<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>danrichardson.net</title>
	<atom:link href="http://danrichardson.net/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://danrichardson.net/blog</link>
	<description>tech / health / fitness blog</description>
	<lastBuildDate>Thu, 01 Jul 2010 09:06:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Remote Desktop Vulnerability</title>
		<link>http://danrichardson.net/blog/uncategorized/2010/07/01/remote-desktop-vulnerability</link>
		<comments>http://danrichardson.net/blog/uncategorized/2010/07/01/remote-desktop-vulnerability#comments</comments>
		<pubDate>Thu, 01 Jul 2010 09:00:10 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://danrichardson.net/blog/?p=44</guid>
		<description><![CDATA[Yesterday I believed I came across a potential security vulnerability whilst using Windows Remote Desktop, Microsoft didn't seem to really think so, maybe that's why they are in their current predicament]]></description>
			<content:encoded><![CDATA[<p>Yesterday I believed I came across a potential security vulnerability whilst using Windows Remote Desktop in that a program failed to close whilst terminating my remote session and kept me logged in and remote desktop open without my knowledge.<br />
So off I went to email them the issue hoping that they would escalate my point and actually look into it, instead I got what looks like a stock response&#8230; I don&#8217;t understand how they can&#8217;t see this as a potential vulnerability with the comment &#8220;how would an attacker leverage this to compromise the system&#8221;. My email and Microsoft response below, what do you think?</p>
<p><strong><span style="text-decoration: underline;"><br />
To Microsoft (from me)</span></strong></p>
<blockquote><p>Good afternoon.</p>
<p>I was working in remote desktop to an online web server whilst trying to troubleshoot a problem I was having with a website but then left remote desktop inactive (still open and logged in) whilst I read some articles on my current machine through a web browser.</p>
<p>The timeout on inactivity is quite short (maybe 10 minutes or so) for the remote desktop and i was away from remote desktop for at least an hour.</p>
<p>However a rather worrying sight was presented to me when I realised it (remote desktop) was still open. When I made the window active again it had an &#8220;End Program&#8221; dialog for a program that had problems ending itself (this was probably due to remote desktop trying to terminate my session). Now the problem here is that when you click &#8220;Cancel&#8221; instead of &#8220;End Now&#8221; the dialog disappears and the remote desktop session is not terminated (i.e. I&#8217;m still logged in).</p>
<p>Obviously this could result in a catastrophic event occurring where (if someone left a machine with remote desktop open and logged in) another person could come onto the client machine and essentially have full reign over the entire remote system, causing serious damage (re-format, install virus, etc..).</p>
<p>Some key information which may be of use to you is:</p>
<ul>
<li>Machine is running &#8211; Windows Server 2003 Standard Edition with Service Pack 2</li>
<li>Program which would not close &#8211; ClamWin (update module I believe it was)</li>
<li>Client remote desktop version &#8211; 6.1.7600.16385 (win7_rtm.090713-1255)</li>
<li>Logged into client machine (running under a domain) under registered NT Account with Administrative capabilities</li>
<li>Logged in (through remote desktop) as Administrator</li>
</ul>
<p>I hope this helps and if I can be of any more assistance, please contact me.</p>
<p>Kind regards<br />
Daniel Richardson</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
From Microsoft (to Me)</span></strong></p>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;">Hello Dan,</span></p>
<p>Thank you for your message. This is not something that we would consider to be a security vulnerability. One of the major questions here is &#8220;how would an attacker leverage this to compromise the system?&#8221;  In this situation, I believe the attacker would require physical access to the system which violates the 10 Immutable Laws of Security which is available at <a style="color: #0065cc;" href="http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx" target="_blank">http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx</a>. Additionally, Terminal Services on Windows Server 2003 allows configuration that will force programs to shutdown based on various criteria. An article on configuring this is available at <a style="color: #0065cc;" href="http://technet.microsoft.com/en-us/library/cc787183(WS.10).aspx" target="_blank">http://technet.microsoft.com/en-us/library/cc787183(WS.10).aspx</a> .</p>
<p>If you have additional information or believe that we mis-read something in your report, please let me know.</p>
<p>Best Regards,<br />
Nate</p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/uncategorized/2010/07/01/remote-desktop-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>danrichardson.net</title>
		<link>http://danrichardson.net/blog/tech/2009/10/14/danrichardson-net</link>
		<comments>http://danrichardson.net/blog/tech/2009/10/14/danrichardson-net#comments</comments>
		<pubDate>Wed, 14 Oct 2009 20:11:26 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[jQuery]]></category>
		<category><![CDATA[ruby]]></category>

