Symantec Security Response - Trojan.Androv:
"Trojan.Androv is a Trojan horse that emails system information to an address in Russia.
This Trojan has reportedly been distributed through IRC. It may be found as the file, %System%\Komunist.exe or %System%\Msuser32.exe."
Type: Trojan Horse
Infection Length: 6K
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
http://securityresponse.symantec.com/avcenter/venc/data/trojan.androv.html
Tuesday, November 11, 2003
Troubleshooting Windows XP, Tweaks and Fixes for Windows XP:
"Registry Edits for Windows XP: 'Tweaks and Tips' "
How to run scheduled tasks without a password
If you're using XP Home, the easiest way to make this change is to download the VBScript file from Kelly's Korner. See line 67 at:
http://www.kellys-korner-xp.com/xp_tweaks.htm
"Registry Edits for Windows XP: 'Tweaks and Tips' "
How to run scheduled tasks without a password
If you're using XP Home, the easiest way to make this change is to download the VBScript file from Kelly's Korner. See line 67 at:
http://www.kellys-korner-xp.com/xp_tweaks.htm
Monday, November 10, 2003
Critical Issues:
"Security Bulletins include information about security issues provided by the Microsoft Security Notification Service. Critical Problem Alerts include non-security based issues."
http://support.microsoft.com/default.aspx?scid=FH;[LN];cpa&sd=vap&fr=0
"Security Bulletins include information about security issues provided by the Microsoft Security Notification Service. Critical Problem Alerts include non-security based issues."
http://support.microsoft.com/default.aspx?scid=FH;[LN];cpa&sd=vap&fr=0
In defense of Microsoft:
"In late September 2003, the Computer and Communications Industry Association (CCIA) in Washington issued a new report that detailed its 'findings' on the state of Internet security. The panel of experts who authored the paper agreed that the Internet security problems faced by corporations, consumers, and government users could not be solved unless these groups made a concerted effort to move away from Microsoft Windows and other Microsoft products. In their opinion, the lack of diversity in computing platforms has made it easy for virus writers and hackers to target systems based on the Windows platform."
With an estimated 90 percent of the world’s desktop PCs running on Windows and a significant share of the enterprise server market as well, Microsoft invites these attacks and, according to the report, doesn’t have the capacity to stop them. So, Mr. or Ms. CIO, is it time to dump Microsoft and move to a radically different computing platform?
Who is the CCIA?
Before you start ripping out your Windows desktops, I think it’s important to consider the source of the information. The CCIA is comprised of a group of Microsoft competitors in the enterprise server and communications market segments, including Sun, Oracle, and IBM. This is the same group that lobbied Washington politicians until it got the DOJ to take Microsoft to court for its monopolistic practices. After nine years of wrangling, what did the DOJ find? Some aggressive marketing and product development practices on Microsoft’s part. What did the taxpayers get for their money from the DOJ investigation? Nothing. What consumers got from Microsoft is exactly what CCIA members don’t want you to have—broadly accessible, affordable, enterprise technology.
Why does the CCIA fear Microsoft?
The CCIA doesn’t want Microsoft to have the same effect on server and middleware software that it did on the desktop. What frustrates me the most about CCIA's propaganda is that many of these "experts" weren’t around in the days before Windows became so popular. They never had to manually configure printer drivers for each piece of software installed on a PC or tweak network settings just to get the PC to talk to crude ARCNet or Ethernet networks. With Windows, Microsoft ushered in an era of innovation by allowing software developers to focus on their products and not have to worry about whether the infrastructure was there for it to run on. The increase in PC sales also drove down the price and led to even more advancements in desktop software development.
Microsoft may not be the most innovative company in the world, but it recognized early on that innovation that languished in a lab was worthless. Innovation needed a standard desktop OS where everyone could take advantage of it and flourish. And here’s the ultimate irony: Even the most die-hard Linux supporters will have to admit that without Microsoft driving down the overall cost of the computing platform, they would not have an inexpensive platform on which to drive Linux. But it’s that same economic equation that has the CCIA worried.
Server software
The CCIA is afraid that Microsoft would do to them what its distribution engine did to Apple, Digital Research (remember Gem?), and others on the desktop. The Microsoft modus operandi is pretty simple and predictable: provide software that's aggressively priced and performs acceptably for the 80 percent of the market that finds the performance available with current microprocessor technology. With Windows 2000, Windows 2003, and enterprise products like SQL Server 2000, the assault on the server has already begun.…
Don't get the CCIA "virus"
Clearly, Microsoft needs to continue with its efforts to make the Windows platform less vulnerable to virus attacks. But companies also have to be willing to pay to defend their assets. First, they have to realize that products like Windows 95, Windows 98, and even Windows NT were designed for a moderately connected world. When a company refuses to either provide adequate protection at the firewall or upgrade to a modern, defensible operating system, they’re getting what they deserve. Current Microsoft operating systems like Windows 2000, Windows 2003, and Windows XP can be updated automatically—even using a corporate approval and scheduling process—if configured properly.
http://www.ccianet.org/press/03/0924.pdf
http://www.ccianet.org/index.php3
http://techrepublic.com.com/5102-6296-5088222.html
"In late September 2003, the Computer and Communications Industry Association (CCIA) in Washington issued a new report that detailed its 'findings' on the state of Internet security. The panel of experts who authored the paper agreed that the Internet security problems faced by corporations, consumers, and government users could not be solved unless these groups made a concerted effort to move away from Microsoft Windows and other Microsoft products. In their opinion, the lack of diversity in computing platforms has made it easy for virus writers and hackers to target systems based on the Windows platform."
With an estimated 90 percent of the world’s desktop PCs running on Windows and a significant share of the enterprise server market as well, Microsoft invites these attacks and, according to the report, doesn’t have the capacity to stop them. So, Mr. or Ms. CIO, is it time to dump Microsoft and move to a radically different computing platform?
Who is the CCIA?
Before you start ripping out your Windows desktops, I think it’s important to consider the source of the information. The CCIA is comprised of a group of Microsoft competitors in the enterprise server and communications market segments, including Sun, Oracle, and IBM. This is the same group that lobbied Washington politicians until it got the DOJ to take Microsoft to court for its monopolistic practices. After nine years of wrangling, what did the DOJ find? Some aggressive marketing and product development practices on Microsoft’s part. What did the taxpayers get for their money from the DOJ investigation? Nothing. What consumers got from Microsoft is exactly what CCIA members don’t want you to have—broadly accessible, affordable, enterprise technology.
Why does the CCIA fear Microsoft?
The CCIA doesn’t want Microsoft to have the same effect on server and middleware software that it did on the desktop. What frustrates me the most about CCIA's propaganda is that many of these "experts" weren’t around in the days before Windows became so popular. They never had to manually configure printer drivers for each piece of software installed on a PC or tweak network settings just to get the PC to talk to crude ARCNet or Ethernet networks. With Windows, Microsoft ushered in an era of innovation by allowing software developers to focus on their products and not have to worry about whether the infrastructure was there for it to run on. The increase in PC sales also drove down the price and led to even more advancements in desktop software development.
Microsoft may not be the most innovative company in the world, but it recognized early on that innovation that languished in a lab was worthless. Innovation needed a standard desktop OS where everyone could take advantage of it and flourish. And here’s the ultimate irony: Even the most die-hard Linux supporters will have to admit that without Microsoft driving down the overall cost of the computing platform, they would not have an inexpensive platform on which to drive Linux. But it’s that same economic equation that has the CCIA worried.
Server software
The CCIA is afraid that Microsoft would do to them what its distribution engine did to Apple, Digital Research (remember Gem?), and others on the desktop. The Microsoft modus operandi is pretty simple and predictable: provide software that's aggressively priced and performs acceptably for the 80 percent of the market that finds the performance available with current microprocessor technology. With Windows 2000, Windows 2003, and enterprise products like SQL Server 2000, the assault on the server has already begun.…
Don't get the CCIA "virus"
Clearly, Microsoft needs to continue with its efforts to make the Windows platform less vulnerable to virus attacks. But companies also have to be willing to pay to defend their assets. First, they have to realize that products like Windows 95, Windows 98, and even Windows NT were designed for a moderately connected world. When a company refuses to either provide adequate protection at the firewall or upgrade to a modern, defensible operating system, they’re getting what they deserve. Current Microsoft operating systems like Windows 2000, Windows 2003, and Windows XP can be updated automatically—even using a corporate approval and scheduling process—if configured properly.
http://www.ccianet.org/press/03/0924.pdf
http://www.ccianet.org/index.php3
http://techrepublic.com.com/5102-6296-5088222.html
Sunday, November 09, 2003
the information hiding homepage -- digital watermarking & steganography :
"Until recently, information hiding techniques received very much less attention from the research community and from industry than cryptography, but this has changed rapidly over the last decade."
The first academic conference on the subject was organised in 1996. It was followed by several other conferences focussing on information hiding as well as watermarking. The fifth international workshop on information hiding was held in Noordwijkerhout (pronounce node-why-cur-how-t) in October 2002.
The main driving force is concern over protecting copyright; as audio, video and other works become available in digital form, it may be that the ease with which perfect copies can be made will lead to large-scale unauthorised copying which will undermine the music, film, book and software publishing industries. There has therefore been significant recent research into ‘watermarking’ (hidden copyright messages) and ‘fingerprinting’ (hidden serial numbers or a set of characteristics that tend to distinguish an object from other similar objects); the idea is that the latter can be used to detect copyright violators and the former to prosecute them.
But there are many other other applications of increasing interest to both the academic and business communities, including anonymous communications, covert channels in computer systems, detection of hidden information, steganography, etc.
http://www.petitcolas.net/fabien/steganography/index.html
"Until recently, information hiding techniques received very much less attention from the research community and from industry than cryptography, but this has changed rapidly over the last decade."
The first academic conference on the subject was organised in 1996. It was followed by several other conferences focussing on information hiding as well as watermarking. The fifth international workshop on information hiding was held in Noordwijkerhout (pronounce node-why-cur-how-t) in October 2002.
The main driving force is concern over protecting copyright; as audio, video and other works become available in digital form, it may be that the ease with which perfect copies can be made will lead to large-scale unauthorised copying which will undermine the music, film, book and software publishing industries. There has therefore been significant recent research into ‘watermarking’ (hidden copyright messages) and ‘fingerprinting’ (hidden serial numbers or a set of characteristics that tend to distinguish an object from other similar objects); the idea is that the latter can be used to detect copyright violators and the former to prosecute them.
But there are many other other applications of increasing interest to both the academic and business communities, including anonymous communications, covert channels in computer systems, detection of hidden information, steganography, etc.
http://www.petitcolas.net/fabien/steganography/index.html
Why Am I Getting All This Spam?:
"Every day, millions of people receive dozens of unsolicited commercial e-mails (UCE), known popularly as 'spam.' Some users see spam as a minor annoyance, while others are so overwhelmed with spam that they are forced to switch e-mail addresses. This has led many Internet users to wonder: How did these people get my e-mail address? "
In the summer of 2002, CDT embarked on a project to attempt to determine the source of spam. To do so, we set up hundreds of different e-mail addresses, used them for a single purpose, and then waited six months to see what kind of mail those addresses were receiving. It should come as no surprise to most e-mail users that many of the addresses CDT created for this study attracted spam, but it is very interesting to see the different ways that e-mail addresses attracted spam -- and the different volumes -- depending on where the e-mail addresses were used.
The results offer Internet users insights about what online behavior results in the most spam. The results also debunk some of the myths about spam.
Major Findings
http://www.cdt.org/speech/spam/030319spamreport.shtml
"Every day, millions of people receive dozens of unsolicited commercial e-mails (UCE), known popularly as 'spam.' Some users see spam as a minor annoyance, while others are so overwhelmed with spam that they are forced to switch e-mail addresses. This has led many Internet users to wonder: How did these people get my e-mail address? "
In the summer of 2002, CDT embarked on a project to attempt to determine the source of spam. To do so, we set up hundreds of different e-mail addresses, used them for a single purpose, and then waited six months to see what kind of mail those addresses were receiving. It should come as no surprise to most e-mail users that many of the addresses CDT created for this study attracted spam, but it is very interesting to see the different ways that e-mail addresses attracted spam -- and the different volumes -- depending on where the e-mail addresses were used.
The results offer Internet users insights about what online behavior results in the most spam. The results also debunk some of the myths about spam.
Major Findings
- Our analysis indicated that e-mail addresses posted on Web sites or in newsgroups attract the most spam.
- Web Sites - CDT received the most e-mails when an address was placed visibly on a public Web site. Spammers use software harvesting programs such as robots or spiders to record e-mail addresses listed on Web sites, including both personal Web pages and institutional (corporate or non-profit) Web pages.
- CDT tested two methods of obstructing address harvesting:
- Replacing characters in an e-mail address with human-readable equivalents, e.g. "example@domain.com" was written "example at domain dot com;" and
- Replacing characters in an e-mail address with HTML equivalents.
E-mail addresses posted to Web sites using these conventions did not receive any spam.
- Replacing characters in an e-mail address with human-readable equivalents, e.g. "example@domain.com" was written "example at domain dot com;" and
- USENET newsgroups -- Newsgroups can expose to spammers the e-mail address of every person who posts to the newsgroup. Newsgroup postings, on average, generated less spam than posting an e-mail address on a high-traffic web site. In our study, we discovered that most newsgroup-related spam is sent to the address in the message header, even if other e-mail addresses are included in the text of the posting.
- Web Sites - CDT received the most e-mails when an address was placed visibly on a public Web site. Spammers use software harvesting programs such as robots or spiders to record e-mail addresses listed on Web sites, including both personal Web pages and institutional (corporate or non-profit) Web pages.
- For the most part, companies that offered users a choice about receiving commercial e-mails respected that choice. Most of the major Web sites to which we provided e-mail addresses respected the privacy choices we made -- when a choice was made available to us.
- Some spam is generated through attacks on mail servers, methods that don't rely on the collection of e-mail addresses at all. In "brute force" attacks and "dictionary" attacks, spam programs send spam to every possible combination of letters at a domain, or to common names and words. While these attacks can be blocked, some spam is likely to get through. In many cases, spam generated by these attacks will be directed to shorter e-mail address (like bob@domain.com) before it is directed to longer addresses (like bobwilliams@domain.com).
http://www.cdt.org/speech/spam/030319spamreport.shtml
Bruce Eckel's MindView, Inc: Free Electronic Book: Thinking in Java, 3rd Edition:
"Free Electronic Book: Thinking in Java, 3rd Edition"
This highly acclaimed online book is intended to provide a thorough introduction to the Java programming language. Spanning sixteen chapters plus appendices, Thinking in Java should be sufficient for all but the most advanced or obscure topics. The book covers the basics of objects, coding style, error handling, the Java input/output system, creating graphical user interfaces, and much more. The full text can be downloaded as a compressed file with additional source code to be used as examples and experimented with. Other electronic books written by the same author are also available on this site and cover C++, Python, and more. [CL]
From The NSDL Scout Report for Math, Engineering, & Technology, Copyright Internet Scout Project 1994-2003. http://www.scout.wisc.edu/
http://www.mindview.net/Books/TIJ/
"Free Electronic Book: Thinking in Java, 3rd Edition"
This highly acclaimed online book is intended to provide a thorough introduction to the Java programming language. Spanning sixteen chapters plus appendices, Thinking in Java should be sufficient for all but the most advanced or obscure topics. The book covers the basics of objects, coding style, error handling, the Java input/output system, creating graphical user interfaces, and much more. The full text can be downloaded as a compressed file with additional source code to be used as examples and experimented with. Other electronic books written by the same author are also available on this site and cover C++, Python, and more. [CL]
From The NSDL Scout Report for Math, Engineering, & Technology, Copyright Internet Scout Project 1994-2003. http://www.scout.wisc.edu/
http://www.mindview.net/Books/TIJ/
Miscellaneous Mathematical Utilities:
"This page contains links to several mathematical utilities. More will be added as I write them. The algorithms underlying these utilities come from the BLAS, EISPACK, and LINPACK collection of subprograms, written by some of the brightest mathematicians and computer scientists (I have cited sources when I found them). Those subprograms incorporate excellent basic algorithms and programming techniques to optimize the routines for speed and accuracy. "
Because these utilities are written in Javascript, make sure Javascript is enabled in your Internet browser.
http://www.akiti.ca/Mathfxns.html
"This page contains links to several mathematical utilities. More will be added as I write them. The algorithms underlying these utilities come from the BLAS, EISPACK, and LINPACK collection of subprograms, written by some of the brightest mathematicians and computer scientists (I have cited sources when I found them). Those subprograms incorporate excellent basic algorithms and programming techniques to optimize the routines for speed and accuracy. "
Because these utilities are written in Javascript, make sure Javascript is enabled in your Internet browser.
http://www.akiti.ca/Mathfxns.html
Honeypot - Frequently Asked Questions:
"The purpose of this page is to answer the most commonly asked questions concerning honeypot technologies, including what is a honeypot, what's its value, how do they work, and what are the different types. Most of this information was obtained from the honeypot mailling list"
What is a honeypot?
