0 installation and disabled before upgrading. The inverse scenario also caused the upgrade to fail. (Reference: 406814, 415166) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The ePolicy Orchestrator 4.0 upgrade no longer fails when the SQL Server UDP port was enabled for the initial ePolicy Orchestrator 4.0 installation and disabled before upgrading. The inverse scenario has also been corrected. &lt;/p&gt;&lt;ol start="17"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The Synchronization Group Agent Deployment checkbox, �??Force installation over existing Version,�?? does not remain selected after saving the Synchronization Group and accessing it again for editing. (Reference: 410246, 426930) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The Synchronization Group Agent Deployment checkbox, �??Force installation over existing Version,�?? now retains the selected value. &lt;/p&gt;&lt;ol start="18"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Installations in clustered server environments incorrectly set the ePolicy Orchestrator services to start �??Automatically.�?? (Reference: 410543) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Installations in clustered server environments now correctly set the ePolicy Orchestrator services to start �??Manually.�?? &lt;/p&gt;&lt;ol start="19"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The managed system name is truncated to a length of 14 characters on the ePolicy Orchestrator console �??Systems�?? tab. (Reference: 410779) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The column �??DNS Name,�?? containing a �??Fully Qualified Domain Name,�?? can now be selected as the managed system name on the ePO console �??Systems�?? tab. &lt;/p&gt;&lt;ol start="20"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The import policies process did not verify the ownership of the existing policies, which could result in policies being overwritten by users other than the owner. (Reference: 410917) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The import policies process now verifies the ownership of the existing policies and prevents policies from being overwritten by users other than the owner. &lt;/p&gt;&lt;ol start="21"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Changes to existing policies were not recorded in the Audit Log. (Reference: 412589) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Changes to existing policies are now recorded in the Audit Log. &lt;/p&gt;&lt;ol start="22"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The ePolicy Orchestrator Alerting extension, used by Rogue System Detection 2.0, was not localized. (Reference: 412661) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The ePolicy Orchestrator Alerting extension is upgraded to a localized version, on ePolicy Orchestrator servers with Rogue System Detection 2.0 installed. &lt;/p&gt;&lt;ol start="23"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The ePolicy Orchestrator server failed to respond if a corrupt package file was checked in. (Reference: 413466) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The ePolicy Orchestrator server responds correctly when a corrupt package file is checked in. &lt;/p&gt;&lt;ol start="24"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Editing a client task could result in the error message �??An Unexpected error occurred�?? being displayed in the ePolicy Orchestrator console. (Reference: 413963) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Editing client tasks no longer results in unexpected errors. &lt;/p&gt;&lt;ol start="25"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Client tasks, for managed product extensions that do not have a default policy, were not available for configuration. (Reference: 415739) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Client tasks, for managed product extensions that do not have a default policy, are now available for configuration. &lt;/p&gt;&lt;ol start="26"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An ePolicy Orchestrator 4.0 upgrade stopped installing the included managed product extensions after the first failure was discovered. (Reference: 415974) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; An ePolicy Orchestrator 4.0 upgrade now attempts to install each of the included managed product extensions, even if an error occurs during the installation of a previous managed product extension. &lt;/p&gt;&lt;ol start="27"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When the ePolicy Orchestrator server did not have a �??Master Agent to Server Communication Key,�?? the ePolicy Orchestrator 4.0 upgrade failed leaving the ePolicy Orchestrator server in a non-functional state. (Reference: 419859) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The ePolicy Orchestrator 4.0 upgrade now verifies the ePolicy Orchestrator server has a �??Master Agent to Server Communication Key�?? before it starts the upgrade. &lt;/p&gt;&lt;ol start="28"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An updated version of the Host Intrusion Prevention 7.0 extension is available. (Reference: 422819) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Version 7.0.1.133 of the Host Intrusion Prevention 7.0 extension is installed during the ePolicy Orchestrator 4.0 upgrade. &lt;/p&gt;&lt;ol start="29"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The �??delayload.log�?? file could grow without limit in the root (C:\) of the ePolicy Orchestrator server. (Reference: 425738) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The �??delayload.log�?? file is no longer used. &lt;/p&gt;&lt;p&gt;Note: The ePolicy Orchestrator 4.0 upgrade process does not remove existing �??delayload.log�?? files. &lt;/p&gt;&lt;ol start="30"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Event queries could not be chained to ePolicy Orchestrator server task actions. (Reference: 427217) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Event queries can now be chained to ePolicy Orchestrator server task actions. &lt;/p&gt;&lt;ol start="31"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Server tasks could not run an event query that was chained to these actions: apply, clear, or exclude tag actions. (Reference: 427708) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Server tasks can now run an event query chained to these actions: apply, clear, or exclude tag actions. &lt;/p&gt;&lt;ol start="32"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The �??View Logs�?? button could fail to display the correct installation log files after an ePolicy Orchestrator 4.0 upgrade failure. (Reference: 429819) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The �??View Logs�?? button now displays the main installation log files after an ePolicy Orchestrator 4.0 upgrade failure. &lt;/p&gt;&lt;ol start="33"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An initial ePolicy Orchestrator 4.0 installation, on a system with a local MSDE database and the UDP port disabled, could result in incorrect ePolicy Orchestrator service dependencies. (Reference: 430390) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The ePolicy Orchestrator 4.0 upgrade repairs the ePolicy Orchestrator service dependencies for systems installed with a local MSDE database and the UDP port disabled. &lt;/p&gt;&lt;ol start="34"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Miscellaneous language translation and localization issues were reported. (Reference: 429847, 430581) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The reported language translation and localization issues were addressed. &lt;/p&gt;&lt;ol start="35"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An updated version of the ePolicy Orchestrator Help extension is available. (Reference: 433198)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Version 1.0.6 of the ePolicy Orchestrator Help extension is now installed during the ePolicy Orchestrator 4.0 upgrade. &lt;/p&gt;&lt;ol start="36"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Inconsistent event times would appear in the Server Task Log. (Reference: 417725)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The problem of inconsistent event times appearing in the Server Task Log after applying patches has been fixed. &lt;/p&gt;&lt;ol start="37"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Console logons using NT authentication, worked only when the ePolicy Orchestrator console was located in a domain where a two-way trust existed between the console and ePolicy Orchestrator server domains. (Reference: 395894)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Authentication support for multiple domain controllers has been added to the product. (For more information see KB article: 616709) &lt;/p&gt;&lt;ol start="38"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The date formats are incorrect for the English (United Kingdom) locale. (Reference: 362588)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; A new choice of English (United Kingdom) has been added to the Language drop-down list of the ePolicy Orchestrator Logon screen.&amp;nbsp; &lt;/p&gt;&lt;ol start="39"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; When installing managed product extensions on ePolicy Orchestrator, the installation could fail with the message: �??ERROR: java.lang.OutOfMemoryError: PermGen space.�?? (Reference: 407724)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The PermGen Memory allocation size has been increased to 128 MB on clean installations and upgrades. (For more information see KB article: 615843) &lt;/p&gt;&lt;ol start="40"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; There was a performance bottleneck when processing a large number of unrelated dashboard requests. (Reference: 407724)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Performance has been improved to allow many users to view the dashboard. &lt;/p&gt;&lt;ol start="41"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Dashboard related caching is not functioning correctly, which caused the user to see stale data. (Reference: 411646)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Dashboard caching has been fixed so the user views the most current data.&amp;nbsp; &lt;/p&gt;&lt;ol start="42"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; An unexpected error occurred while creating a query using a Grouped Bar Chart with Boolean types of data. (Reference: 415069) &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Grouped Bar Charts now correctly display data when using any of the supported data types. &lt;/p&gt;&lt;ol start="43"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Drilling down into a chart, a user could see an unexpected error page if there was a null value in the returned time field. (Reference: 413954, 419692)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Chart drill-down now works as expected and no longer returns an error when drilling down into null time-based reports. &lt;/p&gt;&lt;ol start="44"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Some international characters caused problems in the server log details page. (Reference: 411088)&amp;nbsp; &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Log entries are now correctly formatted prior to being written to the server task log. &lt;/p&gt;&lt;ol start="45"&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Some valid characters caused problems when user names or passwords were typed in the ePO installer. (Reference: 395890) &lt;/li&gt;&lt;/ol&gt;&lt;b&gt;Resolution:&lt;/b&gt; The installer now accepts all valid characters for ePolicy Orchestrator user names and passwords, including all NT authentication-allowed characters.&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=125398" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/487818761" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/fcmVnGdbqYk" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-epolicy-orchestrator-server-4-0-patch-3-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/487818761/mcafee-epolicy-orchestrator-server-4-0-patch-3-released.aspx</feedburner:origLink></item><item><title>McAfee Rogue System Detection 2.0 Patch 1 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/LNAf1e-Ocpk/mcafee-rogue-system-detection-2-0-patch-1-released.aspx</link><pubDate>Wed, 17 Dec 2008 17:04:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:125396</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=125396</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-rogue-system-detection-2-0-patch-1-released.aspx#comments</comments><description>&lt;p&gt;&lt;a href="https://mysupport.mcafee.com"&gt;Download&lt;/a&gt; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Resolved issues&lt;/i&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Issues that are resolved in this release are listed below. &lt;/p&gt;&lt;ol&gt; &lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Selecting the �??Next Page�?? while viewing �??Managed Machines�?? caused this message to be displayed: �??An Unknown Error has Occurred.�?? (Reference: 427453)  &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now when you view a subnet containing more than a single page of system information and you select �??Next Page,�?? the requested information is properly displayed. &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The columns on the �??Managed Systems for Subnet�?? page did not sort when selected.