<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Patch it or Scratch it: RealPlayer</title> <atom:link href="http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/feed/" rel="self" type="application/rss+xml" /><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/</link> <description>In-depth security news and investigation</description> <lastBuildDate>Fri, 30 Jul 2010 04:29:12 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0</generator> <item><title>By: RealPlayer: Rip and Replace &#124; Complete Source</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-975</link> <dc:creator>RealPlayer: Rip and Replace &#124; Complete Source</dc:creator> <pubDate>Mon, 25 Jan 2010 23:55:17 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-975</guid> <description>[...] Krebs declared: Patch it or Scratch it … Securing your computer isn’t just about making sure the doors and [...]</description> <content:encoded><![CDATA[<p>[...] Krebs declared: Patch it or Scratch it … Securing your computer isn’t just about making sure the doors and [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-975" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('975', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-975-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-975" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('975', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-975-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: KFritz</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-915</link> <dc:creator>KFritz</dc:creator> <pubDate>Sun, 24 Jan 2010 07:18:27 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-915</guid> <description>Oops. Missed comment #1.</description> <content:encoded><![CDATA[<p>Oops. Missed comment #1.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-915" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('915', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-915-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-915" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('915', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-915-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: KFritz</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-913</link> <dc:creator>KFritz</dc:creator> <pubDate>Sun, 24 Jan 2010 06:40:57 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-913</guid> <description>How about Real Alternative?http://www.free-codecs.com/download/real_Alternative.htmIt takes up less room that its namesake. I only used Real for music streams that, for whatever reason, use the Real format. RealAlt performs the function with none of the baggage.</description> <content:encoded><![CDATA[<p>How about Real Alternative?</p><p><a
href="http://www.free-codecs.com/download/real_Alternative.htm" rel="nofollow">http://www.free-codecs.com/download/real_Alternative.htm</a></p><p>It takes up less room that its namesake. I only used Real for music streams that, for whatever reason, use the Real format. RealAlt performs the function with none of the baggage.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-913" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('913', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-913-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-913" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('913', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-913-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Minot Isok</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-843</link> <dc:creator>Minot Isok</dc:creator> <pubDate>Fri, 22 Jan 2010 19:22:25 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-843</guid> <description>The NASA website still uses RealPlayer for streaming. The website says that streaming is provided by Yahoo and that you need to use RealPlayer or Windows Media Player.WMP for Windows users and RealPlayer for Macs. I use Windows XP and have never been able to view NASA streams with WMP, I always have to use RealPlayer.</description> <content:encoded><![CDATA[<p>The NASA website still uses RealPlayer for streaming. The website says that streaming is provided by Yahoo and that you need to use RealPlayer or Windows Media Player.</p><p> WMP for Windows users and RealPlayer for Macs. I use Windows XP and have never been able to view NASA streams with WMP, I always have to use RealPlayer.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-843" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('843', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-843-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-843" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('843', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-843-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Plaats hier software gerelateerd nieuws! - Page 17</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-840</link> <dc:creator>Plaats hier software gerelateerd nieuws! - Page 17</dc:creator> <pubDate>Fri, 22 Jan 2010 17:58:48 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-840</guid> <description>[...] beloningsprogramma en RealNetworks zelf. In plaats van updaten krijgen internetgebruikers ook het advies om de mediaspeler te verwijderen. Steeds minder online filmpjes werken alleen met RealPlayer, [...]</description> <content:encoded><![CDATA[<p>[...] beloningsprogramma en RealNetworks zelf. In plaats van updaten krijgen internetgebruikers ook het advies om de mediaspeler te verwijderen. Steeds minder online filmpjes werken alleen met RealPlayer, [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-840" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('840', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-840-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-840" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('840', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-840-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: John</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-831</link> <dc:creator>John</dc:creator> <pubDate>Fri, 22 Jan 2010 16:58:13 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-831</guid> <description>While I agree that VLC Player kicks butt, and has been on my machine for several years, I have to ask myself....1. How often do they do security updates?
2. What makes VLC more secure than, say, RealPlayer? 3. Does VideoLAN commit any resources to keeping its player safe?I am more than happy to remove RealPlayer from my system to patch up any forgotten or unused holes, but am not sure that VLC doesn&#039;t have its own list of potential weaknesses.</description> <content:encoded><![CDATA[<p>While I agree that VLC Player kicks butt, and has been on my machine for several years, I have to ask myself&#8230;.</p><p>1. How often do they do security updates?<br
/> 2. What makes VLC more secure than, say, RealPlayer? 3. Does VideoLAN commit any resources to keeping its player safe?</p><p>I am more than happy to remove RealPlayer from my system to patch up any forgotten or unused holes, but am not sure that VLC doesn&#8217;t have its own list of potential weaknesses.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-831" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('831', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-831-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-831" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('831', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-831-down" style="font-size:12px; color:#990033;">2</span></p>]]></content:encoded> </item> <item><title>By: Paul</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-818</link> <dc:creator>Paul</dc:creator> <pubDate>Fri, 22 Jan 2010 11:47:08 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-818</guid> <description>Your update link at the bottom of the page (http://service.real.com/realplayer/security/01192010_player/en/) is the advisory page rather than an update page. I&#039;m sure your readers are intelligent enough to scroll down to the &quot;Instructions&quot; section to find the update link to their OS. The users I&#039;m responsible for would just be confounded if they saw that page, so I&#039;m telling them to update thus (copied from the bottom of this page http://real.custhelp.com/app/answers/detail/a_id/3208):
