Wednesday, October 01, 2003

The Windows XP startup disk allows computers without a bootable CD-ROM
Windows XP Home Edition with Service Pack 1 Utility: Setup Disks for Floppy Boot Install
The Windows XP startup disk allows computers without a bootable CD-ROM to perform a new installation of the operating system. The Windows XP startup disk will automatically load the correct drivers to gain access to the CD-ROM drive and start a new installation of Setup.

Quick Info
File Name:
winxpsp1_en_hom_bf.exe

Download Size:
4301 KB

Date Published:
9/9/2002

Version:
SP1

http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=FBE5E4FC-695F-43E5-AF05-719F45C382A4
MCSEworld>>>Knowledge Base>>>Tips and Tricks>>>
Shell enhancements or tweaks Windows XP/2000

http://www.petri.co.il/other_free_shell_enhancements.htm

Tuesday, September 30, 2003

IE holes lead to AIM, dial-up attacks
Security holes in Microsoft's Internet Explorer have been exploited by hackers to hijack AOL instant messaging accounts and force unsuspecting Web surfers to run up massive phone bills, computer experts cautioned on Friday.
Some IE users are also finding that malicious Web sites are secretly slipping Trojan programs onto their computers, which could prove an even more dangerous exploit, said Drew Copley, a research engineer at Aliso Viejo, Calif.-based eEye Digital Security, who discovered the original security vulnerability.

Such stealth programs can include keystroke loggers that record everything a person types or software to erase the hard drive, among other things, he said.

Microsoft has released a patch for the original hole, which was reported about a month ago, said Stephen Toulouse, security program manager for Microsoft's Security Response Center. The company is looking into what it says are variations of the original hole that have been discovered since then that the patch does not fix, Toulouse said.

"We will release a fix for the variations," he said.

Security experts are reporting the variations as new security holes, disclosed within the past three weeks and used for different types of attacks, Copley said.

Microsoft and eEye Digital Security said they have issued information for temporary workarounds.

In general, the attacks are accomplished by leading Internet Explorer users to a malicious Web site, either by sending an e-mail with a link to the Web page or distributing a link through instant messaging, Copley said.

When the Web site appears, it downloads code that can execute commands on its own onto the unsuspecting computer user's machine, Copley said.

An attacker has written a program that uses a security hole in Internet Explorer to hijack an already running AOL Instant Messenger account, changes the password and sends a message to the buddies list with a link to the malicious Web page, according to postings on the Bugtraq security e-mail list.

The Web site the posting listed as stealing the AIM passwords appeared to have been shut down.…Another attack is being accomplished by sending computer users to Web sites--typically porn sites--that change the computer's dial-up settings to an expensive long-distance phone number without the person knowing it, said Richard Smith, an independent Boston-based security researcher.

In the so-called "porn dialer" attack, victims are being charged as much as $5 a minute instead of paying their normal Internet service fee, he said.

A third type of attack steers computer users to pay-per-click Web sites, where the spam marketer gets paid each time someone goes to the Web site, Copley said.

Computer users can protect themselves by applying patches, following the workaround instructions, or changing their settings in Internet Explorer to prompt them before a Web site downloads programs that can execute on their own, Toulouse said.

http://zdnet.com.com/2100-1105_2-5083234.html
Put XHTML 1.0 Strict and Transitional to work
XHTML 1.0 Strict
XHTML 1.0 Strict is the most demanding XHTML flavor, but it provides the cleanest structural markup. Strict code is free of any markup used to define layout. It uses cascading style sheets (CSS) to control the presentation. This separation of structure from presentation is what makes XHTML Strict flexible enough to be displayed on different devices. The reliance on CSS to control presentation can be problematic for developers, because it's not a good choice for Web content that needs to be viewed on devices or in browsers that do not recognize style sheets.

XHTML 1.0 Transitional
XHTML 1.0 Transitional is the more forgiving XHTML flavor. Unlike Strict, which completely separates structure from presentation, Transitional allows you to use tags to control the look of your markup. Its goal is bridging the gap between HTML-based pages that allow the markup to control the presentation and XHTML Strict, which does not. Its main benefit is that it overcomes Strict's CSS dependence. Transitional pages are still accessible to users who use older browsers or who are using devices that don't recognize style sheets.

How to choose?
The choice between Strict and Transitional depends on a couple of factors:

Audience. If you find that much of your audience uses older browsers that don't recognize style sheets, Strict may not be the right answer—although I would make the case that supporting standards is more important than backward browser compatibility at this point. If most of your audience is using the latest versions of Internet Explorer, Netscape, Opera, or Safari, Strict is the best long-term choice.

Current code. If you already use CSS and your HTML doesn't contain a lot of markup that controls presentation, you can make the leap to Strict.…

http://builder.com.com/5100-6371-5061538.html?fromtm=e606
2003 CSI/FBI cybercrime survey
The eighth edition of the longest-running annual survey of computer crime and losses has recently been published by the Computer Security Institute. The study, which is conducted in cooperation with the San Francisco FBI office, is based on the results reported by 530 security specialists working in U.S. corporations and government agencies.

The number of incidents remained about the same as in the 2002 survey, but overall economic loss was down significantly; losses due to financial fraud in particular were down by 90 percent.

Theft of proprietary information was reported as being responsible for the most financial loss, with the average reported loss pegged at about $2.7 million per incident.

Denial of service attacks were responsible for more than $65 million in total losses among those surveyed, making it second only to theft of proprietary data in total cost.

Insider attacks and system abuse followed virus infections as the top category of adverse events based on the number of incidents.

In a blow to crackers who think they can move into the mainstream, 68 percent of the respondents were strongly opposed to hiring reformed hackers.

The high incidence of virus attacks reported is also a bit surprising, since 99 percent of the companies surveyed reported using antivirus software. A full 98 percent also report using firewalls.

Back when the survey began, fewer than one in five serious attacks were reported to authorities, but that percentage has doubled in recent years to around 30 percent. Of those who gave a reason for failing to report incidents, more than half said they didn’t know they could report incidents. But nearly three-quarters say that they don’t report incidents because they fear negative publicity.

The report speculates that so many companies said they didn’t know they could report incidents because they simply weren't sure which agency would have jurisdiction. This certainly remains a serious problem, with few local authorities being willing or able to pursue cybercrimes. In some cases, the Secret Service might be involved, but the FBI is often the only agency that would have both the capability to deal with this sort of crime and the jurisdiction. However, the FBI has been swamped with new antiterrorism duties since 9/11, and when it wants to pursue a nonviolent cybercrime, it often doesn't have the resources available.

When asked for his interpretation of the survey results, Special Agent Tom Grasso of the Pittsburgh FBI office pointed out that there was an “even split between unauthorized use by insiders and outsiders” and noted that a big percentage of respondents blamed disgruntled employees for the attack. He also reminded security specialists to consider past survey data when analyzing this year's results. "The authors of the study commented that this [year’s numbers] are in line with pre-2001 data, which could mean that 2001 and 2002 were just unusually high.”

Grasso is the FBI liaison with CERT and is the driving force behind the National Cyber-Forensics and Training Alliance (NCFTA), a partnership among law enforcement, academia, and industry that is working to improve cyberforensic skills.

Free PDF copies of the full report are available.
To obtain your free copy, fill out the form on this page.
Bound and printed versions are also available through
Kinko's DocStore service; a small fee is charged to cover
printing and shipping costs.

Companies can take one commonsense step to help prevent attacks: They can patch their systems. According to the CSI/FBI report, almost unbelievably, even companies that experienced serious computer system intrusions failed in nearly 10 percent of cases to patch the vulnerable systems. In the 2002 report, only 77 percent reported patching known holes that had been exploited. It might be interesting to ask some of them just what economic or other considerations kept them from patching a hole when they knew an exploit existed and had been used to successfully attack them at least once.

http://www.ncfta.net/

http://gocsi.com/forms/fbi/pdf.jhtml?_requestid=990693

Saturday, September 27, 2003

GotDotNet Workspaces
GotDotNet Workspaces is an online collaborative development environment where .NET developers can create, host and manage projects throughout the project lifecycle.

What sort of tools are available to make all of this happen? Check out the About Workspaces page for details on all the features. Still don't have the answers to all your questions? Try looking in the FAQ.…

For those of you unaware of this application, the Workspaces are an open source community written and provided free by Microsoft. Yes, you heard right. I did say open source, free, and Microsoft in the same sentence.

