terça-feira, 13 de janeiro de 2009

Agora também CGEIT!

Recebi hoje a confirmação de ter sido aprovado na certificação CGEIT (Certified in the Governance of Enterprise IT).

Gostaria de agradecer a todos os que me auxiliaram, desde que comecei a trabalhar em TI, nesse longo caminho.

Agora, vamos às próximas!

domingo, 11 de janeiro de 2009

Fake Fingerprints in Japan

This is an interesting article, that I recomend reading:

http://news.yahoo.com/s/afp/20090101/wl_asia_afp/japantechnologyimmigrationcrimesecurity

segunda-feira, 5 de janeiro de 2009

Segurança no Mac em 2008

Segue artigo publicado no blog da Intego (www.intego.com) sobre as ameaças para o Mac OS X.

Como sempre, podem ser tendenciosas, mas vale à pena dar uma olhada: http://blog.intego.com/2009/01/05/the-year-in-mac-security-2008/

Feliz 2009!

sexta-feira, 2 de janeiro de 2009

Licença Gratuita do Parallels

O Parallels para Windows e Linux de graça! 


Sem burocracia nem pegadinhas. Pena que ainda não estão liberando para Mac!

terça-feira, 30 de dezembro de 2008

Como gerar muita documentação com pouco (ou nenhum) conteúdo!

Quantos projetos você já viu, com uma extensa documentação de fazer inveja, mas conteúdo zero? 


Agora você também pode! Veja o site http://www.suicidiovirtual.net/dados/lerolero.html, escolha um título e gere seu trabalho!


sábado, 27 de dezembro de 2008

Dica de leitura

Meus amigos Manuel Funes e Daniel Alcanja me indicaram o livro "Getting Real" (algo como "Caindo na Real").


É uma abordagem muito interessante sobre como simplificar a vida em projetos de software, mas que serve para qualquer projeto de vida.

O livro pode ser acessado (e lido gratuitamente online) no endereço: http://gettingreal.37signals.com/.

quarta-feira, 24 de dezembro de 2008

Symantec unveils Norton Internet Security for Mac 4.0

by Jim Dalrymple, Macworld.com 

Symantec on Thursday unveiled a significant upgrade for its Norton line of security software. Norton Internet Security for Mac features a variety of security tools in one application. 

Norton Internet Security for Mac includes traditional virus protection, a Firewall, and tools to help protect against spyware and identity theft. 

Many Mac users don't see many of these issues as problems for them because of the Mac's reputation as being one of the most secure platforms. However, with the Mac becoming more popular among new users, it's a good idea to be aware and ready for any potential threats. 

"You read so much about Windows threats and not so much about the Mac," Mike Romo, Symantec's Mac product manager, told Macworld. "Our goal is to provide a tool to cover all the bases without scaring people." 

In fact, Macs are becoming more popular in businesses these days, and many companies require security software on all of their computers, according to Romo. 

Norton Internet Security for Mac is also linked to Symantec's DeepSight Threat Management System, updating the firewall rules at least once a day to protect against the latest attacking IP addresses. This ensures that Mac users are protected on an ongoing basis without having to really think about many of the threats out there. 

The new application combines the protection found in Norton AntiVirus 11 for Mac, Norton Confidential, and two-way firewall functionality. 

Symantec says the application also protects against phishing Web sites, protecting your identity and protecting files against keyloggers and other types of eavesdropping applications. 

Symantec also announced Norton Internet Security for Mac Dual Protection. This protects users running Boot Camp or other virtualization software. 

Norton Internet Security for Mac and Norton Internet Security for Mac Dual Protection are 
available immediately for $79.99 and $89.99, respectively. 

NIST Draft Special Publication 800-120 has been Released

DRAFT NIST Special Publication 800-120, Recommendation for EAP Methods Used in Wireless Network Access Authentication

NIST announces the release of draft Special Publication 800-120, Recommendation for EAP Methods Used in Wireless Network Access Authentication. This Recommendation specifies security requirements for authentication methods with key establishment supported by the Extensible Authentication Protocol (EAP) defined in IETF RFC 3748 for wireless access authentications to federal networks. Please submit comments to 800-120comments@nist.gov with "Comments on SP 800-120" in the subject line. The comment period closes on January 30, 2009.

URL to Drafts page:
http://csrc.nist.gov/publications/PubsDrafts.html#800-120


Pat O'Reilly
List Administrator
Computer Security Division
NIST




segunda-feira, 15 de dezembro de 2008

Mac OS X Update - 10.5.6



Iniciar mensagem reenviada:

Data: 15 de dezembro de 2008 22h1min0s GMT-02:00
Assunto: Mac OS X Update - 10.5.6
Responder A: NSArchitect <noreply@blogger.com>
Fonte: iAntiVirus Blog
Autor: NSArchitect <noreply@blogger.com>

Apple has released an update for OS X which addresses some performance and severe security issues. Please run a Software Update and grab it today!



Security Issues addressed
  • Apple Type Services (ATS) server PDF embedded font handling issue (CVE-ID: CVE-2008-4236)
  • Arbitrary code execution in BOM (CVE-ID: CVE-2008-4217)
  • Heap buffer overflow in CoreGraphics' handling of color spaces (CVE-ID: CVE-2008-3623)
  • Possible user credential disclosure in Safari (CVE-ID: CVE-2008-3170)
  • Enhanced download validation capability, previously warnings were not displayed for all unsafe download content types, this allowed for arbitrary code/command execution (CVE-ID: CVE-2008-4234)
  • Multiple vulnerabilities in the Adobe Flash player plugin (CVE-IDs: CVE-2008-4818, CVE-2008-4819, CVE-2008-4820, CVE-2008-4821, CVE-2008-4822, CVE-2008-4823, CVE-2008-4824)
  • Local privilege escalation issue due to integer overflows in the kernel's i386_get_ldt and i386_get_ldt system calls (affects Intel based machines only) (CVE-ID: CVE-2008-4218)
  • Infinite loop when an exception occurs in a program (or dylib) which resides on an NFS share (CVE-ID: CVE-2008-4219)
  • Integer overflow in the LibSystem inet_net_pton function -> this could affect any program which uses that function (CVE-ID: CVE-2008-4220)
  • Memory corruption issue in the strptime function of LibSystem (CVE-ID: CVE-2008-4221)
  • Multiple integer overflows in the strfmon function of LibSystem (CVE-ID: CVE-2008-1391)
  • Per host configuration in managed client system installs sometimes incorrectly identifies the system (CVE-ID: CVE-2008-4237)
  • natd infinite loop due to a maliciously crafted TCP packet -> only affects systems with the Internet Sharing service enabled (CVE-ID: CVE-2008-4222)
  • Authentication bypass in Podcast Producer (OS X server only) (CVE-ID: CVE-2008-4223)
  • Input validation issue when handling malformed UDF volumes, ISO files. Opening a malformed volume may cause an unexpected syustem shutdown. (CVE-ID: CVE-2008-4224)

Information from Apple here .

Note: All CVE IDs will be linked to their respective pages once they become available.

Ler mais…