A honeypot is a security resource who's value lies in being probed, attacked, or compromised. Unlike firewalls or IDS sensors, honeypots are something you want the bad guys to interact with. To learn more about what honeypots are all about, you may want to start with the paper Honeypots: Definitions and Values.
How do honeypots work?
Conceptually, honeypots are very simple. They are a resource that has no production value, it has no authorized activity. Whenever there is any interaction with a honeypot, this is most likely malicious activity.
What is the value of a honeypot, what can it do for me?
Honeypots are unique, they don't solve a specific problem. Instead, they are a highly flexible tool with many different applications to security. It all depends on what you want to achieve. Some honeypots can be used to help prevent attacks, others can be used to detect attacks, while other honeypots can be used for information gathering and research.
What are the advantages of a honeypot?
Honeypots have several powerful advantages. They include:
Small data sets: Honeypots collect small amount of data, but almost all of this data is real attakcs or unauthorized activity. Instead of dealing with 5,000 alerts and 10GB of logs every day, you may only get 30 alerts with your honeypots and 1MB of logs every day. Since honeypots collect only malicious activity, it makes it much easier to analyze and react to the information they collect.
Reduced false positives: With most detection technologies (such as IDS sensors) a large percentage of your alerts are false warnings, making it very difficult to figure out what is a real attack. With honepyots, almost everything you detect or capture is an attack or unauthozied activity, vastly reducing false positives.
False negatives: Unlike most technologies, its very easy for honeypots to detect and records attacks or behavior never seen before in the wild.
Cost effective: Honeypots only interact with malicious activity, you do not need high preformance resources. Most honeypots can easily run on an old Pentium computer with 128 MB of Ram.
Simplicty: Honeypots are very simple, there are no advance algorithims to develop, nor any rulebases to maintaing.
http://www.tracking-hackers.com/misc/faq.html
"The purpose of this page is to answer the most commonly asked questions concerning honeypot technologies, including what is a honeypot, what's its value, how do they work, and what are the different types. Most of this information was obtained from the honeypot mailling list"
What is a honeypot?
A honeypot is a security resource who's value lies in being probed, attacked, or compromised. Unlike firewalls or IDS sensors, honeypots are something you want the bad guys to interact with. To learn more about what honeypots are all about, you may want to start with the paper Honeypots: Definitions and Values.
How do honeypots work?
Conceptually, honeypots are very simple. They are a resource that has no production value, it has no authorized activity. Whenever there is any interaction with a honeypot, this is most likely malicious activity.
What is the value of a honeypot, what can it do for me?
Honeypots are unique, they don't solve a specific problem. Instead, they are a highly flexible tool with many different applications to security. It all depends on what you want to achieve. Some honeypots can be used to help prevent attacks, others can be used to detect attacks, while other honeypots can be used for information gathering and research.
What are the advantages of a honeypot?
Honeypots have several powerful advantages. They include:
Small data sets: Honeypots collect small amount of data, but almost all of this data is real attakcs or unauthorized activity. Instead of dealing with 5,000 alerts and 10GB of logs every day, you may only get 30 alerts with your honeypots and 1MB of logs every day. Since honeypots collect only malicious activity, it makes it much easier to analyze and react to the information they collect.
Reduced false positives: With most detection technologies (such as IDS sensors) a large percentage of your alerts are false warnings, making it very difficult to figure out what is a real attack. With honepyots, almost everything you detect or capture is an attack or unauthozied activity, vastly reducing false positives.
False negatives: Unlike most technologies, its very easy for honeypots to detect and records attacks or behavior never seen before in the wild.
Cost effective: Honeypots only interact with malicious activity, you do not need high preformance resources. Most honeypots can easily run on an old Pentium computer with 128 MB of Ram.
Simplicty: Honeypots are very simple, there are no advance algorithims to develop, nor any rulebases to maintaing.
http://www.tracking-hackers.com/misc/faq.html
Friday, November 07, 2003
ZDNet UK - News - Whois database 'contributes to identity theft':
"A database publishing information about all Internet domain name holders is open to abuse and must be reformed, civil liberties groups have warned"
Whois, an online database that contains personal information about Internet domain name holders, is a major contributor to identity theft and defies advice from the Federal Trade Commission (FTC), according to a group of civil liberties organisations.
When an Internet domain is registered, the details of the owner are entered into the Whois database and published by the Internet Corporation for Assigned Names and Numbers (ICANN). This procedure was designed to ensure that when technical difficulties or incompatibilities arose, it was relatively easy to contact the owner of the domain. However, the database has now grown beyond all expectations and is open for exploitation, privacy groups argue.…
http://news.zdnet.co.uk/0,39020330,39117667,00.htm
"A database publishing information about all Internet domain name holders is open to abuse and must be reformed, civil liberties groups have warned"
Whois, an online database that contains personal information about Internet domain name holders, is a major contributor to identity theft and defies advice from the Federal Trade Commission (FTC), according to a group of civil liberties organisations.
When an Internet domain is registered, the details of the owner are entered into the Whois database and published by the Internet Corporation for Assigned Names and Numbers (ICANN). This procedure was designed to ensure that when technical difficulties or incompatibilities arose, it was relatively easy to contact the owner of the domain. However, the database has now grown beyond all expectations and is open for exploitation, privacy groups argue.…
http://news.zdnet.co.uk/0,39020330,39117667,00.htm
News: Treaty casts shadow on Webcast rights:
"A United Nations committee on Wednesday approved the world's first Webcasting treaty, which has drawn criticism that it limits the use of works that are in the public domain. "
At a meeting in Geneva, the World Intellectual Property Organization's Standing Committee on Copyright and Related Rights agreed to prepare a draft of the treaty by April 1, 2004. A second meeting is scheduled for June, followed by an expected diplomatic conference during which nations that are members of WIPO--a U.N. agency--could sign the final treaty.
The treaty--which was proposed by the Bush administration and is backed by Yahoo, the Washington-based Digital Media Association and other U.S. Webcasters--generally seeks to extend to Webcasters the same level of international intellectual property protection that TV and radio broadcasters currently enjoy. The Webcasting sections are part of a broader proposal titled "Protection of the Rights of Broadcasting Organizations."
Jamie Love, who works for the Ralph Nader-affiliated Consumer Project on Technology, says the treaty is worrisome because it creates an additional legal protection for works in the public domain that are Webcast.
"Say there's a film that's out of copyright and in the public domain, but it's in the vault of some movie studio," Love said. "If you got it from the broadcast, you're not allowed to make a copy. You have to go to the original source."
In other words, anyone viewing a Webcast of material that falls outside of copyright--such as a government-created documentary or a very old movie or audio recording--may not be able to freely store and redistribute that content.…
http://zdnet.com.com/2100-1104_2-5103456.html
"A United Nations committee on Wednesday approved the world's first Webcasting treaty, which has drawn criticism that it limits the use of works that are in the public domain. "
At a meeting in Geneva, the World Intellectual Property Organization's Standing Committee on Copyright and Related Rights agreed to prepare a draft of the treaty by April 1, 2004. A second meeting is scheduled for June, followed by an expected diplomatic conference during which nations that are members of WIPO--a U.N. agency--could sign the final treaty.
The treaty--which was proposed by the Bush administration and is backed by Yahoo, the Washington-based Digital Media Association and other U.S. Webcasters--generally seeks to extend to Webcasters the same level of international intellectual property protection that TV and radio broadcasters currently enjoy. The Webcasting sections are part of a broader proposal titled "Protection of the Rights of Broadcasting Organizations."
Jamie Love, who works for the Ralph Nader-affiliated Consumer Project on Technology, says the treaty is worrisome because it creates an additional legal protection for works in the public domain that are Webcast.
"Say there's a film that's out of copyright and in the public domain, but it's in the vault of some movie studio," Love said. "If you got it from the broadcast, you're not allowed to make a copy. You have to go to the original source."
In other words, anyone viewing a Webcast of material that falls outside of copyright--such as a government-created documentary or a very old movie or audio recording--may not be able to freely store and redistribute that content.…
http://zdnet.com.com/2100-1104_2-5103456.html
FTC Slams Pop-Up Spammer:
"The Federal Trade Commission Thursday took action against a company that it alleges was exploiting a security hole in Microsoft's Messenger Service utility to send full-screen pop-up ads to consumers advertising software that would block the very same pop-up ads."
At the FTC's request, the U.S. District Court for the Northern District of Maryland issued a temporary restraining order against D Squared Solutions LLC, and its officers, Anish Dhingra and Jeffrey Davis, blocking them from continuing their business practices. The FTC plans to seek further legal action against the defendants, including recovering any revenue the company earned from selling its software.
The FTC complaint alleges that the defendants caused Messenger Service windows to pop up on consumers' computer screens as often as every 10 minutes, advertising software that would block future pop-up spam messages.
According to the FTC, the defendants placed their pop-up ads near the center of users' computer screens, blocking the user's work. The ads appeared as long as the users were connected to the Internet, leading to particular trouble for users with always-on broadband connections. The FTC alleges that these users continued to be bombarded by the pop-ups, even when they working in other applications such as word-processing or spreadsheet programs.
The complaint states that the defendants allegedly either sold or licensed their pop-up-sending software to other people, allowing them to engage in the same conduct. The defendants' Web site allegedly offered software that would allow buyers to send pop-ups to 135,000 Internet addresses per hour, along with a database of more than two billion unique addresses.
The defendants advertised their product at a number of sites including broadcastblocker.com, defeatpopupspam.com, directadstopper.com and easypopupblocker.com. D Squared Solutions, of San Diego, has long been vilified for its practices at anti-spam Web sites. The company, usually doing business under the brand name BroadcastMarketer, had been in a running battle with America Online Inc., which was trying to block D Squared's pop-up ads from its Internet service.
D Squared Solutions has allegedly licensed the software to another San Diego company, Scintillant Inc., which sells the software from the byebyeads.com and endads.com sites. The FTC is considering action against that company as well, though those sites remain up.
"It's an unfair practice to [send] advertisements that create a problem and then charge consumers for the solution," said Howard Beales, director of the FTC's Bureau of Consumer Protection. "We call that extortion, and it's not any different in the high-tech world."
http://www.eweek.com/print_article/0,3048,a=111640,00.asp
"The Federal Trade Commission Thursday took action against a company that it alleges was exploiting a security hole in Microsoft's Messenger Service utility to send full-screen pop-up ads to consumers advertising software that would block the very same pop-up ads."
At the FTC's request, the U.S. District Court for the Northern District of Maryland issued a temporary restraining order against D Squared Solutions LLC, and its officers, Anish Dhingra and Jeffrey Davis, blocking them from continuing their business practices. The FTC plans to seek further legal action against the defendants, including recovering any revenue the company earned from selling its software.
The FTC complaint alleges that the defendants caused Messenger Service windows to pop up on consumers' computer screens as often as every 10 minutes, advertising software that would block future pop-up spam messages.
According to the FTC, the defendants placed their pop-up ads near the center of users' computer screens, blocking the user's work. The ads appeared as long as the users were connected to the Internet, leading to particular trouble for users with always-on broadband connections. The FTC alleges that these users continued to be bombarded by the pop-ups, even when they working in other applications such as word-processing or spreadsheet programs.
The complaint states that the defendants allegedly either sold or licensed their pop-up-sending software to other people, allowing them to engage in the same conduct. The defendants' Web site allegedly offered software that would allow buyers to send pop-ups to 135,000 Internet addresses per hour, along with a database of more than two billion unique addresses.
The defendants advertised their product at a number of sites including broadcastblocker.com, defeatpopupspam.com, directadstopper.com and easypopupblocker.com. D Squared Solutions, of San Diego, has long been vilified for its practices at anti-spam Web sites. The company, usually doing business under the brand name BroadcastMarketer, had been in a running battle with America Online Inc., which was trying to block D Squared's pop-up ads from its Internet service.
D Squared Solutions has allegedly licensed the software to another San Diego company, Scintillant Inc., which sells the software from the byebyeads.com and endads.com sites. The FTC is considering action against that company as well, though those sites remain up.
"It's an unfair practice to [send] advertisements that create a problem and then charge consumers for the solution," said Howard Beales, director of the FTC's Bureau of Consumer Protection. "We call that extortion, and it's not any different in the high-tech world."
http://www.eweek.com/print_article/0,3048,a=111640,00.asp
Thursday, November 06, 2003
Weakness Reported in Wireless Security Protocol:
"A researcher at ICSA Labs has reported that some implementations of Wi-Fi Protected Access (WPA), a standard for cryptography of data on Wi-Fi networks, can be compromised through a dictionary attack. Robert Moskowitz, senior technical director at ICSA Labs, detailed the attack scenario in a paper published yesterday."
Not all WPA-based networks are vulnerable. Those most at risk, according to the paper, are the ones that use the "pre-shared key" method for passphrase generation. Most implementations of WPA, in order to make use of the cryptography accessible to unsophisticated users with normal home computing equipment, allow users to enter a common shared phrase into a WPA user interface on the computer. This phrase, along with the SSID, the visible name for the network, is transformed mathematically into a key used by the cryptography routines. Other key management techniques are available to WPA, but these generally require more expensive and complex network management equipment, such as authentication servers.
Moskowitz states that after sniffing a few packets of data from certain points in Wi-Fi standard communication, an attacker could use a "dictionary attack" on the data offline in an attempt to guess the passphrase. Users who employ short, simple passphrases could be quickly cracked. Users who have complex passphrases, such as "elmo2$fruit99.TAMMANY+1875" can feel more secure. According to Moskowitz: "A key generated from a passphrase of less than about 20 characters is unlikely to deter attacks. ... This is considerably longer than most people will be willing to use."
Once the passphrase is guessed, the attacker can join the network like any legitimate user. Moskowitz did not address the use of other techniques, such as MAC address filtering, to stop unauthorized users.…
Weakness in Passphrase Choice in WPA Interface
http://wifinetnews.com/archives/002452.html
http://www.eweek.com/article2/0,4149,1375085,00.asp
"A researcher at ICSA Labs has reported that some implementations of Wi-Fi Protected Access (WPA), a standard for cryptography of data on Wi-Fi networks, can be compromised through a dictionary attack. Robert Moskowitz, senior technical director at ICSA Labs, detailed the attack scenario in a paper published yesterday."
Not all WPA-based networks are vulnerable. Those most at risk, according to the paper, are the ones that use the "pre-shared key" method for passphrase generation. Most implementations of WPA, in order to make use of the cryptography accessible to unsophisticated users with normal home computing equipment, allow users to enter a common shared phrase into a WPA user interface on the computer. This phrase, along with the SSID, the visible name for the network, is transformed mathematically into a key used by the cryptography routines. Other key management techniques are available to WPA, but these generally require more expensive and complex network management equipment, such as authentication servers.
Moskowitz states that after sniffing a few packets of data from certain points in Wi-Fi standard communication, an attacker could use a "dictionary attack" on the data offline in an attempt to guess the passphrase. Users who employ short, simple passphrases could be quickly cracked. Users who have complex passphrases, such as "elmo2$fruit99.TAMMANY+1875" can feel more secure. According to Moskowitz: "A key generated from a passphrase of less than about 20 characters is unlikely to deter attacks. ... This is considerably longer than most people will be willing to use."