If this surprises you, you obviously haven't seen the ASP.NET Starter Kits, Web Matrix, TaskVision, Terrarium, or the Application Blocks. But before you start comparing Workspaces to something out of the movie Antitrust, Microsoft has a very clearly defined user agreement that states your source code will only be stored and not viewed.

http://www.gotdotnet.com/community/workspaces/docs/about.aspx
http://www.gotdotnet.com/community/workspaces/docs/faq.aspx


http://www.gotdotnet.com/community/workspaces/default.aspx

Friday, September 26, 2003

Microsoft Bloggers
Microsoft folks are blogging about
everything from their favorite martini recipes, to marketing
challenges, to the guts of the Common Language Runtime
inside the .Net Framework. And now Microsoft is planning on
making some public noise about its support for RSS 2.0,
according to Empire Blog Watcher Mary Jo Foley.

http://www.microsoft-watch.com/article2/0,4248,933657,00.asp

Thursday, September 25, 2003

Sobig.f proves why focusing on commercial spam is a mistake
One of the biggest mistakes being made on the anti-spam front by vendors, service providers, lawmakers, and lawyers is the focus they are placing on technological and legal solutions that attempt to define, in one-size-fits-all fashion, what spam is.

Many of these solutions start with the notion that spam is unsolicited commercial e-mail. They leave alone other types of unwanted e-mail --- worms, viruses, surveys, political messages, chain letters, etc ---- that are equally empowered to destroy the Internet's e-mail system.

Perhaps now, with the latest variant of the Sobig worm wreaking havoc on the Internet, these misguided anti-spam fighters will realize that defining spam is a waste of time. Tracing Sobig's footsteps and side effects,… shall reveal that focusing on any one type of unwanted e-mail leaves the Internet's e-mail system vulnerable to an irretrievable breakdown. The same industry-wide standards that could help in the battle against spam can also relieve the Internet's e-mail system of the life-threatening congestion caused by worms like Sobig.…

To cover their tracks, senders of unwanted e-mail prey on this weakness --- the ability to "spoof" an e-mail header --- in the Internet's SMTP standards. Even worse, this weakness is often exploited to make an e-mail look to the recipient as though it's coming from someone they already know. This technique increases the likelihood that the unwanted e-mail will get opened by the recipient. .

To a recipient, the Sobig worm and a spammer look very much the same. They're both the source of a tremendous amount of unwanted e-mail. They both forge the originator's credential information to cover their tracks. They both flood the Net with unnecessary traffic. They're both a drain on the recipient's (or receiving organization's) time, money, and productivity. But where they differ is in their distribution. Whereas a spammer will often send transmissions from a single or small number of addresses, Sobig works like a Distributed Denial of Service (DDoS) attack. First, it finds vulnerable systems on the Internet and then, via its payload, it deputizes them into originating more worm-laden e-mail.

The result is very spam-like. An enormous amount of e-mail traversing the Internet, all bearing forged credentials that not only aren't traceable to the originators of the worm itself, but aren't even traceable to the deputized system. But it gets worse.…

http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2914521,00.html

Wednesday, September 24, 2003

Why Verisign's Wildcard DNS is a Bad Idea
Verisign, owners of what was once Network Solutions, have introduced a new wrinkle to the web. By adding 'wildcards' to their domain name settings, any domain name not found will be redirected to their 'helpful search portal.' This is because, in reality, an address was found: Verisign's wildcards match anything not found elsewhere. If the domain is found, but not the page, that domain's 'not found' page will be displayed. I'll leave it to others to discuss the technical details if they choose to.

Why is this a bad idea? Not because it annoys me personally. If that were a valid argument it would deny fans of certain television sitcoms and certain styles of music their rightful enjoyment. Verisign had a Bad Idea from a business perspective, and from a web perspective. It's a bad business model, it violates the spirit of the web, and it confuses and potentially alienates customers.

A Bad Business Model
Network Solutions was once a government-sanctioned monopoly. Not the open-to-debate type of monopoly Microsoft is accused of being, but a true monopoly. As the only vendor for domain name registration, they could essentially make their own rules.

Those days are gone. Now, domain name registrars can be found on any virtual street corner. Verisign, as the new NetSol, is trying to recover from that loss of monopoly. Let's briefly compare these two alleged monopolies, Microsoft and Verisign/Netsol. Microsoft develops (or purchases) tools that are useful to me, and which I usually have a hard time finding elsewhere for a fair price and the same quality. (I realize that's a subjective statement, so if you disagree, feel free to write your own article and make your own subjective statements to the contrary.) Microsoft has done a world-class job of marketing, making their tools the de facto standards of the software world, as far as the average end-user is concerned.

Verisign provides no services which can't be found elsewhere, at a better value for the same or superior quality. Their marketing has done nothing compelling to cause me to desire their services. Although they have lowered prices on extended domain name registration, their first-year price is exactly what it was during the days of their monopoly. This makes bad business sense when equal or better registration services are commonly available for less than one-third the cost. Higher prices, in a good business model, must be offset by some compelling reason for the customer to pay them. Verisign has not provided that reason.…

http://evolt.org/article/Why_Verisign_s_Wildcard_DNS_is_a_Bad_Idea/25/60224/index.html?format=print

Tuesday, September 23, 2003

Microsoft PowerToys for Windows XP
They're back! PowerToys are additional programs that developers work on after a product has been released to manufacturing. They add fun and functionality to the Windows experience.

Note: PowerToys operate as they should, but they are not part of Windows and are not supported by Microsoft. For this reason, Microsoft Technical Support is unable to answer questions about PowerToys. PowerToys are for Windows XP only.

Important Notes
You must uninstall your old PowerToys before installing the new ones.
PowerToys will only work with US-English regional settings.
Just look at your PowerToy choices:


http://www.microsoft.com/windowsxp/pro/downloads/powertoys.asp

Monday, September 22, 2003

Patch issued for critical Sendmail flaw
A critical vulnerability has been found in Sendmail, the most widely used mail server software.

The vulnerability allows attackers to take control of servers using Sendmail, which is commonly used on Linux, Unix and BSD systems.

The discovery and subsequent disclosure of the security flaw comes one day after serious security problems in the OpenSSH secure shell server software were disclosed.…


It's the third time this year that a serious vulnerability has been found in Sendmail software, and the second reported by Michal Zalewski, the researcher that posted the most recent bug. The earlier bug was found by Internet Security Systems in early March.

Users can upgrade to version 8.12.10, which is not affected by the glitch, or apply a patch.

http://zdnet.com.com/2100-1105_2-5078601.html

Sunday, September 21, 2003

Don't Let Your PC Become a Porn Zombie
More than a thousand Windows PCs were hijacked recently, unbeknownst to their owners, to send spam and distribute pornography. This was done via a Trojan known as Migmaf (migrant Mafia) that turned their machines into proxies, or relay points, which hid the real servers involved. (For more information, see the article at www.wired.com/news/print/0,1294,59608,00.html.) The victim machines, controlled from afar, are often called zombies. Here's how to keep your PC from becoming a zombie in the service of spammers, pornographers, and malicious hackers.

It's important to understand that although mainstream news coverage of such exploits is a recent development, these activities have been occurring practically since the general public was allowed to use the Internet in the early 1990s. Back then, hackers who wanted to cover their tracks would take control of machines running certain programs that let Windows-based PCs share Internet connections (before Microsoft built Internet Connection Sharing into the operating system). They'd then use these machines as proxies for their attacks on other systems. When investigators tried to trace the break-ins, they would find only the Windows machine, which kept no record of the hacker's whereabouts.


Pornography and spam make for good headlines, but the purposes for which most compromised machines are used are not nearly as sensational. Most often, machines are used as repositories for warez—pirated software—or as rendezvous points for IRC sessions among hackers. They're also commonly used as soldiers (or zombies) in distributed denial-of-service (DDoS) attacks, in which large numbers of computers focus a barrage of network traffic on a single company or computer system. In most cases, users whose machines are compromised never know that their systems are being used for nefarious purposes.

You can protect your machine by learning to recognize the signs that your computer is being invaded. Are the lights on your cable/DSL modem, or network hub flashing wildly when you're not doing anything on the Net? Is your hard drive seeking frantically when the system ought to be idle? Does your system seem sluggish? While none of these symptoms are sure signs that your computer has become a zombie, they merit investigation.

