Wednesday, December 10, 2003

News: Developers take Linux attacks to heart:
"During the last four months, unknown intruders have breached the security around servers hosting programs and code published by the Linux kernel development team, the Debian Project, the Gentoo Linux Project and the GNU Project, which manages the development of many important programs used by Linux and other Unix-like systems. The attacks have convinced open-source project leaders to take another look at their security. "

"It is a definite eyebrow raiser that there has been this targeting of open-source servers and core open-source development servers," said Corey Shields, a member of the infrastructure team that overseas the distribution system for Gentoo Linux's code. "The worry is that if someone wanted to be malicious, they could change core software and users could be using corrupted packages."

Although the open-source model has led to immense progress in developing a competing operating system to Microsoft's Windows--long a target of hackers--it now seems to be a magnet for attackers itself. In a sort of backhanded compliment, attackers are aiming at the Linux OS and other open-source applications because of the software's popularity. Even developers who believe they've adequately secured their development systems are looking at the trend with some trepidation.

"It is one of those things where you have to hope you are not next and try to be one step ahead of the bad guys," said Jeremy Allison, co-founder and developer of the Samba Project, the programming effort for the popular open-source file server that seamlessly fits into Windows networks.

On Dec. 1, an attack on Gentoo Linux compromised one of 105 volunteer-run servers that make copies of Gentoo's source code available to users. The attack, however, didn't threaten the main source-code database. Moreover, security software on the targeted server detected the attack quickly and kept a detailed record of it.

The incident followed a November attack on the Linux kernel, which similarly happened because another system--this time a developer's--had been breached and used as a stepping-stone. The attacker used the developer's machine to submit code to a secondary server, code that could have been used by a later attacker to gain access to any systems that installed it. That attack also was detected within 24 hours.

Other incidents in the rash of attacks have been more serious.

Intruders gained access to the GNU Project's development system, Savannah, and in a separate incident, to four Debian Project servers used to manage development and community efforts for that Linux distribution.

Both attacks were similarly executed: An attacker managed to garner a legitimate user's log-in name and password and then used a recently discovered vulnerability in the Linux kernel to gain the rights and privileges of the system's owners. Both Debian and GNU Project leaders continue to keep the systems offline--and inaccessible to developers--until they can ensure they're secure.

The GNU Project said the latest attack, and another one that compromised the project's file transfer servers last March, had prompted its leadership to make changes.…

http://zdnet.com.com/2100-1105_2-5117271.html
EasyRGB - Color harmonies, complements and themes.:
"Search for colors complements to your RGB values.

Create color harmonies, combinations and themes.

From your main (or background) color select trim and accents tones."

http://www.easyrgb.com/harmonies.php

Tuesday, December 09, 2003

CSS Design: Creating Custom Corners & Borders: A List Apart:

We’ve all heard the rap:



“Sites designed with CSS tend to be boxy and hard-edged. Where are the rounded corners?”



Answer: the rounded corners are right here. In this article, we’ll show how customized borders and corners can be applied to fully fluid and flexible layouts with dynamic
content, using sound and semantically logical markup.



http://www.alistapart.com/articles/customcorners/
News: U.N. confab to see tussle over Net control:
"Leaders from nearly 200 countries will convene in Geneva for the World Summit on the Information Society (WSIS) on Dec. 10-12, an inaugural conference with lofty goals to discuss bridging the digital divide and fostering press freedoms.

But a contentious political move to grant an international governing body such as the U.N.'s International Telecommunication Union (ITU) control over Internet governance issues--from distributing Web site domains to the public to fighting spam--has all but obscured the more virtuous aspects of the event. "

…the Internet has become a thriving global marketplace since being fully turned over to the private business community in the early 1990s.

But many in the developing world believe a new approach is needed as the medium enters its teen years, one that will see poorer countries harness new technologies to improve their competitive stance.

The most recognizable Internet governance body is a California-based nonprofit company, the International Corporation for Assigned Names and Numbers (ICANN). Under the new plan, it has the most to lose. Incorporated in 1998, ICANN oversees management of the Internet's crucial addressing system which matches numerical addresses to familiar Web site addresses such as www.google.com.

While ICANN's oversight has been confined to the decidedly technical matters behind doling out domain names and establishing a system for resolving domain name disputes, the group has been criticized roundly for adopting a probusiness approach that neglects the developing world.

The ITU, a 138-year-old trade body that among other things established country code rules for international telephone dialing, has been put forth by the developing world as the governing body that will best address its needs.…

So far, a change in leadership has been bogged down by fractious discussion with a definitive resolution not expected until 2005 when the second WSIS summit is held in Tunisia.

But many believe the new guard has already arrived.…

http://zdnet.com.com/2100-1104_2-5113744.html?tag=adnews
Fighting Phishing:
"Phishing, e-mail and Web-based efforts by online scammers to hijack personal information from unsuspecting users, faces a new obstacle. A group of global banks and technology companies have joined forces to fight the scams. The group is running a Web site, Anti-Phishing.Org (www.antiphishing.org), where those who have received phishing messages can report them, and personnel will follow up by trying to track down the originators of the scams."

http://www.pcmag.com/article2/0,4149,1407031,00.asp
Could The Bad Guys Win on Spam?: http://eletters.eweek.com/zd1/cts?d=79-356-2-3-13145-42538-1
"Spam and mail-based attacks are coming to dominate Internet e-mail. Nothing seems able to stop them, and some days it's rare to find real mail among the spam. Could it come to the point that it's not worth dealing with e-mail's problems?"

On some days, life in the security business is more depressing than on others. My recent reading about Mimail.L, the latest in a long line of sociopathic worms, tipped me into the blues.

Mimail.L is particularly vile. Here are some of the actions it takes:

  • It arrives as a pornographic e-mail with an attached ZIP file purporting to contain dirty pictures. That file contains a file with a .jpg.exe extension, so if someone runs it to see the picture they actually infect themselves. As always, this subterfuge works far more often than I'd like to think, but so far it's just a run of the mill worm.

  • It scours the hard disk for e-mail addresses and stores them in a file named xu298da.tmp in the Windows folder. It then mails itself out with the same porno message to these addresses.

  • If there's a problem sending that mail, it instead tries to send a different message without the attachment. This fallback message says that the recipient's credit card has been charged for a purchase of child pornography. It directs the reader, if they want to cancel, to contact security@europe.spamhaus.org.

  • The message also lists more than a half a dozen sites as places you can get more kiddy porn, including Disney.go.com, Spamcop.net and Spews.org, and attempts to perform a denial of service attack on these sites..