Once the passphrase is guessed, the attacker can join the network like any legitimate user. Moskowitz did not address the use of other techniques, such as MAC address filtering, to stop unauthorized users.…
Weakness in Passphrase Choice in WPA Interface
http://wifinetnews.com/archives/002452.html
http://www.eweek.com/article2/0,4149,1375085,00.asp
828041 - Overview of the Office 2003 Critical Update: November 4, 2003:
"Microsoft has released an update for Microsoft Office 2003. This update fixes a problem that occurs when you try to open or to save a Microsoft Office PowerPoint 2003 file, a Microsoft Office Word 2003 file, or a Microsoft Office Excel 2003 file that includes an OfficeArt shape that was previously modified and saved in an earlier version of Microsoft Office. When a PowerPoint 2003 file, a Word 2003 file, or a Excel 2003 file is opened in an earlier version of Office, empty 'complex' properties may be introduced into the file and a bit may be changed in the file record that describes these properties. Earlier version of Office will ignore this bit value but when this bit value is detected in Office 2003, you may experience the following symptoms: "
The document may not open completely.
The document may be corrupted.
The document may open but with missing content.
You might receive an error message.
When you open a PowerPoint presentation in PowerPoint 2003, you may receive one of the following error messages where filename is the name of the file that you are trying to open:
PowerPoint can't read filename.
PowerPoint can't open filename because part of file is missing.
PowerPoint can't open the type of file represented by filename.
When you open a PowerPoint presentation in PowerPoint Viewer 2003, you may receive the following error message where filename is the name of the file that you are trying to open:
PowerPoint Viewer cannot open the file filename because the file is corrupted.
When you open a Word document in Word 2003, you may receive the following error message:
Word experienced an error trying to open the file. Try these suggestions.
* Check the file permissions for the document or drive.
* Make sure there is sufficient free memory and disk space.
* Open the file with the Text Recovery converter.
Additionally, when you open the document in an Office 2003 program, you may receive one of the following error messages where filename is the name of your Office file:
Do you want to save the changes you made to filename?
There is insufficient memory. Save the document now.
filename is read-only. Do you want to save changes to a different file name?
This update is part of the continued attempt by Microsoft to provide the latest product updates to customers.
This article describes how to download and install Office 2003 Critical Update: KB828041.
http://support.microsoft.com/?kbid=828041
"Microsoft has released an update for Microsoft Office 2003. This update fixes a problem that occurs when you try to open or to save a Microsoft Office PowerPoint 2003 file, a Microsoft Office Word 2003 file, or a Microsoft Office Excel 2003 file that includes an OfficeArt shape that was previously modified and saved in an earlier version of Microsoft Office. When a PowerPoint 2003 file, a Word 2003 file, or a Excel 2003 file is opened in an earlier version of Office, empty 'complex' properties may be introduced into the file and a bit may be changed in the file record that describes these properties. Earlier version of Office will ignore this bit value but when this bit value is detected in Office 2003, you may experience the following symptoms: "
The document may not open completely.
The document may be corrupted.
The document may open but with missing content.
You might receive an error message.
When you open a PowerPoint presentation in PowerPoint 2003, you may receive one of the following error messages where filename is the name of the file that you are trying to open:
PowerPoint can't read filename.
PowerPoint can't open filename because part of file is missing.
PowerPoint can't open the type of file represented by filename.
When you open a PowerPoint presentation in PowerPoint Viewer 2003, you may receive the following error message where filename is the name of the file that you are trying to open:
PowerPoint Viewer cannot open the file filename because the file is corrupted.
When you open a Word document in Word 2003, you may receive the following error message:
Word experienced an error trying to open the file. Try these suggestions.
* Check the file permissions for the document or drive.
* Make sure there is sufficient free memory and disk space.
* Open the file with the Text Recovery converter.
Additionally, when you open the document in an Office 2003 program, you may receive one of the following error messages where filename is the name of your Office file:
Do you want to save the changes you made to filename?
There is insufficient memory. Save the document now.
filename is read-only. Do you want to save changes to a different file name?
This update is part of the continued attempt by Microsoft to provide the latest product updates to customers.
This article describes how to download and install Office 2003 Critical Update: KB828041.
http://support.microsoft.com/?kbid=828041
The Search Engine Report - Number 84:
"In This Issue
Search Engine Watch News
SES Chicago Agenda Available!
Search Engine Articles By Danny Sullivan
SearchDay Articles
Search Engine Articles
About The Search Engine Report"
Surprised Google & Microsoft Talked Takeover? You Shouldn't Be!
SearchDay, Nov. 5, 2003
http://searchenginewatch.com/searchday/article.php/3104441
New Developments In Local Search: Part 1, Moves By Overture
SearchDay, Oct. 14, 2003
http://searchenginewatch.com/searchday/article.php/3091341
Local Search Part 2: Google & Mobilemaps Bring Back Geosearching
SearchDay, Oct. 21, 2003
http://searchenginewatch.com/searchday/article.php/3096151
Google's API: For Fun, Not Profit (Yet)
SearchDay, Oct. 30, 2003
http://searchenginewatch.com/searchday/article.php/3096451
Balancing Paid and Organic Search Listings
SearchDay, Oct. 23, 2003
http://searchenginewatch.com/searchday/article.php/3095871
Expand Shorthand Meanings with the Acronym Finder
SearchDay, Oct. 20, 2003
http://searchenginewatch.com/searchday/article.php/3082911
Unusual Power Web Searching Commands
Online, Nov/Dec. 2003
http://www.infotoday.com/online/nov03/OnTheNet.shtml
Are eBay Affiliates Spamming Google with Your Words?
AuctionBytes.com, Nov. 2, 2003
http://www.auctionbytes.com/cab/abu/y203/m11/abu0106/s03
The Amazoning of Google? Search Firm Looks for Book Content
Publishers Weekly, Oct. 28, 2003
http://publishersweekly.reviewsnews.com/index.asp?layout=article&articleid=CA331934&publication=publishersweekly
http://searchenginewatch.com/sereport/article.php/3104511
"In This Issue
Search Engine Watch News
SES Chicago Agenda Available!
Search Engine Articles By Danny Sullivan
SearchDay Articles
Search Engine Articles
About The Search Engine Report"
Surprised Google & Microsoft Talked Takeover? You Shouldn't Be!
SearchDay, Nov. 5, 2003
http://searchenginewatch.com/searchday/article.php/3104441
New Developments In Local Search: Part 1, Moves By Overture
SearchDay, Oct. 14, 2003
http://searchenginewatch.com/searchday/article.php/3091341
Local Search Part 2: Google & Mobilemaps Bring Back Geosearching
SearchDay, Oct. 21, 2003
http://searchenginewatch.com/searchday/article.php/3096151
Google's API: For Fun, Not Profit (Yet)
SearchDay, Oct. 30, 2003
http://searchenginewatch.com/searchday/article.php/3096451
Balancing Paid and Organic Search Listings
SearchDay, Oct. 23, 2003
http://searchenginewatch.com/searchday/article.php/3095871
Expand Shorthand Meanings with the Acronym Finder
SearchDay, Oct. 20, 2003
http://searchenginewatch.com/searchday/article.php/3082911
Unusual Power Web Searching Commands
Online, Nov/Dec. 2003
http://www.infotoday.com/online/nov03/OnTheNet.shtml
Are eBay Affiliates Spamming Google with Your Words?
AuctionBytes.com, Nov. 2, 2003
http://www.auctionbytes.com/cab/abu/y203/m11/abu0106/s03
The Amazoning of Google? Search Firm Looks for Book Content
Publishers Weekly, Oct. 28, 2003
http://publishersweekly.reviewsnews.com/index.asp?layout=article&articleid=CA331934&publication=publishersweekly
http://searchenginewatch.com/sereport/article.php/3104511
Tuesday, November 04, 2003
Will Eolas' Browser Technology Patent Be Revoked?:
"The World Wide Web Consortium's (W3C) request to have the controversial ActiveX (define) patent reexamined and reversed might be unusual but it's not without precedent."
Back in 1994, the U.S. Patent and Trademark Office (USPTO) conducted a thorough reexamination and rescinded Patent Number 5,241,671, which was previously issued to Compton's New Media, a unit of Encyclopedia Britannica. When Compton's attempted to enforce the patent, which covered the use of text, graphics and sounds in multimedia applications, a huge public outcry forced the USPTO to order a re-examination.
Officials at the W3C are crossing fingers and hoping that an industry-wide protest will force the patent office to launch a reexamination to prevent "substantial economic and technical damage" to the operation of the World Wide Web.
U.S Patent No. 5,838,906 is at the heart of a multi-million dollar dispute between Microsoft (Quote, Chart) and Chicago-based Eolas Technology. In addition to forcing major changes Microsoft's flagship Internet Explorer browser, the enforcement of the '906 patent has sent Web developers scrambling to prepare code re-writes for Web pages that carry embedded interactive content.
In an interview with internetnews.com, chairman of the W3C's patent policy working group Daniel Weitzner cited the Compton's precedent and insisted there was enough prior art available to lead to an invalidation of the patent.
The W3C's HTML Patent Advisory Group, in a citation sent to the USPTO's Prior Art Department, presented what Weitzner described as "compelling evidence" of similar technology available long before Eolas even applied for the patent.
"The sole difference between the web browser described in the '906 patent and typical browsers that the patent acknowledges as prior art, is that with prior art browsers, the image in such cases is displayed in its own window, separate from the main browser window, whereas, with the '906 browser the image is displayed in the same window as the rest of the Web page, without the need for a separate window," the W3C said in its filing.
"That feature, (i.e., displaying, or embedding, an image generated by an external program in the same window as the rest of a Web page) had already been described in the prior art publications submitted herewith and was known to the Web development community. The claims of the '906 patent are therefore plainly obvious in view of this prior art," the standards group argued.
According to Weitzner, the W3C has clearly identified technology that established prior art to show that the patent Eolas applied for was "not at all novel at the time."
"It's clear that the patent didn't meet the required standard of novelty. Software developers have long recognized the usefulness of adding objects in word processing programs. This is certainly not novel and our filing attempts to prove that," Weitzner added.
Even if the W3C is successful with its reexamination request, legal experts say the brouhaha is far from being settled. When a patent is revoked, legal sources explained that a process known as "prosecution" follows. During "prosecution," patent attorneys and examiners at the USPTO trade documents in what is usually a long, drawn-out process.
"The patent office throws out patents all the time but rejections don't mean it ends there. Usually, if there's a bitter dispute, it can go all the way to the Supreme Court," the source said.
A spokesperson for the USPTO confirmed receipt of the W3C request and said a decision could come in a few days or could take up to 90 days. "It all depends on the merits of the request. If there are grounds for reexamination and substantial new questions are raised, we can order a reexamination," the spokesperson told internetnews.com.
In addition to poring over the W3C's prior art filings, the USPTO can hold hearings around the country to seek industry-wide opinion, the patent office spokesperson added.
Even as the W3C is insisting prior art is readily available, many wonder why this was never uncovered during the Microsoft/Eolas case that has been before the courts since 1999
According to W3C's Weitzner, efforts to have the jury consider the prior art in the HTML standard was not allowed "for procedural reasons. "It [the prior art] wasn't rejected for any reason that won't allow the patent office to reexamine it. It wasn't presented to the jury because of procedural issues," he insisted.…
http://www.internetnews.com/dev-news/article.php/3102651
"The World Wide Web Consortium's (W3C) request to have the controversial ActiveX (define) patent reexamined and reversed might be unusual but it's not without precedent."
Back in 1994, the U.S. Patent and Trademark Office (USPTO) conducted a thorough reexamination and rescinded Patent Number 5,241,671, which was previously issued to Compton's New Media, a unit of Encyclopedia Britannica. When Compton's attempted to enforce the patent, which covered the use of text, graphics and sounds in multimedia applications, a huge public outcry forced the USPTO to order a re-examination.
Officials at the W3C are crossing fingers and hoping that an industry-wide protest will force the patent office to launch a reexamination to prevent "substantial economic and technical damage" to the operation of the World Wide Web.
U.S Patent No. 5,838,906 is at the heart of a multi-million dollar dispute between Microsoft (Quote, Chart) and Chicago-based Eolas Technology. In addition to forcing major changes Microsoft's flagship Internet Explorer browser, the enforcement of the '906 patent has sent Web developers scrambling to prepare code re-writes for Web pages that carry embedded interactive content.
In an interview with internetnews.com, chairman of the W3C's patent policy working group Daniel Weitzner cited the Compton's precedent and insisted there was enough prior art available to lead to an invalidation of the patent.
The W3C's HTML Patent Advisory Group, in a citation sent to the USPTO's Prior Art Department, presented what Weitzner described as "compelling evidence" of similar technology available long before Eolas even applied for the patent.
"The sole difference between the web browser described in the '906 patent and typical browsers that the patent acknowledges as prior art, is that with prior art browsers, the image in such cases is displayed in its own window, separate from the main browser window, whereas, with the '906 browser the image is displayed in the same window as the rest of the Web page, without the need for a separate window," the W3C said in its filing.
"That feature, (i.e., displaying, or embedding, an image generated by an external program in the same window as the rest of a Web page) had already been described in the prior art publications submitted herewith and was known to the Web development community. The claims of the '906 patent are therefore plainly obvious in view of this prior art," the standards group argued.
According to Weitzner, the W3C has clearly identified technology that established prior art to show that the patent Eolas applied for was "not at all novel at the time."
"It's clear that the patent didn't meet the required standard of novelty. Software developers have long recognized the usefulness of adding objects in word processing programs. This is certainly not novel and our filing attempts to prove that," Weitzner added.
Even if the W3C is successful with its reexamination request, legal experts say the brouhaha is far from being settled. When a patent is revoked, legal sources explained that a process known as "prosecution" follows. During "prosecution," patent attorneys and examiners at the USPTO trade documents in what is usually a long, drawn-out process.
"The patent office throws out patents all the time but rejections don't mean it ends there. Usually, if there's a bitter dispute, it can go all the way to the Supreme Court," the source said.
A spokesperson for the USPTO confirmed receipt of the W3C request and said a decision could come in a few days or could take up to 90 days. "It all depends on the merits of the request. If there are grounds for reexamination and substantial new questions are raised, we can order a reexamination," the spokesperson told internetnews.com.
In addition to poring over the W3C's prior art filings, the USPTO can hold hearings around the country to seek industry-wide opinion, the patent office spokesperson added.
Even as the W3C is insisting prior art is readily available, many wonder why this was never uncovered during the Microsoft/Eolas case that has been before the courts since 1999
According to W3C's Weitzner, efforts to have the jury consider the prior art in the HTML standard was not allowed "for procedural reasons. "It [the prior art] wasn't rejected for any reason that won't allow the patent office to reexamine it. It wasn't presented to the jury because of procedural issues," he insisted.…
http://www.internetnews.com/dev-news/article.php/3102651
SANS Top 20 Vulnerabilities - The Experts Consensus:
"The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus"
The vast majority of worms and other successful cyber attacks are made possible by vulnerabilities in a small number of common operating system services. Attackers are opportunistic. They take the easiest and most convenient route and exploit the best-known flaws with the most effective and widely available attack tools. They count on organizations not fixing the problems, and they often attack indiscriminately, scanning the Internet for any vulnerable systems. The easy and destructive spread of worms, such as Blaster, Slammer, and Code Red, can be traced directly to exploitation of unpatched vulnerabilities.
Three years ago, the SANS Institute and the National Infrastructure Protection Center (NIPC) at the FBI released a document summarizing the Ten Most Critical Internet Security Vulnerabilities. Thousands of organizations used that list, and the expanded Top Twenty lists that followed one and two years later, to prioritize their efforts so they could close the most dangerous holes first. The vulnerable services that led to the examples above Blaster, Slammer, and Code Red, as well as NIMDA worms - are on that list.
This updated SANS Top Twenty is actually two Top Ten lists: the ten most commonly exploited vulnerable services in Windows and the ten most commonly exploited vulnerable services in UNIX and Linux. Although there are thousands of security incidents each year affecting these operating systems, the overwhelming majority of successful attacks target one or more of these twenty vulnerable services.
The Top Twenty is a consensus list of vulnerabilities that require immediate remediation. It is the result of a process that brought together dozens of leading security experts. They come from the most security-conscious federal agencies in the US, UK and Singapore; the leading security software vendors and consulting firms; the top university-based security programs; many other user organizations; and the SANS Institute. A list of participants may be found at the end of this document.