&amp;nbsp;&amp;nbsp; (Reference: 430417)  &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Now when you select a column on the �??Managed Systems for Subnet�?? page, the page is properly sorted. &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Although the Rogue System Detection Sensor deployment task would run, the Rogue System Detection Sensor was not updated. (Reference: 415191)  &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The Rogue System Detection Sensor deployment task now supports build-to-build upgrades. &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The �??Detected Systems Details�?? page displayed the �??Last Detected IP Address�?? with NULL IP addresses as �??unknown error.�?? (Reference: 431047)  &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The �??Last Detected IP Address�?? on the �??Detected Systems Details�?? page now displays NULL IP addresses as �??blank.�?? &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; Rogue System Detection only allowed domain names of up to 16 characters in length. (Reference: 431049)  &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Rogue System Detection now allows domain names of up to 255 characters in length. &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;b&gt;Issue:&lt;/b&gt; The Rogue System Detection Sensor Service was incorrectly described in the �??Services�?? pane of the �??Computer Management�?? window. (Reference: 423608)  &lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The Rogue System Detection Sensor Service is now described as �??Performs broadcast and DHCP detection.�?? &lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=125396" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/487818762" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/LNAf1e-Ocpk" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/RSD/default.aspx">RSD</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-rogue-system-detection-2-0-patch-1-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/487818762/mcafee-rogue-system-detection-2-0-patch-1-released.aspx</feedburner:origLink></item><item><title>McAfee Host Intrusion Prevention Server 7.0.1 Extension Released</title><link>http://feedproxy.google.com/~r/aberges/~3/E4kRwZSiSUA/mcafee-host-intrusion-prevention-7-0-1-extension-released.aspx</link><pubDate>Wed, 17 Dec 2008 17:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:125395</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=125395</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-host-intrusion-prevention-7-0-1-extension-released.aspx#comments</comments><description>&lt;p&gt;&lt;a href="https://mysupport.mcafee.com"&gt;Download &lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;New features&lt;/i&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;New and updated features in the current release of the software are described below: &lt;/p&gt;&lt;p&gt;&lt;b&gt;7.0.1&lt;/b&gt; &lt;/p&gt;&lt;ul&gt; &lt;li&gt;Management of version 6.1 clients from ePolicy Orchestrator 4.0 patch 1 when the 6.1 extension is installed.  &lt;/li&gt;&lt;li&gt;Migration of version 6.x policies to version 7.0 by running a server task from ePolicy Orchestrator 4.0. &lt;/li&gt;&lt;/ul&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=125395" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/487818763" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/E4kRwZSiSUA" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/HIPS/default.aspx">HIPS</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-host-intrusion-prevention-7-0-1-extension-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/487818763/mcafee-host-intrusion-prevention-7-0-1-extension-released.aspx</feedburner:origLink></item><item><title>McAfee Host Intrusion Prevention Version 7.0.0 Patch 3 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/1TwkG_3ouFA/mcafee-host-intrusion-prevention-version-7-0-0-patch-3-released.aspx</link><pubDate>Wed, 17 Dec 2008 16:59:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:125394</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=125394</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-host-intrusion-prevention-version-7-0-0-patch-3-released.aspx#comments</comments><description>&lt;p&gt;&lt;a href="https://mysupport.mcafee.com%20" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB53672&amp;amp;pmv=print" target="_blank"&gt;McAfee KB&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;New Resolved Issues&lt;/i&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Host IPS 7.0 Patch 3 resolves a number of stability issues seen on high availability servers, domain controllers, and backup servers.&amp;nbsp; In addition, the following customer issues were also resolved: &lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;/b&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Issue:&lt;/b&gt; Tivoli does not function when using Check Point VPN-1 Client when Connection Aware Group firewall rules are applied. (Reference: 425392) &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Connection Aware Group matching failed with inbound traffic with some IPSec VPNs. The Connection Aware Group matching logic was extended to handle IPSec VPN re-routing of inbound traffic to the physical adapter�??s NDIS miniport instance. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Issue:&lt;/b&gt; Unable to connect to HTTPS server when a client is connected with T3G wireless network connection. (Reference: 414155) &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; Unsolicited inbound traffic was not being matched by the Connection Aware Group.&amp;nbsp; The Host IPS Firewall will now use the IP address, instead of the MAC address, when matching traffic for Connection Aware Groups. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Issue:&lt;/b&gt; The Host IPS client does not block all SQL injections on a single IIS 6 server hosting multiple sites. (Reference: 419431) &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; The ISAPI filter stub tracked the engine status using a single value even when multiple instances of the stub were loaded. Each ISAPI filter stub instance now tracks its respective engine status. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Issue:&lt;/b&gt; System stops responding or �??hangs�?? at shutdown because of incompatibility with NetMotion VPN. (Reference: 426645) &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resolution:&lt;/b&gt; In certain circumstances, a specific Windows API used during shutdown caused the system to stop responding. This API is no longer used during shutdown. &lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;/b&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Issue: &lt;/b&gt;TCP traffic is blocked when firewall rules use short path names. (Reference: 414249) &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resolution: &lt;/b&gt;The firewall drivers, which failed to convert a short path name to a long form, now obtain a long form of a short path name before matching the rules.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=125394" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/487786994" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/1TwkG_3ouFA" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/HIPS/default.aspx">HIPS</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/12/17/mcafee-host-intrusion-prevention-version-7-0-0-patch-3-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/487786994/mcafee-host-intrusion-prevention-version-7-0-0-patch-3-released.aspx</feedburner:origLink></item><item><title>Links for 2008-12-16 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/0o4z9rRfkLY/aberges</link><pubDate>Wed, 17 Dec 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-12-16</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://www.delltechcenter.com/page/OpenManage+Client+Instrumentation+%28OMCI%29">OpenManage Client Instrumentation (OMCI) - The Dell TechCenter</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/487327747" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/0o4z9rRfkLY" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.delltechcenter.com/page/OpenManage+Client+Instrumentation+%28OMCI%29"&gt;OpenManage Client Instrumentation (OMCI) - The Dell TechCenter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-12-16</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/487327747/aberges</feedburner:origLink></item><item><title>Links for 2008-12-15 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/QiNkTwmHOaI/aberges</link><pubDate>Tue, 16 Dec 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-12-15</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://myitforum.com/cs2/blogs/skissinger/archive/2008/07/09/one-way-to-replace-the-hardware-for-a-secondary-site.aspx">One way to replace the hardware for a Secondary Site - Sherry Kissinger at myITforum.com</a></li>
<li><a href="http://myitforum.com/cs2/blogs/smslist/default.aspx">SMS-ConfigMgr Email Discussion List Archive</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/486318891" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/QiNkTwmHOaI" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://myitforum.com/cs2/blogs/skissinger/archive/2008/07/09/one-way-to-replace-the-hardware-for-a-secondary-site.aspx"&gt;One way to replace the hardware for a Secondary Site - Sherry Kissinger at myITforum.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://myitforum.com/cs2/blogs/smslist/default.aspx"&gt;SMS-ConfigMgr Email Discussion List Archive&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-12-15</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/486318891/aberges</feedburner:origLink></item><item><title>Links for 2008-12-12 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/OnfLGaBUhug/aberges</link><pubDate>Sat, 13 Dec 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-12-12</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://www.delltechcenter.com/page/Using+OMCI+with+ConfigMgr">Using OMCI with ConfigMgr - The Dell TechCenter</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/483387904" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/OnfLGaBUhug" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.delltechcenter.com/page/Using+OMCI+with+ConfigMgr"&gt;Using OMCI with ConfigMgr - The Dell TechCenter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-12-12</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/483387904/aberges</feedburner:origLink></item><item><title>Links for 2008-12-01 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/E4P590Qbc4M/aberges</link><pubDate>Tue, 02 Dec 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-12-01</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://myitforum.com/cs2/blogs/skissinger/archive/2008/10/28/mini-monster-mof-builder.aspx">Mini Monster Mof Builder - Sherry Kissinger at myITforum.com</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/472155203" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/E4P590Qbc4M" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://myitforum.com/cs2/blogs/skissinger/archive/2008/10/28/mini-monster-mof-builder.aspx"&gt;Mini Monster Mof Builder - Sherry Kissinger at myITforum.com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-12-01</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/472155203/aberges</feedburner:origLink></item><item><title>Links for 2008-11-21 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/pmVcIN9CzgY/aberges</link><pubDate>Sat, 22 Nov 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-11-21</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://blogs.msdn.com/steverac/archive/2008/10/19/mdt-and-sccm-2007-better-together.aspx">ConfigMgr/OpsMgr : MDT and SCCM 2007 - better together</a></li>
<li><a href="http://myitforum.com/cs2/blogs/cstauffer/archive/2008/11/21/how-to-check-the-command-line-parameters-in-ad-for-configmgr.aspx">How to check the Command line parameters in AD for ConfigMgr</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/461561181" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/pmVcIN9CzgY" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/steverac/archive/2008/10/19/mdt-and-sccm-2007-better-together.aspx"&gt;ConfigMgr/OpsMgr : MDT and SCCM 2007 - better together&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://myitforum.com/cs2/blogs/cstauffer/archive/2008/11/21/how-to-check-the-command-line-parameters-in-ad-for-configmgr.aspx"&gt;How to check the Command line parameters in AD for ConfigMgr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-11-21</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/461561181/aberges</feedburner:origLink></item><item><title>Links for 2008-11-20 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/iIeCay9Qq_s/aberges</link><pubDate>Fri, 21 Nov 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-11-20</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://www.deployvista.com/Home/tabid/36/EntryID/76/language/en-US/Default.aspx">Sample Storage Drivers and Sysprep.inf for Windows XP builds (MDT 2008)</a></li>
<li><a href="http://blogs.technet.com/deploymentguys/archive/2008/02/15/driver-management-part-1-configuration-manager.aspx">The Deployment Guys : Driver Management (Part 1) - Configuration Manager</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/bb680753.aspx">Planning for PXE Initiated Operating System Deployments</a></li>
<li><a href="http://blogs.msdn.com/steverac/archive/2008/10/19/setting-up-multicasting-in-sccm.aspx">Setting up Multicasting in SCCM</a></li>
<li><a href="http://blogs.msdn.com/steverac/archive/2008/09/21/unknown-computers-in-sccm-2007-r2-overview.aspx">Unknown Computers in SCCM 2007 R2 - overview</a></li>