So, not only is this a particularly offensive worm, but it specifically attacks anti-spam sites! Do the authors of the worm have a particular problem with these groups? Perhaps, or maybe it's just more anti-social behavior. They also attack Register.com, but I doubt they're opposed to domain name registration on principal

After reading about this I'm tempted to agree with a poster on a Slashdot thread on Mimail.L: "They won't stop 'til they've destroyed e-mail." We keep hearing about the ever-increasing percentage of Internet e-mail that is composed of spam. The latest consensus I hear is "over 50 percent," but you can bet your last "F_R_E_E whatever" that the number will continue to climb.…

http://www.eweek.com/article2/0,4149,1403354,00.asp?kc=EWNWS120903DTX1K0000599
News: Worm hits Windows-based ATMs:
"An unknown number of ATMs running Windows XP Embedded were shut down during the spread of the so-called Nachi worm, said executives at Diebold, which made the ATMs and refused to name the customers affected.

The Nachi worm, also dubbed 'Welchia,' was written to clean up after the MSBlast, or Blaster, worm. Instead it crippled or congested networks around the world, including the check-in system at Air Canada. Both worms spread through a hole in Windows XP, 2000, NT and Server 2003. "

"It's a harbinger of things to come," said Bruce Schneier, chief technical officer of network monitoring company Counterpane Internet Security.

"Specific-purpose machines, like microwave ovens and until now ATM machines, never got viruses," said Schneier, author of "Beyond Fear: Thinking Sensibly About Security in an Uncertain World." "Now that they are using a general purpose operating system, Diebold should expect a lot more of this in the future," he said.

John Pescatore, an analyst at Gartner, agreed.

"It's a horrendous security mistake," he said of specific-purpose machines like ATMs running Windows, which is written for general-purpose computers and for which Microsoft releases security fixes on a regular basis. "I'm a lot more worried about my money than I was before this."

Diebold switched from using IBM's OS/2 on its ATMs because banks were requesting Windows, said Steve Grzymkowski, senior product marketing manager at Diebold.

To help prevent future problems Diebold is shipping ATMs with firewall software designed to block out viruses and other attacks, he said.

"As far as it happening again, I wouldn't want to speculate on that," Grzymkowski said.

Schneier and Pescatore said they were worried about the security of other Windows-based Diebold appliances--voting machines, which run Windows CE.…

http://zdnet.com.com/2100-1105_2-5117285.html
Welcome to TechBuilder.org:
"Secure wireless networking can be a reality, but only if you employ some very straightforward techniques."

http://www.techbuilder.org./article.htm?ArticleID=46364

Monday, December 08, 2003

Op-Ed Contributor: A Million Miles From the Green Zone to the Front Lines:
"The other day I told General Petraeus about a young specialist fourth class I had met while waiting for a military flight out of Baghdad. The specialist was a college student from Iowa whose National Guard unit had been called up for the war. He had told me about a prolonged firefight that took place the week before, outside Camp Anaconda on the outskirts of the city of Balad, 40 miles from Baghdad.

'We began taking small arms fire about 8 a.m., from Abu Shakur, the village just north of the base camp's gate,' the specialist told me. 'Our guys responded with small arms and then mortars. Someone on patrol outside the wire got wounded, and they sent Bradley Fighting Vehicles out, and they hit the Bradleys pretty hard, and by 10 a.m., they were firing 155-millimeter howitzers, and attack helicopters were firing missiles into the village, and you could see tracers and smoke everywhere.

'I had just gotten off a night shift, and I was sitting outside my tent about 100 meters from the gate in my pajamas reading a book. Right near me, guys were doing laundry and standing in line for chow. I was sitting there thinking: `Have we had wars like this before? Shouldn't we drop everything and help? I mean, we were spectators! What kind of war is this, sir?' '"

General Petraeus, who graduated from West Point in 1974, just in time to witness the ignominious end to the war in Vietnam, didn't say anything. But slowly, and it seemed, unconsciously, his head began to nod, and his mind seemed far, far away. It seemed clear he knew the answer: yes, specialist, we have had wars like this before.

Commanding generals have had lavishly appointed offices before, as well. My grandfather, Gen. Lucian K. Truscott Jr., occupied the Borghese Palace when his VI Corps swept into Rome in 1943. His aide kept a record of the meals prepared for him by his three Chinese cooks, while every day dozens — and on some days, hundreds — of his soldiers perished on the front lines at Anzio, only a few miles away from his villa on the beach.

So there may be nothing new about this war and the way we are fighting it — with troops on day and night patrols from base camps being hit by a nameless, faceless enemy they cannot see and whose language they do not speak. However, the disconnect between the marbled hallways of the Coalition Provisional Authority palaces in Baghdad and the grubby camp in central Mosul where I spent last week as a guest of Bravo Company, First Battalion, 502nd Infantry Regiment, is profound, and perhaps unprecedented.

An colonel in Baghdad (who will go nameless here for obvious reasons) told me just after I arrived that senior Army officers feel every order they receive is delivered with next November's election in mind, so there is little doubt at and near the top about who is really being used for what over here. The resentment in the ranks toward the civilian leadership in Baghdad and back in Washington is palpable. Another officer described the two camps, military and civilian, inhabiting the heavily fortified, gold-leafed presidential palace inside the so-called Green Zone in Baghdad, as "a divorced couple who won't leave the house."

Meanwhile in Mosul, the troops of Bravo Company bunker down amid smells of diesel fuel and burning trash and rotting vegetables and dishwater and human waste from open sewers running though the maze of stone and mud alleyways in the Old City across the street. Bravo Company's area of operations would be an assault on the senses even without the nightly rattle of AK-47 fire in the nearby streets, and the two rocket-propelled grenade rounds fired at the soldiers a couple of weeks ago.

It is difficult enough for the 120 or so men of Bravo Company to patrol their overcrowded sector of this city of maybe two million people and keep its streets safe and free of crime. But from the first day they arrived in Mosul, Bravo Company and the rest of the 101st Airborne Division were saddled with dozens of other missions, all of them distinctly nonmilitary, and most of them made necessary by the failure of civilian leaders in Washington and Baghdad to prepare for the occupation of Iraq.

The 101st entered Mosul on April 22 to find the city's businesses, civil ministries and utilities looted and its people rioting in the streets. By May 5, the soldiers had supervised elections for mayor and city council. On May 11, they oversaw the signing of harvest accords and the division of wheat profits among the region's frequently warring factions of Arabs, Kurds, Turkmen and Assyrians. On May 14, a company commander of Alpha Company, Third Battalion, 187th Infantry Regiment of the 101st re-opened the Syrian border for trade, and by May 18, soldiers had largely restored the flow of automobile gas and cooking propane, shortages of which had been causing riots.

Since that time, soldiers from the 101st have overseen tens of millions of dollars worth of reconstruction projects: drilling wells for villages that had never had their own water supply; rebuilding playgrounds and schools; repairing outdated and broken electrical systems; installing satellite equipment needed to get the regional phone system up and running; restoring the city's water works; repairing sewers and in some cases installing sewage systems in neighborhoods that had never had them; policing, cleaning and reorganizing the ancient marketplace in the Old City; setting up a de facto social security system to provide "retirement" pay to the 110,000 former Iraqi soldiers in the area; screening and, in most cases, putting back to work most of the former Baath Party members who fled their jobs at the beginning of the war.