If you're running Windows, try typing netstat-a in a command window. Do you see established connections to other machines, even when your browser and e-mail programs are closed? If so, your computer could be compromised. (For helpful information on the ports Trojans generally use, as well as the free PestPatrol Port Checker utility, check out http://pestpatrol.com/Support/About/About_Ports_And_Trojans.asp#advice.)


http://www.pcmag.com/article2/0,4149,1268110,00.asp

Saturday, September 20, 2003

Immunity from the Pop-Up Plague
One lesson from the Internet bust: If something seems too good to be true, it probably is. Take those thousands of pieces of "free" software available on the Net for everything from file sharing and instant messaging to e-mail and calendar applications. The catch? Many come with code or components that allow companies to track your surfing habits, profile your shopping preferences, and sell that data to unprincipled marketers. They can also hijack your browser start page or alter important system files -- all without your knowledge.

The problem could get a lot worse. On Sept. 5, District Judge Gerald Bruce Lee ruled that Gator, a company whose software plasters its own pop-up ads and banners over any that might be contained on a Web site, was legal. But he admitted it's annoying. "Alas, we computer users must endure pop-up advertising along with her ugly brother 'spam' as a burden of using the Internet," Judge Lee wrote in his final ruling. "Ultimately, it is the computer user who controls how windows are displayed on the computer desktop."

UNDERCOVER AGENTS. It sure doesn't feel like that sometimes. Ad-ware like Gator's GAIN network -- which displays various forms of pop-up ads based on the types of Web sites you've visited before and what you click on -- can seriously slow your computer. There have been reports that it can even cause computers to crash. Its more insidious cousin, spyware, which covertly gathers personal information, usually for advertising purposes, can keep track of e-mail addresses and passwords, monitor every keystroke, even dial 900 numbers on the sly, leaving you to pay the price.

Computer experts fear that the Gator ruling will embolden less reputable software firms to bundle or just plain sneak their software onto unsuspecting users' PCs. Already, there's plenty of evidence that programmers are finding ever-more devious ways to spy on cyber-surfers.…

There are, however, several simple software programs to help you scan and destroy both pesky adware and sinister spyware. Two of the most popular are Ad-Aware, published by Swedish firm Lavasoft, and Spybot Search & Destroy from German firm PepiMK Software's. Both work much like an antivirus tool. You can set them up to scan when you boot the computer or request only manual checks. After scanning, the programs will show suspicious files and programs in red and give you the chance to delete them.…




http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2914680,00.html

Thursday, September 18, 2003

SSH security glitch exposes networks
SSH security glitch exposes networks
By Patrick Gray
ZDNet Australia
September 17, 2003, 5:06 AM PT
URL: http://zdnet.com.com/2100-1105-5077796.html
A critical security flaw in SSH has been revealed that threatens servers worldwide.

SSH is a widely used encrypted remote management shell for Unix, Linux and BSD platforms. Experts say attackers have been exploiting the vulnerability to gain access to systems illegally for months.

What started as quiet mumblings and rumors turned into screaming warnings yesterday as the security community slowly learned of the threat. Chief hacking officer of U.S.-based eEye Digital Security told ZDNet Australia by phone the vulnerability should be taken very seriously. "It's pretty close to a skeleton key to most networks," he said.

It's not uncommon for vulnerabilities in Unix-style systems to be exploited for months by the underground community, Maiffret said. "It's definitely happened in the past with SSH vulnerabilities ... it's definitely a recurring theme for Unix vulnerabilities."

…there are actually two vulnerabilities in the software. "[Version] 3.7 was released early this morning, and then 3.7.1 was released about a couple of hours ago," he said. "The thing was just the way the two bugs work.... It looks like the first one was probably fixed with 3.7 and the other one was fixed with 3.7.1."

There are, however, suggestions that some mitigating factors may apply. "There are rumors going around that you need to allow remote root SSH login for the exploit to work," he said. "That's the thing, there are all these rumors going around." Loveless says people should patch to 3.7.1 as soon as they can. "Exploit code will surface within hours," he warned.

CERT published an advisory, however it was issued prior to the release of the 3.7.1 version upgrade. The OpenSSH patch and advisory has been updated. "All versions of OpenSSH's sshd prior to 3.7.1 contain buffer management errors. It is uncertain whether these errors are potentially exploitable, however, we prefer to see bugs fixed proactively," it reads.

http://www.openssh.com/txt/buffer.adv

http://zdnet.com.com/2100-1105_2-5077796.html
Exploit Code Arises for Latest Windows Flaws
Adding more fuel to the fears that another Windows worm is on the horizon, security experts said Tuesday afternoon that they have seen working exploit code in the wild for the latest pair of vulnerabilities in the Windows RPC DCOM interface.

The discovery of the code, which can be used to attack the two buffer overrun flaws in the interface, comes just two days after someone posted to a security mailing list exploit code for a denial-of-service weakness in the same interface. The RPC DCOM problems are particularly troubling and potentially dangerous because they affect nearly every current version of Windows, including the new Windows Server 2003.

A previously discovered buffer overrun in the interface was exploited by the Blaster worm that tore through the Internet in August.

The newly released exploit code gives attackers the ability to get privileged access to vulnerable machines and also allows for the creation of a new account with a preset password. The exploit tool also gives attackers the option of targeting specifically configured machines, i.e., Windows 2000 Service Pack 3 or machines that have the patch for the original RPC DCOM flaw installed but not the fix for the more recent vulnerabilities, according to an analysis by iDefense Inc., based in Reston, Va.

Ken Dunham, malicious code manager at iDefense, said he expects to see widespread compromise of vulnerable PCs in the next few days and also anticipates the release of a worm based on this code. The exploit code has been posted to at least one well-known cracker Web site.

"We've seen it, we've brought it into the lab and it works. We haven't seen any infections yet, but it's only a matter of time before it gets going in the wild," said Bruce Schneier, CTO and founder of Counterpane Internet Security Inc., in Cupertino, Calif., a managed security monitoring provider. "When [a new worm] hits, it's likely to be a fast-spreader. Someone could just take the old Blaster code, rip out the old infection mechanism, drop this one in, and you're done."

The new code exploits two buffer overruns in the Remote Procedure Call (RPC) Distributed Component Object Model (DCOM) interface in Windows. Specifically, the problems lie in the portion of the service that handles RPC messages for the activation of the DCOM. Microsoft Corp. released a patch for the flaws last week.…

http://www.eweek.com/article2/0,4149,1270468,00.asp

Tuesday, September 16, 2003

Product Documentation
Get easy access to product documentation and online Help resources here for Windows, Office, Servers and Visual Studio.


http://www.microsoft.com/technet/treeview/default.asp?url=/TechNet/itsolutions/proddocs/default.asp
Microsoft Security Bulletin MS03-034
Flaw in NetBIOS Could Lead to Information Disclosure
Who should read this bulletin: Customers using Microsoft® Windows®

Impact of vulnerability: Information disclosure

Maximum Severity Rating: Low

Recommendation: Users should evaluate whether to apply the security patch to affected systems.

End User Bulletin:
An end user version of this bulletin is available at:
http://www.microsoft.com/security/security_bulletins/ms03-034.asp.


http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-034.asp

Monday, September 15, 2003

Listutorial
Listutorial takes you through the basics of building CSS lists with "background images for bullets" and "simple rollovers" with a few variations along the way.

http://www.maxdesign.com.au/presentation/listutorial/
Why you must install a firewall NOW
If you haven't already installed a personal firewall on your Windows computer, consider this your last warning.

MSBlast, the recent worm that exploited the buffer overflow in Windows's DCOM RPC protocol, wasn't the sort of e-mail-borne pest that antivirus software is good at catching. Instead, it infiltrated computers directly through their Internet connections.

Although installing the latest Microsoft patches should prevent infections from this sort of worm, a simple software firewall will do the trick, too, whether or not you have antivirus software installed.

I MENTION THIS because Microsoft announced last week another critical flaw affecting DCOM RPC, and released a new patch to fix it that supercedes the previous patch for this protocol. While there are still no public exploits that take advantage of this flaw (exploits are often precursors to major worms), the clock is ticking. History has shown that worms are usually released within 30 days of a major vulnerability announcement.

In July, for example, Microsoft reported and patched a buffer overflow vulnerability in RPC based on the work of the Last Stage of Delirium Research Group. The MSBlast worm, which capitalized on this vulnerability, appeared on Aug. 12.