<li><a href="http://blogs.msdn.com/steverac/archive/2008/09/21/unknown-computers-in-sccm-2007-r2-how-it-works.aspx">Unknown Computers in SCCM 2007 R2- how it works</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/460432753" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/iIeCay9Qq_s" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.deployvista.com/Home/tabid/36/EntryID/76/language/en-US/Default.aspx"&gt;Sample Storage Drivers and Sysprep.inf for Windows XP builds (MDT 2008)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/deploymentguys/archive/2008/02/15/driver-management-part-1-configuration-manager.aspx"&gt;The Deployment Guys : Driver Management (Part 1) - Configuration Manager&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb680753.aspx"&gt;Planning for PXE Initiated Operating System Deployments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/steverac/archive/2008/10/19/setting-up-multicasting-in-sccm.aspx"&gt;Setting up Multicasting in SCCM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/steverac/archive/2008/09/21/unknown-computers-in-sccm-2007-r2-overview.aspx"&gt;Unknown Computers in SCCM 2007 R2 - overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/steverac/archive/2008/09/21/unknown-computers-in-sccm-2007-r2-how-it-works.aspx"&gt;Unknown Computers in SCCM 2007 R2- how it works&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-11-20</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/460432753/aberges</feedburner:origLink></item><item><title>Links for 2008-11-19 [del.icio.us]</title><link>http://feedproxy.google.com/~r/aberges/~3/2mBAL4TVySw/aberges</link><pubDate>Thu, 20 Nov 2008 00:00:00 -0600</pubDate><guid isPermaLink="false">http://del.icio.us/aberges#2008-11-19</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<ul>
<li><a href="http://java.sun.com/javase/6/docs/technotes/guides/deployment/deployment-guide/contents.html">Contents</a></li>
<li><a href="http://packetlife.net/cheatsheets/">Cheat Sheets - PacketLife.net</a></li>
</ul><img src="http://feeds.feedburner.com/~r/aberges/~4/459222941" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/aberges/~4/2mBAL4TVySw" height="1" width="1"/>]]></content:encoded><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://java.sun.com/javase/6/docs/technotes/guides/deployment/deployment-guide/contents.html"&gt;Contents&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://packetlife.net/cheatsheets/"&gt;Cheat Sheets - PacketLife.net&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><feedburner:origLink>http://del.icio.us/aberges#2008-11-19</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/459222941/aberges</feedburner:origLink></item><item><title>SANS Internet Storm Center; Adobe Reader vulnerability exploited in the wild</title><link>http://feedproxy.google.com/~r/aberges/~3/fbzWZOg0zsE/sans-internet-storm-center-adobe-reader-vulnerability-exploited-in-the-wild.aspx</link><pubDate>Fri, 07 Nov 2008 16:41:56 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:123926</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=123926</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/11/07/sans-internet-storm-center-adobe-reader-vulnerability-exploited-in-the-wild.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=5312"&gt;Adobe Reader vulnerability exploited in the wild&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Published: 2008-11-07,&lt;br /&gt;Last Updated: 2008-11-07 15:54:09 UTC&lt;br /&gt;by Bojan Zdrnja (Version: 1)  &lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=5312#comment"&gt;0 comment(s)&lt;/a&gt; &lt;p&gt;One of our readers, Wayne Dilly, sent couple of malicious PDF documents to us. Wayne noticed that some machines got infected and wondered if the PDF documents exploited the vulnerability patched by Adobe couple of days ago (CVE-2008-2992 - see &lt;a href="http://isc.sans.org/diary.html?storyid=5282"&gt;http://isc.sans.org/diary.html?storyid=5282&lt;/a&gt;). &lt;p&gt;Unfortunately, Wayne was right �?? these PDF documents exploit the JavaScript buffer overflow vulnerability. This is not surprising, though, as a fully working PoC has been recently published as well, but it&amp;#39;s interesting to see that the attackers modified the PoC a little bit, probably in order to evade anti-virus detection. &lt;p&gt;And indeed �?? at the time of writing this article, according to VirusTotal 0 (&lt;strong&gt;yes �?? ZERO&lt;/strong&gt;) AV products detected this malicious PDF. Very, very bad. &lt;p&gt;The payload is in a JavaScript object embedded in the PDF document. Once extracted, it just contains first level obfuscation with a simple eval(unescape()) call. &lt;p&gt;Once deobfuscated, parts of the publicly posted PoC are visible, but the attackers also modified certain parts. For example, the PoC defines a long number variable (referenced to the advisory by CORE), as shown below: &lt;p&gt;var num = 129999999999999999�?�. [a lot of numbers]&lt;br /&gt;util.printf(&amp;quot;%45000f&amp;quot;,num);&lt;br /&gt;However, the exploit code in the wild has the following loops:&lt;br /&gt;var nm = 12;&lt;br /&gt;for(i = 0; i &amp;lt; 18; i++){ nm = nm + &amp;quot;9&amp;quot;; }&lt;br /&gt;for(i = 0; i &amp;lt; 276; i++){ nm = nm + &amp;quot;8&amp;quot;; }&lt;br /&gt;util.printf(unescape(&amp;quot;&amp;quot;+&amp;quot;%&amp;quot;+&amp;quot;25%34%35%30%30%30%66&amp;quot;), nm);&lt;br /&gt;See how they manage to do exactly the same thing? Unfortunately, this was probably enough to fool the AV vendors.&lt;br /&gt;In any case, if you haven&amp;#39;t patched your Adobe Reader installations �?? do it ASAP as the attacks are in the wild.&lt;br /&gt;--&lt;br /&gt;Bojan&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=123926" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/445643241" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/fbzWZOg0zsE" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Malware/default.aspx">Malware</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Adobe/default.aspx">Adobe</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/11/07/sans-internet-storm-center-adobe-reader-vulnerability-exploited-in-the-wild.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/445643241/sans-internet-storm-center-adobe-reader-vulnerability-exploited-in-the-wild.aspx</feedburner:origLink></item><item><title>CounterSpy Enterprise 3.1 Maintenance Release</title><link>http://feedproxy.google.com/~r/aberges/~3/5Hvyl8_1Yhk/counterspy-enterprise-3-1-maintenance-release.aspx</link><pubDate>Wed, 29 Oct 2008 19:24:26 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:123621</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=123621</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/10/29/counterspy-enterprise-3-1-maintenance-release.aspx#comments</comments><description>&lt;p&gt;Just posted to the web at the below URL:&lt;/p&gt; &lt;p&gt;&lt;a href="http://go.sunbeltsoftware.com/?linkid=400"&gt;http://go.sunbeltsoftware.com/?linkid=400&lt;/a&gt;  &lt;p&gt;List of fixes below: &lt;p&gt;Enterprise Console and Service: (Agent fixes/features are further down). &lt;p&gt;1. Removed Custom Reports from UI and Service. &lt;p&gt;2. Added support for Agent Shutdown/Agent Start from Console. &lt;p&gt;3. Give the administrator the ability to Unquarantine and send to Sunbelt for Analysis. &lt;p&gt;4. Changed name of Sunbelt Software Research Center to Sunbelt Malware Research Labs. &lt;p&gt;5. Added Force Full Threat DB Update for selected agents on Agents &amp;amp; Policy Grid. &lt;p&gt;6. Removed Custom from Admin Known Good/Bad controls (Not necessary). &lt;p&gt;7. Allow end-user to manually edit Known Good/Bad files and folders. Also disallow the addition of invalid file names and paths and wildcards for file names. &lt;p&gt;8. Added tab in Policy for Agent Proxy settings. &lt;p&gt;9. Allow end-user to delete System Message at both Agent and System levels. &lt;p&gt;10. Added &amp;quot;Archives&amp;quot; checkbox to scanning tab in the policy. &lt;p&gt;11. Added admin ability to turn on/off On-Access file extensions from the console. &lt;p&gt;12. Fixed bug that resulted in &amp;quot;Rootkit Scanned&amp;quot; being displayed as the title for &amp;quot;Rootkit Found&amp;quot;. &lt;p&gt;13. Cleaned up the Known Good/Bad file dialogs and grids. &lt;p&gt;14. Fixed context menu on the agents/policy grid to enable/disable entries properly in sub-menus. &lt;p&gt;15. Changed minimum agent version to 3.1.2300 to support Unquarantine and Send for Analysis. &lt;p&gt;16. Added support for migrating SystemMessage table from MSAccess to SQL. &lt;p&gt;17. Added Power Management Tab to UI and settings to the policy. &lt;p&gt;18. Enable remote starting of service from console on logon, if service is not running. User must be admin on box running service. &lt;p&gt;19. Added Ping Agent, Say Hello and Check for Policy Update to Advanced Sub-menu of agents &amp;amp; policy control context menu. &lt;p&gt;20. Fixed bug on console that disabled File menu if a connection w/ the server was lost. &lt;p&gt;21. Added ability to report back to admin if Unquarantine or Delete from Quarantine failed. &lt;p&gt;22. Reworded Power Management tab, changed the order of the items to match consumer UI. &lt;p&gt;23. Fixed &amp;quot;Perform quick scan approximately...&amp;quot; so that it saves data to the policy. &lt;p&gt;24. Prevented logging of error messages to the System Messages table in the DeferredWorkQueueHandler, this could result in deadlock. &lt;p&gt;25. Enhanced code that Pings an agent box, pinging by both Machine Name and IP and presenting the results of both pings in a dialog after completion of the ping. &lt;p&gt;26. Added the ability to turn off information balloons in the policy &lt;p&gt;Agent: &lt;p&gt;1. Add a System Event for missed scheduled scans. &lt;p&gt;2. Added logic to report when a quarantine, unquarantine or delete from quarantine action failed. &lt;p&gt;3. Added logic in the service to set the services display name in Service Control Manager to the Product Name Long or Enterprise Product Name Long string in the resource file. &lt;p&gt;4. Added the definitions version to the hover text for the main tray icon. &lt;p&gt;5. Changed ALL history lists to sort in reverse chronological order by default. &lt;p&gt;6. Added logic to the tray to provide an Active Protection snooze feature. The user can turn AP off for a few minutes. &lt;p&gt;7. Added logic to disable AP when a machine is started in safe mode. &lt;p&gt;8. Added logic to not start tray in safe mode. &lt;p&gt;9. Fix bug where Quick/Deep Scans were not always scanning all local drives. &lt;p&gt;10. Changed the label &amp;quot;Risk definitions&amp;quot; on the overview panel to &amp;quot;Definitions version&amp;quot;. &lt;p&gt;11. Removed the seconds from the definitions date/time on all screens. &lt;p&gt;12. Added logic to the Enterprise Agent dll to not send Hello calls when the machine is on battery and in power save mode. &lt;p&gt;13. Added code in the Enterprise Agent to recognize the Service State of Paused and stop sending Hello calls to the service. &lt;p&gt;14. Added a double click handler for the warning icon. It will perform the first item on the warning icon context menu. &lt;p&gt;15. Create an option that allows user to specify auto shutdown of computer once manual scan has completed (non-sticky). &lt;p&gt;16. Fix code that shows, &amp;quot;Bad Date Format&amp;quot; when there are no definitions present. &lt;p&gt;17. Added a browse button on the Safe Mode UI where a user can manually apply a definitions file that they downloaded. &lt;p&gt;18. Added a browse button on the UI Update settings page where a user can manually apply a definitions file that they downloaded. &lt;p&gt;19. Fixed a bug where the Scan Archives was not being properly set for the Enterprise Agent. &lt;p&gt;20. Removed the software version from the updates section of the overview panel. &lt;p&gt;21. Scan history panel. Changed the &amp;quot;Date&amp;quot; column headers to say &amp;quot;Date/Time&amp;quot;. Also changed scan history to use the start date/time not end date/time of the scan. &lt;p&gt;22. Scan history panel. Changed column label, &amp;quot;Risks Total&amp;quot; to &amp;quot;Total Risks&amp;quot;. &lt;p&gt;23. Scan history panel. Changed label for days to keep history to from, &amp;quot;Delete history files older than 15 days&amp;quot; to &amp;quot;History files older than 15 days will be deleted&amp;quot;. &lt;p&gt;24. Change enterprise agent to set the sku config for the UI to always show the proxy settings tab. &lt;p&gt;25. Added support in the Enterprise Agent dll for reporting a possible False Positive as part of Unquarantine. &lt;p&gt;26. Added support in the Quarantine Panel for reporting a possible False Positive as part of Unquarantine or directly from the quarantine list. &lt;p&gt;27. Added logic in the Enterprise Agent to support a deferred work item from the service to force a definitions update. &lt;p&gt;28. Added scanner and cleaner errors to scan results xml file (threat engine). &lt;p&gt;29. Fixed Rootkit bug that could casuse BSOD. &lt;p&gt;30. Added more parameter validation in process scanning. &lt;p&gt;31. Fixed bug in the UI where Update Dialog breaks during application of multiple incremental Updates. &lt;p&gt;32. Fix AP bug where AP did not detect threats on some removable USB devices on XP SP2 and possibly other OSs. &lt;p&gt;33. Fixed a bug in the Threat Engine where one of the traces of the CommonName threat was not being detected. &lt;p&gt;34. Fixed a bug in the Enterprise Agent where cookies were only scanned for a custom scan but not quick and deep when initiated from the agent console. &lt;p&gt;35. Fixed a bug where the Enterprise Agent would show as a consumer UI when installed but could not communicate with the Enterprise service. &lt;p&gt;36. Added option to hide all balloons shown by the tray. &lt;p&gt;37. Added a policy setting from the Enterprise service to allow the admin to show/hide tray balloons. &lt;p&gt;38. Added two tray menu items; Show Balloons and Hide Balloons. &lt;p&gt;39. Fixed bug in Threat Engine where it was always calculating an MD5 for every file scanned by AP On Access. &lt;p&gt;40. Prevent premature scheduled Risk Definitions and Software Updates on wake for scheduled scans. &lt;p&gt;41. Junction point bug fix in boot time scanner and root kit engine. &lt;p&gt;42. The right click scanner shell extension was loading the resource dll one per second on Vista. Fixed to only load SBAMRes.dll once per right click 43. Fixed bug where VIPRE was not rescheduling updates when they were canceled. (Update intervals being ignored)  &lt;p&gt;44. Added logic to the Enterprise Agent SOAP class to set the timeout parameter for calls to the Enterprise service. This helps resolve SOAP error 5 communications errors. Added to the policy so the Admins can change it. &lt;p&gt;45. Fixed bug where items that are moved from quarantine to always allowed aren&amp;#39;t all making it to the always allowed section.