The SANS Top Twenty is a living document. It includes step-by-step instructions and pointers to additional information useful for correcting the security flaws. We will update the list and the instructions as more critical threats and more current or convenient methods are identified, and we welcome your input along the way. This is a community consensus document -- your experience in fighting attackers and in eliminating the vulnerabilities can help others who come after you. Please send suggestions via e-mail to top20@sans.org.
Top Vulnerabilities to Windows Systems
W1 Internet Information Services (IIS)
W2 Microsoft SQL Server (MSSQL)
W3 Windows Authentication
W4 Internet Explorer (IE)
W5 Windows Remote Access Services
W6 Microsoft Data Access Components (MDAC)
W7 Windows Scripting Host (WSH)
W8 Microsoft Outlook and Outlook Express
W9 Windows Peer to Peer File Sharing (P2P)
W10 Simple Network Management Protocol (SNMP)
Top Vulnerabilities to UNIX Systems
U1 BIND Domain Name System
U2 Remote Procedure Calls (RPC)
U3 Apache Web Server
U4 General UNIX Authentication Accounts with No Passwords or Weak Passwords
U5 Clear Text Services
U6 Sendmail
U7 Simple Network Management Protocol (SNMP)
U8 Secure Shell (SSH)
U9 Misconfiguration of Enterprise Services NIS/NFS
U10 Open Secure Sockets Layer (SSL)
http://www.sans.org/top20/index.php
"The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus"
The vast majority of worms and other successful cyber attacks are made possible by vulnerabilities in a small number of common operating system services. Attackers are opportunistic. They take the easiest and most convenient route and exploit the best-known flaws with the most effective and widely available attack tools. They count on organizations not fixing the problems, and they often attack indiscriminately, scanning the Internet for any vulnerable systems. The easy and destructive spread of worms, such as Blaster, Slammer, and Code Red, can be traced directly to exploitation of unpatched vulnerabilities.
Three years ago, the SANS Institute and the National Infrastructure Protection Center (NIPC) at the FBI released a document summarizing the Ten Most Critical Internet Security Vulnerabilities. Thousands of organizations used that list, and the expanded Top Twenty lists that followed one and two years later, to prioritize their efforts so they could close the most dangerous holes first. The vulnerable services that led to the examples above Blaster, Slammer, and Code Red, as well as NIMDA worms - are on that list.
This updated SANS Top Twenty is actually two Top Ten lists: the ten most commonly exploited vulnerable services in Windows and the ten most commonly exploited vulnerable services in UNIX and Linux. Although there are thousands of security incidents each year affecting these operating systems, the overwhelming majority of successful attacks target one or more of these twenty vulnerable services.
The Top Twenty is a consensus list of vulnerabilities that require immediate remediation. It is the result of a process that brought together dozens of leading security experts. They come from the most security-conscious federal agencies in the US, UK and Singapore; the leading security software vendors and consulting firms; the top university-based security programs; many other user organizations; and the SANS Institute. A list of participants may be found at the end of this document.
The SANS Top Twenty is a living document. It includes step-by-step instructions and pointers to additional information useful for correcting the security flaws. We will update the list and the instructions as more critical threats and more current or convenient methods are identified, and we welcome your input along the way. This is a community consensus document -- your experience in fighting attackers and in eliminating the vulnerabilities can help others who come after you. Please send suggestions via e-mail to top20@sans.org.
Top Vulnerabilities to Windows Systems
W1 Internet Information Services (IIS)
W2 Microsoft SQL Server (MSSQL)
W3 Windows Authentication
W4 Internet Explorer (IE)
W5 Windows Remote Access Services
W6 Microsoft Data Access Components (MDAC)
W7 Windows Scripting Host (WSH)
W8 Microsoft Outlook and Outlook Express
W9 Windows Peer to Peer File Sharing (P2P)
W10 Simple Network Management Protocol (SNMP)
Top Vulnerabilities to UNIX Systems
U1 BIND Domain Name System
U2 Remote Procedure Calls (RPC)
U3 Apache Web Server
U4 General UNIX Authentication Accounts with No Passwords or Weak Passwords
U5 Clear Text Services
U6 Sendmail
U7 Simple Network Management Protocol (SNMP)
U8 Secure Shell (SSH)
U9 Misconfiguration of Enterprise Services NIS/NFS
U10 Open Secure Sockets Layer (SSL)
http://www.sans.org/top20/index.php
Apple Alerts Users of Issues With FireWire Storage:
"Following a growing number of online reports of problems when using external FireWire 800 hard drives with the recently released Mac OS X 10.3, aka Panther, Apple late Friday issued a blanket warning to users of all OS X versions. "
Posted on Apple's Web site, the "special message" said the company had identified an issue with external FireWire hard drives. It pointed to the Oxford Semiconductor Ltd.'s 922 bridge chipset with Version 1.02 firmware as the source of the problem. "In the interim, Apple recommends that you do not use these drives. To stop using the drive, you should unmount or eject the disk drive before doing anything else," the message stated.
This problem occurs with external drives using the FireWire 800 interface. All current Macs, desktops and notebooks, come either with the older FireWire 400 or faster FireWire 800 interface, or both.…
http://www.eweek.com/article2/0,4149,1369891,00.asp
"Following a growing number of online reports of problems when using external FireWire 800 hard drives with the recently released Mac OS X 10.3, aka Panther, Apple late Friday issued a blanket warning to users of all OS X versions. "
Posted on Apple's Web site, the "special message" said the company had identified an issue with external FireWire hard drives. It pointed to the Oxford Semiconductor Ltd.'s 922 bridge chipset with Version 1.02 firmware as the source of the problem. "In the interim, Apple recommends that you do not use these drives. To stop using the drive, you should unmount or eject the disk drive before doing anything else," the message stated.
This problem occurs with external drives using the FireWire 800 interface. All current Macs, desktops and notebooks, come either with the older FireWire 400 or faster FireWire 800 interface, or both.…
http://www.eweek.com/article2/0,4149,1369891,00.asp
ZDNet: Printer Friendly - New worm poses DoS attack threat:
"Security experts warned Friday of a potentially harmful new e-mail worm that is slowly spreading among corporate and home e-mail users.
The Mimail.c worm, a variant of an earlier pest that achieved modest distribution by posing as a message from a company's information technology staff, was first detected late Thursday and managed to infect a handful of PCs. "
According to McAfee's description, Mimail.c spreads by e-mail, appearing in mailboxes as a message with the subject "our private photos." The body of the message promises revealing photos, if the recipient opens up an attached file saved in the Zip compression format. If the file is opened, the worm attempts to spread itself by sending messages to e-mail addresses culled from the infected PC.
The worm also attempts to launch a denial-of-service attack by sending large volumes of "garbage data" to Web addresses associated with DarkProfits, a gaming enthusiast site that has been the subject of a persistent e-mail hoax.
Mimail.c also spoofs the address the message is generated from, with all messages appearing to come from "James" at the same domain as the recipient.
http://zdnet.com.com/2100-1105_2-5100741.html?tag=adnews
"Security experts warned Friday of a potentially harmful new e-mail worm that is slowly spreading among corporate and home e-mail users.
The Mimail.c worm, a variant of an earlier pest that achieved modest distribution by posing as a message from a company's information technology staff, was first detected late Thursday and managed to infect a handful of PCs. "
According to McAfee's description, Mimail.c spreads by e-mail, appearing in mailboxes as a message with the subject "our private photos." The body of the message promises revealing photos, if the recipient opens up an attached file saved in the Zip compression format. If the file is opened, the worm attempts to spread itself by sending messages to e-mail addresses culled from the infected PC.
The worm also attempts to launch a denial-of-service attack by sending large volumes of "garbage data" to Web addresses associated with DarkProfits, a gaming enthusiast site that has been the subject of a persistent e-mail hoax.
Mimail.c also spoofs the address the message is generated from, with all messages appearing to come from "James" at the same domain as the recipient.
http://zdnet.com.com/2100-1105_2-5100741.html?tag=adnews
Monday, November 03, 2003
Music-Sharing Service at M.I.T. Is Shut Down:
"It was hailed as ingenious: a way to listen to music on demand while avoiding the legal battleground of file sharing. Best of all, the music was fully licensed, so there would be no legal trouble."
But it was not, and there is. On Friday, the Massachusetts Institute of Technology announced that it would temporarily shut down its groundbreaking Library Access to Music System until the licensing rights can be worked out.
The music service had its official start one week ago but within hours, music companies, including the Universal Music Group, complained that they had not granted - or been paid for - the required legal permission to make the copies of their songs used by the system.
The creators of the new service, M.I.T. students Keith Winstein and Josh Mandel, were dumbfounded by the industry move, since they had paid Loudeye, a company in Seattle, to fill a hard drive with licensed songs. Mr. Winstein and Mr. Mandel said that they thought the contract with the company guaranteed that the copyright issues had been resolved.
"So far as I know, we bought this music fair and square," Mr. Winstein said.
He called the decision to suspend the service crushing, but he hoped it would only be temporary.
"The prudent thing to do, the good faith thing to do, is to take it down while we feel out where we stand," he said.
The music library idea is a clever blend of technology and law. Its creators built the system within the school's cable TV network; the analog TV network would, the students thought, help sidestep the expensive and restrictive laws and regulations that have grown up around the copying and sharing digital copies of music.
It was supposed to resemble the analog world of radio, in which stations pay performance fees to artists representatives like the American Society of Composers, Authors and Publishers but do not pay royalties to the music labels. Because students could listen to the music without making or trading copies, the system's creator thought that they only had to make sure they had legally purchased the music and would not require further payments to the labels.…
http://www.nytimes.com/2003/11/03/technology/03mitt.html
"It was hailed as ingenious: a way to listen to music on demand while avoiding the legal battleground of file sharing. Best of all, the music was fully licensed, so there would be no legal trouble."
But it was not, and there is. On Friday, the Massachusetts Institute of Technology announced that it would temporarily shut down its groundbreaking Library Access to Music System until the licensing rights can be worked out.
The music service had its official start one week ago but within hours, music companies, including the Universal Music Group, complained that they had not granted - or been paid for - the required legal permission to make the copies of their songs used by the system.
The creators of the new service, M.I.T. students Keith Winstein and Josh Mandel, were dumbfounded by the industry move, since they had paid Loudeye, a company in Seattle, to fill a hard drive with licensed songs. Mr. Winstein and Mr. Mandel said that they thought the contract with the company guaranteed that the copyright issues had been resolved.
"So far as I know, we bought this music fair and square," Mr. Winstein said.
He called the decision to suspend the service crushing, but he hoped it would only be temporary.
"The prudent thing to do, the good faith thing to do, is to take it down while we feel out where we stand," he said.
The music library idea is a clever blend of technology and law. Its creators built the system within the school's cable TV network; the analog TV network would, the students thought, help sidestep the expensive and restrictive laws and regulations that have grown up around the copying and sharing digital copies of music.
It was supposed to resemble the analog world of radio, in which stations pay performance fees to artists representatives like the American Society of Composers, Authors and Publishers but do not pay royalties to the music labels. Because students could listen to the music without making or trading copies, the system's creator thought that they only had to make sure they had legally purchased the music and would not require further payments to the labels.…
http://www.nytimes.com/2003/11/03/technology/03mitt.html
Mars Orbiter Camera Public Target Request Site -- Introduction:
"If you would like to recommend a picture of Mars, this is the place.
The purpose of this web site is to solicit public and science community suggestions for future high resolution images to be obtained by the Mars Global Surveyor (MGS) Mars Orbiter Camera (MOC)."
We are looking for excellent suggestions for pictures of areas on Mars that MOC has not previously imaged. Using this web site interface, you will indicate the location of the recommended MOC image, and you will describe, in detail, the purpose of the image. When your request is received, it will be evaluated by the Mars science staff at Malin Space Science Systems (MSSS), then put into a database for future acquisition by MOC. At some time in the future, if the MGS ground track passes over the site you suggested, and there are no pre-existing conflicts with other MOC images, the camera will be commanded to take the picture. Recent images suggested by the public will be posted on the MSSS web site once a month; if the image you suggested is among them, and if you registered using your email address, you will be notified by email.
System requirements:
At this time, the Target Request site only works with Internet Explorer (IE). It was developed and tested with IE 6 / Windows 98 SE and IE 5.2.3 / Mac OS X (10.2.6). It is impractical for us to make it work with every browser on every platform, due to the incompatibility of various browsers.
JavaScript must be enabled.
Use of this site will be much more enjoyable with a broadband connection. Its map images take many minutes to download over a dialup connection.
Screen resolution of 1280 x 1024 or higher is recommended.
http://www.msss.com/plan/intro
"If you would like to recommend a picture of Mars, this is the place.
The purpose of this web site is to solicit public and science community suggestions for future high resolution images to be obtained by the Mars Global Surveyor (MGS) Mars Orbiter Camera (MOC)."
We are looking for excellent suggestions for pictures of areas on Mars that MOC has not previously imaged. Using this web site interface, you will indicate the location of the recommended MOC image, and you will describe, in detail, the purpose of the image. When your request is received, it will be evaluated by the Mars science staff at Malin Space Science Systems (MSSS), then put into a database for future acquisition by MOC. At some time in the future, if the MGS ground track passes over the site you suggested, and there are no pre-existing conflicts with other MOC images, the camera will be commanded to take the picture. Recent images suggested by the public will be posted on the MSSS web site once a month; if the image you suggested is among them, and if you registered using your email address, you will be notified by email.
System requirements:
At this time, the Target Request site only works with Internet Explorer (IE). It was developed and tested with IE 6 / Windows 98 SE and IE 5.2.3 / Mac OS X (10.2.6). It is impractical for us to make it work with every browser on every platform, due to the incompatibility of various browsers.
JavaScript must be enabled.
Use of this site will be much more enjoyable with a broadband connection. Its map images take many minutes to download over a dialup connection.
Screen resolution of 1280 x 1024 or higher is recommended.
http://www.msss.com/plan/intro
Friday, October 31, 2003
Preview: Microsoft's Windows Longhorn: "Disclaimer: This is a preview based on a very early release of Microsoft's next-generation operating system. It lacks the modern user interface elements that will be in the final version. Given that the code is far from final and may contain many debug elements, the system's performance will likely improve in subsequent releases. Any statements we make about perceived performance may not apply to the final version, and any feature discussed here may also change before Longhorn's final release in 2006. "
Longhorn is the codename for the next-generation version of Microsoft's flagship Windows operating system. It's also the company's most ambitious project since the first Windows NT release. An impressive array of new technologies will be built into the new OS -- a few of which were included in the pre-release version we checked out.
Due to its ambitious nature, Longhorn has had its release pushed out to sometime in 2006. Because of this, Microsoft has committed to a second service pack release for Windows XP, which may add a few Longhorn elements – particularly in the realm of security.
Some of the key features of Longhorn include:
Improved security -- through it's NGSCB initiative
WinFS, a new file system based around relational database technology (NTFS will still be available)
New user interface technologies based on DirectX rather than the aging GDI interface. Every window in the release version will be a 32-bit, z-buffered, 3D surface.
A new presentation and UI design subsystem, codenamed "Avalon," based around XAML (Extensible Application Markup Language).
A new communications architecture, codenamed "Indigo," that's an enhanced and integrated version of Microsoft's .NET framework.
http://www.extremetech.com/print_article/0,3998,a=111043,00.asp
Longhorn is the codename for the next-generation version of Microsoft's flagship Windows operating system. It's also the company's most ambitious project since the first Windows NT release. An impressive array of new technologies will be built into the new OS -- a few of which were included in the pre-release version we checked out.
Due to its ambitious nature, Longhorn has had its release pushed out to sometime in 2006. Because of this, Microsoft has committed to a second service pack release for Windows XP, which may add a few Longhorn elements – particularly in the realm of security.
Some of the key features of Longhorn include:
Improved security -- through it's NGSCB initiative
WinFS, a new file system based around relational database technology (NTFS will still be available)
New user interface technologies based on DirectX rather than the aging GDI interface. Every window in the release version will be a 32-bit, z-buffered, 3D surface.