		<guid isPermaLink="false">http://danrichardson.net/blog/?p=37</guid>
		<description><![CDATA[Over the last few weeks I have been re-designing this site and plan to add a new &#8220;code&#8221; section. Along with that I have a fair bit of freelance work on-the-go, so things are on the go-slow.
I&#8217;m really liking my new design (if I may say so myself!), and I cannot wait to get it [...]]]></description>
			<content:encoded><![CDATA[<p>Over the last few weeks I have been re-designing this site and plan to add a new &#8220;code&#8221; section. Along with that I have a fair bit of freelance work on-the-go, so things are on the go-slow.</p>
<p>I&#8217;m really liking my new design (if I may say so myself!), and I cannot wait to get it marked up and online. It&#8217;s not going to be fully active right away as I plan to learn and re-program it all in Ruby (on rails).</p>
<p>The most exciting part of this overhaul is the new &#8220;code&#8221; section. In my day-to-day job with <a title="Skylight Media" href="http://www.skylightmedia.co.uk" target="_blank">Skylight Media</a>, I come across lots of instances where I need/WANT to learn new/better/faster ways of doing things. I will be mainly focusing the code section on <a href="http://www.jquery.com" target="_blank">jQuery</a> though as i absolutely love this library and constantly find myself writing a wide range of small and big plugins to make my everyday job easier.<br />
One of my first posts on the new site will be of an image plugin I recently made for a Skylight Media client Rachel Ellen. Not another I hear you say, but this one I believe is pretty unique and is pretty scalable, best of all it rocks! :p</p>
<p>Keep your eyes peeled as hopefully something will be online soon! :)</p>
<p>Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/tech/2009/10/14/danrichardson-net/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cardio Tuesday</title>
		<link>http://danrichardson.net/blog/health/2009/03/04/cardio-tuesday</link>
		<comments>http://danrichardson.net/blog/health/2009/03/04/cardio-tuesday#comments</comments>
		<pubDate>Wed, 04 Mar 2009 22:08:49 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[fitness]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[cardio]]></category>
		<category><![CDATA[cycling]]></category>
		<category><![CDATA[rowing]]></category>

		<guid isPermaLink="false">http://danrichardson.net/blog/?p=34</guid>
		<description><![CDATA[Yesterday was a good day for my Cardio Tuesday, but i didn&#8217;t get enough time to run. I should have to stop getting drawn in by the tv when eating my breakfast, makes me late every time!
The rowing and bike times for yesterday are:
Cycling 10km &#8211; 15:12 &#8211; NEW RECORD
Rowing 2000m &#8211; 8:21 &#8211; NEW [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday was a good day for my Cardio Tuesday, but i didn&#8217;t get enough time to run. I should have to stop getting drawn in by the tv when eating my breakfast, makes me late every time!</p>
<p>The rowing and bike times for yesterday are:</p>
<p>Cycling <strong>10km</strong> &#8211; <strong>15:12</strong> &#8211; NEW RECORD<br />
Rowing <strong>2000m</strong> &#8211; <strong>8:21</strong> &#8211; NEW RECORD</p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/health/2009/03/04/cardio-tuesday/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5k running</title>
		<link>http://danrichardson.net/blog/fitness/2009/02/16/5k-running</link>
		<comments>http://danrichardson.net/blog/fitness/2009/02/16/5k-running#comments</comments>
		<pubDate>Mon, 16 Feb 2009 22:07:51 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[fitness]]></category>
		<category><![CDATA[5k]]></category>
		<category><![CDATA[running]]></category>