&lt;pre&gt;&amp;nbsp;&lt;/pre&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=123621" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/436165642" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/5Hvyl8_1Yhk" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/CounterSpy/default.aspx">CounterSpy</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Sunbelt/default.aspx">Sunbelt</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/10/29/counterspy-enterprise-3-1-maintenance-release.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/436165642/counterspy-enterprise-3-1-maintenance-release.aspx</feedburner:origLink></item><item><title>Adobe PSIRT: Clipboard attack update</title><link>http://feedproxy.google.com/~r/aberges/~3/3GtqsLMBoJY/adobe-psirt-clipboard-attack-update.aspx</link><pubDate>Fri, 26 Sep 2008 18:09:18 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:122701</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=122701</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/09/26/adobe-psirt-clipboard-attack-update.aspx#comments</comments><description>&lt;p&gt; &lt;p&gt;Here&amp;#39;s a quick update to note that we will be changing the way Flash Player interacts with the clipboard to help prevent the potential clipboard attacks that have been reported recently. Please see the &lt;a href="http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html#head31"&gt;following Article on security changes in Flash Player 10&lt;/a&gt; for more information. These changes will be available in the final Flash Player 10 release soon.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;This posting is provided �??AS IS�?? with no warranties and confers no rights&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.adobe.com/psirt/2008/09/clipboard_attack_update.html"&gt;Clipboard attack update&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=122701" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/404008341" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/3GtqsLMBoJY" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Adobe/default.aspx">Adobe</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Vulnerability/default.aspx">Vulnerability</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/09/26/adobe-psirt-clipboard-attack-update.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/404008341/adobe-psirt-clipboard-attack-update.aspx</feedburner:origLink></item><item><title>McAfee VirusScan Enterprise 8.7i Released</title><link>http://feedproxy.google.com/~r/aberges/~3/iEg3uNkNJWg/mcafee-virusscan-enterprise-8-7i-released.aspx</link><pubDate>Fri, 26 Sep 2008 18:07:01 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:122700</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=122700</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/09/26/mcafee-virusscan-enterprise-8-7i-released.aspx#comments</comments><description>&lt;p&gt;&lt;b&gt;New and updated features in the current release of the software&lt;/b&gt;: &lt;p&gt;Support for Microsoft Windows Server 2008 &lt;p&gt;This release provides support for Windows Server 2008 (Longhorn). &lt;p&gt;&lt;b&gt;Architectural changes&lt;/b&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt; &lt;p&gt;· VirusScan Enterprise incorporates some significant architectural changes that affect the manner in which the VirusScan Enterprise 8.7i core components work. These changes result in greater security benefits to customers, including: &lt;p&gt;· Better rootkit detection and cleaning without system restart �?? Safe memory patching, better IRP repair support at the system core, and the ability to read locked files at the kernal level provide better rootkit detection and the ability to clean detections without restarting the system. &lt;p&gt;· On-access scan performance improvements during system startup �?? A new boot cache process improves on-access scan performance during system startup. &lt;p&gt;· Greater self-protection �?? The self-protection feature has been enhanced to protect against a wider range of mal-processes that can terminate McAfee processes. This provides greater VirusScan Enterprise self-protection and product stability. &lt;p&gt;· Real-time malware protection &lt;p&gt;A new feature, Heuristic network check for suspicious files, provides customers with real-time detections for malware.  &lt;p&gt;This feature uses sensitivity levels that can be configured, based on your risk tolerance, to look for suspicious files on your endpoints that are running VirusScan Enterprise 8.7i. &lt;p&gt;When enabled, this feature detects a suspicious program and sends a DNS request containing a fingerprint of the suspicious file to McAfee Avert Labs, which then communicates the appropriate action back to VirusScan Enterprise 8.7i. &lt;p&gt;The real-time defense feature also provides protection for classes of malware for which signatures might not be available. &lt;p&gt;This protection is in addition to the world-class DAT-based detection VirusScan Enterprise has always provided. The user experience remains the same and no additional client software is required. &lt;p&gt;In this release, this feature is available only for on-demand scans and email scanning and is disabled by default. You must select a sensitivity level to enable the feature. &lt;p&gt;&lt;b&gt;Performance improvements&lt;/b&gt; &lt;p&gt;These changes improve performance. &lt;p&gt;· New scan deferral options improve local control of on-demand scans, including the ability to defer scans when using battery power or during presentations. One option can be configured to allow end users to defer scheduled on-demand scans for the increment of time you specify. You can specify hourly increments up to twenty-four hours, or forever. &lt;p&gt;· Enhanced system throttling now includes registry and memory scanning in addition to file scanning. &lt;p&gt;· Improved email scanner &lt;p&gt;The email scanner now supports double-byte and multi-byte languages. This improves detection reliability. &lt;p&gt;· Buffer overflow protection exclusions by API &lt;p&gt;The ability to specify buffer overflow exclusions by API was removed from VirusScan Enterprise 8.5i, but has been reinstated for the VirusScan Enterprise 8.7i release. The API exclusion name is case-sensitive. &lt;p&gt;· On-access scanner �?? Scan processes on enable &lt;p&gt;A new feature, Scan processes on enable, scans processes that are already running when the McShield service becomes enabled. When the McShield service starts, the scanner examines any process that is already running and any process as it is launched. &lt;p&gt;· On-demand scan usability improvements &lt;p&gt;When initiating an on-demand right-click scan, you can now choose an action to take on items detected by the scan. These options are available: &lt;p&gt;· Clean �?? Report and clean the detection. &lt;p&gt;· Continue �?? Report the detection and continue scanning.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=122700" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/403989891" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/iEg3uNkNJWg" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/09/26/mcafee-virusscan-enterprise-8-7i-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/403989891/mcafee-virusscan-enterprise-8-7i-released.aspx</feedburner:origLink></item><item><title>SunbeltBlog: CounterSpy Enterprise 3.1 ships</title><link>http://feedproxy.google.com/~r/aberges/~3/0ObeliV2wgY/sunbeltblog-counterspy-enterprise-3-1-ships.aspx</link><pubDate>Wed, 20 Aug 2008 15:56:06 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121441</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121441</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/20/sunbeltblog-counterspy-enterprise-3-1-ships.aspx#comments</comments><description>&lt;p&gt;Screenshot here:&lt;/p&gt; &lt;p&gt;&lt;a title="http://sunbeltblog.blogspot.com/2008/08/counterspy-enterprise-31-ships.html" href="http://sunbeltblog.blogspot.com/2008/08/counterspy-enterprise-31-ships.html"&gt;http://sunbeltblog.blogspot.com/2008/08/counterspy-enterprise-31-ships.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;This is a big upgrade to their product.&amp;nbsp; I&amp;#39;m quite excited to deploy it in our environment as the performance increase and definition overhead decrease have been talked about on their mailing lists for months now.&amp;nbsp; I&amp;#39;ll be sure to post my impressions when I begin testing.&lt;/p&gt; &lt;p&gt;More info on the product can be found here:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.prweb.com/releases/2008/08/prweb1223244.htm" href="http://www.prweb.com/releases/2008/08/prweb1223244.htm"&gt;http://www.prweb.com/releases/2008/08/prweb1223244.htm&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121441" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/370081410" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/0ObeliV2wgY" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Malware/default.aspx">Malware</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/CounterSpy/default.aspx">CounterSpy</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Sunbelt/default.aspx">Sunbelt</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/20/sunbeltblog-counterspy-enterprise-3-1-ships.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/370081410/sunbeltblog-counterspy-enterprise-3-1-ships.aspx</feedburner:origLink></item><item><title>Adobe PSIRT: Flash Player "Clipboard Attack"</title><link>http://feedproxy.google.com/~r/aberges/~3/VKQayHXh828/adobe-psirt-flash-player-quot-clipboard-attack-quot.aspx</link><pubDate>Wed, 20 Aug 2008 13:06:51 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121430</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121430</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/20/adobe-psirt-flash-player-quot-clipboard-attack-quot.aspx#comments</comments><description>&lt;p&gt;&lt;a title="http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html" href="http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html"&gt;http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;We are aware of recent press reports about a potential �??Clipboard attack�?? issue that involves Flash Player. Adobe is currently investigating potential solutions to this issue and will update customers as soon as we have more information to provide.&lt;/p&gt; &lt;p&gt;More information and links available from the below source:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.theregister.co.uk/2008/08/15/webbased_clipboard_hijacking/" href="http://www.theregister.co.uk/2008/08/15/webbased_clipboard_hijacking/"&gt;http://www.theregister.co.uk/2008/08/15/webbased_clipboard_hijacking/&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121430" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/369958265" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/VKQayHXh828" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Adobe/default.aspx">Adobe</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Vulnerability/default.aspx">Vulnerability</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/20/adobe-psirt-flash-player-quot-clipboard-attack-quot.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/369958265/adobe-psirt-flash-player-quot-clipboard-attack-quot.aspx</feedburner:origLink></item><item><title>CVE-2008-3648: Remote Code Execution Exploit with Windows XP nslookup.exe</title><link>http://feedproxy.google.com/~r/aberges/~3/0EDmGueDqnQ/cve-2008-3648-remote-code-execution-exploit-with-windows-xp-nslookup-exe.aspx</link><pubDate>Tue, 19 Aug 2008 13:49:59 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121405</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121405</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/cve-2008-3648-remote-code-execution-exploit-with-windows-xp-nslookup-exe.aspx#comments</comments><description>&lt;p&gt;&lt;a title="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3648" href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3648"&gt;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3648&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Overview &lt;p&gt;nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.  &lt;p&gt;Impact &lt;p&gt;CVSS Severity (version 2.0):&lt;br /&gt;CVSS v2 Base score: &lt;a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2008-3648&amp;amp;vector=%28AV:N/AC:M/Au:N/C:C/I:C/A:C%29"&gt;9.3&lt;/a&gt; (High) &lt;a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2008-3648&amp;amp;vector=%28AV:N/AC:M/Au:N/C:C/I:C/A:C%29"&gt;(AV:N/AC:M/Au:N/C:C/I:C/A:C)&lt;/a&gt; (&lt;a href="http://nvd.nist.gov/cvss.cfm?vectorinfo&amp;amp;version=2"&gt;legend&lt;/a&gt;) &lt;br /&gt;Impact Subscore: 10.0&lt;br /&gt;Exploitability Subscore: 8.6 &lt;br /&gt;Access Vector: Network exploitable , Victim must voluntarily interact with attack mechanism &lt;br /&gt;Access Complexity: Medium &lt;br /&gt;Authentication: Not required to exploit &lt;br /&gt;Impact Type: Allows unauthorized disclosure of information , Allows unauthorized modification , Allows disruption of service &lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121405" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/369049579" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/0EDmGueDqnQ" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Microsoft/default.aspx">Microsoft</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/cve-2008-3648-remote-code-execution-exploit-with-windows-xp-nslookup-exe.