A new presentation and UI design subsystem, codenamed "Avalon," based around XAML (Extensible Application Markup Language).
A new communications architecture, codenamed "Indigo," that's an enhanced and integrated version of Microsoft's .NET framework.
http://www.extremetech.com/print_article/0,3998,a=111043,00.asp
Panther Patches Mac OS X Security Holes: "Security researchers have identified three new vulnerabilities in Apple Computer Inc.'s Mac OS X, one of which may allow attackers to execute some arbitrary commands as a root user under some circumstances. "
The flaws affect all versions of the operating system through 10.2 and are fixed in release 10.3, also known as Panther, according to Apple.
The first vulnerability is a buffer overrun that allows an attacker to crash the OS X kernel simply by entering a command line argument of a specific length. Once the attack is executed, the machine crashes immediately, without generating any log files or error messages, according to an advisory on the issue released Tuesday by @stake Inc., based in Cambridge, Mass., which discovered both weaknesses. The crashed machine will reboot eventually.…
However, an attacker can also use this vulnerability to get the machine to return small amounts of its memory to him. Researchers at @stake said it appears the only thing being returned to the attacker is memory addresses, which aren't normally considered to be sensitive information.
Although they were unable to use this flaw to run code on vulnerable machines, the @stake researchers said that it may be possible, given that the weakness lies in the OS X kernel itself.
The second new problem involves the way that the OS handles core files, which are a snapshot of the system's state when a machine crashes. When core files are enabled in OS X, processes owned by root will write a core file to the /cores directory. These files are owned by the root process, which would have read-only access to them. The attacker can also read the contents of the core files created by the root process.
But, because the directory is writable and the names of the files in it are predictable, an attacker could create symbolic links to these files and point them to files elsewhere on the system. In this way, he could essentially overwrite any of the core files. To do this, the attacker would need interactive shell access to the machine, @stake said.…
The third vulnerability involves the fact that OS X allows many applications to be installed with insecure file permissions. This can result in many of the files and directories in these applications being globally writable, @stake said.
Although Apple has provided fixes for these flaws in Panther, the latest version of OS X, it has declined to create any patches for users who plan to stick with earlier versions. Panther has only been available since Oct. 24 and costs $129 for a single-user upgrade. The lack of a fix for existing, still-supported versions of OS X has been a topic of much conversation on security mailing lists this week.…
http://www.eweek.com/article2/0,4149,1365177,00.asp
The flaws affect all versions of the operating system through 10.2 and are fixed in release 10.3, also known as Panther, according to Apple.
The first vulnerability is a buffer overrun that allows an attacker to crash the OS X kernel simply by entering a command line argument of a specific length. Once the attack is executed, the machine crashes immediately, without generating any log files or error messages, according to an advisory on the issue released Tuesday by @stake Inc., based in Cambridge, Mass., which discovered both weaknesses. The crashed machine will reboot eventually.…
However, an attacker can also use this vulnerability to get the machine to return small amounts of its memory to him. Researchers at @stake said it appears the only thing being returned to the attacker is memory addresses, which aren't normally considered to be sensitive information.
Although they were unable to use this flaw to run code on vulnerable machines, the @stake researchers said that it may be possible, given that the weakness lies in the OS X kernel itself.
The second new problem involves the way that the OS handles core files, which are a snapshot of the system's state when a machine crashes. When core files are enabled in OS X, processes owned by root will write a core file to the /cores directory. These files are owned by the root process, which would have read-only access to them. The attacker can also read the contents of the core files created by the root process.
But, because the directory is writable and the names of the files in it are predictable, an attacker could create symbolic links to these files and point them to files elsewhere on the system. In this way, he could essentially overwrite any of the core files. To do this, the attacker would need interactive shell access to the machine, @stake said.…
The third vulnerability involves the fact that OS X allows many applications to be installed with insecure file permissions. This can result in many of the files and directories in these applications being globally writable, @stake said.
Although Apple has provided fixes for these flaws in Panther, the latest version of OS X, it has declined to create any patches for users who plan to stick with earlier versions. Panther has only been available since Oct. 24 and costs $129 for a single-user upgrade. The lack of a fix for existing, still-supported versions of OS X has been a topic of much conversation on security mailing lists this week.…
http://www.eweek.com/article2/0,4149,1365177,00.asp
Good Information Architecture Increases Online Sales:
Imagine you’re downtown and you want to buy a Kraftwerk CD.
You visit Tower Records, go to the Electronic section, find category K, locate Kraftwerk, and select their Tour De France CD. Great! You’re off to the checkout and…
Hang on. Where’s the checkout?
They’ve moved it to the second floor. When you get there, you hand over you credit card. Big mistake. You should have registered downstairs first.
You head back down to the basement. Do you have two copies of your ID? No. “But it’s only a $9.99 CD!” you argue. The store stands firm. Wonderful music though it is, you’re soon off to a store that’s more conducive to purchasing.
This scenario may be a little far-flung, but if you’ve ever shopped online, you’ve probably had a similar experience at some point. You wanted to buy something, were ready to use your credit card… but the process was so excruciating that you gave up.…
http://www.sitepoint.com/print/1235
Imagine you’re downtown and you want to buy a Kraftwerk CD.
You visit Tower Records, go to the Electronic section, find category K, locate Kraftwerk, and select their Tour De France CD. Great! You’re off to the checkout and…
Hang on. Where’s the checkout?
They’ve moved it to the second floor. When you get there, you hand over you credit card. Big mistake. You should have registered downstairs first.
You head back down to the basement. Do you have two copies of your ID? No. “But it’s only a $9.99 CD!” you argue. The store stands firm. Wonderful music though it is, you’re soon off to a store that’s more conducive to purchasing.
This scenario may be a little far-flung, but if you’ve ever shopped online, you’ve probably had a similar experience at some point. You wanted to buy something, were ready to use your credit card… but the process was so excruciating that you gave up.…
http://www.sitepoint.com/print/1235
World Domination for Small Web Businesses: "Most Web designers define their target market as either:
Both these “target markets” cost Web designers revenue, time and money. This article explains why. Then, it shows how to focus on a specific target market to increase revenue, cut marketing costs, and make business development easier and more effective.…
http://www.sitepoint.com/print/1238
- 'Small to mid-sized businesses'
- 'People who can be reached through word of mouth from clients and colleagues'
Or:
Both these “target markets” cost Web designers revenue, time and money. This article explains why. Then, it shows how to focus on a specific target market to increase revenue, cut marketing costs, and make business development easier and more effective.…
http://www.sitepoint.com/print/1238
"About Us" -- Presenting Information About an Organization on Its Website (Jakob Nielsen's Alertbox):
Summary:
Study participants searched websites for background information ranging from company history to management biographies and contact details. Their success rate was 70%, leaving much room for usability improvements in the 'About Us' designs. "
Representing a company or organization on the Internet is one of a website's most important jobs. Explaining the company's purpose and what it stands for provides essential support for any of the site's other goals. Unfortunately, most websites do a poor job on this explanation.
It is fairly common for sites to have an About Us section, and in fact I recommend having a homepage link that's explicitly called either About or About Us. This link need not be the most prominent on the homepage, but it should be present and easily visible. In our study, users had trouble locating company information when the link had a nonstandard name, like Info Center, or when it was placed near graphical elements that looked like advertisements and thus were ignored.…
http://www.useit.com/alertbox/20031027.html
Summary:
Study participants searched websites for background information ranging from company history to management biographies and contact details. Their success rate was 70%, leaving much room for usability improvements in the 'About Us' designs. "
Representing a company or organization on the Internet is one of a website's most important jobs. Explaining the company's purpose and what it stands for provides essential support for any of the site's other goals. Unfortunately, most websites do a poor job on this explanation.
It is fairly common for sites to have an About Us section, and in fact I recommend having a homepage link that's explicitly called either About
http://www.useit.com/alertbox/20031027.html
Thursday, October 30, 2003
OJR article: The E-mail Paradox: Bane and Boon for Journalists' Productivity: "Close your eyes and imagine a world without e-mail. No more SoBig viruses, no more spam, no more forwarded jokes. Gosh, what would you do with all that free time? Maybe you'd be more productive. That's the thinking behind the internal office e-mail ban at British mobile phone company, Phones4u.
That's all well and good, but for journalists, an e-mail ban is like going back to the Stone Age. Media folks depend on e-mail for news tips, feedback from readers and discussion lists. Journalists are the power users of e-mail and the Web, so that leaves them with a paradox: The constant barrage of e-mail does as much harm as good."
http://www.ojr.org/ojr/glaser/1067022673.php
That's all well and good, but for journalists, an e-mail ban is like going back to the Stone Age. Media folks depend on e-mail for news tips, feedback from readers and discussion lists. Journalists are the power users of e-mail and the Web, so that leaves them with a paradox: The constant barrage of e-mail does as much harm as good."
http://www.ojr.org/ojr/glaser/1067022673.php
Political Animation on the Web: "Mark Fiore creates a single editorial cartoon a week, yet he's among the hardest-working artists in the profession. That's because Fiore does political animation -- a compelling mix of words, pictures, motion, voices, sound effects, and music.
A prime example is last month's animation marking the second anniversary of 9/11. As a piano plays mournfully in the background, title cards announce: 'Two years after more than 3,000 innocent people were killed, we present ... A Nation Remembers.' Then Fiore shows scenes of Ground Zero workers 'who were told by the EPA the air was safe'; the 19 hijackers, 'none of whom were from Iraq'; and New York City firehouses, 'six of which have been closed due to budget cuts.' Meanwhile, a cartoon version of President Bush frantically advises viewers not to remember all that. But Bush does want people to remember things like his wearing of a flight suit this spring. 'That was sure cool,' intones the president, as voiced by Fiore. 'I'll never forget that day!'"
Fiore, whose clients include newspaper Web sites, spends more than 35 hours on each 45-to-60-second animation. Part of the process is familiar to any print editorial cartoonist -- a position Fiore once held as a freelancer and San Jose (Calif.) Mercury News staffer. Fiore checks out the news, comes up with an idea, and does research before writing and sketching a storyboard showing various scenes.
Then, Fiore does anywhere from 10 to 30 drawings the old-fashioned way -- ink on paper. "That's really important to my work," he told E&P Online. "I want to have a line so it doesn't look too 'computery.' My goal is to bring my style from the print world to animation." He also letters some of the text by hand.
http://www.editorandpublisher.com/editorandpublisher/features_columns/article_display.jsp?vnu_content_id=2013532
A prime example is last month's animation marking the second anniversary of 9/11. As a piano plays mournfully in the background, title cards announce: 'Two years after more than 3,000 innocent people were killed, we present ... A Nation Remembers.' Then Fiore shows scenes of Ground Zero workers 'who were told by the EPA the air was safe'; the 19 hijackers, 'none of whom were from Iraq'; and New York City firehouses, 'six of which have been closed due to budget cuts.' Meanwhile, a cartoon version of President Bush frantically advises viewers not to remember all that. But Bush does want people to remember things like his wearing of a flight suit this spring. 'That was sure cool,' intones the president, as voiced by Fiore. 'I'll never forget that day!'"
Fiore, whose clients include newspaper Web sites, spends more than 35 hours on each 45-to-60-second animation. Part of the process is familiar to any print editorial cartoonist -- a position Fiore once held as a freelancer and San Jose (Calif.) Mercury News staffer. Fiore checks out the news, comes up with an idea, and does research before writing and sketching a storyboard showing various scenes.
Then, Fiore does anywhere from 10 to 30 drawings the old-fashioned way -- ink on paper. "That's really important to my work," he told E&P Online. "I want to have a line so it doesn't look too 'computery.' My goal is to bring my style from the print world to animation." He also letters some of the text by hand.
http://www.editorandpublisher.com/editorandpublisher/features_columns/article_display.jsp?vnu_content_id=2013532
W3C Seeks Re-examination of Eolas Browser Patent: "The World Wide Web Consortium is seeking a reexamination of a Web browser patent that it says threatens to undermine the smooth operation of the Web."
The patent is at the heart of a legal wrangle between Eolas Technologies Inc., which holds a license to it from the University of California, and Microsoft Corp. Microsoft in August lost a $521 million patent-infringement jury verdict in the case and since has announced changes to its Internet Explorer browser that it says sidesteps the patent's method for embedding and invoking interactive applications such as plug-ins and applets from Web browsers.
On Tuesday, W3C Director Tim Berners-Lee sent a letter to the United States Patent and Trademark Office formally requesting a reexamination of the patent, U.S. Patent No. 5,838,906. The Web standards group claims that the patent is invalid because "prior art" (a legal term in patent law referring to whether an invention existed prior to the filing of a patent) was not considered at the time the patent was granted in 1998 or during the trial.
"A patent whose validity is demonstrably in doubt ought not be allowed to undo years of work that have gone into building the Web," Berners-Lee wrote in his letter to James E. Rogan, undersecretary of commerce for intellectual property in the patent office
In a separate filing with the patent office, the W3C last week outlined examples of prior art, including two publications from a Hewlett Packard Laboratories researcher, Dave Raggett, about a proposed HTML+ specification that it says were published a year before the patent filing.
The W3C claims that the publications describe the EMBED tag in HTML+ in an identical way to the EMBED tag in the patent.…
http://www.eweek.com/article2/0,4149,1366698,00.asp
The patent is at the heart of a legal wrangle between Eolas Technologies Inc., which holds a license to it from the University of California, and Microsoft Corp. Microsoft in August lost a $521 million patent-infringement jury verdict in the case and since has announced changes to its Internet Explorer browser that it says sidesteps the patent's method for embedding and invoking interactive applications such as plug-ins and applets from Web browsers.
On Tuesday, W3C Director Tim Berners-Lee sent a letter to the United States Patent and Trademark Office formally requesting a reexamination of the patent, U.S. Patent No. 5,838,906. The Web standards group claims that the patent is invalid because "prior art" (a legal term in patent law referring to whether an invention existed prior to the filing of a patent) was not considered at the time the patent was granted in 1998 or during the trial.
"A patent whose validity is demonstrably in doubt ought not be allowed to undo years of work that have gone into building the Web," Berners-Lee wrote in his letter to James E. Rogan, undersecretary of commerce for intellectual property in the patent office
In a separate filing with the patent office, the W3C last week outlined examples of prior art, including two publications from a Hewlett Packard Laboratories researcher, Dave Raggett, about a proposed HTML+ specification that it says were published a year before the patent filing.
The W3C claims that the publications describe the EMBED tag in HTML+ in an identical way to the EMBED tag in the patent.…
http://www.eweek.com/article2/0,4149,1366698,00.asp
Sliding Doors of CSS, Part II: A List Apart : Sliding Doors of CSS (Part I) introduced a new technique for creating visually stunning interface elements with simple, text-based, semantic markup. In Part II, we’ll push the technique even further. If you haven’t read Part I yet, you should read it now.
Here, we’ll cover a new scenario where no tab is highlighted, combine Sliding Doors with a single-image rollover, provide a fix for the clickable region in IE/Win, and suggest an alternate method of targeting tabs. We’ll skip a basic recap of the technique (see Part I for this) in favor of jumping right back in where we left off.…
http://www.alistapart.com/articles/slidingdoors2/
Here, we’ll cover a new scenario where no tab is highlighted, combine Sliding Doors with a single-image rollover, provide a fix for the clickable region in IE/Win, and suggest an alternate method of targeting tabs. We’ll skip a basic recap of the technique (see Part I for this) in favor of jumping right back in where we left off.…
http://www.alistapart.com/articles/slidingdoors2/
: In the last month the music-downloading landscape online has shifted once more with these five major events, not all of them good:
¶Apple Computer made its iTunes player and music store available to PC users.
¶A legal version of Napster emerged.
¶A new download store called Audio Lunchbox announced that it would open on Halloween.
¶Musicmatch added an online store to its music player.
¶EMusic added restrictive rules to its music subscription service.
In a striking lack of originality, every new service above is in some way a designer imposter of iTunes, which sells songs for 99 cents each and albums for $9.99.
The war for a legitimate digital-music store began in 1995, when a New York company called Sonicnet started offering singles for download. The artists were allowed to set the prices of their songs and to keep all the money from the download. Of course, in those olden times, a download could take anywhere from five minutes to five hours, and the sound quality was described by the company itself as "better than an AM radio in a '72 Nova."
