Posts Tagged ‘security’

Update: SecureCRT 6.5.4

Tuesday, August 10th, 2010

A new SecureCRT maintenance update has been released, 6.5.4, only fixing a fair number of bugs.

I for one, am really happy to see the first one (see changelog below). The crash didn’t happen very often, but when it did, it was really really annoying…

SECURECRT 6.5.4 DOWNLOADS
SECURECRT 6.5.4 CHANGELOG
- When multiple instances of SecureCRT were running, attempting to display a connection closed message could cause SecureCRT to crash.
- SecureCRT could lock up when a Send ASCII command was used to send a large file (e.g., 100,000 lines).
- SecureCRT hung when attempting to open the Customize dialog if multiple instances of SecureCRT were running.
- In some cases, when characters with diacritics were pasted into a session using VT220 emulation, they were not displayed correctly.
- The way characters were clipped when they were displayed in the session affected the behavior of the JAWS screen reading software.

Update: ZOC 6.10

Monday, May 18th, 2009

ZOC running on Windows 7 Beta

ZOC running on Windows 7 Beta

ZOC skips a version number and reaches 6.10.

DOWNLOAD ZOC 6.10
Get it now: Download ZOC 6.10 (Windows)
exe installer, 3.98MB, MD5 sum: 42DC60BA13F049E0504D89F305854EE9

Mac OS X version: Download ZOC 6.10 for Mac

Other platforms, resources: ZOC download page

WHAT’S NEW IN ZOC 6.10
NEW: option (Program Settings, Misc) to show cursor position 1-based
NEW: telnet option for SOCKS4 proxy (via Telnet ‘Configure…’ button)
NEW: SSH option for SOCKS4 proxy (via SSH ‘Configure…’ button)
NEW: layout option (session profile) to render fonts with antialising
NEW: now supports folders and subfolders within host directory sections
NEW: REXX command ZocFilename(“GETVOLUMELABEL”, …)
NEW: REXX ZocUpload command now supports multiple files
NEW: option to draw cursor in user defined color
NEW: first attempt to support extended colors on TN3270
BETA: VERS 6.09 (internal only)
FIX: cursor style restore failed for htop and mc under Linux
FIX: possible crash when using File, New Window
FIX: possible crash when starting
FIX: quirk with lognames and ^+ placeholder (use session name for log name)
FIX: better error messages for some SSH connection problems
FIX: wrong background color in ‘Configure…’ dialogs (OS X Leopard only)
FIX: cursor style changed after cursor store/restore operation
FIX: TN3270 minor screen redraw glitches
FIX: possible crash when pasting large chunks from the clipboard
FIX: could not login if an SSH password contained a double quote character
FIX: error in host directory when doing ‘mark due’ in folder
FIX: moving an entry to the last folder of a host directory section failed
FIX: possible crash when leaving scrollback while find dialog was open
FIX: problem with 3270/5250 misaligned fields on screen
FIX: problem with 3270/5250 not unlocking the keyboard on receiving screens
FIX: crash when loading version (version 608d Windows only)
CHG: host directory file format changed (internal)
FIX: possible crash when loading bad options files
FIX: quirks with Xterm emulation and meta key in MC (Alt+Tab, Alt+Enter)
FIX: unexpected condition error when using EREXX.DLL (Windows only)
FIX: using REXX ZocGetScreen after a ZocWait sometimes returned nothing
FIX: possible crash when remote host sets window title to a very long string
CHG: internal storage of host directory changed for less memory consumption
FIX: problem initiating a scrollback through tracking the scrollbar (OS X only)
FIX: paging through scrollback via scrollbar skipped two pages (OS X only)
FIX: lines which wrapped around the end now not broken when put to clipboard
FIX: host directory call stats were wrong (Mac OS X PPC only)
FIX: possible crash on startup running on machine with long computer name

Update: SecureCRT 6.2.1

Thursday, April 30th, 2009

A SecureCRT maintenance update has been released: 6.2.1.