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/369049579/cve-2008-3648-remote-code-execution-exploit-with-windows-xp-nslookup-exe.aspx</feedburner:origLink></item><item><title>BlackBerry Updates Attachment Service PDF Security Advisory</title><link>http://feedproxy.google.com/~r/aberges/~3/SUujOh8AnTE/blackberry-updates-attachment-service-pdf-security-advisory.aspx</link><pubDate>Tue, 19 Aug 2008 13:30:34 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121403</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121403</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/blackberry-updates-attachment-service-pdf-security-advisory.aspx#comments</comments><description>&lt;p&gt;RIM has released version 4.1 Service Pack 6 (4.1.6) to address the vulnerability, giving an alternative to their prior suggested workaround of blocking the processing of PDF files:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB15766&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=KB15766" href="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB15766&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=KB15766"&gt;http://www.blackberry.com/btsc/dynamickc.do?externalId=KB15766&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=KB15766&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Download the new version here:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.blackberry.com/go/serverdownloads" href="http://www.blackberry.com/go/serverdownloads"&gt;http://www.blackberry.com/go/serverdownloads&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121403" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/369049580" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/SUujOh8AnTE" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/blackberry-updates-attachment-service-pdf-security-advisory.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/369049580/blackberry-updates-attachment-service-pdf-security-advisory.aspx</feedburner:origLink></item><item><title>Cisco Security Advisory: Vulnerability in Cisco WebEx Meeting Manager ActiveX Control</title><link>http://feedproxy.google.com/~r/aberges/~3/uDMXot2ZCY4/cisco-security-advisory-vulnerability-in-cisco-webex-meeting-manager-activex-control.aspx</link><pubDate>Tue, 19 Aug 2008 13:23:15 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121402</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121402</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/cisco-security-advisory-vulnerability-in-cisco-webex-meeting-manager-activex-control.aspx#comments</comments><description>&lt;h4&gt;&lt;a name="summary"&gt;Summary&lt;/a&gt;&lt;/h4&gt; &lt;blockquote&gt; &lt;p&gt;A buffer overflow vulnerability exists in an ActiveX control used by the WebEx Meeting Manager. Exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the user client machine. The WebEx Meeting Manager is a client-side program that is provided by the Cisco WebEx meeting service. The Cisco WebEx meeting service automatically downloads, installs, and configures Meeting Manager the first time a user begins or joins a meeting. &lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;When users connect to the WebEx meeting service, the WebEx Meeting Manager is automatically upgraded to the latest version. There is a manual workaround available for users who are not able to connect to the WebEx meeting service. &lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;Cisco WebEx is in the process of upgrading the meeting service infrastructure with fixed versions of the affected file.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Full advisory here: &lt;a title="http://www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml" href="http://www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml"&gt;http://www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml&lt;/a&gt; &lt;p&gt;PDF download here: &lt;a title="http://www.cisco.com/univercd/cc/lib/csco/pdf_opt.gif" href="http://www.cisco.com/univercd/cc/lib/csco/pdf_opt.gif"&gt;http://www.cisco.com/univercd/cc/lib/csco/pdf_opt.gif&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121402" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/369049581" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/uDMXot2ZCY4" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Vulnerability/default.aspx">Vulnerability</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/cisco-security-advisory-vulnerability-in-cisco-webex-meeting-manager-activex-control.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/369049581/cisco-security-advisory-vulnerability-in-cisco-webex-meeting-manager-activex-control.aspx</feedburner:origLink></item><item><title>SunbeltBlog: CounterSpy 3.1 ships</title><link>http://feedproxy.google.com/~r/aberges/~3/XwwYCI1ALj0/sunbeltblog-counterspy-3-1-ships.aspx</link><pubDate>Tue, 19 Aug 2008 13:11:37 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121401</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121401</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/sunbeltblog-counterspy-3-1-ships.aspx#comments</comments><description>&lt;p&gt;&lt;/embed&gt;&lt;br /&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;Today, we officially released the consumer version of our all-new CounterSpy 3.1 product. (It�??s actually version 3, but due to having to align our version numbering scheme with our Enterprise version, it was released as 3.1). &lt;/p&gt; &lt;p&gt;This is a major upgrade to CounterSpy. All-new threat engine, all new technology �?? completely re-written from the ground-up for fast performance. As always, none of our products bundle toolbars, our trial versions are full versions, and we provide free support.&lt;br /&gt;&lt;br /&gt;Give it a whirl and let me know what you think. You can always email me your opinions &lt;a href="mailto:alexe@sunbeltsoftware.com"&gt;directly&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Users of VIPRE will find the interface familiar �?? CounterSpy is simply a sub-set of VIPRE, excluding features specific to viruses. CounterSpy customers can &lt;a href="http://shop.sunbelt-software.com/upgrade.cfm"&gt;upgrade&lt;/a&gt; at anytime to the VIPRE product for a small cost.&lt;br /&gt;&lt;br /&gt;One small note: Unlike a �??silent�?? preview edition posted last week on our website, this version comes with the On Access feature of Active Protection disabled by default (it can always be re-enabled). This feature will invariably conflict with some antivirus programs�?? real-time protection, and since almost everyone runs this product alongside their existing antivirus product, it�??s not necessary. A further explanation is in our video tutorial &lt;a href="http://www.sunbeltsoftware.com/ihs/aptutorial.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Full company propaganda &lt;a href="http://www.sunbeltsoftware.com/Press/Releases/?id=240"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;/p&gt; &lt;div class="feedflare"&gt;&lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=UcDKFK"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=UcDKFK" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=ydSgIK"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=ydSgIK" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=SdBvAK"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=SdBvAK" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=F8SmXk"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=F8SmXk" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=9wrO9k"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=9wrO9k" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=KzK74k"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=KzK74k" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=HeIbpK"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=HeIbpK" border="0" alt="" /&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SunbeltBlog?a=oNvtAk"&gt;&lt;img src="http://feeds.feedburner.com/~f/SunbeltBlog?i=oNvtAk" border="0" alt="" /&gt;&lt;/a&gt; &lt;/div&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://feeds.feedburner.com/~r/SunbeltBlog/~3/368233034/counterspy-31-ships.html"&gt;CounterSpy 3.1 ships&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121401" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/369031378" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/XwwYCI1ALj0" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/CounterSpy/default.aspx">CounterSpy</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Sunbelt/default.aspx">Sunbelt</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/19/sunbeltblog-counterspy-3-1-ships.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/369031378/sunbeltblog-counterspy-3-1-ships.aspx</feedburner:origLink></item><item><title>Adobe Customization Wizard 9 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/tRXaGiC51yA/adobe-customization-wizard-9-released.aspx</link><pubDate>Fri, 08 Aug 2008 14:54:27 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121056</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121056</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/08/adobe-customization-wizard-9-released.aspx#comments</comments><description>&lt;p&gt;Adobe&amp;#39;s customization tool has been updated for the latest version 9 release.&lt;/p&gt; &lt;p&gt;Download it here:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3993" href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3993"&gt;http://www.adobe.com/support/downloads/detail.jsp?ftpID=3993&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121056" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/359514954" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/tRXaGiC51yA" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Adobe/default.aspx">Adobe</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/08/adobe-customization-wizard-9-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/359514954/adobe-customization-wizard-9-released.aspx</feedburner:origLink></item><item><title>F-Secure Weblog: F-Secure Rescue CD 3.00</title><link>http://feedproxy.google.com/~r/aberges/~3/ea0SUokIUWw/f-secure-weblog-f-secure-rescue-cd-3-00.aspx</link><pubDate>Fri, 08 Aug 2008 14:53:03 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:121055</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=121055</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/08/f-secure-weblog-f-secure-rescue-cd-3-00.aspx#comments</comments><description>&lt;p&gt;Our colleagues from the &lt;a href="http://www.f-secure.com/linux-weblog/"&gt;Linux team&lt;/a&gt; blogged about it last month, but it&amp;#39;s worth repeating:&lt;br /&gt;&lt;br /&gt;The latest version of our &lt;b&gt;Emergency Rescue CD&lt;/b&gt; is available.&lt;br /&gt;&lt;br /&gt;It&amp;#39;s a bootable Linux CD that can scan Windows hard drives (NTFS and FAT) as well attached USB drives.&lt;br /&gt;&lt;br /&gt;If the computer has an Internet connection, the virus definition databases are &lt;b&gt;updated automatically&lt;/b&gt;. If an Internet connection isn&amp;#39;t available, the definition databases can be manually updated using a USB drive.&lt;br /&gt;&lt;br /&gt;It&amp;#39;s an excellent support tool. It&amp;#39;s also one of the best ways to scan for MBR rootkit infections.&lt;br /&gt;&lt;br /&gt;You can download it from &lt;a href="http://www.f-secure.com/linux-weblog/files/f-secure-rescue-cd-release-3.00.zip"&gt;here&lt;/a&gt; and read more details from the Linux team&amp;#39;s &lt;a href="http://www.f-secure.com/linux-weblog/2008/06/19/f-secure-rescue-cd-300-released/"&gt;post&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;img height="300" alt="F-Secure Rescue CD3" src="http://www.f-secure.com/weblog/archives/FS_Rescue_CD3.gif" width="200" border="0" /&gt;  &lt;p&gt;On 24/07/08 At 03:43 PM&lt;/p&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.f-secure.com/weblog/archives/00001474.html"&gt;F-Secure Rescue CD 3.00&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121055" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/359514960" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/ea0SUokIUWw" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Malware/default.aspx">Malware</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Antivirus/default.aspx">Antivirus</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/08/f-secure-weblog-f-secure-rescue-cd-3-00.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/359514960/f-secure-weblog-f-secure-rescue-cd-3-00.aspx</feedburner:origLink></item><item><title>McAfee VirusScan 5300 Engine Released</title><link>http://feedproxy.google.com/~r/aberges/~3/Z-jvLFzlVmc/mcafee-virusscan-5300-engine-released.aspx</link><pubDate>Thu, 07 Aug 2008 15:33:18 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:120997</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=120997</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/07/mcafee-virusscan-5300-engine-released.aspx#comments</comments><description>&lt;p&gt;New Features:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Improved automatic identification and removal of malware delivering to the customer the next generation of best-of-breed Anti-Virus Scanning Engines. The 5300 Anti-Virus Scanning Engine offers improved protection against existing, new and future threats and increases the depth and breadth of the protection McAfee provide our customers.  &lt;li&gt;100% drop-in compatibility with the existing McAfee Anti-Virus Scanning Engine and DAT files. It&amp;#39;s easy to upgrade; just replace your existing Engine with the new version and you&amp;#39;re protected.  &lt;li&gt;Enhanced support for detection and repair for Office 12 documents, as well as improved ZIP file support.  &lt;li&gt;Support for Solaris 10 on Intel x86 and x64.  &lt;li&gt;Support for FreeBSD 6.2 and 7.0  &lt;li&gt;Support for HP-UX 11i v3 on PA-Risc &lt;/li&gt;&lt;/ul&gt;Download here: &lt;p&gt;&lt;a title="http://www.mcafee.com/apps/downloads/security_updates/engines.asp" href="http://www.mcafee.com/apps/downloads/security_updates/engines.asp"&gt;http://www.mcafee.com/apps/downloads/security_updates/engines.asp&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=120997" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/358532374" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/Z-jvLFzlVmc" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Antivirus/default.aspx">Antivirus</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/07/mcafee-virusscan-5300-engine-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/358532374/mcafee-virusscan-5300-engine-released.aspx</feedburner:origLink></item><item><title>VIPRE Enterprise Released</title><link>http://feedproxy.google.com/~r/aberges/~3/2e6TnXE4YXo/vipre-enterprise-released.aspx</link><pubDate>Tue, 05 Aug 2008 18:20:15 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:120937</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=120937</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/05/vipre-enterprise-released.aspx#comments</comments><description>&lt;p&gt;The new enterprise managed AV / AntiSpyware solution from Sunbelt Software:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.vipreenterprise.com/" href="http://www.vipreenterprise.com/"&gt;http://www.vipreenterprise.com/&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Press release available here:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.sunbeltsoftware.com/Press/Releases/?id=238" href="http://www.sunbeltsoftware.com/Press/Releases/?id=238"&gt;http://www.sunbeltsoftware.com/Press/Releases/?id=238&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=120937" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/356636507" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/2e6TnXE4YXo" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Malware/default.aspx">Malware</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Antivirus/default.aspx">Antivirus</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Sunbelt/default.aspx">Sunbelt</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/08/05/vipre-enterprise-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/356636507/vipre-enterprise-released.aspx</feedburner:origLink></item><item><title>CounterSpy Agent 2.x Enterprise: ThreatDB download "stuck"</title><link>http://feedproxy.google.com/~r/aberges/~3/WpJhDU4BF5Q/counterspy-agent-2-x-enterprise-threatdb-download-quot-stuck-quot.aspx</link><pubDate>Tue, 29 Jul 2008 19:15:09 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:120614</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=120614</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/29/counterspy-agent-2-x-enterprise-threatdb-download-quot-stuck-quot.aspx#comments</comments><description>&lt;p&gt;Today I ran into an issue with a client that seemed unable to download the latest CounterSpy Enterprise ThreatDB.&lt;/p&gt; &lt;p&gt;Normally invoking a quick or full scan forces a download of the local ThreatDB -- either from the local server or from the Internet as a fallback if the client is so configured.&lt;/p&gt; &lt;p&gt;In this particular case, the client was not updating the DB, which was causing problems with network connectivity due to certain safeguards we have in place.&lt;/p&gt; &lt;p&gt;I&amp;#39;ve found that the best solution in these types of cases is to stop the CounterSpyAgent service and delete SBTS.dat and SBTEDef.idx.&amp;nbsp; These are the ThreatDB files themselves and when the CounterSpyAgent service is then restarted, it will re-download a full DB from the server/Internet as the case may be.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=120614" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/349722964" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/WpJhDU4BF5Q" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/CounterSpy/default.aspx">CounterSpy</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/29/counterspy-agent-2-x-enterprise-threatdb-download-quot-stuck-quot.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/349722964/counterspy-agent-2-x-enterprise-threatdb-download-quot-stuck-quot.aspx</feedburner:origLink></item><item><title>McAfee Agent 4.0 - Comments and Complaints</title><link>http://feedproxy.google.com/~r/aberges/~3/SC99-3-mVUg/mcafee-agent-4-0-comments-and-complaints.aspx</link><pubDate>Mon, 28 Jul 2008 19:19:12 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:120555</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=120555</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/mcafee-agent-4-0-comments-and-complaints.aspx#comments</comments><description>&lt;p&gt;Recently I deployed McAfee Agent 4.0 to one of our company&amp;#39;s ePO 4 Server and Windows workstation clients after a bit of testing with relative success.&amp;nbsp; &lt;/p&gt; &lt;p&gt;For those interested, the master list of support articles for the 4.0 Agent is located here:&lt;/p&gt; &lt;p&gt;&lt;a title="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=615002&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=615002" href="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=615002&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=615002"&gt;https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=615002&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=615002&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Release notes are available here:&lt;/p&gt; &lt;p&gt;&lt;a title="https://knowledge.mcafee.com/SupportSite/dynamickc.do?sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;externalId=615005" href="https://knowledge.mcafee.com/SupportSite/dynamickc.do?sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;externalId=615005"&gt;https://knowledge.mcafee.com/SupportSite/dynamickc.do?sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;externalId=615005&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Major changes to the Windows agent include the ability to detect laptops and x64 OS&amp;#39;s and query/tag based on those properties (which also means you can now leverage things like only deploying PreScan to Win32 clients, or only applying HIPS to laptops without using a 3rd party deployment tool), changes to the sitelist.xml format that allow for DNS and NetBIOS-based entries instead of solely IP-based, as well as changes to the installer format.&lt;/p&gt; &lt;p&gt;Since the new McAfee Agent 4.0 enters itself in Add/Remove Programs, I created a WQL query to create a collection that would identify those that did not have the McAfee Agent listed in ARP.&amp;nbsp; In the future, I&amp;#39;ll need to change this to query on version but currently this is how I&amp;#39;m identifying clients that need the upgrade:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;select SMS_R_System.ResourceID,SMS_R_System.ResourceType,SMS_R_System.Name,SMS_R_System.SMSUniqueIdentifier,SMS_R_System.ResourceDomainORWorkgroup,SMS_R_System.Client from SMS_R_System where Name not in (select SMS_R_System.Name from SMS_R_System inner join SMS_G_System_ADD_REMOVE_PROGRAMS on SMS_G_System_ADD_REMOVE_PROGRAMS.ResourceID = SMS_R_System.ResourceId where SMS_G_System_ADD_REMOVE_PROGRAMS.DisplayName = &amp;quot;McAfee Agent&amp;quot;)&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;This WQL statement will definitely need to be revised in the near future to account for version variations.&amp;nbsp; When I make the adjustments, I&amp;#39;ll post them here.&lt;/p&gt; &lt;p&gt;Incidentally, McAfee Windows Agent 4.0 Hotfix 1 has been released.&amp;nbsp; (FYI The build version for this particular hotfix is 4.0.0.1318 vs. 4.0.0.1180 for the shipping version) &lt;/p&gt; &lt;p&gt;You&amp;#39;ll need to open a case with PrimeSupport in order to receive it however as it is not yet available via the PrimeSupport portal.&amp;nbsp; More details here:&lt;/p&gt; &lt;p&gt;&lt;a title="https://knowledge.mcafee.com/article/200/616270_f.SAL_Public.html" href="https://knowledge.mcafee.com/article/200/616270_f.SAL_Public.html"&gt;https://knowledge.mcafee.com/article/200/616270_f.SAL_Public.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Resolved issues:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;Issue: The McAfee Agent&amp;#39;s ability to perform updates is blocked when the name of the installation or data folders includes an extended ASCII character. (Reference: 404111)&lt;br /&gt;Resolution:The McAfee Agent&amp;#39;s ability to update is no longer blocked if the installation or data folder names include an extended ASCII character. &lt;li&gt;Issue: The McAfee Agent process &amp;quot;RunPullTask&amp;quot; would run, but it wouldn&amp;#39;t copy SiteStat.xml to the specified mirror location. (Reference: 409637)&lt;br /&gt;Resolution:The McAfee Agent process &amp;quot;RunPullTask&amp;quot; now creates a SiteStat.xml file in the appropriate mirror location. &lt;li&gt;Issue:When a managed product&amp;#39;s plug-in required a reboot, the user was prompted, but the computer rebooted even when the user selected No. (Reference: 410573)&lt;br /&gt;Resolution:The McAfee Agent now responds correctly based on the user&amp;#39;s selection. &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Impressions of McAfee Agent 4.0:&lt;/p&gt; &lt;p&gt;Although I can&amp;#39;t say installation went off flawlessly (more on that in a moment), the installation was completely transparent to the end user and the new x64 and IsLaptop properties seem to be detected correctly on clients, as I have tags automatically applied based on these criteria and they began functioning immediately.&amp;nbsp; I cannot speak for the changes to the sitelist.xml as we&amp;#39;re not basing our repositories on DNS or NetBIOS, I can only say that the clients are still updating properly post-installation.&lt;/p&gt; &lt;p&gt;Gripes about installation:&lt;/p&gt; &lt;p&gt;Just like many McAfee updates before, despite the fact that I alter my deployment and update tasks accordingly, often days and/or weeks before checking an update package into the server, I still find that the update will be applied to numerous machines where the task explicitly states not to update that particular component.&amp;nbsp; In this case, checking in Agent 4 resulted in it being deployed to numerous machines where the deployment task should have prevented its installation.&amp;nbsp; One of the advantages of ePolicy Orchestrator 4 is the ability to view task inheritance and review that no task inheritance is broken (or at least only those you want broken), and I verified this days before checking in the package.&amp;nbsp; In an environment such as ours where due to compliance issues we tightly regulate the deployment of *ANY* software update, this is unacceptable.&lt;/p&gt; &lt;p&gt;It isn&amp;#39;t as if I haven&amp;#39;t observed this many times in the past in multiple environments, but it is disappointing to see that it is still an issue.&amp;nbsp; I don&amp;#39;t know if this is a remnant of the glitches I&amp;#39;ve observed in 3.6, but I&amp;#39;m hopeful that the 4.0 agent may address this glaring flaw moving forward.&amp;nbsp; I guess I&amp;#39;ll find out when I begin applying &lt;a href="http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/mcafee-virusscan-enterprise-8-5-patch-6-1-released.aspx"&gt;McAfee VirusScan 8.5 Patch 6.1&lt;/a&gt;...&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=120555" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/348703809" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/SC99-3-mVUg" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Complaints/default.aspx">Complaints</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/mcafee-agent-4-0-comments-and-complaints.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/348703809/mcafee-agent-4-0-comments-and-complaints.aspx</feedburner:origLink></item><item><title>Light posting lately...</title><link>http://feedproxy.google.com/~r/aberges/~3/-3SFrHhIVmQ/light-posting-lately.aspx</link><pubDate>Mon, 28 Jul 2008 18:32:15 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:120546</guid><dc:creator>aberges</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=120546</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/light-posting-lately.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;ve been working on a few things in and out of the office which I will blog about soon, but mainly, things have been pretty much busy yet uneventful and I haven&amp;#39;t had much to say here.&amp;nbsp; All that will change soon, as I have a few new projects about to begin...&lt;/p&gt; &lt;p&gt;But before that, expect there will be very few updates in the next week, as I will be basking in the Bermuda sun starting Wednesday afternoon :)&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=120546" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/348648003" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/-3SFrHhIVmQ" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Miscellaneous/default.aspx">Miscellaneous</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/light-posting-lately.