So many civil projects were reported on at a recent battle update briefing I attended that staff officers sometimes sounded more like board members of a multinational corporation than the combat-hardened infantry soldiers they are.…The Coalition Provisional Authority nominally has the job of "rebuilding" Iraq — using $20 billion or so of the $78 billion that recently flew out of America's deficit-plagued coffers. But during the time the 101st has been in Mosul, three regional coalition authority directors have come and gone. Only recently, long after the people of Mosul elected their mayor and city council, was a civilian American governance official sent to the area. And, according to the division leadership, not a nickel of the $20 billion controlled by the provisional authority has reached them.

"First they want a planning contractor to come in here, and even that step takes weeks to get approved," one officer in Mosul complained of the civilian leadership. "The planners were up here for months doing assessments, and then more weeks go by because everything has to be approved by Baghdad. If we sat around waiting for the C.P.A. and its civilian contractors to do it, we still wouldn't have electricity and running water in Mosul, so we just took our own funds and our engineers and infantry muscle and did it ourselves. We didn't have the option of waiting on the guys in the Green Zone."

But the guys in the Green Zone seem to have plenty of time on their hands. The place is something to behold, surrounded on one side by the heavily patrolled Tigris River, and on the three others by a 15-foot-high concrete wall backed by several rows of concertina razor wire and a maze of lesser concrete barriers. There's only one way in and out, through a heavily fortified checkpoint near the Jumhiriya Bridge guarded by tanks and Bradley Fighting Vehicles from the First Armored Division and an invisible array of British commando teams. More tanks guard key intersections inside the walls, machine gun towers line the wide boulevards, snipers man firing positions atop palaces great and small.

In all, hundreds of uniformed soldiers and heavily armed civilian security guards stand watch all day, every day over a display of grim garishness that would have given Liberace nightmares. If you're curious about how your tax dollars are being spent in Baghdad, you should get one of the many colonels strolling about the Green Zone to take you on a tour of the rebuilt duck pond across the road from the marble and gold-leafed palace serving as headquarters of an Army brigade. As I went to sleep one night a couple of weeks ago in the Green Zone, listening to the gurgle of the duck pond fountain and the comforting roar of Black Hawk helicopters patrolling overhead, it occurred to me that it was the safest night I've spent in about 25 years.

Which was a blessing for me, but a curse on the war effort. The super-defended Green Zone is the biggest, most secure American base camp in Iraq, but there is little connection between the troops in the field and the bottomless pit of planners and deciders who live inside the palace. Soldiers from the 101st tell me that they waited months for the Bechtel Corporation to unleash its corporate might in northern Iraq. "Then one of the Bechtel truck convoys got ambushed on the way up here three weeks ago, and one of the security guys got wounded," an infantryman told me. "They abandoned their trucks on the spot and pulled out, and we haven't seen them since."

"It's really not helpful when people down in Baghdad and politicians back in Washington refer to the `disorganized and ineffective' enemy we supposedly face," said one young officer, as we walked out of a battalion battle briefing that had been concerned largely with the tactics of an enemy force that is clearly well organized and very, very effective. After spending more than a week with the soldiers of Bravo Company, I know that they resent not only the inaccuracy of such statements, but the implication that soldiers facing a disorganized and ineffective enemy have an easy job.

No matter what you call this stage of the conflict in Iraq — the soldiers call it a guerrilla war while politicians back home often refer to it misleadingly and inaccurately as part of the amorphous "war on terror" — it is without a doubt a nasty, deadly war. And the people doing the fighting are soldiers, not the civilian employees of Kellogg, Brown & Root, or the officials of the Coalition Provisional Authority, or the visiting bigwigs from the Defense Department.

The troops in Bravo Company don't pay much attention to the rear-guard political wars being waged back in Washington, but they loved President Bush's quick visit to Baghdad on Thanksgiving. While it was clearly a political stunt, they were quick to credit the risks he took. I can confirm that flying in and out of Baghdad — even at night, when it's safest — is not for the faint of heart. A C-130 on approach takes a nervous, dodgy route, banking this way and that, gaining and losing altitude. Hanging onto one of those web-seats by only a seat belt (no shoulder harnesses), you're nearly upside down half the time — it would feel like the ultimate roller-coaster ride, except it's very much for real.

When Bravo Company troops roll out of the rack at 2 a.m. for street patrols, they walk the broad boulevards and narrow alleyways spread out as if they're walking a jungle trail — wheeling to the rear, sideways, back to the front; their eyes searching doorways, alleys, windows, rooftops, passing cars, even donkey carts — trying to keep one another alive for another day, another week, another month, whatever it takes to get home.

Meanwhile, two soldiers armed with M-4 carbines and fearsome M-249 Saws machine guns stand guard inside concrete and sandbag bunkers atop the Bravo Company camp's roof, while squads of soldiers patrol alleys with no names in Mosul's Old City, and everyone prays.

http://www.nytimes.com/2003/12/07/opinion/07TRUS.html?pagewanted=all&position=
IE 6.0 - QuirksMode - for all your browser quirks:
"QuirksMode.org is the personal and professional site of Peter-Paul Koch, freelance web developer in Amsterdam, the Netherlands. It contains more than 150 pages with CSS and JavaScript tips and tricks, and is one of the best sources on the WWW for studying and defeating browser incompatibilities.
It is free of charge and ads, and largely free of copyrights."


This site is quite large. The table of contents mostly leads to other tables of contents.

http://www.quirksmode.org/

Friday, December 05, 2003

Warning: Look Out for the eBay Scam:
"The trick message arrived with a very official looking header featuring eBay's logo. It was signed 'Thank you, Accounts Management.' The text read: 'Dear eBay Member, We at eBay are sorry to inform you that we are having problems with the billing information of your account. We would appreciate it if you would visit our website, eBay Billing Center, and fill out the proper information that we are needing to keep you as an eBay member.' The 'eBay Billing Center' referenced was a link to a Web page asking for a credit card number, a social security number, and more. The message also contained an 'ebay.com' suffix, just as a real message from an eBay employee might."

As is often true in spoof messages and phishing efforts, the trick e-mail contained telltale signs that it did not come from eBay. The subject line of the message read "eBay Member Billing Information Uptade" with the word "update" misspelled. The text string "fill out the proper information that we are needing" also had suspicious syntax.…

http://www.pcmag.com/article2/0,4149,1402431,00.asp
News: Antispammers again targeted by worm:
"Antispam organizations are the target of a new Internet worm outbreak that tries to knock them offline with a crippling data barrage, computer security experts said Tuesday.

Virus experts believe the worm, W32/Mimail-L, is the work of a vengeful spam e-mail peddler bent on paralyzing organizations that try to deal with spam, the torrents of get-rich-quick schemes and body-enhancement deals that clog in-boxes daily.