1. Open RealPlayer and click the Tools menu, then Preferences.
2. In the Category pane on the left side, click AutoUpdate.
3. Click the Check for Update now button.</description> <content:encoded><![CDATA[<p>Your update link at the bottom of the page (<a
href="http://service.real.com/realplayer/security/01192010_player/en/" rel="nofollow">http://service.real.com/realplayer/security/01192010_player/en/</a>) is the advisory page rather than an update page. I&#8217;m sure your readers are intelligent enough to scroll down to the &#8220;Instructions&#8221; section to find the update link to their OS. The users I&#8217;m responsible for would just be confounded if they saw that page, so I&#8217;m telling them to update thus (copied from the bottom of this page <a
href="http://real.custhelp.com/app/answers/detail/a_id/3208)" rel="nofollow">http://real.custhelp.com/app/answers/detail/a_id/3208)</a>:<br
/> 1. Open RealPlayer and click the Tools menu, then Preferences.<br
/> 2. In the Category pane on the left side, click AutoUpdate.<br
/> 3. Click the Check for Update now button.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-818" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('818', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-818-up" style="font-size:12px; color:#009933;">2</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-818" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('818', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-818-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Conrad Longmore</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-816</link> <dc:creator>Conrad Longmore</dc:creator> <pubDate>Fri, 22 Jan 2010 10:24:56 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-816</guid> <description>If you&#039;re a home user, then Secunia PSI - http://secunia.com/vulnerability_scanning/personal/ - is an excellent tool for tracking the patch levels of installed applications and helping you to keep them up-to-date. There&#039;s also an online scanner at http://secunia.com/vulnerability_scanning/online/ if you don&#039;t want to install anything.</description> <content:encoded><![CDATA[<p>If you&#8217;re a home user, then Secunia PSI &#8211; <a
href="http://secunia.com/vulnerability_scanning/personal/" rel="nofollow">http://secunia.com/vulnerability_scanning/personal/</a> &#8211; is an excellent tool for tracking the patch levels of installed applications and helping you to keep them up-to-date. There&#8217;s also an online scanner at <a
href="http://secunia.com/vulnerability_scanning/online/" rel="nofollow">http://secunia.com/vulnerability_scanning/online/</a> if you don&#8217;t want to install anything.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-816" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('816', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-816-up" style="font-size:12px; color:#009933;">3</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-816" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('816', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-816-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: BrianKrebs</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-805</link> <dc:creator>BrianKrebs</dc:creator> <pubDate>Fri, 22 Jan 2010 04:22:31 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-805</guid> <description>Josef -- I don&#039;t know the answer to your question, but it&#039;s a good one and I&#039;ll be happy to put it to someone at Sun.</description> <content:encoded><![CDATA[<p>Josef &#8212; I don&#8217;t know the answer to your question, but it&#8217;s a good one and I&#8217;ll be happy to put it to someone at Sun.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-805" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('805', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-805-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-805" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('805', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-805-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: josef</title><link>http://krebsonsecurity.com/2010/01/patch-it-or-scratch-it-realplayer/#comment-800</link> <dc:creator>josef</dc:creator> <pubDate>Fri, 22 Jan 2010 02:38:49 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=648#comment-800</guid> <description>Brian,You mentioned Java as an optional program above.  I noticed that after installing their recent version 6 update 18 that I have several Java console Add-ins for Firefox installed now, which correspond to older versions (Java Console 6.0.16, Java Console 6.0.17, Java Console 6.0.18).Do you know if these older consoles pose security risks (i.e. that programs can indicate which version of Java to use)?  I thought Java was removing older versions on the update process.Thanks!</description> <content:encoded><![CDATA[<p>Brian,</p><p>You mentioned Java as an optional program above.  I noticed that after installing their recent version 6 update 18 that I have several Java console Add-ins for Firefox installed now, which correspond to older versions (Java Console 6.0.16, Java Console 6.0.17, Java Console 6.0.18).</p><p>Do you know if these older consoles pose security risks (i.e. that programs can indicate which version of Java to use)?  I thought Java was removing older versions on the update process.</p><p>Thanks!</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-800" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('800', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-800-up" style="font-size:12px; color:#009933;">2</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-800" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('800', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-800-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached (user agent is rejected)
Database Caching 1/9 queries in 0.002 seconds using memcached

Served from: krebsonsecurity.com @ 2010-07-30 05:34:42 -->