Last Wednesday, based on additional research by the companies eEye Digital Security, NSFOCUS, and Tenable Network Security, Microsoft reported two more buffer overflows and one denial-of-service vulnerability within its RPC protocol. The fact that it is similar to the first flaw could mean a shorter timeline to the next major RPC worm.

The Remote Procedure Call (RPC) is a protocol used by the Windows operating system. It's based on an RPC protocol from the Open Software Foundation, but it's the Microsoft-specific parts that are afflicted with vulnerabilities. The Distributed Component Model (DCOM), previously called Network Object Linking and Embedding (OLE), is a service that allows software on one computer to communicate directly with software on other computers over a network. In short, DCOM RPC in Windows allows a program on one machine to run code on another machine. To do so, a Windows computer must first listen on a dedicated port, usually 135.

…RPC, like other services that use DCOM, is turned on by default for all Windows versions, whether or not you are working on a network. Also, when your system's connected to the Internet, DCOM makes Windows automatically listen on port 135 (and others) for remote signals. This means a hacker need only construct a special message and aim it at port 135 on your Windows computer to cause a buffer overflow error. The buffer overflow, in turn, could replace part of a program's original code with new code.

That's how a hacker could use this flaw to take over your computer remotely. Upon seizing control of your computer, a hacker could then reformat the hard drive, use the computer to damage other computers, or steal personal data. (Note that this description makes it sound easier than it truly is to execute.)

http://www.zdnet.com/anchordesk/stories/story/0,10738,2914667,00.html
JavaScript tips & how-tos
You'll find details and tips on writing cross-platform code, debugging,
using reusable components, and much more.

http://builder.cnet.com/webbuilding/0-7264.html?tag=dir

Sunday, September 14, 2003

Internet Scout Project > NSDL Scout Reports > Math, Engineering, and Technology >Topic In Depth >Voice over Internet Protocol

Voice over Internet protocol (VoIP) is a technology that integrates voice services, such as those provided by long distance telephone carriers, into data networks. VoIP has received considerable attention in recent years since it blurs the line between telecommunications and Internet. Among other things, it has the potential for enabling virtually free person-to-person communication for anyone with an Internet connection.

Copyright 1994-2003 Internet Scout Project - http://scout.wisc.edu

http://scout.wisc.edu/Reports/NSDL/MET/2003/met-030912-topicindepth.php

Friday, September 12, 2003

New Worm Headed Our Way?
Administrators and security specialists hoping for a breather now that Blaster has faded and SoBig.F has expired may be in for a long weekend.

The nature of the new vulnerabilities revealed yesterday in the RPC DCOM implementation in Windows is so similar to the one that Blaster exploits that security experts believe it's only a matter of days, if not hours, before someone releases a worm to attack the new weaknesses. Even though it infected close to a million machines, experts say the Blaster worm was poorly coded and as a result did not do nearly the damage that a more efficient worm could have done. Blaster easily could be modified to work much better, and because the source code for the worm is readily available online, it's likely that someone is already at work on that task.

"It all adds up to a situation where we'll probably see a worm in the next 24 hours or so," said Jerry Brady, chief technology officer at managed security provider Guardent Inc., based in Waltham, Mass. "This could be worse. It wouldn't take very much—just some very minor changes to the way the RPC connections work or the duration of the connections."

Like the vulnerability that Blaster exploits, two of the three new flaws reported in the RPC DCOM implementation in Windows are buffer overruns that could enable an attacker to run arbitrary code on a vulnerable machine. The flaws affect Windows NT 4.0, 2000, XP and Windows Server 2003.

Although the vulnerability itself isn't found in other operating systems, Brady said that some of Guardent's customers had Blaster-related problems on non-Windows systems. Some of the customers' problems stemmed from the fact that Unix-based management systems have a hard time handling the volume of RPC requests that were being generated by infected PCs.

"Some of these systems were seeing 15 to 22 times the normal number of connection attempts, which doesn't sound like that much but it's still out of bounds for these workstations," Brady said.

Another issue causing concern in the security community is the fact that many of the control systems for utilities such as water plants and nuclear power plants use RPC to link their supervisory control and data acquisition (SCADA) systems to their Internet-connected networks. SCADA systems comprise central controllers and sensors and are used to remotely control complex systems such as power grids and water treatment facilities.

There have been some reports that Blaster played some role in causing the large blackout last month that affected much of the Northeast United States and parts of the Midwest. Brady said he fears that an improved RPC worm could produce far worse results.

Three New Critical RPC Flaws Found http://www.eweek.com/article2/0,4149,1261390,00.asp

http://www.eweek.com/article2/0,4149,1264676,00.asp

Thursday, September 11, 2003

Product Security Notification
To subscribe to the Microsoft Security Notification Service, please visit the Microsoft Profile Center at http://register.microsoft.com/regsys/pic.asp

To unsubscribe to the Microsoft Security Notification Service, please visit the Microsoft Profile Center at http://register.microsoft.com/regsys/pic.asp

This is a free e-mail notification service that Microsoft uses to send information to subscribers about the security of Microsoft products.

The goal of this service is to provide accurate information to our customers that they can use to inform and protect themselves from malicious attacks. Our security team investigates issues reported directly to Microsoft, as well as issues discussed in certain popular security newsgroups. When we publish bulletins, they'll contain information on what the issue is, what products it affects-if any, how to protect yourself against, what we plan to do to fix the problem, and links to other sources of information on the issue.

This service supplements our existing security reporting procedures. You can continue to read security bulletins and other information about Microsoft product security on http://www.microsoft.com/technet/security.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/notify.asp
Microsoft Security Bulletin MS03-039
Buffer Overrun In RPCSS Service Could Allow Code Execution (824146)
Originally posted: September 10, 2003

Summary
Who should read this bulletin: Users running Microsoft ® Windows ®

Impact of vulnerability: Three new vulnerabilities, the most serious of which could enable an attacker to run arbitrary code on a user’s system.

Maximum Severity Rating: Critical

Recommendation: System administrators should apply the security patch immediately

End User Bulletin:
An end user version of this bulletin is available at:
http://www.microsoft.com/security/security_bulletins/ms03-039.asp.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-039.asp
PC Client Helps Those Desperately Seeking WiFi
WiNc works with almost all WiFi hardware and provides a simple way to find, save, link up to, and manage personal WiFi connections. Even better, Cirond has developed a smaller version for PocketPC, so mobile users can enjoy WiNc's capabilities as well.

How It Works

The interface looks roughly the same on both platforms. It provides three tabs to help you locate, select, and connect to wireless networks. The Connection Management tab is where you identify and select wireless networks. By default, the software scans for new networks every 10 seconds, but you can reduce the frequency to every 2 minutes. The software sorts networks by signal strength initially, but you can sort by SSID, channel, WEP-key status (locked or unlocked), and more.

This window also helps you select the best network. For example, the software uses a closed padlock symbol to mark networks secured by WEP keys. You can even use WiNc to bypass potential areas of congestion. Typically, your system connects to the most powerful WiFi signal. But if two or more access points are operating on the same channel—say 6—you can select an AP using 11 instead, even if the signal strength is lower. You'll likely get a better connection than from the AP with the best signal, because you'll avoid interference. You can mark a network you like as preferred, and when that network is available, your system will automatically connect to it.

Once you connect, the General tab gives you details on the connection—how fast the link is, total packets sent and received, and more. This is also where you can enter the WEP key for a network.

Another really nice WiNc feature automates the often frustrating process of setting up an ad hoc network—a peer-to-peer connection between two WiFi computers. You do this for quick file transfers or head-to-head gaming.

The IP Properties tab is a bit geeky, but longtime wireless users will appreciate both the information and the capabilities it gives. Here you can track exactly what Internet address parameters have been granted to your computer through DHCP, the automatic network configuration protocol used by most networks today. Many WiFi connection problems result from faulty or old IP configurations. Even if you don't know what all the stuff on this screen means, you can easily ask the network's server to reconfigure you, making obtaining a new IP address easy.

http://www.pcmag.com/print_article/0,3048,a=59192,00.asp

Wednesday, September 10, 2003

The Blaster School of Hard Knocks
Blaster is teaching Microsoft how to better communicate. But there are other lessons Redmond could stand to learn.

Microsoft learned a lot from the Blaster worm that blasted onto the scene last month. But it could have learned more.
Thanks to Blaster, the Redmond software giant has come to realize:
It needed to make its emergency communications with its customers simpler and quicker. The recently rolled-out 1-2-3 Protect Your PC campaign shows Microsoft learned this lesson quite well — and quickly, to boot.