'It's the third Mimail variation to come after us, except this one is trying to do more,' said Steve Linford, founder of The Spamhaus Project, a British-based group that singles out spammers. Spamhaus was hit by Mimail late Monday. "

According to anti-virus and spam-filtering company Sophos Plc, the Mimail-L program comes as an attachment to an e-mail purporting to be from a woman named Wendy who details an erotic encounter and then offers naked photographs.

Clicking on the attachment activates the virus. Once triggered, the worm forwards itself to other e-mail users.


The worm can also turn the affected PC into a "zombie," which can then be remotely commanded to bombard one of a select group of targets, such as Spamhaus, with a disabling blizzard of data--a so-called denial-of-service attack.


In a new twist, a follow-up e-mail is sent to the infected user stating that an order for a CD containing images of child pornography will be delivered to their postal address.


To stop the order, the e-mail advises, they should respond to what appears to be an e-mail address for billing complaints, but which is actually an e-mail for one of the eight targets.…

http://zdnet.com.com/2100-1105_2-5112997.html

Wednesday, December 03, 2003

'Critical' IE Security Warning Released:
"A Chinese security researcher has warned of five serious vulnerabilities in Microsoft's (Quote, Chart) Internet Explorer browser, warning that a successful exploit could lead to system takeover.

Liu Die Yu released details of the flaws on the Bugtraq mailing list and issued a warning that the vulnerabilities could lead to system access, exposure of sensitive information, cross site scripting and security bypass.

Yu also released proof-of-concept exploits on the popular mailing list, noting that the flaws affect Internet Explorer versions 5.0, 5.5 and 6.0."

Independent security consultant Secunia has rated the flaws 'Extremely Critical' and urged IE users to disable Active Scripting as a workaround until Microsoft issues a fix.

The flaws related to a redirection feature in the browser using the "mhtml:" URI handler. The researcher warned that it could be exploited to bypass a security check in Internet Explorer which normally blocks web pages in the "Internet" zone from parsing local files.

Yu said the redirection feature could also be exploited to download and execute a malicious file on a user's system. Successful exploitation requires that script code can be executed in the "MyComputer" zone, he explained.

The security alert also included a cross-site scripting vulnerability that could allow a malicious attacker to execute script code in the security zone associated with another Web page if it contains a subframe.

A variant of a previously fixed flaw can still be exploited to hijack a user's clicks and perform certain actions without the user's knowledge, the researcher explained.

Microsoft late Wednesday confirmed it was investigating Lu's warnings. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," said Stephen Toulouse, Security Program Manager, Microsoft Security Response Center.

Toulouse told internetnews.com Microsoft would take the "appropriate action to protect our customers" and hinted that a fix could come via an out-of-cycle patch, depending on the seriousness of its findings.

He said Microsoft was concerned that Lu's warnings were not disclosed responsibly, potentially putting computer users at risk. "We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality patches for security vulnerabilities with no exposure to malicious attackers while the patch is being developed," Toulouse declared.

In the interim, Toulouse is recommending that IE users install the cumulative patch issued earlier this month (MS03-048).…

http://www.internetnews.com/dev-news/print.php/3114171

Tuesday, December 02, 2003

Webmasters Wary of Latest Google Tweaks:
"Some sites have fallen from high rankings to the nether reaches, while others have gained better slots. While such shifts are nothing new, this time around some observers say it appears that Google is trying to penalize sites using the most aggressive search-engine-optimization techniques with keywords and links to rank well on Google results. "

The problem is that along with these abusers of search engine optimization, many more innocent sites have fallen as well, said Barry Lloyd, CEO of Clogher, Ireland-based search-engine marketing company Microchannel Technologies Ltd.

"It's gone from a Google love fest to some of the most vitriolic attacks I've ever heard," he said of the reaction to the latest tweaks. "My genuine belief is that there's been too much collateral damage. A lot of people not deliberately gaming the system have been affected."

Google, as a matter of policy, does not discuss changes to its search engine algorithm. A spokesman said that the Mountain View, Calif., regularly tweaks its algorithms to improve the relevancy of search results.

"This is why it is common to see movement in the ranking of sites on Google search results pages," he said.

It remains to be seen to what extent the common user of Google has noticed the shifting positions of sites in search results. Search-engine marketers and optimizers readily admit that they watch the results with hawk eyes, noticing the slightest shifts in rank.

To Danny Sullivan, editor of SearchEngineWatch.com, the current spat of debate filling Webmaster and search-engine message boards is part of the regular cycle of complaints that follows a Google change. Quantifying whether the latest shifting is producing better or worse results is difficult since the results vary depending on the search query.

"If your job is to optimize a site for a particular term, then you know intimately what site comes up for that term," Sullivan said. "For a typical Google user, they probably won't notice anything."

Along with link tricks, some sites and search-engine optimizers have created doorway pages. The pages are designed specifically for search engine spiders indexing Web pages and are optimized to match coveted keywords. They are often invisible to actual users or appear as a quick introductory page that leads into the main site.

"(Google) had to come up with a way of overcoming the gaming of their algorithm because it was becoming so corrupted," Lloyd said.

In the course of combating techniques what Google and others consider search-engine spam, Google's algorithm changes also appear to have caught other sites in the crosshairs, Lloyd said. The changes appear to be affecting the rank of commercial-oriented search terms the most, ones where over-optimization is often common, and to be hurting sites that use a given keyword term frequently in the site or in the domain, Lloyd said.

At the same time, Lloyd and others have noticed that the results for some search terms seem more focused on directory listings or non-commercial sites rather than commercial sites. On one example, Lloyd tried searching for "Web design Calgary," expecting to find Web design companies in Calgary, Canada. Instead the first result was the site for the Calgary Flames hockey team.

More than anything, the most recent brouhaha over Google algorithm changes points to the danger of relying too heavily on search-result positioning for one's business, experts say.…

http://www.eweek.com/print_article/0,3048,a=113607,00.asp
News: Flaw in Linux kernel allows attack:
"The Debian Project warned on Monday that a flaw in the Linux kernel helped attackers compromise four of the open-source software project's development servers.

During several intrusions Nov. 19, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.

Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released Friday, eight days after the Debian breach."

The unknown attacker compromised at least four servers. The systems--known as Master, Murphy, Gluck and Klecker--had maintained the open-source project's bug tracking system, source code database, mailing lists, Web site and security patches.

The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published Friday. When the programmer logged into the klecker system, the attacker recorded his password.

Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw--in a part of the kernel that manages memory--allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.

The attacks have been the latest leveled at open-source software. In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open-source projects.

http://zdnet.com.com/2100-1104_2-5112427.html
Economy & Business: I.R.S. Set to Resolve Disputes Online:
"The I.R.S. is testing a system called Electronic Account Resolution with a handful of tax professionals. Lawyers, accountants and enrolled agents - a kind of preparer who is authorized to represent taxpayers before the I.R.S. - will be able to use the system; they can go online now to register. But individuals and other paid preparers will not have access.

James Leimbach, an enrolled agent in Panama City, Fla., who is one of the testers, is enthusiastic. 'Through a simple three-step process,' Mr. Leimbach said, 'I will be able to electronically access my client's tax records and then resolve problems.'