		<guid isPermaLink="false">http://danrichardson.net/wp/?p=27</guid>
		<description><![CDATA[On Saturday, I felt as though I had reached a fitness level that allowed me to attempt my first 5km run, so off I went! The full distance of the route I ran is ~5.5km, and with a time of 24:30 secs, I&#8217;m quite chuffed with it.
Adding to my &#8220;Cardio Tuesday&#8217;s&#8221;, i&#8217;m going to attempt [...]]]></description>
			<content:encoded><![CDATA[<p>On Saturday, I felt as though I had reached a fitness level that allowed me to attempt my first 5km run, so off I went! The full distance of the route I ran is ~<strong>5.5km</strong>, and with a time of <strong>24:30</strong> secs, I&#8217;m quite chuffed with it.</p>
<p>Adding to my &#8220;Cardio Tuesday&#8217;s&#8221;, i&#8217;m going to attempt the 5km run every month around the same day, and try and improve my time each month, my goal being 15 mins. All this is in an attempt to raise my fitness levels for a half/full marathon this year, not sure which one yet, will have to start looking into it VERY soon though.</p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/fitness/2009/02/16/5k-running/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cardio Tuesday&#8217;s</title>
		<link>http://danrichardson.net/blog/health/2009/02/10/cardio-tuesdays</link>
		<comments>http://danrichardson.net/blog/health/2009/02/10/cardio-tuesdays#comments</comments>
		<pubDate>Tue, 10 Feb 2009 21:21:50 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[fitness]]></category>
		<category><![CDATA[health]]></category>
		<category><![CDATA[cardio]]></category>
		<category><![CDATA[cycling]]></category>
		<category><![CDATA[rowing]]></category>
		<category><![CDATA[running]]></category>

		<guid isPermaLink="false">http://danrichardson.net/wp/?p=10</guid>
		<description><![CDATA[Carido tuesday excerpt]]></description>
			<content:encoded><![CDATA[<p>I went to the gym today, and decided that Tuesday&#8217;s are now &#8220;Cardio Tuesday&#8217;s&#8221;.</p>
<p>Giving myself ~1 hour at the gym, i&#8217;m going/have stareted doing bike, followed by rowing and then running.</p>
<p>I&#8217;m going to be doing</p>
<ul>
<li>interval training for <strong>10km</strong> on <strong>bike</strong></li>
<li><strong>2000m</strong> on the rower on <strong>level 9</strong> of 10 (<a href="http://www.concept2shop.co.uk/product/indoor_rower_d3" target="_blank">older version of this Concept 2 rower</a>)</li>
<li>running for <strong>15 minutes<br />
</strong></li>
</ul>
<p>I will be posting my times/distances managed each week, starting with today&#8217;s!</p>
<h2><em><strong>Results</strong></em></h2>
<p><strong>Bike</strong> (time taken to do 10km) : <strong>16 minutes</strong> &#8211; Average of <strong>37.5km/h</strong></p>
<p><strong>Rower</strong> (time taken to do 2000m): <strong>8 minutes, 42 seconds</strong> &#8211; Average of <strong>3.83m/s</strong></p>
<p><strong>Run</strong> (for 15 minutes): <strong>3.km</strong> &#8211; Average of <strong>12km/h</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/health/2009/02/10/cardio-tuesdays/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moved to WordPress!</title>
		<link>http://danrichardson.net/blog/tech/2009/02/10/hello-world</link>
		<comments>http://danrichardson.net/blog/tech/2009/02/10/hello-world#comments</comments>
		<pubDate>Tue, 10 Feb 2009 20:42:39 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://danrichardson.net/wp/?p=1</guid>
		<description><![CDATA[WordPress says hi]]></description>
			<content:encoded><![CDATA[<p>Well it&#8217;s been far too long and i haven&#8217;t had a chance to create an admin backend to my site. So i have decided to just use wordpress as it does just what i need. So expect more post&#8217;s, as it&#8217;s no longet a chore to get a post in! :)</p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/tech/2009/02/10/hello-world/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ruby On Rails</title>
		<link>http://danrichardson.net/blog/tech/2008/12/16/ruby-on-rails</link>
		<comments>http://danrichardson.net/blog/tech/2008/12/16/ruby-on-rails#comments</comments>
		<pubDate>Tue, 16 Dec 2008 23:32:12 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[ruby on rails]]></category>