Security is a customer-satisfaction issue. Microsoft understands its current and future users might be less-than-thrilled to be approached if their Blaster pain isn't thoroughly acknowledged. The company has cautioned its sales force and partners to lead with an acknowledgement that Blaster has wreaked havoc on customers' businesses before pitching them on new business.


There's nothing wrong with saying you are sorry (even if you don't really believe something is your fault). Right after the Blaster attack, Redmond held a series of conference calls with key customers. (It even published the transcript of one of them.) The key message: We are sorry that Blaster blasted you. And we are pulling out all the stops to make sure this doesn't happen again.

Making Windows and other key infrastructure software more secure is Priority No. 1. No exceptions. It matters more to users than getting their hands on a Longhorn beta, receiving a sneak peek of a Motorola Smartphone, or being granted another round of Software Assurance licensing concessions. Accordingly, Redmond seems to be accelerating its schedule for patching its software-patching mechanisms as a key first step.

But school's not out for Microsoft on Blaster. There are a few lessons that Redmond seemingly hasn't taken to heart.…

http://www.microsoft.com/security/protect/default.asp

http://www.microsoft-watch.com/article2/0,4248,1237609,00.asp
SoBig Not Gone Yet
Like Ben and J. Lo, the SoBig.F virus long ago overstayed its welcome and seems to be intent on hanging around to annoy as many people as possible. But, unlike Bennifer, the virus mercifully is set to expire on Wednesday, providing worm-weary administrators and users with a bit of relief.

The original SoBig virus appeared in early January, welcoming workers back from the holidays with a raft of infected messages from big@boss.com. In the intervening eight months, five more variants have been set loose, with varying degrees of success.

But none of the previous versions even remotely approached the infection rates that SoBig.F has achieved.

The latest iteration of the virus hit the Internet on Aug. 18 and spawned more than a million copies of itself in the first 24 hours of its existence. At its peak later that week, one in every 17 pieces of e-mail inspected by e-mail security provider MessageLabs Inc. was infected with SoBig.F. Since then, the infection rate has slowed, but MessageLabs continues to stop as many as 600,000 copies of the virus each day.

The respite from SoBig may be short-lived however, as many anti-virus experts expect another variant to be released soon after this one expires. There is some debate in the community on this point, as well as the question of whether all of the previous versions of SoBig have been created by one person. But if history is any guide, it won't be long before another variant is flooding inboxes with maddening levels of junk.…

http://www.eweek.com/article2/0,4149,1252887,00.asp

Tuesday, September 09, 2003

Using nested positioned DIVs to automatically adjust to variable sized DIVs using CSS positioning.
An explanation of their use in the Adaptive Path redesign by Doug Bowman

http://www.stopdesign.com/log/2003/09/03/absolute.html
Listamatic
Can you take a simple list and use different Cascading Style Sheets to create radically different list options? The Listamatic shows the power of CSS when applied to one simple list using samples from Eric Meyer, ProjectSeven, SimpleBits, Jeffrey Zeldman and others.

http://www.maxdesign.com.au/presentation/listamatic/

Monday, September 08, 2003

Get ready for the latest Microsoft products and technologies:
Microsoft Windows Server™ 2003, Microsoft Exchange Server 2003, and Microsoft Visual Studio® .NET. Receive a free analysis of your current skills; a personalized learning plan to improve your skills, including Microsoft Official Curriculum courses, Microsoft Press books, and Microsoft TechNet resources; and a comparison of your skills to those of others, with high scores posted daily.

http://www.microsoft.com/traincert/assessment/

Sunday, September 07, 2003

A Hearty Buffet of Look-Up Databases
Need to look up an address, postal code, place name or similar information? Forget search engines -- this one-stop source provides free access to lookup databases.

The Lookup Directory from Melissa Data provides a first-rate collection of 18 look-up databases, accessible from a single page. All of these tools are available for free!

Specialized databases like these can save you large amounts of time versus using a general web engine to search, and search, and search and hope to find an answer.

http://www.melissadata.com/Lookups/index.htm

http://searchenginewatch.com/searchday/article.php/2245831

Saturday, September 06, 2003

Writing photo captions for the Web by Ruth Garner, Mark Gillingham, and Yong Zhao
Photographs are rarely self-sufficient. They need captions. A caption tells us something about the person or thing photographed, also something about the photographer. In this article, we discuss how to write photo captions for the Web. We provide examples from adults’ and children’s work.

Photo captions — the good ones, at least — are informative. Without the caption for the Queen Victoria photograph, we might recognize the woman pictured as someone rich and famous (she sits so regally on horseback, after all), but we might not know which rich and famous person she is.

Does that matter? It doesn’t, if we are skimming through the Barthes (1981) book simply to take note of the great variety of photographers’ subject matter. If, however, we find this particular photograph of historical interest, if we are studying it, we surely will want to know more — who the woman is, when the photograph was taken, and so on. For someone studying a photograph, an image is seldom self-sufficient. A caption is required.

A photograph requiring a caption need not be a portrait of a queen, and it need not be a photograph reproduced in a book. It might be an online photograph of a robot.…

http://firstmonday.org/issues/issue8_9/garner/

Thursday, September 04, 2003

The Search Engine Report - Number 82
In This Issue
+ Search Engine Watch News
+ SES Dates For 2004 Set
+ Search Engine Size Wars IV & Google's Supplemental Index
+ SEMPO, Search Engine Marketing Professional Organization, Opens To Members
+ Search Engine Resources
+ SearchDay Articles
+ Search Engine Articles

http://searchenginewatch.com/sereport/article.php/3071471
A Script to Teach You About Using Forms with ASP(2.2 KB)
Here's a script that was designed for no purpose other then
to teach new ASP users about using forms. If you're new to
ASP or even if you just need a refresher course on form
handling, you've got to take a look at this script.

http://www.asp101.com/resources/visitors/index.asp#formtest

Tuesday, September 02, 2003

Web Page Analyzer - 0.80
Enter a URL below to calculate page size, composition, and download time. The script calculates the size of individual elements and finds the total for each type of web page component. Based on these page characteristics the script then offers advice on how to improve page display time. The script incorporates best practices from HCI research into its recommendations.

http://www.websiteoptimization.com/speed/1/

http://www.websiteoptimization.com/services/analyze/

Saturday, August 30, 2003

Microsoft Guide to Security Patch Management
Organizations depend on information technology resources and expect them to be trustworthy: a few days of downtime is expensive, while a security compromise of corporate assets can have disastrous consequences.

Viruses and worms such as Klez, Nimda, and SQL Slammer exploit security vulnerabilities in software to attack a computer and launch new attacks on other computers. These vulnerabilities also provide opportunities for attackers to compromise information and assets by denying access to valid users, enabling escalated privileges, and exposing data to unauthorized viewing and tampering.

The operational cost of a day's downtime can be calculated for most, but what if the information with which others entrust your organization is compromised publicly?

A breach of corporate security and the resulting loss of credibility (with customers, partners, and governments) can put the very nature of an organization at risk. Organizations that fail to perform proactive security patch management as part of their information technology security strategy do so at their own peril.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/topics/patch/secpatch/default.asp
411 DV: Web Resources for Non-Linear Editors
Have a question on the latest nonlinear editing software? Need a hard-to-find piece of video editing equipment? Or are you just starting out in the field of digital video and need some direction? . Like virtually every other topic imaginable, the digital video fieldhas seen an explosion of online resources, discussion groups, and chat areas to help both neophytes and seasoned pros achieve their goals more effectively and do their jobs more efficiently. Here, we'll take a look at ten sites that specialize in the world of digital video, though each one offers its own unique features that range user forums to tutorials to sales. (And don't forget about EMedia's own site, http://www.emedialive.com, which offers twice-weekly breaking news, online product "demo rooms," and articles from the magazine.)


http://www.emedialive.com/news/2003/0722_4.html

Friday, August 29, 2003

3 Ways to Help Ensure Your System Is Protected

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tips/pcprotec.asp
Batten Down Those Ports
With worms such as Blaster prowling the Net, every user ought to know the ways a computer may be exposing itself to attacks. One of the simplest but most vital tests you can do to determine potential vulnerabilities is to find out which ports your PC has open to the outside world.

http://www.pcmag.com/print_article/0,3048,a=55855,00.asp
Code that directs infected computers to seven mail and name servers owned by an AOL Time Warner Inc. subsidiary.
Anti-virus experts are downplaying recent claims that there is a second hidden cache of data in the SoBig worm's code that directs infected computers to contact a group of seven mail and name servers owned by an AOL Time Warner Inc. subsidiary.
Officials at BitDefender, a unit of Softwin SRL in Bucharest, Romania, said on Tuesday that they had found a second set of encrypted server addresses in the code of the eminently annoying SoBig.F worm. All of the server names appear to belong to Time Warner Telecom Inc.

