The blog

DSO Exploit explained

When you run Spybot S&D, it may complain that your system is vulnerable to something called a “DSO exploit.” What’s that all about? Maybe a lot less than you think. I stumbled across this excellent article: “dso Exploit” Explained” href=”http://forums.net-integration.net/index.php?showtopic=23930″>”dso Exploit” Explained at the Net-Integration Forums.

In a nutshell, this specific security exploit is old and has long since been fixed. However, a bug in Spybot S&D 1.3 incorrectly detexts this as a problem even if it has been fixed. Bottom line, according to this article’s author, is that you can safely ignore the warning from Spybot S&D if you are current on your Windows security updates.

Bonus: The Net-Integration Forums have a very nice page listing malware removal procedures.

Spreading outdated security advice

Professor Michael Froomkin of the University of Miami School of Law is one of my favorite bloggers. His insights on civil rights and legal issues are always worth reading. However, when the good professor strays into territory where he’s not an expert, things sometimes go a little wrong. Witness this post from today: Fix a Microsoft Vulnerability

If you read the blog entry in question, it sounds alarming. Unfortunately, the third-party security advisory that Prof. Froomkin references was from February 2002. It has long since been corrected. Any Windows user who is up to date with security patches – a procedure that is required with ALL operating systems, including the Mac OS and all variants of Linux – is protected from this.

It’s also one of the least problematic security issues I know. An attacker who successfully exploited this issue on an unpatched machine could not plant a program on your computer or execute a program from another location. He could only run an existing program on your PC, and then only if he knows the exact location of that program on your PC. It was an interesting proof of concept but it required a lot more work before it could be used for a hostile action.

And in fact, the system worked. GreyMagic published this security advisory in February 2002. On March 28, 2002, Microsoft published Security Bulletin MS02-015, which publicly addressed the problem. A fix was included in an accompanying Internet Explorer Security Update. This fix is included in Windows XP with Service Pack 1 or later.

I promise to chat with Professor Froomkin before I write about complex legal issues here. In exchange, I offer my technical expertise on Windows and Windows security advisories to my favorite law professor the next time he thinks about wrinting another Windows-related post.

Update: Professor Froomkin, in the comments below, notes that he was misled by a false report from Spybot S&D. This is indeed an error in Spybot, as I note in a follow-up post to this one. Click here for details about the phony “DSO exploit” error in Spybot S&D 1.3. Oh, and I meant what I said about his blog, Discourse.net. His work is just excellent, and it’s on my list of essential blogs to follow.

More Dell woes

I guess when it rains it pours. I’ve previously chronicled the saga of my neighbor Jerry’s Dimension 4100, whose case fan has failed and can’t be replaced. Yesterday, he called me to tell me that his just-over-a-year-old Dimension 4600 won’t start.

We hauled the PC over to my office, where I plugged it in and took a look. Yep, it’s dead, Jim. I made the obligatory call to Dell’s support line, where I spent 15 minutes on hold before a cheerful tech told me that Jerry’s account was from the Large Systems division. Ha! While I was on hold waiting for those techs to pick up, I surfed over to the Dell Community Forum. And wonder of wonders, I read this thread, and this one, and then hit the mother lode on this one.

In short, lots of people have been complaining about a sudden rash of power supply failures in the Dimension 4600 line, typically just after the one-year anniversary. After I read through all the threads, I decided not to waste any more time waiting for a tech to pick up and tell me the computer was out of warranty. Instead, I’m heading for CompUSA to pick up a generic power supply and swap it with the defective one.

I’ll give kudos to Dell for having a Community Forum, but it’s a double-edged sword. This is one of three problems I’ve experienced with Dell products and support in recent months, and thanks to the forums I’ve learned that I’m not alone. Unfortunately, Dell doesn’t seem to have invested any energy in capturing the feedback on these forums to identify and fix common problems. I can only imagine how annoyed and angry their customers are who are getting the run-around from a support tech and don’t realize that there’s a place to share information and horror stories with other customers.

In general, I think Dell makes good, solid computers, but their support is troublesome. If you’re a Dell customer, do yourself a favor and start in the message boards the next time you have a problem. You might save yourself a lot of pointless aggravation.

Update: Yep, the new power supply fixed the problem.

Update: I’ve closed the comments on this post. They’re now read-only. A lot of people are asking for detailed help with their computers that I can’t offer, and the comments section isn’t really set up to work like a bulletin board or forum. A better suggestion is to go to the Dell forums.

Thanks for all the great feedback. – Ed Bott, February 2006

Bill G.’s mailbox

Steve Ballmer says Bill Gates gets 4 million e-mails a day.

Ballmer said Microsoft has special technology that just filters spam intended for Gates. In addition, several Microsoft employees are dedicated to ensuring that nothing unwanted gets into his inbox.

“Literally there’s a whole department almost that takes care of it,” he said.

Bill has had the same e-mail address for as long as I can remember, and it’s been printed in more places than anyone can count. Still, you have to be pretty amused at the notion that the world’s richest man would even think of buying a fake Rolex or male enhancement products via an anonymous e-mail message.

I’ve had the same e-mail address since 1994. Most spam gets blocked at the server, with a combination of SpamAssassin and some manual filters I’ve set up. When I shut off those filters, I get roughly 200-300 unwanted messages a day. With them in place, I’ve cut the flood to a trickle of fewer than 10 spams a day, and virtually all of those are filtered into my Junk Mail folder in Outlook.

Do you have a spam horror story or a favorite spam-blocking product? Click the Comments link and give me the details.

The Great Software List

Zaine Ridling has posted a couple of interesting comments here recently. I followed the link on his name to The Great Software List and was astounded.