Clearly, Sonicnet's music store was more of a me-first venture than a moneymaker, but the message was clear: the Internet was a place for artists to control and directly profit from their music. But in most online services today that dream has been lost, with the services functioning as online arms of the record companies while the artists receive pennies (or fractions of pennies) for each download.
The second dream from the golden age of music downloading was summarized in a catchphrase: All you can eat. The future of the business was in allowing fans access to all the music they wanted for a monthly fee. So far, only the free unauthorized services have accomplished this, chiefly ones that are now defunct, like Napster and Audiogalaxy. The reason the authorized downloading services haven't accomplished this goal is not because the technology or will is lacking, but because full cooperation from record labels and publishers has not been forthcoming. They fear they would become obsolete.
Thus the authorized services online today are all compromises. The service perceived as the greatest success is the iTunes Music Store, originally a feature of the Macintosh computer. The service is based more on the retail model than the cable television one. Its charges of 99 cents to download a song and $9.99 to download an album are not much cheaper than buying the CD at a discount retailer. Within four days after iTunes began offering a PC version of its technology this month, one million PC users had downloaded the software, Apple reports.
With the success of the iTunes Music Store, other services are rushing to copy it. By and large, they are not succeeding, because what works about the iTunes Music Store is not necessarily its pricing system but its ease of use, its lack of restrictions on downloaded music, its design and its integration of Apple's iTunes media player and iPod portable digital music player.
Nonetheless, that hasn't stopped the competition. There's Buymusic, an online song store that has little going for it, and Musicmatch, which has integrated an Apple-like store into its music jukebox. And the newest service, Audio Lunchbox, tries to squeeze into a gap by offering music for Mac and PC users that the iTunes Music Store does not: chiefly songs from artists on independent record labels.
Perhaps the greatest competition for iTunes on the PC is the new and very legal Napster 2.0. The service combines the song-selling of iTunes (even the prices are the same) with a semblance of the community feel of the original Napster. Users willing to pay $9.99 a month for a subscription get extra features, such as being able to listen to the playlists of other members, access to message boards and a personal mailbox and the ability to download as many songs as they want onto their PC (but with a catch: they still have to buy the song if they want to take it off their home computer and put it on, say, a portable digital music player).
But iPod owners won't be flocking to Napster because its songs are encoded as Windows Media files, which are not compatible with the iPod. Samsung, however, has created a digital music player specifically designed to be used with Napster 2.0.
If it sounds as if it's a mess out there in the online retail world, it is, and ultimately only a few services will flourish.
Online Music Business, Neither Quick Nor Sure
¶Apple Computer made its iTunes player and music store available to PC users.
¶A legal version of Napster emerged.
¶A new download store called Audio Lunchbox announced that it would open on Halloween.
¶Musicmatch added an online store to its music player.
¶EMusic added restrictive rules to its music subscription service.
In a striking lack of originality, every new service above is in some way a designer imposter of iTunes, which sells songs for 99 cents each and albums for $9.99.
The war for a legitimate digital-music store began in 1995, when a New York company called Sonicnet started offering singles for download. The artists were allowed to set the prices of their songs and to keep all the money from the download. Of course, in those olden times, a download could take anywhere from five minutes to five hours, and the sound quality was described by the company itself as "better than an AM radio in a '72 Nova."
Clearly, Sonicnet's music store was more of a me-first venture than a moneymaker, but the message was clear: the Internet was a place for artists to control and directly profit from their music. But in most online services today that dream has been lost, with the services functioning as online arms of the record companies while the artists receive pennies (or fractions of pennies) for each download.
The second dream from the golden age of music downloading was summarized in a catchphrase: All you can eat. The future of the business was in allowing fans access to all the music they wanted for a monthly fee. So far, only the free unauthorized services have accomplished this, chiefly ones that are now defunct, like Napster and Audiogalaxy. The reason the authorized downloading services haven't accomplished this goal is not because the technology or will is lacking, but because full cooperation from record labels and publishers has not been forthcoming. They fear they would become obsolete.
Thus the authorized services online today are all compromises. The service perceived as the greatest success is the iTunes Music Store, originally a feature of the Macintosh computer. The service is based more on the retail model than the cable television one. Its charges of 99 cents to download a song and $9.99 to download an album are not much cheaper than buying the CD at a discount retailer. Within four days after iTunes began offering a PC version of its technology this month, one million PC users had downloaded the software, Apple reports.
With the success of the iTunes Music Store, other services are rushing to copy it. By and large, they are not succeeding, because what works about the iTunes Music Store is not necessarily its pricing system but its ease of use, its lack of restrictions on downloaded music, its design and its integration of Apple's iTunes media player and iPod portable digital music player.
Nonetheless, that hasn't stopped the competition. There's Buymusic, an online song store that has little going for it, and Musicmatch, which has integrated an Apple-like store into its music jukebox. And the newest service, Audio Lunchbox, tries to squeeze into a gap by offering music for Mac and PC users that the iTunes Music Store does not: chiefly songs from artists on independent record labels.
Perhaps the greatest competition for iTunes on the PC is the new and very legal Napster 2.0. The service combines the song-selling of iTunes (even the prices are the same) with a semblance of the community feel of the original Napster. Users willing to pay $9.99 a month for a subscription get extra features, such as being able to listen to the playlists of other members, access to message boards and a personal mailbox and the ability to download as many songs as they want onto their PC (but with a catch: they still have to buy the song if they want to take it off their home computer and put it on, say, a portable digital music player).
But iPod owners won't be flocking to Napster because its songs are encoded as Windows Media files, which are not compatible with the iPod. Samsung, however, has created a digital music player specifically designed to be used with Napster 2.0.
If it sounds as if it's a mess out there in the online retail world, it is, and ultimately only a few services will flourish.
Online Music Business, Neither Quick Nor Sure
Wednesday, October 29, 2003
The Ten Most Abused Words in Tech
This is not a Letterman-style Top Ten list. This topic deserves more serious attention than a mildly humorous rundown.…
Most of the guilt for these abuses lies squarely on marketers. These are the people whose very livelihoods depend on the ability to "create unmet needs." If that phrase doesn't make you shudder, then you're probably in marketing or PR. It's not that I consider the profession an evil one, but the need to communicate complex technologies has often forced some marketing and public relations people to come up with new and exciting ways to abuse the English language.
In response, I've compiled a list of the ten most abused words in the tech industry. This list, by the way, is in no particular order -- though I find the first two or three particularly egregious.
Experience
The most obvious misuse of this word is the way Microsoft overuses it, but they are by no means the only abuser. We hear about the "Windows experience," the "gaming experience," and, by God, the "driver installation experience." Life is full of experiences, so I'm unclear as to what's really special about the "living room experience." I experience my living room every day and no TV or computer exists in it. It's to the point now that when I hear the word "experience" used in a product pitch or presentation, I feel vaguely nauseous. Whatever's being pitched to me at that point had better be damned good to overcome my queasiness.
Seamless
I get particularly annoyed with a sentence like, "This should be a seamless experience." Even my Gore-Tex parka isn't seamless -- although I did once have a pair of hiking boots with only one seam. I know what's trying to be communicated here, but the term has become so overused that it's meaningless.…
http://www.extremetech.com/print_article/0,3998,a=110431,00.asp
This is not a Letterman-style Top Ten list. This topic deserves more serious attention than a mildly humorous rundown.…
Most of the guilt for these abuses lies squarely on marketers. These are the people whose very livelihoods depend on the ability to "create unmet needs." If that phrase doesn't make you shudder, then you're probably in marketing or PR. It's not that I consider the profession an evil one, but the need to communicate complex technologies has often forced some marketing and public relations people to come up with new and exciting ways to abuse the English language.
In response, I've compiled a list of the ten most abused words in the tech industry. This list, by the way, is in no particular order -- though I find the first two or three particularly egregious.
Experience
The most obvious misuse of this word is the way Microsoft overuses it, but they are by no means the only abuser. We hear about the "Windows experience," the "gaming experience," and, by God, the "driver installation experience." Life is full of experiences, so I'm unclear as to what's really special about the "living room experience." I experience my living room every day and no TV or computer exists in it. It's to the point now that when I hear the word "experience" used in a product pitch or presentation, I feel vaguely nauseous. Whatever's being pitched to me at that point had better be damned good to overcome my queasiness.
Seamless
I get particularly annoyed with a sentence like, "This should be a seamless experience." Even my Gore-Tex parka isn't seamless -- although I did once have a pair of hiking boots with only one seam. I know what's trying to be communicated here, but the term has become so overused that it's meaningless.…
http://www.extremetech.com/print_article/0,3998,a=110431,00.asp
Search Inside the Book
How It Works
A significant extension of our groundbreaking Look Inside the Book feature, Search Inside the Book allows you to search millions of pages to find exactly the book you want to buy. Now instead of just displaying books whose title, author, or publisher-provided keywords that match your search terms, your search results will surface titles based on every word inside the book. Using Search Inside the Book is as simple as running an Amazon.com search. For example:
1. Let's say that you're interested in finding books about "rocket experiments." Just as you do today, type "rocket experiments" into our search box and click the GO! button. You'll get a list of the books that contain that term in the author's name, the book's title, or in the book's text. Books participating in our Search Inside the Book feature with "rocket experiments" in their text will show an excerpt with your search term highlighted. To see all references to "rocket experiments" within a particular book, click the "See more references to 'rocket experiments' in this book" link.
2. This link will take you to an index page for the book you selected, where you will see excerpts from all the pages where "rocket experiments" appears. This is a great way to quickly and easily browse sections of the book that are relevant to your search. If you want to see a specific page from the book in its entirety, simply click on the link to that page.
3. At this point, one of two things will happen. If you are a registered, recognized Amazon.com customer, you will go directly to the page you selected. If you are not a recognized customer, we will ask you to sign in or create an Amazon.com account (if you're not already a customer). Once you have signed in or set up an account with us, we'll take you directly to the page you selected. Once there, you'll see that "rocket experiments" is highlighted throughout the page and that you can browse forward and back two pages. Additionally, you'll find a navigation bar above the page that allows you to search for other terms in the book and browse other pages. Of course, you can always purchase the book by adding it to your Shopping Cart or by using 1-Click ordering, and we'll deliver the book to your door.
Search Inside the Book FAQ
http://www.amazon.com/exec/obidos/tg/browse/-/10197041/102-8019720-7150504
http://www.amazon.com/exec/obidos/tg/browse/-/10197021/ref%3Dsib%5Fmerch%5Fgw/102-8019720-7150504
How It Works
A significant extension of our groundbreaking Look Inside the Book feature, Search Inside the Book allows you to search millions of pages to find exactly the book you want to buy. Now instead of just displaying books whose title, author, or publisher-provided keywords that match your search terms, your search results will surface titles based on every word inside the book. Using Search Inside the Book is as simple as running an Amazon.com search. For example:
1. Let's say that you're interested in finding books about "rocket experiments." Just as you do today, type "rocket experiments" into our search box and click the GO! button. You'll get a list of the books that contain that term in the author's name, the book's title, or in the book's text. Books participating in our Search Inside the Book feature with "rocket experiments" in their text will show an excerpt with your search term highlighted. To see all references to "rocket experiments" within a particular book, click the "See more references to 'rocket experiments' in this book" link.
2. This link will take you to an index page for the book you selected, where you will see excerpts from all the pages where "rocket experiments" appears. This is a great way to quickly and easily browse sections of the book that are relevant to your search. If you want to see a specific page from the book in its entirety, simply click on the link to that page.
3. At this point, one of two things will happen. If you are a registered, recognized Amazon.com customer, you will go directly to the page you selected. If you are not a recognized customer, we will ask you to sign in or create an Amazon.com account (if you're not already a customer). Once you have signed in or set up an account with us, we'll take you directly to the page you selected. Once there, you'll see that "rocket experiments" is highlighted throughout the page and that you can browse forward and back two pages. Additionally, you'll find a navigation bar above the page that allows you to search for other terms in the book and browse other pages. Of course, you can always purchase the book by adding it to your Shopping Cart or by using 1-Click ordering, and we'll deliver the book to your door.
Search Inside the Book FAQ
http://www.amazon.com/exec/obidos/tg/browse/-/10197041/102-8019720-7150504
http://www.amazon.com/exec/obidos/tg/browse/-/10197021/ref%3Dsib%5Fmerch%5Fgw/102-8019720-7150504
Where Is Windows Going?
The next version of Windows isn't due out until at least 2005, leaving us to wonder: Will Microsoft address the big questions users have about stability, security, and features? In this special report, we look at where Windows is heading.
Love it or hate it, Microsoft Windows is almost ubiquitous. Well over 90 percent of desktop and laptop computers run Windows. In the two years since Windows XP first shipped, it has become a tremendous commercial success.
In our reader surveys, most respondents seem happier with Win XP than with previous versions of Windows; it crashes less often and has more features. But it has its shortcomings. Although it's more stable than previous versions, it still crashes and hangs. And more important, the number of security threats against Windows is growing. Although Microsoft has responded with updates and patches, it's disheartening that they are needed weekly.
The next Windows OS, code-named Longhorn, isn't expected until 2005 at the earliest. Because the industry needs to plan ahead, outlines of the system are beginning to come out. Longhorn looks ambitious; Microsoft calls it a "big bet," the kind that it makes only every decade or so.
Among the areas Microsoft is working on are making the system more "trustworthy" and secure, adding new communications and collaboration tools, creating a new content-based storage system, making it easier for developers to create stable applications, and improving the user interface and presentation of media.
In some areas, Microsoft's plans are clear. For example, for developers, Microsoft has long promoted switching to "managed code," which should result in more stable applications.
On security, Microsoft's goal is "trustworthy computing," including a Next-Generation Secure Computing Base, which splits the OS into halves, one tied to the hardware for secure communication and authentication, one for everything else. This would allow for more secure applications and better digital rights management, but it also requires hardware and software changes.
We know Microsoft is working on a storage system called WinFS that should make finding information easier.
In the pages that follow, you'll find out more about each of these areas—and where Microsoft's competitors are going.…
http://www.pcmag.com/print_article/0,3048,a=109987,00.asp
The next version of Windows isn't due out until at least 2005, leaving us to wonder: Will Microsoft address the big questions users have about stability, security, and features? In this special report, we look at where Windows is heading.
Love it or hate it, Microsoft Windows is almost ubiquitous. Well over 90 percent of desktop and laptop computers run Windows. In the two years since Windows XP first shipped, it has become a tremendous commercial success.
In our reader surveys, most respondents seem happier with Win XP than with previous versions of Windows; it crashes less often and has more features. But it has its shortcomings. Although it's more stable than previous versions, it still crashes and hangs. And more important, the number of security threats against Windows is growing. Although Microsoft has responded with updates and patches, it's disheartening that they are needed weekly.
The next Windows OS, code-named Longhorn, isn't expected until 2005 at the earliest. Because the industry needs to plan ahead, outlines of the system are beginning to come out. Longhorn looks ambitious; Microsoft calls it a "big bet," the kind that it makes only every decade or so.
Among the areas Microsoft is working on are making the system more "trustworthy" and secure, adding new communications and collaboration tools, creating a new content-based storage system, making it easier for developers to create stable applications, and improving the user interface and presentation of media.
In some areas, Microsoft's plans are clear. For example, for developers, Microsoft has long promoted switching to "managed code," which should result in more stable applications.
On security, Microsoft's goal is "trustworthy computing," including a Next-Generation Secure Computing Base, which splits the OS into halves, one tied to the hardware for secure communication and authentication, one for everything else. This would allow for more secure applications and better digital rights management, but it also requires hardware and software changes.
We know Microsoft is working on a storage system called WinFS that should make finding information easier.
In the pages that follow, you'll find out more about each of these areas—and where Microsoft's competitors are going.…
http://www.pcmag.com/print_article/0,3048,a=109987,00.asp
Ever wonder how a certain company sending unsolicited e-mail messages got your address?
Michael Rathbun, the director of policy enforcement at Allegiance Telecom, an Internet service provider in Dallas, says he thinks he has much of the answer.