"The code is quite straightforward and accurately indicates that the virus asks for information at this address, waits for the answer and than runs the downloaded file on the infected host," said Mihai Chiriac, a virus researcher at BitDefender. "As for the moment, there is no information at any of these addresses; we can't predict the code's effects."

http://www.eweek.com/article2/0,3959,1232316,00.asp

Wednesday, August 27, 2003

Microsoft Baseline Security Analyzer
As part of Microsoft's Strategic Technology Protection Program, and in response to direct customer need for a streamlined method of identifying common security misconfigurations, Microsoft has developed the Microsoft Baseline Security Analyzer (MBSA).

MBSA Version 1.1.1 includes a graphical and command line interface that can perform local or remote scans of Windows systems. MBSA runs on Windows 2000, Windows XP, and Windows Server 2003 systems and will scan for common system misconfigurations in the following products: Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, Internet Information Server (IIS) 4.0 and 5.0, SQL Server 7.0 and 2000, Internet Explorer (IE) 5.01 and later, and Office 2000 and 2002. MBSA will also scan for missing security updates for the following products: Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, IIS 4.0 and 5.0, SQL Server 7.0 and 2000, IE 5.01 and later, Exchange 5.5 and 2000, and Windows Media Player 6.4 and later.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp
Windows XP Security Checklist
Although Windows XP Professional is built on the Windows 2000 kernel, there are significant differences between the operating systems - especially when it comes to security. This checklist is partially based on our popular Windows 2000 security checklist and covers both Windows XP Professional and XP Home Edition. Unfortunately, Windows XP Home Edition doesn't have all of the security features of XP Professional, so not all of the options are available for both versions. If you're concerned about your data, we strongly recommend upgrading to XP Professional as soon as possible. When implementing these recommendations, keep in mind that there is a trade off between increased security levels and usability for any Operating System. To help you decide how much security you need, we've divided the checklist into Basic, Intermediate, and Advanced Security options. You should assess your potential security risks, determine the value of your data, and balance your needs accordingly.

This is a "live" document which will be updated over time as new security recommendations are published by Microsoft. We have tried to make the checklist as complete as possible, however if you have any suggestions or feedback, please e-mail bernie@labmice.net


http://www.labmice.net/articles/winxpsecuritychecklist.htm

Monday, August 25, 2003

A Cumulative Patch for Internet Explorer
Microsoft (Quote, Company Info) Wednesday issued a cumulative patch for its Internet Explorer browser that also protects against several newly discovered vulnerabilities that it labeled as "critical."

Microsoft said the patch combines all the previously released patches for IE 5.01, 5.5 and 6.0 and also addresses several vulnerabilities that would allow an attacker to use a malicious Web site or specially-formed HTML email to access certain privileges on a user's computer.

The first new flaw patched involves the cross-domain security model of IE, which is intended to keep windows of different domains from sharing information. Microsoft said the flaw could allow an attacker to execute script in the user's My Computer zone, run an executable file already present on the local system, or view files on the computer.

To exploit the flaw, an attacker would have to host a malicious Web site that contained a page specifically designed to exploit the vulnerability, and then persuade a victim to visit the site. Once the user is on the site, Microsoft said the attacker could run malicious script by misusing the method IE uses to retrieve files from the browser cache, causing that script to access information in a different domain.

The second new vulnerability patched would allow an attacker to run arbitrary code on a user's system because Internet Explorer doesn't properly determine an object type returned from a Web server, Microsoft said. This vulnerability could be exploited either through convincing a user to visit a malicious Web site or through an HTML email.

The cumulative patch also sets the Kill Bit on the BR549.DLL ActiveX control, which was originally implemented to support the Windows Reporting Tool. IE no longer supports the tool, which has been found to contain a security vulnerability. The new patch prevents the control from running or from being reintroduced onto a user's system.

Microsoft has also used the cumulative patch to change the way IE renders HTML files, in order to address a flaw that could cause IE or Outlook Express to fail. Currently, IE does not properly render an input tag, Microsoft said, which would allow an attacker to craft a malicious Web site that would cause the browser to fail. The flaw would also allow an attacker to create a specially-formed HTML email that would cause Outlook Express to fail when the email is opened or previewed.

Finally, the patch modifies an earlier patch in order to cover specific languages.

http://www.internetnews.com/dev-news/article.php/3066741
A recent eWEEK.com article quotes a network administrator critical of Microsoft for not providing essentially what Automatic Updates provides, especially in conjunction with Microsoft's Software Update Services, which basically allows an administrator to set up an internal update server for clients to use instead of the Windows Update site.

Tightening The Security Screws In Windows
Either we're not educating people or education is not working: Too many users still fail to take simple precautions to protect themselves, and many engage in dangerous practices that perpetuate attacks.

The incidents of the past couple of weeks are both illustrative. The Blaster worm succeeded in spite of a massive publicity campaign on the danger of the relevant flaw in Windows and the existence of a patch.

Worse, in monitoring several security mailing lists I saw many users looking for any excuse not to apply the patch. According to conservative estimates, some 500,000 systems were infected with Blaster, and I've seen much higher estimates. For example, Satellite ISP DirecWay just sent out an e-mail to their customers stating that "approximately 10 to 20 percent of DIRECWAY end-users are infected with the Blaster virus."

Meanwhile, based on the hundreds of Sobig.F e-mails I received in the first 24 hours of this week's outbreak, clearly users have left themselves wide open to it as well.

Has education failed? Short of making computer hygiene mandatory like driver's education with tests, something on the order of John Dvorak's idea to license computer users, I can't see public education campaigns having any better results than we found with Blaster. And that was completely unacceptable.

If users won't take care of their computers, the unfortunate answer (depending on your point of view) is to do it for them. This is what Microsoft is considering, according to a recent Washington Post article. It states that Microsoft is considering having Windows download and apply security patches automatically.

Currently available in Windows XP and Windows 2000 SP3+, this updating capability is called Automatic Updates and is accessible through the Control Panel System applet. It is turned off by default. (For Windows 2000 Server, Automatic Updates is only aware of patches for the OS, not for important server applications like SQL Server or IIS).

The applet has 3 options if you turn Automatic Updates on:


Notify the user that updates are available;

Download any updates that are available and notify the user, but don't install them; and

Download any updates that are available and install them according to a schedule specified by the user.
So, it sounds as if Microsoft is considering making the third option the default behavior, at least with respect to certain very critical updates, such as the one that prevented the Blaster worm.

Believe it or not, even some experienced admins are unaware of this feature in its current state. A recent eWEEK.com article quotes a network administrator critical of Microsoft for not providing essentially what Automatic Updates provides, especially in conjunction with Microsoft's Software Update Services, which basically allows an administrator to set up an internal update server for clients to use instead of the Windows Update site. This administrator said: "The only way it's going to happen is automation...Microsoft should provide this free."