SECURECRT 6.2.1 FINAL DOWNLOADS
SECURECRT 6.2.1 CHANGELOG
- SecureCRT could not be installed on systems where InstallShield custom actions do not work.
- If a license with a maintenance date in the format MM-DD-YY was entered, SecureCRT crashed.
- Under Vista, the mouse wheel did not scroll if the system used the MS Explorer Mouse driver.
- Function and arrow keys did not work correctly with servers that expect all the characters in escape sequences to be sent in the same packet.
- In a session with the “Retain size and font” option set, if the window was resized so that it was smaller than the logical rows and columns, the wrong text was highlighted during a find operation.
- If a session was opened in a new window and the window was closed prior to authentication completing, authentication prompts continued to be displayed.
- In the Keymap Editor, if a key was selected and a keymap that mapped that key was loaded, the keymap assignment display was not updated.
- In the Connect dialog, a session that was copied could not be pasted more than two times.
- If the Visual Studio 2008 DLLs were not in the side-by-side cache, MFC90.DLL errors were written to the event viewer when SecureCRT ran.
- SSH1/SSH2: If an RSA key with a passphrase was added in the Manage Agent Keys dialog and the wrong passphrase was entered, the incorrect error “The key packet is corrupt, damaged, or incompatibly formatted” was reported and was still reported after the correct passphrase was entered.

Update: ZOC 6.08

Friday, April 17th, 2009

ZOC running on Windows 7 Beta

ZOC running on Windows 7 Beta

ZOC 6.08 is now available.

Among the usual fixes, there’s a new small (but interesting) feature that enables users to manually enter the username each time a session is opened (useful if your username changes often). Simply input a question mark (?) instead of the username when saving the session.

DOWNLOAD ZOC 6.08
Get it now: Download ZOC 6.08 (Windows)
exe installer, 3.88MB, MD5 sum: 679A54D4432B1DC82ED5FC54945784A4

Mac OS X version: Download ZOC 6.08 for Mac

Other platforms, resources: ZOC download page

WHAT’S NEW IN ZOC 6.08
CHG: price change with U.S. and European distributor
FIX: cd-valid opt in serial/modem in session profile did not stick (OS X only)
FIX: save-as button for serial/modem AT commands was broken (OS X only)
FIX: cursor keys in local typing (Windows only)
FIX: possibly lost the main window in multi monitor setup (OS X only)
FIX: ssh.exe and telnet.exe were linked with msvcr80.dll instead of megadodo.dll
FIX: possible crash when switching away from TN5250 emulation
NEW: using a questionmark as SSH username will show a username prompt
FIX: tabs opened in background always started as 80×25
FIX: uninstaller did not remove empty subdirectories in startmenu (Windows only)
FIX: possible assert msg when closing tabs through ‘Send to all tabs’
FIX: minor quirk with selection of host directory entries (Windows only)
FIX: keyboard shortcuts did not work in the local typing field (Windows only)

Update: SecureCRT 6.2 Beta 3

Friday, March 20th, 2009

SecureCRT BETA running on Windows 7 BETA :D

SecureCRT BETA running on Windows 7 BETA :D

A new SecureCRT beta, fixing some of the bugs in the newly introduced features for 6.2.

SECURECRT 6.2 BETA 3 DOWNLOADS
WHAT’S NEW IN SECURECRT 6.2 BETA 3
- SecureCRT crashed if a session was disconnected before the shell request succeeded.
- SecureCRT crashed if the File menu was selected after the menu bar was reset to Default from the Menus tab in the Customize menu.
- When some escaped ASCII characters such as “\200″ were sent to the remote system from a script or a mapped key, they were transformed first.
- With the “Retain size and font” option set, the PageUp and PageDown keys scrolled a different amount than when using the mouse to page up and page down.
- The trace output displayed garbage for an “Unknown CHANNEL_REQUEST” message.
- When generating a public key in the Key Generation wizard, the progress bar was not displayed until after the key had been generated.
- Three-year licenses were not being honored.
- In the Connect dialog, when a new folder was added, a folder called “New Folder” was also added.
- In the Connect dialog, attempting to rename a session to the same name as its parent folder reported an error that the name was already in use.
- After pasting a copied session into a folder in the Connect dialog, the folder was selected.
- SSH1: When SecureCRT was installed on a U3 drive, public-key authentication always failed for SSH1 sessions.
- SSH2: Attempting to authenticate using GSSAPI with the 64-bit MIT Kerberos DLL failed.
- SFTP: If a transfer operation was cancelled using CTRL+C, the SFTP tab became unresponsive.

Update: ZOC 6.06

Wednesday, March 11th, 2009

ZOC running on Windows 7 Beta

ZOC running on Windows 7 Beta

ZOC 6.06 is now available.