Some five years ago, Mr. Rathbun bought a Palm hand-held organizer and, in registering it on Palm's Web site, gave the company an e-mail address he never used for anything else. Initially his in-box received only offers for products related to the organizer, but eventually he started getting advertising from some well-known companies like Bank of America, SBC Communications and Sprint. Lately, that one address alone has been receiving dozens of e-mails a month offering everything from travel clubs to acne remedies.
"This is not stuff," Mr. Rathbun said, "that I should be getting from them."
The problem of spam or unwanted commercial e-mail is usually attributed to outlaws and hucksters — peddlers of pornography, get-rich-quick schemes and pills of dubious merit — who use hackers to send their fraudulent messages in ways that cannot be traced.
But the torrent of spam that is flowing into people's electronic mailboxes comes not only from the sewers but also from the office towers of the biggest and most well-known corporations.
Established companies insist they send e-mail only to people who have voluntarily agreed to receive marketing offers. A spokeswoman for Palm says it does not know how Mr. Rathbun's e-mail address got into the hands of spammers and says it has never sold its customer list.
But often companies rent e-mail lists from a cottage industry that has emerged to lure Internet users, through a variety of schemes, into signing up for e-mail marketing.
At best, if you have ever entered a contest to win a prize, subscribed to an online newsletter or simply purchased a product on the Web, you may well have also agreed, as many such fine-print contracts put it, "to receive valuable offers from our marketing partners."
This practice falls under the rubric of what is called opt-in marketing, or getting permission to send advertising messages.
But many e-mail executives admit that these same list companies also add to their databases by buying, trading — sometimes even stealing — names.
"Everyone is looking for a quick buck now, and people are claiming to sell opt-in data who don't have it," said Pesach Lattin, who runs Adspyre, a New York e-mail marketing firm.
Moreover, some companies have allowed the e-mail addresses of their own customers, either deliberately or inadvertently, to fall into the hands of list peddlers who in turn sell them to e-mail marketers of all stripes. Sometimes, the lists are stolen from corporate owners by employees or vendors looking to make a quick profit. But in many cases, the big companies are deliberately buying and selling access to names, relying on privacy policies — often hard to find on their sites — that they say permit such actions.
"White-collar spam" is how Nick Usborne, a newsletter writer and Internet marketing consultant, refers to this phenomenon.
"When a responsible company," Mr. Usborne said, "gets someone to sign up for a newsletter and says, now that we have their e-mail address let's make more money off it and send them e-mail they didn't ask for, that's white-collar spam."
The antispam bill passed unanimously by the Senate last week imposes tough penalties on people involved in the lowest forms of spam but it does not deal with the central questions Mr. Usborne and others raise about white-collar spam. It does nothing, for example, to establish rules defining an appropriate list of names that a purveyor of a legitimate product can use to send an offer by e-mail. Nor does it regulate the transfer of names between companies.
The law would require that every e-mail message offer recipients a method to remove themselves from an advertiser's mailing list. But with the way that names are traded today, this method would do little to reduce the amount of e-mail people receive, industry executives say.
"People don't realize that once you sign up for a contest or free stuff on the Web and you forget to uncheck a box, these people will pass your name to a hundred other people,'` said Paul Nute, a partner of Soho Digital, a New York advertising agency that represents e-mail marketers. "You've just raised your hand and said, `Send me the diet pill offers.' And there is no way to get them all to stop."
http://www.nytimes.com/2003/10/28/technology/28SPAM.html?pagewanted=all&position=
Michael Rathbun, the director of policy enforcement at Allegiance Telecom, an Internet service provider in Dallas, says he thinks he has much of the answer.
Some five years ago, Mr. Rathbun bought a Palm hand-held organizer and, in registering it on Palm's Web site, gave the company an e-mail address he never used for anything else. Initially his in-box received only offers for products related to the organizer, but eventually he started getting advertising from some well-known companies like Bank of America, SBC Communications and Sprint. Lately, that one address alone has been receiving dozens of e-mails a month offering everything from travel clubs to acne remedies.
"This is not stuff," Mr. Rathbun said, "that I should be getting from them."
The problem of spam or unwanted commercial e-mail is usually attributed to outlaws and hucksters — peddlers of pornography, get-rich-quick schemes and pills of dubious merit — who use hackers to send their fraudulent messages in ways that cannot be traced.
But the torrent of spam that is flowing into people's electronic mailboxes comes not only from the sewers but also from the office towers of the biggest and most well-known corporations.
Established companies insist they send e-mail only to people who have voluntarily agreed to receive marketing offers. A spokeswoman for Palm says it does not know how Mr. Rathbun's e-mail address got into the hands of spammers and says it has never sold its customer list.
But often companies rent e-mail lists from a cottage industry that has emerged to lure Internet users, through a variety of schemes, into signing up for e-mail marketing.
At best, if you have ever entered a contest to win a prize, subscribed to an online newsletter or simply purchased a product on the Web, you may well have also agreed, as many such fine-print contracts put it, "to receive valuable offers from our marketing partners."
This practice falls under the rubric of what is called opt-in marketing, or getting permission to send advertising messages.
But many e-mail executives admit that these same list companies also add to their databases by buying, trading — sometimes even stealing — names.
"Everyone is looking for a quick buck now, and people are claiming to sell opt-in data who don't have it," said Pesach Lattin, who runs Adspyre, a New York e-mail marketing firm.
Moreover, some companies have allowed the e-mail addresses of their own customers, either deliberately or inadvertently, to fall into the hands of list peddlers who in turn sell them to e-mail marketers of all stripes. Sometimes, the lists are stolen from corporate owners by employees or vendors looking to make a quick profit. But in many cases, the big companies are deliberately buying and selling access to names, relying on privacy policies — often hard to find on their sites — that they say permit such actions.
"White-collar spam" is how Nick Usborne, a newsletter writer and Internet marketing consultant, refers to this phenomenon.
"When a responsible company," Mr. Usborne said, "gets someone to sign up for a newsletter and says, now that we have their e-mail address let's make more money off it and send them e-mail they didn't ask for, that's white-collar spam."
The antispam bill passed unanimously by the Senate last week imposes tough penalties on people involved in the lowest forms of spam but it does not deal with the central questions Mr. Usborne and others raise about white-collar spam. It does nothing, for example, to establish rules defining an appropriate list of names that a purveyor of a legitimate product can use to send an offer by e-mail. Nor does it regulate the transfer of names between companies.
The law would require that every e-mail message offer recipients a method to remove themselves from an advertiser's mailing list. But with the way that names are traded today, this method would do little to reduce the amount of e-mail people receive, industry executives say.
"People don't realize that once you sign up for a contest or free stuff on the Web and you forget to uncheck a box, these people will pass your name to a hundred other people,'` said Paul Nute, a partner of Soho Digital, a New York advertising agency that represents e-mail marketers. "You've just raised your hand and said, `Send me the diet pill offers.' And there is no way to get them all to stop."
http://www.nytimes.com/2003/10/28/technology/28SPAM.html?pagewanted=all&position=
Changing the product key on Windows XP
For most Windows XP installs, you’ll never need to worry about the validity of the product key assigned to your copy of the OS. However, software does tend to get installed without authorization, even in the most carefully managed shops, and so from time to time you may need to reset the XP product key.
For example, perhaps a user installed a pirated copy of XP but now wants to go legal. Maybe you've been hired by an organization that installed 100 pirated copies of XP but now has a legitimate volume-licensing key (VLK). Perhaps an end user purchased an additional retail license for XP but needs to use his original CD to install the software. When situations like these arise, changing XP's product key is often the most practical—or only—solution.
Determining if you have a valid product ID
Hopefully you already know if you're dealing with a pirated copy of XP. But if you're unsure, a quick way to tell is to install Service Pack 1. Shortly after releasing Windows XP, Microsoft realized that most pirated XP installations were using two specific VLKs, the most popular of which begins with "FCKGW.” These VLKs produce product IDs that match either XXXXX-640-0000356-23XXX or XXXXX-640-2001765-23XXX, where X is any number.
If you try to install SP1 and get the following error message:
The Product Key used to install Windows is invalid. Please contact your system administrator or retailer immediately to obtain a valid Product Key…"
You are dealing with a pirated copy of Windows. For more information about obtaining a valid product key, see Microsoft Knowledge Base article 326904.
You can also directly check the OS’sproduct ID by right-clicking on My Computer, clicking Properties, and selecting the General tab. The machine's product ID will be located under the Registered To section. If the ID matches either of the two models commonly associated with VLK fraud, you’ll need to obtain a valid XP product key before proceeding. None of the procedures described below will work without a legitimate product key.…
How to Change the Product ID in Windows XP
HOW TO: Change the Volume Licensing Product Key on a Windows XP SP1-Based Computer
http://support.microsoft.com/default.aspx?scid=kb;EN-US;326904
http://support.microsoft.com/default.aspx?scid=kb;en-us;321636
http://support.microsoft.com/default.aspx?scid=kb;en-us;328874
http://techrepublic.com.com/5100-6270-5034890.html?fromtm=e103
For most Windows XP installs, you’ll never need to worry about the validity of the product key assigned to your copy of the OS. However, software does tend to get installed without authorization, even in the most carefully managed shops, and so from time to time you may need to reset the XP product key.
For example, perhaps a user installed a pirated copy of XP but now wants to go legal. Maybe you've been hired by an organization that installed 100 pirated copies of XP but now has a legitimate volume-licensing key (VLK). Perhaps an end user purchased an additional retail license for XP but needs to use his original CD to install the software. When situations like these arise, changing XP's product key is often the most practical—or only—solution.
Determining if you have a valid product ID
Hopefully you already know if you're dealing with a pirated copy of XP. But if you're unsure, a quick way to tell is to install Service Pack 1. Shortly after releasing Windows XP, Microsoft realized that most pirated XP installations were using two specific VLKs, the most popular of which begins with "FCKGW.” These VLKs produce product IDs that match either XXXXX-640-0000356-23XXX or XXXXX-640-2001765-23XXX, where X is any number.
If you try to install SP1 and get the following error message:
The Product Key used to install Windows is invalid. Please contact your system administrator or retailer immediately to obtain a valid Product Key…"
You are dealing with a pirated copy of Windows. For more information about obtaining a valid product key, see Microsoft Knowledge Base article 326904.
You can also directly check the OS’sproduct ID by right-clicking on My Computer, clicking Properties, and selecting the General tab. The machine's product ID will be located under the Registered To section. If the ID matches either of the two models commonly associated with VLK fraud, you’ll need to obtain a valid XP product key before proceeding. None of the procedures described below will work without a legitimate product key.…
How to Change the Product ID in Windows XP
HOW TO: Change the Volume Licensing Product Key on a Windows XP SP1-Based Computer
http://support.microsoft.com/default.aspx?scid=kb;EN-US;326904
http://support.microsoft.com/default.aspx?scid=kb;en-us;321636
http://support.microsoft.com/default.aspx?scid=kb;en-us;328874
http://techrepublic.com.com/5100-6270-5034890.html?fromtm=e103
WinXPnews™ E-Zine
Tue, Oct 28, 2003 (Vol. 3, 43 - Issue 99)
Does Tech Jargon Cause Confusion?
This issue of WinXPnews™ contains:
EDITOR'S CORNER
Speaking the Language: Does Tech Jargon Cause Confusion?
Followup: Office 2003
HINTS, TIPS, TRICKS & TWEAKS
lder Settings: Another Fix
What to do if HAL is missing
Another Alternative Browser
What is thumbs.db?
Better Movie Playing with Older Media Player
HOW TO'S: ALL THE NEW XP FEATURES
How to Clear the Page file at Shutdown
How to Remove the NetMeeting Remote Desktop Sharing icon from the tray
How to make file names appear on the left when you use the DIR command
How to Keep your Internet connection open when switching users
WINXP SECURITY: UPDATES & PATCHES
New Security Bulletin Warns of Flaw in Windows Messenger
WINXP QUESTION CORNER
How to Format the Hard Disk on an XP Machine
AutoComplete Stopped Working
WINXP CONFIGURING & TROUBLESHOOTING
Can't Install XP Pro to a Separate Folder After Installing XP Home?
Compatibility Mode Setting is Ignored
"Memory Could Not be Read" Error
http://www.winxpnews.com/
Tue, Oct 28, 2003 (Vol. 3, 43 - Issue 99)
Does Tech Jargon Cause Confusion?
This issue of WinXPnews™ contains:
EDITOR'S CORNER
Speaking the Language: Does Tech Jargon Cause Confusion?
Followup: Office 2003
HINTS, TIPS, TRICKS & TWEAKS
lder Settings: Another Fix
What to do if HAL is missing
Another Alternative Browser
What is thumbs.db?
Better Movie Playing with Older Media Player
HOW TO'S: ALL THE NEW XP FEATURES
How to Clear the Page file at Shutdown
How to Remove the NetMeeting Remote Desktop Sharing icon from the tray
How to make file names appear on the left when you use the DIR command
How to Keep your Internet connection open when switching users
WINXP SECURITY: UPDATES & PATCHES
New Security Bulletin Warns of Flaw in Windows Messenger
WINXP QUESTION CORNER
How to Format the Hard Disk on an XP Machine
AutoComplete Stopped Working
WINXP CONFIGURING & TROUBLESHOOTING
Can't Install XP Pro to a Separate Folder After Installing XP Home?
Compatibility Mode Setting is Ignored
"Memory Could Not be Read" Error
http://www.winxpnews.com/
Tuesday, October 28, 2003
Microsoft Security Bulletin MS03-043
Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
Affected Software:
Microsoft Windows NT Workstation 4.0, Service Pack 6a -
Microsoft Windows NT Server 4.0, Service Pack 6a -
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6 -
Microsoft Windows 2000, Service Pack 2 -
Microsoft Windows 2000, Service Pack 3, Service Pack 4 -
Microsoft Windows XP Gold, Service Pack 1 -
Microsoft Windows XP 64-bit Edition -
Microsoft Windows XP 64-bit Edition Version 2003 -
Microsoft Windows Server 2003 -
Microsoft Windows Server 2003 64-bit Edition -
Non Affected Software:
Microsoft Windows Millennium Edition
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-043.asp
Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
Affected Software:
Microsoft Windows NT Workstation 4.0, Service Pack 6a -
Microsoft Windows NT Server 4.0, Service Pack 6a -
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6 -
Microsoft Windows 2000, Service Pack 2 -
Microsoft Windows 2000, Service Pack 3, Service Pack 4 -
Microsoft Windows XP Gold, Service Pack 1 -
Microsoft Windows XP 64-bit Edition -
Microsoft Windows XP 64-bit Edition Version 2003 -
Microsoft Windows Server 2003 -
Microsoft Windows Server 2003 64-bit Edition -
Non Affected Software:
Microsoft Windows Millennium Edition
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-043.asp
Build cross-browser XML paging code
If scrolling through a long XML table is not an optimal experience for
your browser app, why not implement pagination? Presenting data in
page-length chunks can help your users find the data they need. See how
to build
fast, cross-browser XML pagination.
From Builder.com Bulletin
http://builder.com.com/5100-6371-5085227.html?tag=sc&fromtm=e601
If scrolling through a long XML table is not an optimal experience for
your browser app, why not implement pagination? Presenting data in
page-length chunks can help your users find the data they need. See how
to build
fast, cross-browser XML pagination.
From Builder.com Bulletin
http://builder.com.com/5100-6371-5085227.html?tag=sc&fromtm=e601
Comment Spam
We've all seen that comment spam is becoming a serious problem. Particularly on Movable Type weblogs, where the generated pages are all very similar in structure and semantics, spammers are abusing comment systems to increase their rank on Google.
Even more frustrating than the spamming problem is the fact that there isn't a simple solution that will work for everyone and that all options have their own sets of pros and cons. During the past couple of months, we've been throwing around ideas at Six Apart about the best ways to combat spammers.
Readers of your weblog must register before posting to your weblog.
Before someone can post a comment to your weblog, they must register with your site.
For many webloggers, this solution is not ideal. Informal polling of webloggers has revealed that many do not want to require someone to register before posting. It usually discourages conversations from forming and is a barrier for open discussion. Additionally, without federation, logins on multiple weblogs become unmanageable.