Under the present nonelectronic system, tax professionals must show the agency a power of attorney from the taxpayer before the I.R.S. will talk to them. While I.R.S. clerks will sometimes accept a faxed form, getting approval to represent a client can take days."

With the new system, a taxpayer fills out the power of attorney form and gives it to the tax adviser. Then the adviser logs on to an I.R.S. computer, using a secure Internet connection, punching in the client's adjusted gross income from any of the three previous years, the year of the return and the taxpayer's birth date. The taxpayer also gives a self-selected personal identification number.

"You get disclosure authorization almost instantly," Mr. Leimbach said. Immediately, a request can be made for the taxpayer's records, known as a transcript.

"Typically, getting a transcript took 5 to 10 days when ordered through the mail," he said. "With the new system, I will be able to pull transcripts up electronically."

Such speedy gathering of information and problem resolution - in contrast to hours or days of work - should hold down the fees taxpayers pay their advisers.

At first, the system can be used to resolve simple problems, like tracing payments, tracking refunds and entering into installment agreements to pay taxes.

The agency has not begun to work on more complex problems, like proposals to settle a tax debt for less than the full amount…

http://www.nytimes.com/2003/12/01/business/01taxx.html
News: Sobig lingers despite shutdown date:
"Sobig is still rampaging around the Internet, two months after the virus was supposed to have terminated itself. "

E-mail security firm MessageLabs said Friday that Sobig was the third most active virus in November, with some 264,000 copies being detected by its e-mail virus-scanning servers.

Although this activity is well below the virus's peak, it is still surprising as Sobig--like several other members of the Sobig family--contained a built-in shutdown date that was supposed to prevent it propagating after Sept. 10. Sobig.F's continued proliferation is due to a combination of factors, including the successful efforts that prevented it wreaking even more havoc and the fact that many PCs are set to the wrong date, according to MessageLabs.

http://zdnet.com.com/2100-1104_2-5112207.html
Score one for the spammers: CAN SPAM bill to become law - TechUpdate - ZDNet:
"For the umpteenth time: Anti-spam laws are a bad idea as long as they're written by those out of touch with the underpinnings of Internet e-mail. For example, writing into law anything that ventures down the path of 'opting out' (short-hand for 'optioning out,' deselecting, or unsubscribing yourself from membership in a mailing list) --- which CAN SPAM does --- creates a virtually unenforceable law since there are a million and one reasons (most of which would not be due to negligence on behalf of mailing list operators) that an opt-out mechanism may not work at some given point in time. Before opt-out language can be included in a law, there needs to exist an opt-out standard under the guise of what I call a relationship termination protocol over which dissimilar email clients and servers can interoperate. "

Perhaps you think I'm on the lunatic fringe, an ultraconservative who refuses to see the good in legislation that clearly has the welfare of the spam-afflicted in mind? OK ignore me. But don't ignore the following warning, reported in a recent CNET News.com story about the CAN SPAM bill, that was sent from the National Association of Attorneys General to Congress: "The bill creates so many loopholes, exceptions, and high standards of proof, that it provides minimal consumer protections and creates too many burdens for effective enforcement...We respectfully request that you not move forward."

Lack of enforceability has been my main point all along and it's refreshing to see the very folks chartered with upholding the CAN SPAM bill saying to Congress "Hey, you're all off your rockers if you move forward with this law." Still not convinced? Assuming that the law's effectiveness is dependent on the fact that all evil spammers fall within its jurisdiction (a very bad assumption considering the mounting tide of spam from China and South Korea), then you, as a concerned Netizen, should consider its definition of spam. To the relief of e-mail marketers everywhere, spam will not be the first unsolicited commercial email you get from someone you consider to be a spammer. It's one of the subsequent ones. That's right. It's the second, third, fourth, or later one and it is only such if, after receiving the first one, you issued an objection according to a method the sender, not you, says you are permitted to do so (the vaulted "opt-out" for which no standard method exists and no auditable test for proven functionality has been created).

Are you getting ill yet?

Despite the fact that the Attorneys General will be reluctant to expend the resources necessary to prosecute given the loopholes it envisions, Senators Burns and Wyden cited the financial implications in their declarations of victory. Sen. Ron Wyden, D-Ore., said that "when this bill takes effect, the big-time spammers who up until now have faced virtually no penalties will suddenly be at risk of criminal prosecution, (Federal Trade Commission) prosecution and million-dollar lawsuits." Sen. Conrad Burns, R-Mont., said: "In cases where e-mail marketers don't comply with the CAN-SPAM bill, the penalties are very severe...Spammers are actually on the hook for (per e-mail) damages, with a cap of $2 million."

Newsflash. The big time spammers --- at least the ones who are intentionally sidestepping all sense of Internet decorum in order to invade the sanctity of your inbox --- have about a hundred dollars in their checking accounts--collectively. It was only about six months ago, at the now infamous Federal Trade Commission three-day workshop on spam, that we heard from several Attorneys General and Internet Service Providers about how their investments in certain investigations, indictments, prosecutions, and lawsuits were disproportionate to the final outcome: one or two bad apples (out of an ocean-sized apple orchard) with little or no money to their names shut down. My inbox didn't notice. Did yours? Despite efforts to publicly draw, quarter, flog, and hang the offenders, the rest of the orchard didn't appear to flinch. It may have yawned, though. We'll never know. They're a secretive bunch. It's not like they have offices on Madison Avenue.

http://techupdate.zdnet.com/techupdate/stories/main/Score_one_for_the_spammers.html

Friday, November 28, 2003

Beware the Worm in Your Handset:
"As more consumers begin surfing the Web and sending e-mail messages on cellphone and hand-held devices, along comes a new worry: worms and viruses spread via Internet-enabled handsets."

The problem is still small, with only a few cases reported globally. But as operating systems in cellphones become standardized, hackers will probably begin focusing on vulnerabilities in those systems as they have with personal computers. And as cellphones and personal digital assistants connect to the Internet at ever faster speeds, more users will be able to download files with attachments - some of which may be infected.

Asia, where high-speed networks and text messaging on mobile phones are common, is the most vulnerable to these threats. As carriers in Europe and North America adopt similar technology, they will confront the same kinds of hazards.

Telecommunications companies currently spend as much as $8 billion a year fixing handsets with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business.

"The danger to mobile phone networks is probably five times bigger than with personal computers because very few people are focused on this problem now," said Andrew Cole, senior vice president at Adventis, a Boston-based consultant specializing in telecommunications issues. "The dominant form of messaging is going to be cell-to-cell, so this could escalate very rapidly and overload phone networks. What if viruses phone 911 randomly?"