Among bugfixes, there are also a few new features, two of which I find very interesting:

- sending commands typed in the “Local typing” field to all currently open connections

- and the ability to copy to clipboard the entire contents of the scrollback buffer with a single click (saves me from occasional clumsy scrolling “sessions”)

DOWNLOAD ZOC 6.06
Get it now: Download ZOC 6.06 (Windows)
exe installer, 3.88MB, MD5 sum: 68DD186EDB4939423637EFA5A839C306

Mac OS X version: Download ZOC 6.06 for Mac
dmg, 4.30MB, MD5 sum: 039625FB9845E9C62E2AAF73794F36E3

Other platforms, resources: ZOC download page

WHAT’S NEW IN ZOC 6.06
- FIX: possible hangup via modem before/after file transfers
- FIX: problem switching to modem parameters different from 8N1 (OS X only)
- FIX: possible error about unused variable (Windows only)
- CHG: SSH now also uses supplied password to auth via keyboard-interactive
- FIX: problem with some characters on Linux/VT220 emulation and DOS codepages
- FIX: problem with disabled menu items with multiple windows (OS X only)
- FIX: could not access context menus using a single-button mouse (OS X only)
- FIX: small graphical glitch in tabs’ close buttons (OS X only)
- FIX: possible crash on malformed xterm sequence
- FIX: some safety promts when closing program were inconsistent with multiple tabs
- FIX: quirk with radio buttons on layout page in session profiles (Windows only)
- FIX: possible crash on startup when using Wyse emulation as default
- NEW: a few extra items when right-clicking the empty area on the tabs bar
- FIX: zmodem download statistic showed wrong value after transfer finished
- NEW: special control code ^8 now also includes a counter for tabs
- NEW: added checkbox to Local Typing to send output to all tabs
- CHG: upper limit for scrollback now 64000 lines
- NEW: command in Edit menu to write scrollback to clipboard
- NEW: command in Logging menu to open the logfiles folder
- FIX: incorrect or missing colors when doing a ls command on Linux
- FIX: various quirks with case sensitive file systems (OS X only)

Update: Opera 9.64 – Security Fix Rush

Tuesday, March 3rd, 2009

Opera 9.64 Final is now available for download.

It mainly serves as a security refresh, with several issues being fixed and new security related features being implemented.

OPERA 9.64 DOWNLOADS
Get it now: Download Opera 9.64
EXE installer, no toolbar, 5.36MB, MD5 sum: 4CEDF5AF0C18F33FC4B738233406FA76
WHAT’S NEW IN OPERA 9.64
Security
- Fixed an issue where specially crafted JPEG images ccould be used to execute arbitrary code, as reported by Tavis Ormandy of the Google Security Team; see our advisory
- Fixed an issue where plug-ins could be used to allow cross domain scripting, as reported by Adam Barth; details will be disclosed at a later date.
- Fixed a moderately severe issue; details will be disclosed at a later date.
- Added support for the following platform-specific features:
- DEP (Data Execution Prevention) in Microsoft WindowsXP® with Service Pack 2 and higher and Microsoft Windows Server 2003® with Service Pack 1
- ASLR (Address Space Layout Randomization) in Microsoft Windows Vista®
- Added Untrusted Rootstore Capability:
- Opera downloads only the detailed information about untrusted (blacklisted) certificates when they are encountered
- If download fails for certificate information in the list, Opera considers any certificate matching the ID as untrusted
- Added version conditional fetching of certificate dependencies from an online repository
- Fixed a problem downloading the CRL (Certificate Revocation List)
- Fixed a problem that could cause SSL to deadlock in one state, hanging the connection
- Fixed a problem that could cause the incorrect calculation of Certificate IDs
- Implemented Extended Validation (EV) for cross-signed EV Root Certificates not shipped by default
- Implemented preshipping of the Entrust 2048 CA (Certificate Authority)
- Implemented Root Certificate fetching from an online repository when an intermediate matches a certificate in the repository
- Improved support for weak encryption when importing .p12 private certificates
- Prevented security information documents from being written to disk

Miscellaneous
- Fixed a problem which created separate feed notifications; Opera now groups them together
- Fixed a problem with inline find when no content was entered and the Enter key was pressed
- Implemented opacity on text styled with hexidecimal color codes
- Installing an external source viewer no longer requires an Opera restart
- Installing Opera sets it as the default browser; this may be reset during the install process

Stats by WP SlimStat