While we do plan on integrating comment registration into Movable Type Pro (which we'll be talking about in more detail very soon), it's an option that serves a different purpose than just blocking spam. If you want to prevent links to explicit pornography from appearing on your site, you shouldn't have to be required to turn on comment registration.
Comments require approval before being posted
When a comment is posted, you can receive an email that provides a clickable link you must visit before the comment can be posted on your site.
For webloggers with a small amount of readers, this solution may be ideal. However, if you receive a good deal of comments, it's a solution that doesn't scale. Additionally, it may ruin the spontaneity of discussion.
Image comprehension technology
Before a comment can be posted on a weblog, human eyes must enter a code that, ideally, is not readable by a computer.
This solution is not feasible because of accessibility issues. Additionally, spammers seem to be searching with bots and entering spam manually.…
http://www.sixapart.com/log/2003/10/comment_spam.shtml
We've all seen that comment spam is becoming a serious problem. Particularly on Movable Type weblogs, where the generated pages are all very similar in structure and semantics, spammers are abusing comment systems to increase their rank on Google.
Even more frustrating than the spamming problem is the fact that there isn't a simple solution that will work for everyone and that all options have their own sets of pros and cons. During the past couple of months, we've been throwing around ideas at Six Apart about the best ways to combat spammers.
Readers of your weblog must register before posting to your weblog.
Before someone can post a comment to your weblog, they must register with your site.
For many webloggers, this solution is not ideal. Informal polling of webloggers has revealed that many do not want to require someone to register before posting. It usually discourages conversations from forming and is a barrier for open discussion. Additionally, without federation, logins on multiple weblogs become unmanageable.
While we do plan on integrating comment registration into Movable Type Pro (which we'll be talking about in more detail very soon), it's an option that serves a different purpose than just blocking spam. If you want to prevent links to explicit pornography from appearing on your site, you shouldn't have to be required to turn on comment registration.
Comments require approval before being posted
When a comment is posted, you can receive an email that provides a clickable link you must visit before the comment can be posted on your site.
For webloggers with a small amount of readers, this solution may be ideal. However, if you receive a good deal of comments, it's a solution that doesn't scale. Additionally, it may ruin the spontaneity of discussion.
Image comprehension technology
Before a comment can be posted on a weblog, human eyes must enter a code that, ideally, is not readable by a computer.
This solution is not feasible because of accessibility issues. Additionally, spammers seem to be searching with bots and entering spam manually.…
http://www.sixapart.com/log/2003/10/comment_spam.shtml
How spammers are targeting blogs
Technology analyst Bill Thompson has been getting lots of comments on his weblogs, unfortunately most of the want to sell him Viagra. He has been "flyblogged".
Earlier this week I got an e-mail to tell me that someone called Levitra had commented on one of my entries on the VoxPolitics weblog.
Since it's a group weblog for "e-democracy titbits and crumbs", we get quite a few comments from random readers, and often they are useful and informative, so I read it with interest.
Sadly, it was not about the latest e-voting disasters in California - a topic of great interest to me - but a rather obvious piece of spam.
It said; "Interesting comments and a Superb Web Site" and then, like so many spam e-mails, had a link to a site that wanted to sell me a Viagra alternative.
Over the next few days I got 20 more, most offering Viagra substitutes but one featuring a cable TV scam - presumably for the times when I would have used up all my Viagra supplies.
Every one of them was posted as a comment on the blog, and they could only be removed individually through the administrative pages of the site, which takes ages.
It felt like the digital equivalent of flyposting - coming home one day to find your windows covered with posters for dodgy clubs and bands you have never head of.…
http://news.bbc.co.uk/2/hi/technology/3210623.stm
Technology analyst Bill Thompson has been getting lots of comments on his weblogs, unfortunately most of the want to sell him Viagra. He has been "flyblogged".
Earlier this week I got an e-mail to tell me that someone called Levitra had commented on one of my entries on the VoxPolitics weblog.
Since it's a group weblog for "e-democracy titbits and crumbs", we get quite a few comments from random readers, and often they are useful and informative, so I read it with interest.
Sadly, it was not about the latest e-voting disasters in California - a topic of great interest to me - but a rather obvious piece of spam.
It said; "Interesting comments and a Superb Web Site" and then, like so many spam e-mails, had a link to a site that wanted to sell me a Viagra alternative.
Over the next few days I got 20 more, most offering Viagra substitutes but one featuring a cable TV scam - presumably for the times when I would have used up all my Viagra supplies.
Every one of them was posted as a comment on the blog, and they could only be removed individually through the administrative pages of the site, which takes ages.
It felt like the digital equivalent of flyposting - coming home one day to find your windows covered with posters for dodgy clubs and bands you have never head of.…
http://news.bbc.co.uk/2/hi/technology/3210623.stm
Generating Thumbnails on the Fly Using ASP.NET!
If you've ever attempted to create image thumbnails for your site, you'll know it's a tiresome task. You either do it manually, or use an inflexible system such as the FrontPage thumbnail feature.
However, as you've seen in previous tips, ASP.NET gives us tremendous control over how our images work. As such, we should be able to generate thumbnails on the fly... and this snippet will enable you to do just that.
http://www.developer.com/net/asp/article.php/3098311
If you've ever attempted to create image thumbnails for your site, you'll know it's a tiresome task. You either do it manually, or use an inflexible system such as the FrontPage thumbnail feature.
However, as you've seen in previous tips, ASP.NET gives us tremendous control over how our images work. As such, we should be able to generate thumbnails on the fly... and this snippet will enable you to do just that.
http://www.developer.com/net/asp/article.php/3098311
Syndicated Photography Feeds
Pheed.com is a database of information about photographs available on the web. We present the work of photographers who have made information about their images available as an RSS feed. RSS is a simple document format based on XML that is used to syndicate web-based content. A pheed is simply an rss feed that has been extended to include information about photographs; a photo feed. The links to the left will show you how to create an rss pheed and include information about your photographs in our database.
http://www.pheed.com/
Pheed.com is a database of information about photographs available on the web. We present the work of photographers who have made information about their images available as an RSS feed. RSS is a simple document format based on XML that is used to syndicate web-based content. A pheed is simply an rss feed that has been extended to include information about photographs; a photo feed. The links to the left will show you how to create an rss pheed and include information about your photographs in our database.
http://www.pheed.com/
Effective XML: 50 Specific Ways to Improve Your XML
Item 3, Stay with XML 1.0
This book excerpt is from Elliotte Rusty Harold's "Effective XML: 50 Specific Ways to Improve Your XML;" ISBN 0321150406. All rights reserved. Item 3, Stay with XML 1.0 is posted with permission from Addison-Wesley.
http://www.webreference.com/programming/xml/
Item 3, Stay with XML 1.0
This book excerpt is from Elliotte Rusty Harold's "Effective XML: 50 Specific Ways to Improve Your XML;" ISBN 0321150406. All rights reserved. Item 3, Stay with XML 1.0 is posted with permission from Addison-Wesley.
http://www.webreference.com/programming/xml/
Sunday, October 26, 2003
Columns & Editorials from the ACM
Association for Computing Machinery
Founded in 1947, ACM is a major force in advancing the skills of information technology professionals and students worldwide. Today, our 75,000 members and the public turn to ACM for the industry's leading Portal to Computing Literature, authoritative publications and pioneering conferences, providing leadership for the 21st century.
http://www.acm.org/~hlb/col-edit/
Association for Computing Machinery
Founded in 1947, ACM is a major force in advancing the skills of information technology professionals and students worldwide. Today, our 75,000 members and the public turn to ACM for the industry's leading Portal to Computing Literature, authoritative publications and pioneering conferences, providing leadership for the 21st century.
http://www.acm.org/~hlb/col-edit/
The Basics of Color Systems and Color Management
If you talk to a printing professional they will most likely tell you that they have been doing color management their entire life! They will say that they have been getting customer correct color off their printing presses and they've been getting this off their scanners and they've been proofing it and the press operator has been doing color management for his or her entire career.
How are they accomplishing this? They've been chasing color.
If you talk to a designer, they will most likely tell you that they send their files to the printer. What does the printer do with these files? They rework them to translate the color that the designer has created into the capabilities of their printing facility. And that's how the designer has managed color.
What has that done with color? It's made color magic.…
http://www.eworld.com/colorsync/benefits/training/index.html
If you talk to a printing professional they will most likely tell you that they have been doing color management their entire life! They will say that they have been getting customer correct color off their printing presses and they've been getting this off their scanners and they've been proofing it and the press operator has been doing color management for his or her entire career.
How are they accomplishing this? They've been chasing color.
If you talk to a designer, they will most likely tell you that they send their files to the printer. What does the printer do with these files? They rework them to translate the color that the designer has created into the capabilities of their printing facility. And that's how the designer has managed color.
What has that done with color? It's made color magic.…
http://www.eworld.com/colorsync/benefits/training/index.html
Introduction to Cryptography
People mean different things when they talk about cryptography. Children play with toy ciphers and secret languages. However, these have nothing to do with real security and strong encryption. Strong encryption is the kind of encryption that can be used to protect information of real value against organized criminals, multinational corporations, and major governments. Strong encryption used to be only military business; however, in the information society it has become one of the central tools for maintaining privacy and confidentiality.
As we move into an information society, the technological means for global surveillance of millions of individual people are becoming available to major govenments. Cryptography has become one of the main tools for privacy, trust, access control, electronic payments, corporate security, and countless other fields.
Cryptography is no longer a military thing that should not be messed with. It is time to demystify cryptography and make full use of the advantages it provides for the modern society. In the following, basic terminology and the main methods of cryptography are presented. Any opinions and evaluations presented here are speculative, and the author cannot be held responsible for their correctness.
http://www.networksolution.com/understanding/introduction.htm
People mean different things when they talk about cryptography. Children play with toy ciphers and secret languages. However, these have nothing to do with real security and strong encryption. Strong encryption is the kind of encryption that can be used to protect information of real value against organized criminals, multinational corporations, and major governments. Strong encryption used to be only military business; however, in the information society it has become one of the central tools for maintaining privacy and confidentiality.
As we move into an information society, the technological means for global surveillance of millions of individual people are becoming available to major govenments. Cryptography has become one of the main tools for privacy, trust, access control, electronic payments, corporate security, and countless other fields.
Cryptography is no longer a military thing that should not be messed with. It is time to demystify cryptography and make full use of the advantages it provides for the modern society. In the following, basic terminology and the main methods of cryptography are presented. Any opinions and evaluations presented here are speculative, and the author cannot be held responsible for their correctness.
http://www.networksolution.com/understanding/introduction.htm
Friday, October 24, 2003
Accessing Dreamweaver's JavaScript API
Macromedia's Dreamweaver is one of the most popular visual HTML editing tools. And for good reason -- it's powerful, accessible, and it generates pretty good code. During Dreamweaver's evolution, Macromedia has added some interesting new features -- most notable for our purposes is the enhanced JavaScript functionality.
Not only the application is scriptable, it (almost) supports the DOM Level 1 spec and defines its own JavaScript-API with more than 400 different functions. It's also possible to customize the menus and incorporate new commands into it.
http://www.oreillynet.com/lpt/a/902
Macromedia's Dreamweaver is one of the most popular visual HTML editing tools. And for good reason -- it's powerful, accessible, and it generates pretty good code. During Dreamweaver's evolution, Macromedia has added some interesting new features -- most notable for our purposes is the enhanced JavaScript functionality.
Not only the application is scriptable, it (almost) supports the DOM Level 1 spec and defines its own JavaScript-API with more than 400 different functions. It's also possible to customize the menus and incorporate new commands into it.
http://www.oreillynet.com/lpt/a/902
Son of MSBlast on the way?
A program that exploits a software vulnerability Microsoft recently described could spell trouble for companies that haven't quickly patched their system, security experts said this week.
Released on a security mailing list earlier this week, the program takes advantage of a flaw in Microsoft's Messenger Service to cause Windows-based computers to crash. The vulnerability affects almost every current Microsoft Windows system, leaving security experts concerned that independent hackers will quickly find a way to take control of a large number of computers by exploiting the flaw.
"I think we are going to see a repeat of the (MSBlast worm)," said Vincent Weafer, senior director of Symantec's antivirus research center, referring to the program that spread across the Internet in August. The program used a similarly widespread Windows flaw to break through computers' security. "It took three weeks (for hackers) to figure out a working worm in that case."
http://zdnet.com.com/2100-1105_2-5095935.html?tag=adnews
A program that exploits a software vulnerability Microsoft recently described could spell trouble for companies that haven't quickly patched their system, security experts said this week.
Released on a security mailing list earlier this week, the program takes advantage of a flaw in Microsoft's Messenger Service to cause Windows-based computers to crash. The vulnerability affects almost every current Microsoft Windows system, leaving security experts concerned that independent hackers will quickly find a way to take control of a large number of computers by exploiting the flaw.
"I think we are going to see a repeat of the (MSBlast worm)," said Vincent Weafer, senior director of Symantec's antivirus research center, referring to the program that spread across the Internet in August. The program used a similarly widespread Windows flaw to break through computers' security. "It took three weeks (for hackers) to figure out a working worm in that case."
http://zdnet.com.com/2100-1105_2-5095935.html?tag=adnews
It's time to re-examine the security hurdles facing businesses every day--worms, viruses, wireless worries, identity theft, the list goes on. How secure are your systems? Are you ready for what might be around the corner?
Last month, we gathered a panel of experts from around the country to tackle the latest security challenges while our live audience provided the pulse of the IT community by answering real-time poll questions. Now, you can be part of the Webcast--watch, learn and take the polls to see how your answers compare. In Digital Defense Test 2003 you'll see three scenarios based on real security breaches, and you'll see how the experts would solve the crises and prevent future problems.
http://zdnet.com.com/html/z/tu/1003/ddt2003.html
Last month, we gathered a panel of experts from around the country to tackle the latest security challenges while our live audience provided the pulse of the IT community by answering real-time poll questions. Now, you can be part of the Webcast--watch, learn and take the polls to see how your answers compare. In Digital Defense Test 2003 you'll see three scenarios based on real security breaches, and you'll see how the experts would solve the crises and prevent future problems.
http://zdnet.com.com/html/z/tu/1003/ddt2003.html
Wednesday, October 22, 2003
Flont
Need a font forecast? Enter your words, choose a size and click 'preview'. Need a headline for comping? Just drag the Flont image to your desktop.
from Veer
http://www.veer.com/flont/
Need a font forecast? Enter your words, choose a size and click 'preview'. Need a headline for comping? Just drag the Flont image to your desktop.
from Veer
http://www.veer.com/flont/
Tuesday, October 21, 2003
The Visual Basic .NET Resource Kit
The Visual Basic .NET Resource Kit is an essential resource for any Visual Basic .NET developer.
http://msdn.microsoft.com/vbasic/vbrkit/
The Visual Basic .NET Resource Kit is an essential resource for any Visual Basic .NET developer.
http://msdn.microsoft.com/vbasic/vbrkit/
Sunday, October 19, 2003
SVG Mobile Competition
Entries due 3 November 2003
Announcing the first official SVG Mobile Competition. Nokia have provided a 3650 tri-band GSM handset as a prize for the best SVG Mobile greeting card. What do we mean by greeting card? It's really up to you! It could be a birthday card, a funny cartoon story, a demonstration of the power of SVG - whatever you want. We're intentionally leaving it open in order to give you as much freedom as possible. Here is your chance to be known as the first SVG champion.…
This is the first in a series of SVG competitions …running over the next few months. Each competition will have a slightly different theme. There is a collection of prizes from different industry sponsors to give away, so watch this space!
http://www.w3.org/Graphics/SVG/Competition
Entries due 3 November 2003
Announcing the first official SVG Mobile Competition. Nokia have provided a 3650 tri-band GSM handset as a prize for the best SVG Mobile greeting card. What do we mean by greeting card? It's really up to you! It could be a birthday card, a funny cartoon story, a demonstration of the power of SVG - whatever you want. We're intentionally leaving it open in order to give you as much freedom as possible. Here is your chance to be known as the first SVG champion.…
This is the first in a series of SVG competitions …running over the next few months. Each competition will have a slightly different theme. There is a collection of prizes from different industry sponsors to give away, so watch this space!
http://www.w3.org/Graphics/SVG/Competition
Subscribe to:
Posts (Atom)