That, in fact, is what happened in Japan in 2000 and 2001. NTT DoCoMo, the country's largest cellular phone provider, received complaints from customers who were being sent messages that froze their screens and automatically dialed 110, the emergency line to the police in Japan.…

That event was a shock because the company is spending billions of dollars introducing its high-speed third-generation, or 3G, network that allows users to download data up to 40 times faster than conventional mobile phone networks. A rash of viruses might turn off users to the new network before it was released. Eventually, DoCoMo dealt with the problem by installing special security software on its servers and new handsets, which were also being bombarded with unwanted commercial e-mail and text messages from advertisers, dating clubs and other marketers. DoCoMo blocks about 55 percent of the one billion text messages that reach its servers each day because of suspicious return addresses or attachments. Another 26 percent of those messages are blocked by DoCoMo users who have programmed their handsets to turn back unwanted mail or spam.

http://www.nytimes.com/2003/11/28/technology/28cell.html

Wednesday, November 26, 2003

News: The computer virus--no cures to be found:
"Of all the accomplishments in the annals of technology, Fred Cohen's contribution is undeniably unique: He introduced the term 'virus' to the lexicon of computers."
"The design of the Internet facilitates the distribution of information--all sorts of information; it's a double-edged sword," Gordon said in a recent e-mail interview. "Even if (viruses) are not designed to be intentionally malicious or dangerous, if they get outside of a controlled environment, there can be unexpected results."


The University of New Haven professor used the phrase in a 1984 research paper, in which he described threats self-propagating programs pose and explored potential defenses against them. When he asked for funding from the National Science Foundation three years later to further explore countermeasures, the agency rebuffed him.

"They turned it down," said Cohen, who is also principal analyst for research firm Burton Group. "They said it wasn't of current interest."

Two decades later, countless companies and individuals are still paying for that mistake. The technology industry has yet to find a blanket solution to the ever-growing list of viruses and worms that constitute the greatest risk to computers on the Internet. Every year, companies lose billions of dollars when forced to halt work and deal with infectious digital diseases, such as Sobig and Slammer.

While much attention has been paid to the malicious online attackers who exploit technology's vulnerabilities, little has been documented about the origins of the virus. Its early iterations were not created by malcontent teenagers or antisocial geeks but by campus researchers, system administrators and a handful of old-school hackers who thought that the ability to reproduce their programs automatically was a neat trick.


http://zdnet.com.com/2100-1105_2-5111442.html
Domain Theft is Still a Little Too Easy:
"Do you ever get spam offering to sell you fake IDs? Here's one reason why some people want to buy one: a fake ID, a fax machine, and an absence of morals are all that's needed to hijack any domain name. "

Yes, stealing a domain name from its rightful owners still appears to be child's play. A reader contacted me about his case involving the domain name DVDMovies.com. Several weeks ago Arnold Jones of Visionario Inc., a storage consulting firm and owner of dvdmovies.com, discovered that this domain had been transferred to someone else.

This person had sent in to Network Solutions, the registrar holding the registry of dvdmovies.com, a request by fax to change the e-mail contacts on the registration to a free yahoo.com address. Even though his identification information had been forged, including a copy of a fake Florida drivers license with Jones's work address on it, Network Solutions happily obliged and did not scrutinize the license.

Once the e-mail contact had been changed, the domain pirate simply sent a request to reset the password on the account, and he replied from the new address. Now that he had control over the account, he could transfer the registration to another registrar.

However, according to Jones' account, there were many other glaring red flags that should have alerted Network Solutions to a possible hijacking:

The fax requesting the e-mail change came from area code 530, in California, but all registrant information was for Florida.
The key administrative contact e-mail address was changed to a free, untraceable yahoo.com address.
The fake Florida drivers license lacked all the major characteristics of a legitimate Florida drivers license.

Jones required two weeks of time and effort before he got his domain back. If he was less sophisticated about these matters, it might have taken him much longer to take control of the domain. To compensate him for the two weeks of time and the lack of his domain, Network Solutions extended his registration by a year, a $35 value. Gosh, I hope he declares this on his taxes.…

http://www.eweek.com/article2/0,4149,1384450,00.asp
Creating Interactive Video With MPEG4:
"MPEG4 is finally starting to gain some traction. The allure of platform and vendor independence and ubiquitous players on all kinds of devices is strong. But in many areas, MPEG4 is still a 'bleeding-edge' technology. You'll quickly feel the pain when you try to do any but the most basic audio/video delivery using it. Today, all the major streaming players support MPEG4, mostly through the EnvivioTV plugin. And Apple's Quicktime lets you convert all kinds of movies to MPEG4 using the best-$30-you-ever-spent-on-software Quicktime Pro. But to really unlock the promise of MPEG4 – universal and reliable authoring and playback of complex interactive multimedia – you still have to go out on the edge."

Profiles and Compatibility
MPEG4 is designed to be useful for video playback across a wide variety of devices, from cell phones to powerful desktop computers; from pocket sized handhelds to TV set top boxes. To support this flexibility, the spec is divided into different profiles and levels, each defining a subset of MPEG4's total feature set. An MPEG player will support a particular profile by implementing all of that profile's features. IBM's SamplesForMPEG4 (also available at alphaWorks) includes dozens of examples of varied XMT and MPEG4 features. Many of these play in the QT and Real players, while others do not. (Of course, they all play in IBM's M4Play, part of the Toolkit.)

http://www.streamingmedia.com/article.asp?id=8544

Tuesday, November 25, 2003

washingtonpost.com: On the Web, Research Work Proves Ephemeral:
"It was in the mundane course of getting a scientific paper published that physician Robert Dellavalle came to the unsettling realization that the world was dissolving before his eyes.

The world, that is, of footnotes, references and Web pages."


Dellavalle, a dermatologist with the Veterans Affairs Medical Center in Denver, had co-written a research report featuring dozens of footnotes -- many of which referred not to books or journal articles but, as is increasingly the case these days, to Web sites that he and his colleagues had used to substantiate their findings.

Problem was, it took about two years for the article to wind its way to publication. And by that time, many of the sites they had cited had moved to other locations on the Internet or disappeared altogether, rendering useless all those Web addresses -- also known as uniform resource locators (URLs) -- they had provided in their footnotes.

"Every time we checked, some were gone and others had moved," said Dellavalle, who is on the faculty at the University of Colorado Health Sciences Center. "We thought, 'This is an interesting phenomenon itself. We should look at this.' "

He and his co-workers have done just that, and what they have found is not reassuring to those who value having a permanent record of scientific progress. In research described in the journal Science last month, the team looked at footnotes from scientific articles in three major journals -- the New England Journal of Medicine, Science and Nature -- at three months, 15 months and 27 months after publication. The prevalence of inactive Internet references grew during those intervals from 3.8 percent to 10 percent to 13 percent.

"I think of it like the library burning in Alexandria," Dellavalle said, referring to the 48 B.C. sacking of the ancient world's greatest repository of knowledge. "We've had all these hundreds of years of stuff available by interlibrary loan, but now things just a few years old are disappearing right under our noses really quickly."


http://www.washingtonpost.com/ac2/wp-dyn/A8730-2003Nov23
Debian: Attack Didn't Harm Source Code:
But Open Source is Safer?

