Vote Machine Malfunction
Mar 8 2005, 09:27 AM
A couple more for the hosts file.
127.0.0.1 time.windows.com # Microsoft's default time sync server
127.0.0.1 time.nist.gov # MS's secondary time sync
Why in hosts?
1. Time sync servers built into Windows for automated updates by default.
2. Sync occurs at startup, and the clock starts before many firewalls (both of these are already in bluetack's blocklists).
3. Even if sync is disabled, it doesn't hurt to keep it in hosts in the event a "fix" from MS or something else reactivates them.
4. Their sync client is probably not well tested against exploits of yet unknown vulnerabilities simply because it seems so innocent, harmless, and useful. Just another way for big brother to sneak into your computer silently.
Kimberly
Mar 8 2005, 02:22 PM
HI Vote Machine Malfunction,
You can add them yourself if you like, but I ain't gonna add them to the Hosts file. A lot of people are using Time Sync and I don't wanna receive any complaints about that. Time Sync is easy to disable in the date/time properties and a M$ fix will not re-enable it.
Kim
Vote Machine Malfunction
Mar 8 2005, 11:39 PM
I feel your pain, Kim, and may I say you look simply smashing today. Of course, Microsoft never releases fixes for fixes that fixed fixes found in service packs.
http://www.microsoft.com/technet/security/...n/ms05-014.mspx
Kimberly
Mar 9 2005, 12:29 AM
Sorry but I don't see the relationship between that Cumulative Security Update for IE and blocking Windows Time Sync servers. Time servers work on port 13 or 37. Furthermore, a decent firewall will not allow internet connections on boot. You can test this by allowing the root certificates update ... if your firewall is working like it should be, you'll find a deny entry in your logs refering to crl.microsoft.com
| QUOTE |
Microsoft Security Bulletin MS05-014 Cumulative Security Update for Internet Explorer (867282)
Vulnerability Details
Drag-and-Drop Vulnerability - CAN-2005-0053 URL Decoding Zone Spoofing Vulnerability - CAN-2005-0054 DHTML Method Heap Memory Corruption Vulnerability - CAN-2005-0055 Channel Definition Format (CDF) Cross Domain Vulnerability - CAN-2005-0056 |
Like I said before, feel free to add the entries in your HOSTS file.
Kim
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.