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/348648003/light-posting-lately.aspx</feedburner:origLink></item><item><title>McAfee VirusScan Enterprise 8.5 Patch 6.1 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/hA32ZEkjG9U/mcafee-virusscan-enterprise-8-5-patch-6-1-released.aspx</link><pubDate>Mon, 28 Jul 2008 14:24:46 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:120534</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=120534</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/mcafee-virusscan-enterprise-8-5-patch-6-1-released.aspx#comments</comments><description>&lt;p&gt;Details here:&lt;/p&gt; &lt;p&gt;&lt;a title="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=616311&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=616311" href="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=616311&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=616311"&gt;https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=616311&amp;amp;sliceId=SAL_Public&amp;amp;command=show&amp;amp;forward=nonthreadedKC&amp;amp;kcId=616311&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Improvements:&lt;/p&gt; &lt;p&gt;1.&amp;nbsp; The on-demand scanner has been updated to better&amp;nbsp; use the System Utilization setting throughout the entire scanning process.  &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Refer to McAfee Support Knowledgebase article 9197288 for further information.  &lt;p&gt;2.&amp;nbsp; This Patch contains a new Buffer Overflow and Access Protection DAT (version 378) which adds an Access Protection category for Virtual Machine Protection. These rules provide access protection functionality for virtual machines.  &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; In order to manage the new Virtual Machine Protection category with ePolicy Orchestrator 3.x or Protection Pilot, you will need to use the latest NAP file, included in this Patch&amp;nbsp; package, or VirusScan 8.5i Repost Patch 5.  &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; For ePolicy Orchestrator 4.x users, the Extension update also contains the updated rule file. The updated Extension package is available on the web product download area under the Patches category. &lt;p&gt;PATCH 6.1 RESOLVED ISSUES &lt;p&gt;1. ISSUE:&lt;br /&gt;An issue can occur when the 5300 engine is installed prior to installing VirusScan 8.5i Patch 6. The scanner engine files are partially overwritten with the previous 5200 version that is stored in the MSI cache. This mismatch causes the scanner engine to fail to initialize. &lt;p&gt;RESOLUTION:&lt;br /&gt;The Patch installation package has been updated to correct this issue, and does not overwrite the engine files. &lt;p&gt;PATCH 6 RESOLVED ISSUES &lt;p&gt;1. ISSUE:&lt;br /&gt;The VirusScan Enterprise management plug-in writes all settings to the registry on every policy enforcement. McShield service monitors the registry and reloads whenever the settings are written, generating frequent pause events in the Windows System log. &lt;p&gt;RESOLUTION:&lt;br /&gt;The VirusScan Enterprise management plug-in has been updated to only write to the registry if it sees that it is different from the current policy. This will prevent McShield from generating events on policy enforcement, unless that policy has changed. &lt;p&gt;This is an addendum to the original solution in Patch 5, where the fix did not work when the preferred language was set to something other then automatic. &lt;p&gt;2. ISSUE:&lt;br /&gt;A compatibility issue has been seen with VirusScan�??s port blocking feature, and Veritas backup applications. This was causing the backup software services to stop running. &lt;p&gt;RESOLUTION:&lt;br /&gt;The VirusScan Anti-Virus Mini-Firewall Driver has been updated to correct the compatibility issue. &lt;p&gt;3. ISSUE:&lt;br /&gt;A race condition in the On-Access Scanner service can cause high CPU utilization with high performance systems. &lt;p&gt;RESOLUTION:&lt;br /&gt;The On-Access Scanner service has been updated to remedy multi-threading synchronization issues and remove occurrences of runaway threads. &lt;p&gt;4. ISSUE:&lt;br /&gt;The On-Access Scanner service sometimes crashes during a system shutdown or during installation of a Patch/HotFix. &lt;p&gt;RESOLUTION:&lt;br /&gt;The On-Access Scanner service has been repaired to correct a race condition in which a critical-section synchronization object is deleted before another thread has entered. &lt;p&gt;5. ISSUE:&lt;br /&gt;A deadlock could occur on high end servers caused by a race condition in VirusScan�??s link driver. &lt;p&gt;RESOLUTION:&lt;br /&gt;The link driver has been changed to properly handle the release of system objects, while holding a lock on resources. &lt;p&gt;6. ISSUE:&lt;br /&gt;Port blocking fails on Microsoft Windows Vista Service Pack 1. &lt;p&gt;RESOLUTION:&lt;br /&gt;The McAfee Driver Installer has been update to handle the changes in network stack load order. &lt;p&gt;7. ISSUE:&lt;br /&gt;The On-Demand Scanner system utilization changes that were put in patch 5 changed the memory scanning function. This caused the process&lt;br /&gt;scanning to only scan the first process ID. &lt;p&gt;RESOLUTION:&lt;br /&gt;The change has been reversed so that all processes are scanning irrespective of process ID. &lt;p&gt;8. ISSUE:&lt;br /&gt;When applied to a client installation that was customized by McAfee Installation Designer (MID), the patch installer deletes the MidFileTime registry value. This caused MID .CAB files to be re-applied to the system. &lt;p&gt;RESOLUTION:&lt;br /&gt;The patch installer has been updated to no longer delete the MidFileTime registry value. &lt;p&gt;9. ISSUE:&lt;br /&gt;A newly created user defined Unwanted Program Policy, does not take affect immediately if the file has been scanned by the On-Access Scanner before the change occurred. &lt;p&gt;RESOLUTION:&lt;br /&gt;The On-Access Scanner service has been updated to properly recognize changes to the user defined detections and clear the cache of files that have already been scanned so that the new settings take effect immediately. &lt;p&gt;10. ISSUE:&lt;br /&gt;A trust relationship exists in McAfee drivers that can be leveraged by McAfee processes to avoid triggering access protection rules and other compatibility symptoms. When the link driver was updated to newer releases this trust relationship was lost until a reboot occurred. &lt;p&gt;RESOLUTION:&lt;br /&gt;The link driver has been modified to better handle the process of future upgrades to itself without the need for a reboot.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=120534" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/348435658" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/hA32ZEkjG9U" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Antivirus/default.aspx">Antivirus</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/28/mcafee-virusscan-enterprise-8-5-patch-6-1-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/348435658/mcafee-virusscan-enterprise-8-5-patch-6-1-released.aspx</feedburner:origLink></item><item><title>WQL - Identifying Clients requiring Adobe Acrobat and Reader 8.1.2 Security Update 1</title><link>http://feedproxy.google.com/~r/aberges/~3/PYoIqwZDAiw/wql-identifying-clients-requiring-adobe-acrobat-and-reader-8-1-2-security-update-1.aspx</link><pubDate>Fri, 11 Jul 2008 15:24:40 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:119778</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=119778</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/11/wql-identifying-clients-requiring-adobe-acrobat-and-reader-8-1-2-security-update-1.aspx#comments</comments><description>&lt;p&gt;After reading &lt;a href="http://isc.sans.org/diary.php?storyid=4711&amp;amp;rss"&gt;this post&lt;/a&gt; on the SANS ISC weblog, I thought I would provide the WQL I&amp;#39;m currently using in SMS to deploy the Adobe Acrobat and Reader 8.1.2 security update.&lt;/p&gt; &lt;p&gt;The following WQL will query Add/Remove Programs on clients and identify those who have Acrobat or Reader 8.1.2 but not the Security Update 1.&amp;nbsp; Hope someone finds this useful:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;select SMS_R_System.ResourceID,SMS_R_System.ResourceType,SMS_R_System.Name,SMS_R_System.SMSUniqueIdentifier,SMS_R_System.ResourceDomainORWorkgroup,SMS_R_System.Client from SMS_R_System inner join SMS_G_System_ADD_REMOVE_PROGRAMS on SMS_G_System_ADD_REMOVE_PROGRAMS.ResourceID = SMS_R_System.ResourceId where SMS_R_System.Name not in (select SMS_R_System.Name from&amp;nbsp; SMS_R_System inner join SMS_G_System_ADD_REMOVE_PROGRAMS on SMS_G_System_ADD_REMOVE_PROGRAMS.ResourceID = SMS_R_System.ResourceId where SMS_G_System_ADD_REMOVE_PROGRAMS.DisplayName = &amp;quot;Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)&amp;quot; ) and SMS_G_System_ADD_REMOVE_PROGRAMS.DisplayName in ( &amp;quot;Adobe Acrobat 8.1.2 Professional&amp;quot;, &amp;quot;Adobe Acrobat 8.1.2 Standard&amp;quot;, &amp;quot;Adobe Reader 8.1.2&amp;quot; )&lt;/p&gt;&lt;/blockquote&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=119778" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/332766227" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/PYoIqwZDAiw" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/SMS/default.aspx">SMS</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Adobe/default.aspx">Adobe</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/WQL/default.aspx">WQL</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/11/wql-identifying-clients-requiring-adobe-acrobat-and-reader-8-1-2-security-update-1.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/332766227/wql-identifying-clients-requiring-adobe-acrobat-and-reader-8-1-2-security-update-1.aspx</feedburner:origLink></item><item><title>Rogue System Detection 2.0 Update</title><link>http://feedproxy.google.com/~r/aberges/~3/yBKsEuJAGR0/rogue-system-detection-2-0-update.aspx</link><pubDate>Fri, 11 Jul 2008 14:51:01 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:119775</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=119775</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/11/rogue-system-detection-2-0-update.aspx#comments</comments><description>&lt;p&gt;Despite my HIPS exclusion to completely ignore port scans, I still was bombarded with alerts for a TCP port scan.&lt;/p&gt; &lt;p&gt;More interesting still, the System event viewer on many Windows clients was showing the following error once a day:&lt;/p&gt; &lt;p&gt;Event Type:&amp;nbsp;&amp;nbsp;&amp;nbsp; Error&lt;br /&gt;Event Source:&amp;nbsp;&amp;nbsp;&amp;nbsp; TermDD&lt;br /&gt;Event Category:&amp;nbsp;&amp;nbsp;&amp;nbsp; None&lt;br /&gt;Event ID:&amp;nbsp;&amp;nbsp;&amp;nbsp; 50&lt;br /&gt;Description:&lt;br /&gt;The RDP protocol component X.224 detected an error in the protocol stream and has disconnected the client.  &lt;p&gt;For more information, see Help and Support Center at &lt;a href="http://go.microsoft.com/fwlink/events.asp"&gt;http://go.microsoft.com/fwlink/events.asp&lt;/a&gt;.&lt;br /&gt; &lt;p&gt;So, yesterday I disabled &amp;quot;&lt;strong&gt;Device details detection&lt;/strong&gt;&amp;quot; in the policy for RSD sensors.&amp;nbsp; Today, no more alerts and no more errors.&amp;nbsp; Too bad I have to turn this off, but it seems to be more trouble than it&amp;#39;s worth.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=119775" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/332741057" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/yBKsEuJAGR0" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/HIPS/default.aspx">HIPS</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/RSD/default.aspx">RSD</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/11/rogue-system-detection-2-0-update.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/332741057/rogue-system-detection-2-0-update.aspx</feedburner:origLink></item><item><title>Java Runtime Environment 6.0 Update 7 Released</title><link>http://feedproxy.google.com/~r/aberges/~3/jv29QjTuipY/java-runtime-environment-6-0-update-7-released.aspx</link><pubDate>Wed, 09 Jul 2008 20:04:34 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:119632</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=119632</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/09/java-runtime-environment-6-0-update-7-released.aspx#comments</comments><description>&lt;p&gt;Download the update here:&lt;/p&gt; &lt;p&gt;&lt;a href="http://tinyurl.com/6zdjph"&gt;http://tinyurl.com/6zdjph&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Release notes here:&lt;/p&gt; &lt;p&gt;&lt;a title="http://java.sun.com/javase/6/webnotes/ReleaseNotes.html" href="http://java.sun.com/javase/6/webnotes/ReleaseNotes.html"&gt;http://java.sun.com/javase/6/webnotes/ReleaseNotes.html&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=119632" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/331992663" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/jv29QjTuipY" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Updates/default.aspx">Updates</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Java/default.aspx">Java</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/09/java-runtime-environment-6-0-update-7-released.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/331992663/java-runtime-environment-6-0-update-7-released.aspx</feedburner:origLink></item><item><title>McAfee Rogue System Detection 2.0 - HIPS 7.0 Port Scan Alerts</title><link>http://feedproxy.google.com/~r/aberges/~3/zINdPryR5u4/mcafee-rogue-system-detection-2-0-hips-7-0-port-scan-alerts.aspx</link><pubDate>Wed, 09 Jul 2008 19:55:02 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:119630</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=119630</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/09/mcafee-rogue-system-detection-2-0-hips-7-0-port-scan-alerts.aspx#comments</comments><description>&lt;p&gt;I installed Rogue System Detection 2.0 for ePolicy Orchestrator 4.0 yesterday.