This page is provided so that you don’t have to spend weeks finding the perfect program. You can come here and confidently download software of the highest quality and not fear that you might waste money. You won’t go wrong choosing any of the programs on this list. And if you do find a great software program not listed here, maybe you’ll share your find with me and it might make the list.

This list is intelligent, cleanly designed, and just packed with great information. I already use several of the programs on this list and can attest to the thoroughness of Zaine’s reviews and the accuracy of the details he’s posted.

It’s earned a permanent place in my bookmarks list.

Browsing on a cell phone

Scoble says everyone needs to redesign their Web sites so it looks good on a cell phone.

There’s some very simple tips to make your site work great on cell phones (millions of people look at the Web on cell phones and that number is going up every day). A poorly designed site does makes it very frustrating to look at sites on cell phones, though.

Just for the record, I don’t plan to redesign my site so it can be browsed on a cell phone. I don’t want people browsing my site from a two-inch screen. On this site I talk about how to make better use of your personal computer running Windows and Office. It only makes sense to read it on a PC running Windows.

I think Robert may need an intervention.

More misinformation about spyware

In today’s Seattle Times, Paul Andrews writes Tired of spyware? Try another browser. The trouble is, he appears to know just enough to spread misinformation.

During a recent six-week period, I conducted a small spyware experiment on my Windows computer.

I kept track of days I opened Microsoft Internet Explorer. At the close of each day, I ran Spybot, a detection and prevention program.

Here’s what happened: On nearly every day I used Internet Explorer, I was infected with a new batch of malware — spyware or adware. On days I used Mozilla Firefox for browsing and avoided IE, without exception I remained uninfected.

Oh really? I wonder what sorts of programs were getting installed on Paul’s computer, if any. Because on any computer running Windows XP, there are only two ways a program can be installed:

  • You install it yourself. This can be accomplished by clicking OK to a dialog box or by downloading a setup file and running it.
  • It installs itself, without your approval. This happens ONLY on a computer that does not have the latest security patches installed. The only way a program can be planted on your computer without your permission is to take advantage of a known security flaw.

Look, I take care of a dozen computers for friends, family, and neighbors. On not one of those computers would the situation that Paul describes be accurate. None of these people are experts, none of them scan their computers for spyware daily. So what’s the difference?

This quote from later in Paul’s story provides a clue:

What drove me to my experiment was sheer desperation at a constant, growing barrage of attacks on my Windows PC. Not only was the computer slowed to a crawl, it was almost impossible to perform any function without being assaulted by pop-ups.

Aha! It sounds like some particularly nasty piece of malware had infected the computer some time ago – the sort that Spybot S&D couldn’t remove. Every day, it was reinstalling itself or some variant of itself. At least that’s my guess.

Paul’s mistake is to assume that this is the normal course of events. It’s not normal, not by a long shot. And to write a story that implies that this is the normal state of affairs that anyone should expect when using Internet Explorer is misleading and inaccurate.

Paul, call someone for help. Once you get that piece of junk off your computer, you’ll find that the experience is completely different.

Update: Reading through the article again, I found another inaccuracy. Paul says that installing another browser (Firefox) is the only cure for spyware and adds: “You need to configure it to block cookies from third-party sites. That means the occasional inconvenience of having to re-enter logins and passwords on certain Web pages.” No, no, and no! First, you don’t need to block third-party cookies, although it can’t hurt and I think it’s a reasonable security precaution. Second, you can easily block third-party cookies with IE as well. The impact on spyware in either case will be nonexistent. Finally, blocking third-party cookies has ZERO effect on login prompts.

This article is horribly, horribly wrong.

SP2 woes? Don’t give up

In the Seattle P-I, Dan Richman has written a well-balanced piece on SP2, “Microsoft’s SP2: A fix that derails some computers.” I’d say the single most important sentence in the story is this piece of advice:

Don’t give up. The protection it offers is worth the pain it may cause.

On a healthy PC, SP2 should install quickly and without incident. In unbiased surveys, I’ve seen indications that more than 90% of the people who install SP2 have no issues at all, and my personal experience matches that figure. If you’re experiencing problems with SP2, those are warning signs that something is wrong with your computer. If you ignore those signs and just decide to deal with them by uninstalling SP2, your PC is a ticking time bomb. A far better strategy is to find out what the problem is and fix it.

If you’ve successfully installed SP2 and you want more information about how to work with it, consider picking up a copy of Windows XP Inside Out, Second Edition. If you’re an IT professional or you work with corporate networks, pick up the Deluxe Edition. Carl Siechert, Craig Stinson, and I worked with SP2 throughout the best testing cycle and have lots of good information on how it works and how to work with it.

Your favorite backup software?

I’m working on the revision of Windows Security Inside Out and am currently researching backup software. You can help.

If you have a favorite backup program, leave a note in the Comments section here. Give me enough information to find the program, and tell me why you like the software you’ve chosen.

Thanks.

Google bug fixed (apparently)

Elliott Back links to an old post of mine and reports that Google has fixed a longstanding problem:

In a news release today, Google releases new numbers for the number of pages it can search. Looks like Google has overcome its 4-byte DocID problem and happily doubled its index:

You probably never notice the large number that appears in tiny type at the bottom of the Google home page, but I do. It’s a measure of how many pages we have in our index and gives an indication of how broadly we search to find the information you’re looking for. Today that number nearly doubled to more than 8 billion pages.

As Elliott correctly notes, Google’s apparently relying less and less on its flawed pagerank formula and more on other measures of relevance. I’m still impressed with how often Google finds just exactly the right page in response to a search request.