Hello. They do.…

http://security.ziffdavis.com/article2/0,3973,1227322,00.asp
SoBig: What You Need to Know
If you or someone you know (or on your network) is infected, here's the manual process for recovering and for preventing SoBig from spreading to other users:

Unplug your computer from the network.
Boot the computer, then hit the F8 key to activate the text-only boot menu; choose Safe mode.
Wait until the boot process completes.
Open Task Manager by pressing Ctrl+Alt+Del and select the Processes tab.
Find and Highlight Winppr32.exe in the Processes tab.
To kill Winppr32.exe, click the End Process button at the bottom of the Processes tab window.
Click the Start button and select Find or Search from the menu. Search All files and Folders for the file Winppr32.exe on all local drives.
Delete all files named Winppr32.exe from the search window.
Repeat steps 7 and 8 for this file Winstt32.dat
Repeat steps 7 and 8 for this file: Winstf32.dll
Got to the Start menu, select Run and type in RegEdit to run the Registry Editor.
From the menu, select Edit/Find to search for this string: WINPPR32.EXE /sinc. Check only the Data box.
Select the Registry Key in the right-hand pane and Edit/Delete from the menu.
Press F3 to find and delete additional keys with values containing WINPPR32.EXE /sinc
Close Registry Editor.
Reboot in normal mode and reconnect to the network.
Install an antivirus and update to the latest antivirus definitions.
Make sure you have firewall software running, because part of SoBig's job is to connect to its master server and try to install a program that would create a back door into your system.
If you have not yet been infected, follow steps 17 and 18 and add these simple rules

Run Outlook with the preview pane closed. Visually scan the subject lines and look for red flags like:
"Details"
"Thank You"
"A Wicked Screen Saver"
SoBig e-mails can come from friends, because you're likely on each other's contact lists in Outlook. If you see an e-mail from a contact that's unexpected or has a telltale subject line, do not open or respond to it.
Never open any attachment from an unknown sender, and think twice before opening unexpected ones from friends or business contacts.
There's some more excellent information as well as removal instructions and even cleaning tools at these sources:

University of Virginia: http://www.itc.virginia.edu/desktop/virus/results.php3?virusID=76
NAI: http://vil.nai.com/vil/content/Print100561.htm
Symantec: http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html#removalinstructions
TrendMicro: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBIG.F
TrendMicro: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBIG.F&VSect=T
BitDefender: http://www.bitdefender.com/html/virusinfo.php?menu_id=1&v_id=152
McAfee: http://msn.mcafee.com/virusInfo/default.asp?id=description&virus_k=100561&affid=102
Central Command: http://www.centralcommand.com

http://www.pcmag.com/print_article/0,3048,a=55015,00.asp
SoBig Virus Breaks Speed Records
By Dennis Fisher

So far, SoBig.

The virus that has been rampaging through corporate networks and bringing mail servers to their figurative knees all week is now officially the most prolific piece of malware ever, at least by one measure. MessageLabs Inc., an e-mail security company based in New York, said it saw more copies of SoBig.F in its first 24 hours of life than it has of any other virus in a comparable period. Ever.

That's no mean feat, considering some of the digital refuse that has hit the Internet in the past couple of years. Viruses such as Klez, Melissa and the Love Bug all caused their fair share of damage and each was at one time or another considered to be as bad as it gets. But this most recent incarnation of SoBig has taken the title, at least for now.

http://www.eweek.com/article2/0,3959,1227345,00.asp

Saturday, August 23, 2003

BBC News Styleguide
Avoid clichés and improve your journalism with this PDF version of the BBC News Styleguide. The Guide gives practical suggestions on many aspects of journalism style, including abbreviations, clichés, reported speech - and how to avoid irritating your editor.

Who it's for:
This guide was written for BBC journalists but is a valuable resource for anyone who wants to write well.

Outline:
Every time anyone writes a script for BBC News they are potentially touching the lives of millions of people – through radio, tv and the internet. That is the privilege of working for one of the biggest news organisations in the world. It brings with it responsibilities. BBC News is expected to set the highest standards in accuracy, fairness, impartiality – and in the use of language. Clear story-telling and language is at the heart of good journalism. This PDF styleguide will help you to strengthen your journalism and connect with your audiences.

http://www.bbctraining.co.uk/onlineCourse.asp?tID=5487&cat=3
Sobig.f prevention and cure
Yet another member of the Sobig virus family is loose. Sobig.f (w32.sobig.f@mm) spreads via e-mail and shared network files and could slow e-mail servers with excessive traffic, so it rates a 7 on the ZDNet Virus Meter. This worm affects only Windows computers, not Mac, Linux, or Unix systems. Like its siblings, Sobig.f has a built-in termination date, September 10, 2003, and can attempt to retrieve, download, and finally execute a Trojan to steal credit card numbers and other personal account information. But Sobig.f differs in that it appends garbage characters to the end of the infected file, making it harder for antivirus products to recognize Sobig.f.

How it works
Sobig.f arrives as an e-mail with the following characteristics:

The From and To addresses are collected from infected PCs, from files ending with the extensions .dbx, .eml, .htm, .html, .txt, and .wab.

The Sobig.f subject line reads:


Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details

Its body text reads:

See the attached file for details
Please see the attached file for details.…

Removal
Most antivirus-software companies have updated their signature files to include this worm. The updates will stop the infection upon contact and, in some cases, will remove an active infection from your system.…
http://reviews-zdnet.com.com/4520-6600_16-5065487.html

Thursday, August 21, 2003

Google Labs
http://labs.google.com/
This Web site is the testing ground for new concepts unearthed by the creative minds that developed the Google Web search engine. "Google staffers with wild and crazy ideas post their prototypes on Google Labs and solicit feedback on how the technology could be used or improved." One of the current projects listed on the site is a distributed computing effort that allows users to contribute their computer's idle time to help solve a scientific research problem. Others add to the Web searching experience by providing a unique display of the results or enabling keyboard shortcuts. People who have experimented with the prototypes are encouraged to email their comments and suggestions to help with the development effort. Some of the prototypes require users to download and install software. [CL]

From The NSDL Scout Report for Math, Engineering, & Technology, Copyright Internet Scout Project 1994-2003. http://www.scout.wisc.edu/


http://labs.google.com/
How to Stop Sobig.F
Tips and links to help you stop the Sobig variant from infecting your PC.
The Sobig.F worm is a variant of June's Sobig.A worm. The worm is also known as I-Worm.Sobig.f, W32/Sobig.F-mm, W32/Sobig.f@MM, and WORM_SOBIG.F.

Sobig.F only affects Windows systems, and it has been spreading rapidly since earlier this week. Machines running Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, and Windows XP are all susceptible to the worm.

On an infected system, the worm scans various documents for email addresses. The worm then distributes itself to other inboxes using a built-in SMTP engine. When it distributes itself, it "spoofs" in the "From:" field an email address it finds on the infected machine instead of using the infected user's address. Because the address doesn't match that of the infected machine, it's difficult to trace the string of infected computers.

The worm also has a built-in shutoff date. It'll stop working on September 10, 2003.

http://www.techtv.com/screensavers/howto/story/0,24330,3505076,00.html

Tuesday, August 19, 2003

Broadband Networking How-to Articles
This collection of articles will help you with the common procedures and tasks you might need to perform on your network. To learn more about a specific procedure, choose from one of the categories below.

Using your base station
Using your network

http://www.microsoft.com/hardware/broadbandnetworking/howto.aspx
Broadband Networking How-to Articles
This collection of articles will help you with the common procedures and tasks you might need to perform on your network. To learn more about a specific procedure, choose from one of the categories below.

Using your base station
Using your network

http://www.microsoft.com/hardware/broadbandnetworking/howto.aspx
Microsoft Virtual PC
Microsoft Virtual PC is a powerful software virtualization solution that allows you to run multiple PC-based operating systems simultaneously on one workstation, providing a safety net to maintain compatibility with legacy applications while you migrate to a new operating system. It also saves reconfiguration time, so your support, development, and training staff can work more efficiently.

Microsoft will release Microsoft Virtual PC 2004 late in calendar year 2003. In the meantime, a 45-day free trial of the Connectix Virtual PC for Windows version 5, now from Microsoft, can be downloaded for evaluation purposes.

http://www.microsoft.com/windowsxp/virtualpc/downloads/trial.asp

http://www.microsoft.com/windowsxp/virtualpc/

Monday, August 18, 2003

Verifying Blaster E-mail Communications from Microsoft
http://go.microsoft.com/?linkid=221444
The above link resolves to https://register.microsoft.com/security/incident/verify.asp

If you applied security patch MS03-026 prior to the discovery of the Blaster worm, your system is secure from the vulnerability that W32.Blaster is using. For the most current information on determining if your systems are infected and how to recover from the infection, please go to the following web site and perform the prescribed steps: http://www.microsoft.com/security/incident/blast.asp. This site will be updated as more information regarding the W32.blaster worm becomes available.

In order to help protect your computing environment from security vulnerabilities, use the Windows Update service by going to http://windowsupdate.microsoft.com and also subscribe to Microsoft's security notification service at http://register.microsoft.com/subscription/subscribeme.asp?ID=135. By using these two services you will automatically receive information on the latest software updates and the latest security notifications, thereby improving the likelihood that your computing environment will be safe from the worms and viruses that occur.

https://register.microsoft.com/security/incident/verify.asp
How To Avoid Blaster Infection
What's more important than figuring out how to get uninfected? Avoiding infection in the first place. Here are some simple steps you can take to safeguard your systems.

http://www.pcmag.com/article2/0,4149,1220051,00.asp
typoGRAPHIC
typoGRAPHIC, an interactive experience informed by type and typography. It aims to illustrate the depth and import of type, and to raise relevant questions about how typography is treated in the digital media, specifically online.

http://www.rsub.com/typographic/

Sunday, August 17, 2003

Actions for the Blaster Worm
For Windows XP
1. If your computer reboots repeatedly, please unplug your network cable from
the wall.