		<guid isPermaLink="false">http://danrichardson.net/wp/?p=24</guid>
		<description><![CDATA[After a bit of umming and arring last week, i finally decided to take another look at Ruby and Rails.
So far i&#8217;m quite liking what I see and some of it&#8217;s in-built functionality looks pretty darn sweet. I&#8217;m very much liking the scaffold command to do a quick &#38; dirty table manipulation setup.
I&#8217;m reading a [...]]]></description>
			<content:encoded><![CDATA[<p>After a bit of umming and arring last week, i finally decided to take another look at Ruby and Rails.</p>
<p>So far i&#8217;m quite liking what I see and some of it&#8217;s in-built functionality looks pretty darn sweet. I&#8217;m very much liking the scaffold command to do a quick &amp; dirty table manipulation setup.</p>
<p>I&#8217;m reading a really nice simple beginner&#8217;s guide on sitepoint (<a title="Learn Ruby On Rails" href="http://www.sitepoint.com/article/learn-ruby-on-rails" target="_blank">which can be found here</a>) which set&#8217;s a good understanding to the basics of Ruby On Rails.</p>
<p>Will probably be playing more with Ruby On Rails over the christmas period (or at least until my xbox comes back from Microsoft after its RRoD :( ), so will keep an update on here as to how I&#8217;m getting on with it.</p>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/tech/2008/12/16/ruby-on-rails/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dynamic getURL in flash</title>
		<link>http://danrichardson.net/blog/tech/2008/07/29/dynamic-geturl-in-flash</link>
		<comments>http://danrichardson.net/blog/tech/2008/07/29/dynamic-geturl-in-flash#comments</comments>
		<pubDate>Tue, 29 Jul 2008 14:24:52 +0000</pubDate>
		<dc:creator>reason</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[flash]]></category>

		<guid isPermaLink="false">http://danrichardson.net/wp/?p=18</guid>
		<description><![CDATA[Dynamic getURL in flash]]></description>
			<content:encoded><![CDATA[<p>Today i got asked to add links to a flash animation that i have done recently. The flash animation in question has dynamic title&#8217;s and content based on two movie clips, which are built from an array of data pulled in from XML.</p>
<p>Knowing i needed to add a &#8220;getUrl()&#8221; function and &#8220;onRelease&#8221; event handler for the dynamic movie clips, I thought to myself <em>&#8220;what would be the easiest was to do this&#8230;&#8221;</em></p>
<p>With the clips being made inside a simple for loop, i hoped the data being pulled from the array would be retained and correct for when the event handler was eventually triggered (optimistic i know!). If you hadn&#8217;t already guessed this didn&#8217;t work, so off i went thinking how i can have the right data when the event handler fires.</p>
<p>After a little while and tinkering with my code i finally figured out a solution. When attaching the movieClip you can store the instance in a variable and then set a variable inside the movie clip. When the event handler is triggered it simply calls &#8220;this.linkTo&#8221; (&#8221;this&#8221;, referring to the movieClip, and &#8220;linkTo&#8221; refferring to the variable) as the getURL() address parameter</p>
<p>The code snippet for this is:</p>
<pre>
// Create new instance of the Section_Title movie clip
var SectionTitle = attachMovie("Section_Title", Sections[ii][0], ii, { _x:-230, _y:_yPos });

// Set a variable for this movie clip for the navigate link
SectionTitle.linkTo = Sections[ii][2];

// Create event handler for the click release
SectionTitle.onRelease = function(){
// Goto page save in thje movie clip linkTo variable
getURL(this.linkTo);
}</pre>
]]></content:encoded>
			<wfw:commentRss>http://danrichardson.net/blog/tech/2008/07/29/dynamic-geturl-in-flash/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