"Despite a cracker incursion into Debian Project servers this week, representatives of the Debian Linux distribution said the open-source code behind it remains untouched."

This is not the first time an open-source site has been attacked by crackers. In March of this year, the Free Software Foundation Inc.'s GNU Project ftp servers were attacked. This assault, which caused no damage to the code, was only discovered months afterwards.

In the Debian case, though, the break-in was discovered within 24 hours. The cracker had gained access to four machines: "master," the bug-tracking system; "murphy," the mailing-list manager; "gluck," the Web server and Concurrent Versions System (CVS) system; and "klecker," which houses security, quality assurance and search-engine code. Martin Schulze, a Debian spokesman, reported that the Debian source code archives themselves were "not affected by this compromise."

"This kind of attack is inevitable in open source," Murdoch said. "We've increased security. At the beginning of Debian, becoming a developer was as easy as sending me an e-mail, but these days there are checks and balances in place to make sure that only real developers get in and that the code stays clean."

http://www.eweek.com/article2/0,4149,1394420,00.asp?kc=EWNWS112403DTX1K0000599

Monday, November 24, 2003

Take note of critical Office 2003 update and MiMail worm - TechRepublic:
"Fix
Symantec has posted a free tool for removing MiMail variants A through E, which will:

End the W32.Mimail viral processes.
Remove the W32.Mimail files.
Delete dropped files.
Delete the worm’s registry values."


http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.removal.tool.html

http://techrepublic.com.com/5100-6264_11-5104786.html
Chicago Tribune | Survey: 31 Percent of U.S. Tech-Savvy:
"Technology geeks, unite. There are more of you than you might have realized. A study released Sunday found that 31 percent of Americans are 'highly tech-savvy' people for whom the Internet, cell phones and handheld organizers are more indispensable than TVs and old-fashioned wired phones. "

John Horrigan, author of the report by the Pew Internet & American Life Project, said the size of this "tech elite" was somewhat surprising. And while this group is predominantly young, the Pew researchers found plenty of baby boomers and seniors who are equally ardent about using technology.

The difference, though, is that techies in their late teens and 20s are more likely to create online content, like Web logs, or "blogs." Generation Xers are more likely to pay for content on the Web, while wired boomers and seniors generally plumb the Internet for news or to do work-related research.

So are you part of the "tech elite"? Consider these other Pew findings about how they live:…

http://www.chicagotribune.com/technology/sns-ap-tech-elite.story
Chicago Tribune | Questions, answers on cell phone changes:
"Questions and answers for consumers about changes in telecommunications rules:"

http://www.chicagotribune.com/technology/sns-ap-cell-phone-qa,1,1844433.story

Friday, November 21, 2003

Apple Plugs Vulnerabilities in Panther, Jaguar:
"The software updates a number of libraries, services and programs, including Personal File Sharing and QuickTime for Java. While described as the Security Update 2003-11-19 for Jaguar 10.2.8, the update is also recommended for Mac OS X 10.3, called Panther through Apple's automatic Software Update program. "

The update comes after Apple in October had been criticized for fixing some security problems in Mac OS X within its latest Panther release but not providing patches for earlier versions of the operating system. Later, the company indicated that it planned to offer patches for Jaguar.

http://www.eweek.com/article2/0,4149,1393307,00.asp?kc=EWNWS112103DTX1K0000599
AeANET : 11/19/2003 - U.S. High-Tech Industry Sheds More than One-Half Million Jobs in 2002, AeA Report Says:
"However, Decline in 2003 Has Slowed Dramatically"

A study released today by AeA shows that in 2002 the U.S. high-tech industry lost 540,000 jobs, dropping from 6.5 million to 6.0 million. A preliminary look at data for 2003 shows that the decline in high-tech employment slowed considerably in 2003. The report, AeA’s annual Cyberstates 2003: A State-by-State Overview of the High-Technology Industry, details national and state trends in high-tech employment, wages, exports, and other economic indicators.

The sector with the largest decrease in jobs was electronics manufacturing, accounting for more than half of all tech jobs lost between 2001 and 2002. For the first time in the seven years of publishing Cyberstates, the software sector recorded a loss of nearly 150,000 jobs last year. Indeed, the once-thriving software sector posted large increases in employment in all previous editions of Cyberstates. The communications services sector posted a similar loss of jobs. The engineering and tech services sector lost 15,000 jobs in 2002. The one bright spot was in R&D and testing labs, where employment increased by 7,000 in 2002.

"While high-tech employment fell by eight percent last year, preliminary 2003 data show a significant slowdown in high-tech job losses, with a decline of four percent," said AeA’s President and CEO William T. Archey. "We project that the 2003 high-tech job losses will total 234,000--down 57 percent from the 540,000 decline in 2002."

Archey further stated, "However, these declines have caused us to pause about two important issues. We are aware of current budget constraints, but now is not the time to cut back on education, particularly in math and science. We need a world class workforce to deal with world class challenges. Our second concern is the decline in basic research, particularly in technology, by the federal government. We worry that we have eaten the seed corn of federal research of 20 and 30 years ago that is not being replenished."

For the first time, Cyberstates 2003 is based on the newly implemented North American Industry Classification System (NAICS). AeA selected 49 NAICS codes to define the high-tech industry. They fall into four broad categories: electronics manufacturing, communications services, software, and engineering and tech services. This more current and comprehensive system allows us to capture several sectors which we could not with the previous system. These include fiber optic cable manufacturers, semiconductor machinery manufacturers, and web search portals.

This new industry classification system is fundamentally different from the old Standard Industrial Classification (SIC) system. Every sector of the economy has been restructured and redefined by the NAICS. Consequently, the data presented in this report are not comparable in any way to previous editions of Cyberstates. In this edition, however, 2001, 2002, and 2003 data use the NAICS system and are therefore comparable.

Cyberstates 2003 found that all but three states lost high-tech jobs in 2002. California lost the greatest number of tech jobs, shedding some 123,000 jobs. Texas was second with tech jobs down by 61,000 jobs. Interestingly, the District of Columbia, Wyoming, and Montana were the only three cyberstates to add technology jobs between 2001 and 2002.

http://www.aeanet.org/PressRoom/idmk_cs2003_US.asp
Customers rage at Google tweak | CNET News.com:
"In a rare sign of trouble for the booming search marketing business, Google is fending off complaints from angry customers who say recent changes to the company's advertising program are costing them sales.
The search engine giant tweaked its AdWords service in late October, saying it was making the move to better identify successful ads--those that get clicks--and to increase their visibility. It also took steps to reduce the number of unsuccessful ads that show up on its search results pages. A company representative said overall ad response rates have improved since the changes took effect. "


As keyword marketing grows in popularity, providers will likely face a tough balancing act to satisfy advertisers intent on bidding up prices and fighting for visibility on increasingly crowded lists.