&amp;nbsp; Setup completed without a hitch, and I didn&amp;#39;t even need to install it separately as an extension like most of their products.&lt;/p&gt; &lt;p&gt;It&amp;#39;s not much different than the 1.0 version.&amp;nbsp; The sensor deployment seems a bit more reliable, and the new web frontend is definitely slick.&amp;nbsp; I spent the better part of the day methodically identifying and excluding networking devices and the like, and I&amp;#39;m pleased to say that there are a negligible number of malfunctioning McAfee agents in our environment.&amp;nbsp; Deploying an agent package cleared most of the issues up and I&amp;#39;m addressing the few remain individually.&lt;/p&gt; &lt;p&gt;The one thing I&amp;#39;ve noticed is that HIPS is flagging a Port Scan threat from the RSD sensor as it interrogates the client.&amp;nbsp; I&amp;#39;ve tried writing an exception for HIPS to disregard alerts for Port Scans against the IP&amp;#39;s in question, but it doesn&amp;#39;t seem to work.&amp;nbsp; Even excluding the signature altogether doesn&amp;#39;t seem to do it.&amp;nbsp; Actually, it doesn&amp;#39;t appear that the exclusions work all that well in HIPS 7 period... 6.x worked far more reliably and would say it was definitely easier to manage.&lt;/p&gt; &lt;p&gt;I am curious whether disabling &amp;quot;&lt;strong&gt;Device details detection&lt;/strong&gt;&amp;quot; in the Rogue System Detection policy would resolve this, or whether it just does an aggressive nmap style scan on detected systems altogether... in which case changing this would likely accomplish nothing.&amp;nbsp; Either way, I don&amp;#39;t think it&amp;#39;s the preferred method to take, as I&amp;#39;ll have a lot less data available for identifying IP&amp;#39;s that don&amp;#39;t report hostnames etc.&lt;/p&gt; &lt;p&gt;I suppose I&amp;#39;ll wait another day to see if client policy catches up and the HIPS clients stop sending me these darn alerts.&amp;nbsp; More to follow.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=119630" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/331992664" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/zINdPryR5u4" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/HIPS/default.aspx">HIPS</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/RSD/default.aspx">RSD</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/09/mcafee-rogue-system-detection-2-0-hips-7-0-port-scan-alerts.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/331992664/mcafee-rogue-system-detection-2-0-hips-7-0-port-scan-alerts.aspx</feedburner:origLink></item><item><title>ePolicy Orchestrator 4.0 Patch 2 / SQL 2005 / VMware - FAILURE: In LaunchAppAndWait</title><link>http://feedproxy.google.com/~r/aberges/~3/xnTSr4ovZlM/epolicy-orchestrator-4-0-patch-2-sql-2005-vmware-failure-in-launchappandwait.aspx</link><pubDate>Wed, 09 Jul 2008 15:09:44 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:119609</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=119609</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/09/epolicy-orchestrator-4-0-patch-2-sql-2005-vmware-failure-in-launchappandwait.aspx#comments</comments><description>&lt;p&gt;Monday I attempted to update our ePolicy Orchestrator server from 4.0 Patch 1 to 4.0 Patch 2.&lt;/p&gt; &lt;p&gt;Our ePO 4.0 Server resides as a guest on a VMware server with a remote SQL backend.&amp;nbsp; This is dissimilar from our old ePO 3.6.1 Server, which had its own instance of SQL 2000 locally.&amp;nbsp; Also, this time we are (well, were) using Windows authentication instead of SQL authentication, which we had in the past.&lt;/p&gt; &lt;p&gt;Patching the ePO Server has generally been a painless process, but this particular patch was over 150MB, so I had a sinking feeling that this wouldn&amp;#39;t be one of those times...&lt;/p&gt; &lt;p&gt;Turns out, I was right.&amp;nbsp; I got partway through the install - everything&amp;#39;s looking good... then BAM... out of the blue:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;Setup has encountered the error:&lt;br /&gt;FAILURE: In LaunchAppAndWait while trying to run the following program:  &lt;p&gt;&amp;quot;&amp;quot;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;And, yes, those are empty quotes.&amp;nbsp; Weird, I know.&lt;/p&gt; &lt;p&gt;A little digging in C:\Docume~1\username\Local Settings\Temp\NAILogs\EPO400-Patch-MSI.LOG shows a bit more to the error:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;FAILURE: In LaunchAppAndWait while trying to run the following program:&lt;br /&gt;&amp;quot;C:\PROGRA~1\McAfee\EPOLIC~1\jre\bin\java.exe&amp;quot; ... blah ... &lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Some Googling gave a bit more information in the form of a McAfee technote, appropriately titled &amp;quot;&lt;strong&gt;ePO 4.0 Patch 2 fails to install on a VMWare image containing ePO 4.0 and SQL Server 2005 / SQL 2005 Express&lt;/strong&gt;&amp;quot; and located here:  &lt;p&gt;&lt;a title="https://knowledge.mcafee.com/article/60/615839_f.SAL_Public.html" href="https://knowledge.mcafee.com/article/60/615839_f.SAL_Public.html"&gt;https://knowledge.mcafee.com/article/60/615839_f.SAL_Public.html&lt;/a&gt;  &lt;p&gt;The issue apparently results from the use of Windows authentication for SQL 2005, specifically when used on a VMware server.&amp;nbsp; In order to complete the patch, ePO must be configured to use an account with dbowner rights (note that it is &lt;strong&gt;*not*&lt;/strong&gt; required to use sa despite the KB using that as an example).&lt;/p&gt; &lt;p&gt;The following steps will resolve the issue:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Log in to your ePO Server at &lt;a href="http://servername:port/core/config"&gt;http://servername:port/core/config&lt;/a&gt;&amp;nbsp;&lt;/li&gt; &lt;li&gt;Change the user name to an appropriate SQL ID&lt;/li&gt; &lt;li&gt;Set the password accordingly&lt;/li&gt; &lt;li&gt;Remove the domain listed next to &lt;strong&gt;User domain&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;Click &lt;strong&gt;Test Connection&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;If the test completes successfully, click &lt;strong&gt;Apply&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;Restart the &amp;quot;&lt;strong&gt;McAfee ePolicy Orchestrator 4.0.0 Application Server&lt;/strong&gt;&amp;quot; service&lt;/li&gt; &lt;li&gt;Reapply the patch&lt;/li&gt; &lt;li&gt;Verify that the patch applied and all extensions were checked in successfully via the logfiles as per the patch 2 readme file&lt;/li&gt; &lt;li&gt;Verify that dashboards, etc function as intended.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;At this point you should be able to reverse the steps above to return ePO Server to use Windows authentication if you so desire.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=119609" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/331992667" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/xnTSr4ovZlM" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/McAfee/default.aspx">McAfee</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Patches/default.aspx">Patches</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/SQL/default.aspx">SQL</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/VMware/default.aspx">VMware</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/09/epolicy-orchestrator-4-0-patch-2-sql-2005-vmware-failure-in-launchappandwait.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/331992667/epolicy-orchestrator-4-0-patch-2-sql-2005-vmware-failure-in-launchappandwait.aspx</feedburner:origLink></item><item><title>Dusting off the blog...</title><link>http://feedproxy.google.com/~r/aberges/~3/BeXImw_gkCg/dusting-off-the-blog.aspx</link><pubDate>Wed, 02 Jul 2008 18:12:55 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:119281</guid><dc:creator>aberges</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=119281</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/02/dusting-off-the-blog.aspx#comments</comments><description>&lt;p&gt;It&amp;#39;s been over a year since I posted here.&amp;nbsp; I&amp;#39;ve been keeping myself busy at work with various projects... and many family obligations and other circumstances dictated that my blogging needed to take a backseat for the time being.&lt;/p&gt; &lt;p&gt;So what have I been up to tech-wise?&amp;nbsp; To name a few of the larger endeavors:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;I&amp;#39;ve upgraded our SMS heirarchy to SP3 and integrated the Asset Intelligence feature as well as the catalog update.&lt;/li&gt; &lt;li&gt;Installed Ron&amp;#39;s Web Remote Tools with Sherry&amp;#39;s tweaks, much to the happiness of both our technicians and my management.&amp;nbsp; If either of you read this, kudos to you both for providing these to the community.&amp;nbsp; It&amp;#39;s certainly made my life easier :)&lt;/li&gt; &lt;li&gt;I&amp;#39;ve replaced our production ePolicy Orchestrator 3.6.x environment with a VMware host running ePolicy Orchestrator 4.0 with Patch 1.&amp;nbsp; All VirusScan clients were upgraded to 8.5i with the 5200 engine.&amp;nbsp; All McAfee HIPS clients were upgraded to 7.0 with Patch 1.&amp;nbsp; More gripes about McAfee to follow in coming weeks, I&amp;#39;m sure.&amp;nbsp; There&amp;#39;s just not enough room here to post them all :)&lt;/li&gt; &lt;li&gt;I&amp;#39;ve deployed a series of CounterSpy Enterprise 2.0 &amp;quot;servers&amp;quot; (I use this term loosely) in our home office and branch offices throughout the globe and deployed a series of CounterSpy Enterprise agent versions to all clients in those offices.&amp;nbsp; CounterSpy was later upgraded to 3.0 for the servers.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;As well as many other, far-less interesting things like application deployments, which I won&amp;#39;t get in to here.&lt;/p&gt; &lt;p&gt;Lately I&amp;#39;ve been working in a few &amp;quot;new-to-me&amp;quot; areas: the Microsoft Deployment Toolkit (and WDS), SCCM 2007, x64 Operating Systems, and of course Vista&amp;nbsp; - all of which will be deployed as the standard within my organization in coming months.&lt;/p&gt; &lt;p&gt;I&amp;#39;ve recently been approved to begin a side-by-side deployment of SCCM SP1 and migrate all our existing SMS clients to the new infrastructure.&amp;nbsp; Following that, I anticipate going to SCCM Native Mode, and leveraging the OSD aspects of MDT and SCCM to standardize on a single image, phasing out the multiple Ghost image approach that is currently used by our technicians.&amp;nbsp; I hope to utilize this blog in part to document my process and any &amp;quot;lessons learned&amp;quot; along the way.&lt;/p&gt; &lt;p&gt;With that said, I&amp;#39;ll close this entry.&amp;nbsp; Stay tuned, more to follow!&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=119281" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/330820931" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/BeXImw_gkCg" height="1" width="1"/&gt;</description><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2008/07/02/dusting-off-the-blog.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/330820931/dusting-off-the-blog.aspx</feedburner:origLink></item><item><title>Anti-Malware Blog: SAP Internet Graphics Service (IGS) Remote Buffer Overflow</title><link>http://feedproxy.google.com/~r/aberges/~3/DPvdw4xLaYQ/anti-malware-blog-sap-internet-graphics-service-igs-remote-buffer-overflow.aspx</link><pubDate>Thu, 25 Jan 2007 14:58:13 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:92492</guid><dc:creator>aberges</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://myitforum.com/cs2/blogs/aberges/rsscomments.aspx?PostID=92492</wfw:commentRss><comments>http://myitforum.com/cs2/blogs/aberges/archive/2007/01/25/anti-malware-blog-sap-internet-graphics-service-igs-remote-buffer-overflow.aspx#comments</comments><description>&lt;p&gt; &lt;p&gt; &lt;p&gt;SAP is the largest business application and Enterprise Resource Planning (ERP) solution software provider in terms of revenue.&lt;/p&gt; &lt;p&gt;CYBSEC Security Systems has discovered a vulnerability in SAP IGS which when exploited can result in remote code execution with the privileges of the LocalSystem on Windows and SAP System Administrator Account on UNIX systems.&lt;/p&gt; &lt;p&gt;For more information about the vulnerability, read &lt;a href="http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_SAP_IGS_Remote_Buffer_Overflow.pdf"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;SAP has already released a solution for this and customers that are affected should apply the patch as soon as possible. For more information about the patch read SAP Note 968423.&lt;/p&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blog.trendmicro.com/sap-internet-graphics-service-28igs29-remote-buffer-overflow/"&gt;Link to SAP Internet Graphics Service (IGS) Remote Buffer Overflow&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=92492" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/330820932" height="1" width="1"/&gt;&lt;img src="http://feeds.feedburner.com/~r/aberges/~4/DPvdw4xLaYQ" height="1" width="1"/&gt;</description><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Security/default.aspx">Security</category><category domain="http://myitforum.com/cs2/blogs/aberges/archive/tags/Vulnerability/default.aspx">Vulnerability</category><feedburner:origLink>http://myitforum.com/cs2/blogs/aberges/archive/2007/01/25/anti-malware-blog-sap-internet-graphics-service-igs-remote-buffer-overflow.aspx</feedburner:origLink><feedburner:origLink>http://feeds.feedburner.com/~r/aberges/~3/330820932/anti-malware-blog-sap-internet-graphics-service-igs-remote-buffer-overflow.aspx</feedburner:origLink></item><lastBuildDate>Wed, 08 Jul 2009 00:00:00 PDT</lastBuildDate></channel></rss>