2. First, enable Internet Connection Firewall (ICF) in Windows XP:
http://support.microsoft.com/?id=283673
--In Control Panel, double-click "Networking and Internet Connections", and
then click "Network Connections".
--Right-click the connection on which you would like to enable ICF, and then
click "Properties".
--On the Advanced tab, click the box to select the option to "Protect my
computer or network".

3. Plug the network cable back into the wall to reconnect your computer to the
Internet

4. Download the MS03-026 security patch from Microsoft and install it on your
computer:

5.Install or update your antivirus signature software and scan your computer

6.Download and run the worm removal tool from your antivirus vendor.

Windows XP (32 bit)
http://www.microsoft.com/downloads/details.aspx?FamilyID=2354406c-c5b6-44ac-9532-3de40f69c074&displaylang=en

Related Knowledge Base Articles:
http://support.microsoft.com/?kbid=826955

Related Microsoft Security Bulletins:
http://www.microsoft.com/technet/security/bulletin/MS03-026.asp

http://www.microsoft.com/security/incident/blast.asp

Free Software servers breached
A key server housing software used in Linux and other projects was open to an attacker for four months, creating fears that source code was compromised

The GNU Project, which develops many of the components in the Linux operating system, said this week that the system housing its primary download servers has been compromised by an attacker. The project urged those who have downloaded software from the server since March to check that the source code has not been tampered with.

Linux, an open-source operating system that dominates the Web server market, uses the compiler, libraries and other software that was originally developed by the GNU project. The project warned that the attacker may have inserted malicious code into its software, although it said all the code checked so far appeared to be intact.

In an alert issued on Wednesday, computer security response organisation CERT warned that the breach could prove to be a serious problem. "Because this system serves as a centralised archive of popular software, the insertion of malicious code into the distributed software is a serious threat," the warning stated.…

http://news.zdnet.co.uk/0,39020330,39115701,00.htm
Worm a Sign of Horrors to Come?
The attack forced Maryland's motor vehicle agency to close for the day and kicked Swedish Internet users offline as it spread.

Security experts said the world was lucky this time because LovSan is comparatively mild and doesn't destroy files. They worry that a subsequent attack exploiting the same flaw -- one of the most severe to afflict Windows -- could be much more damaging.

"We think we're going to be dealing with it for quite some time," said Dan Ingevaldson, engineering manager at Internet Security Systems in Atlanta.

Although LovSan does not appear to do any permanent damage, Ingevaldson said instructions to do that could easily be written into a worm that propagates in the same way.

Microsoft itself still faces the wrath of the worm's coder.…

The attack was preventable for many machines running Windows. On July 16, Microsoft posted on its website a free patch that prevents LovSan and similar infections. The patch fixes an underlying flaw that affects nearly all versions of the software giant's flagship Windows operating system.

Notwithstanding high-profile alerts issued by Microsoft and the Department of Homeland Security, many businesses did not install the patches and scrambled Tuesday to shore up their computers.

Security experts say patches often stay on "to do" lists until outbreaks occur.

"You're looking at 70 new vulnerabilities every week," said Sharon Ruckman, senior director at the research lab for antivirus vendor Symantec. "It's more than a full-time job trying to make sure you are up-to-date."

Microsoft spokesman Sean Sundwall acknowledged that the blame does not really lie with customers.

"Ultimately, it's a flaw in our software," he said.

Non-Microsoft systems were not vulnerable, though some may have had trouble connecting with websites, e-mail and other servers that run on Windows.

Symantec's probes detected more than 125,000 infected computers worldwide.

The worm exploits a flaw in a Windows feature for sharing data files across computer networks. It was reported Monday in the United States first and spread across the globe as businesses opened Tuesday and workers logged on.

Additional U.S. computers were hit Tuesday, and Maryland's Motor Vehicle Administration shut all its offices at noon.

"There's no telephone service right now. There's no online service right now. There's no kiosk or express office service," spokeswoman Cheron Wicker said. "We are currently working on a fix and expect to be operational again in the morning."

In Sweden, Internet provider TeliaSonera said about 20,000 of its customers were affected after the infection clogged 40 servers that handle Internet traffic.

Among companies affected in Germany was automaker BMW, said spokesman Eckhard Vannieck. He said the problems did not affect production.

The worm also affected networks in China, but the damage apparently was not serious.…

http://www.wired.com/news/infostructure/0,1377,59994,00.html
http://www.wired.com/news/technology/0,1282,60019,00.html
Breadcrumb Navigation: Further Investigation of Usage
The term “breadcrumb” derives its name from the Grimm’s fairy tale, Hansel and Gretel. Hansel left a trail of breadcrumbs through the woods as a strategy to find his way back home. Since today’s internet user often has a need to navigate back through a website path, the cyber-version “breadcrumb trail” was named1.

There are three different types of breadcrumbs represented in websites – path, attribute, and location…

In general, the breadcrumb trail serves two purposes: 1) it provides information to users as to where they are located within the site, and 2) it offers shortcut links for users to “jump” to previously viewed pages without using the Back button, other navigation bars, or typing in a keyword search. Breadcrumb trails give location information and links in a backward linear manner; whereas, navigation methods, such as search fields or horizontal/vertical navigation bars, serve to retrieve information for the user in a forward-seeking approach. As suggested by Marchionini (1995), systems that support navigation by both browsing and analytical strategies are most beneficial to users since tactics associated with both types of strategies are normally used. According to Steven Krug (2000), breadcrumb trails are most valuable as an accessory to a site’s navigational scheme and are optimally located at the top of a web page in a smaller font.

There has been speculation that a breadcrumb trail also aids the user’s “mental model” of the site’s layout to reduce disorientation within the site (Bernard, 2003); however, we have not found research to validate this assumption. It would seem logical, however, that a constant visualization of the path to the user’s current location would increase their awareness and knowledge of the site structure. Toms (2000) suggests that users need both a stable orienting device, such as a menu, to facilitate pathways through the site, as well as a system that supports scanning to smooth the progress of the search. Research has reported that breadcrumb navigation improves measures of site efficiency (Maldonado & Resnick, 2002; Bowler, Ng & Schwartz, 2001). Our earlier study, however, found limited use of breadcrumb trails as a navigational tool and no differences in site efficiency for two online sites, OfficeMax and Google Directory (Lida, et al. 2003).…

http://psychology.wichita.edu/surl/usabilitynews/52/breadcrumb.htm

Saturday, August 16, 2003

The Sensible Internet Design Journal

Issue 40 of The Sensible Internet Design Letter
http://smallinitiatives.com/journal75_0_1_0_C4.html

http://smallinitiatives.com/
Text style sampler
Instructions by Jay Small of Small Initiatives

Use this page to try different combinations of typefaces, text line height, paragraph indents and widths, and see the results (and the Cascading Style Sheet properties that made them) in the blocks of text below. Try this in different browsers and observe the subtle differences.

Here are the variables:

Font: Choose from four commonly installed, screen-friendly fonts: Times New Roman, default on many browsers; Verdana, a popular sans-serif choice; Arial, another popular sans-serif face; and Georgia, a serif face that is screen- and printer-friendly.

Line height: The default setting is 1 em. In printing, this setting would be known as "set solid." The line height is identical to the height of the letters themselves. But Web browsers fudge this a bit when they render text -- in fact, if your font size and line height are both left to defaults, there will be at least a pixel of space between lines of text. You may wish to add more space, especially on text set very wide.

Paragraph indents: By default, stacks of paragraphs in Web browsers do not have first-line indents; instead, the first line of each paragraph is flush-left but you see a full line of space between paragraphs. Most printed text is set with paragraph indents, however, and if you want them they are easy to create. The samples with indents have a half line (0.5 em) of space between paragraphs.

Set base font size

Then, select a base font size. The default size (1 em, or what would be applied if you used no style sheets at all) is typically rendered at 16 pixels.…
http://smallinitiatives.com/whatwevedone/presentations/textsampler/