But the new system hasn't improved results for everyone, leading to an outcry from those on the losing end. Disgruntled customers say the new system pits smaller companies against bigger ones, ultimately favoring deep-pocketed advertisers that can afford to outbid rivals for coveted keywords. In addition, some customers say the changes may be responsible for decreased conversion rates--the crucial sales that come after someone clicks on a Web advertisement.

"We would love to spend more with Google, but we're not going to overpay on (search) terms, when the surfer will click on terms and be frustrated and go elsewhere," said Daniel Mardorf, the Webmaster at Cellphonecarriers.com, who said he's seen response rates and sales from his Google ads drop since last month's changes took effect

http://news.com.com/2102-1024_3-5107406.html?tag=st_util_print

Thursday, November 20, 2003

ZDNet AnchorDesk: It wasn't me, it was the Trojan horse:
"Remember the Twinkie defense? Well, now there's the Trojan horse defense. That's right: In three recent court cases in the United Kingdom, defendants pleaded not guilty on the basis that someone else put code on their computer (via a Trojan horse) that caused their machines to break the law. "

While these cases have no direct bearing on U.S. court cases, they could lead to creative defenses for computer-related crimes in this country as well.

THE FIRST TWO cases involved the downloading of child pornography, while the third concerned a denial-of-service attack that caused real-world economic damage. All three defendants were acquitted.

In one of the child pornography cases, Karl Schofield of Whitley, England was cleared of processing 14 images of child pornography on his home PC. In the other, Julian Green of Devon, England, who was acquitted of storing 172 images of child pornography on his system.

In both cases, computer forensics experts found evidence of Trojan horses on the suspects' hard drives. The rogue code was allegedly deposited there via pop-up advertisements, banner ads, or Internet worms.

The third case involved a U.K. teenager named Aaron Caffrey. U.S. police discovered that his computer was responsible for the denial-of-service attack that crashed servers at the Port of Houston in October. However, Caffrey claimed that someone else put a Trojan horse on his PC that allowed his system to be controlled remotely. When investigators were unable to find evidence of such a remote-control Trojan, Caffrey claimed the Trojan had automatically erased itself.

THIS SEEMS suspicious to me, if only because Microsoft Windows (the operating system on Caffrey's computer) is notorious for creating duplicates or logs of all data. So either Caffrey was lying, or the authorities who investigated him were inept, as evidence of a Trojan horse should be relatively easy to find. Computer forensics tools, such as Guidance Software's EnCase, can quickly reveal hidden, partial, or even deleted files.…

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5107486.html?tag=adss

Saturday, November 15, 2003

15 Seconds : Implementing Paging and XSLT Extensions Using XSLT in .NET - Part 1:
"When you have to display a large number of records, the common practice is to use data paging so the information can be presented in a more user-friendly manner. There are many solutions one can use to implement such a system, and each of them has its own advantages and disadvantages. One of the excellent ways of implementing this solution is using XML and XSL.…
One of the main benefits of XML is that it separates data from the presentation. By combining XML data with an XSL Transformation (XSLT) stylesheet, you can dynamically transform the XML data and present the information in any format you want. "


http://www.15seconds.com/issue/031105.htm
Digital Web Magazine - Features: User Interface Design for Web Applications
It’s a Different World from Web Site Design

This article could be also be titled “Things I Wish I'd Known Before Designing My Latest Web-Based Application.”

http://www.digital-web.com/features/feature_2003-11.shtml

Friday, November 14, 2003

New Windows Worm on the Way?:
"The cycle began Tuesday when Microsoft Corp. released its monthly passel of patches, including one for a flaw in the Workstation service in Windows 2000 and XP. A successful exploitation would give the attacker complete control of the compromised PC, Microsoft said.."

Less than 24 hours after Microsoft issued the fix, two members of the BugTraq security mailing list posted exploit code for the vulnerability. The author of one of the exploits said the code had been tested only on a Windows 2000 machine with Service Pack 4 installed and the FAT32 file system running. The other exploit is designed for machines running Windows XP. However, experts said it would take little effort to adapt the code for other Windows machines.

And, more importantly, the Workstation vulnerability appears to be a prime candidate for a worm."


http://www.eweek.com/article2/0,4149,1382096,00.asp?kc=EWNWS111403DTX1K0000599
News: Wireless dilemma: Security isn't cool:
"Wireless communication has dramatically changed the way people work and interact. Unfortunately, the wireless era also continues to be plagued by insufficient security, and both corporations and users are being put at risk."

http://zdnet.com.com/2100-1107_2-5105460.html
Evaluating the wireless networking options - TechUpdate - ZDNet:
"Now that wireless networking has been around for several years and is starting to mature, companies have a variety of wireless networking standards and products to choose from. There are long-distance products used to send data between buildings miles away and then there are the shorter range products that typically provide wireless networking services within an office building or a warehouse. Both of these areas have a lot of different products and standards available, and there is no way that I could discuss them all within one article. However, since Wi-Fi is the dominant wireless networking technology at the moment, I want to discuss the various Wi-Fi options available and how to choose between them. "

http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2914510,00.html
Wireless Toolkit - NOW - TechUpdate - ZDNet:
"Wireless Networks Toolkit - Now
Keep up on the latest wireless trends and products
Extend your network range
Support your wireless network "


http://techupdate.zdnet.com/networking_upgrades/wireless_now.html?tag=tu.nu.toplink5
News: Spam spike signals more junk e-mail:
"An e-mail security firm has warned that spammers may be increasing their assault on Web users, after detecting a rise in the amount of unsolicited junk messages sent across the Internet.

FrontBridge, which provides outsourced e-mail filtering services for companies, said this week that it detected a 15 percent increase in spam between the 14th and 18th October--which it believes is a sign that organized spammers are ratcheting up their activities.

'Users who until this point had remained spam-free are now reporting multiple messages per day,' said Craig Whitney, FrontBridge's European director. 'This latest jump in the volume of spam being generated just adds to the load that enterprises have to manage every day,' Whitney added. "


http://zdnet.com.com/2100-1105_2-5105526.html?tag=adnews
Under Attack!:
"The largest virus outbreak in history hit millions of computers around the world this past August. Even before Microsoft Corp. and millions of victims could find a way to cope with the Blaster worm and a spate of imitators and mutations, Sobig began to live up to its name—with a vengeance.

Headline-making malware—viruses, worms, and Trojan horses—have managed to find a surprising number of unprotected PCs, despite the computer industry and media repeatedly urging people to use antivirus and firewall software. Some of the computers Sobig attacked had outdated antivirus software installed or none at all. A May 2003 study for the National Cyber Security Alliance conducted by America Online concluded that 62 percent of broadband consumers were not running up-to-date antivirus (AV) software.

But AV software alone isn't enough these days: You need a firewall, too, and privacy controls and spam filtering can further protect you. The AOL study also showed that 67 percent of broadband consumers did not have properly configured firewalls.

All manner of malware has been spreading via friendly e-mails and—more irritating—through mail no one wants in the first place—spam. Using the latest method of infection, worms send themselves out to the Internet from infected systems. Where do the worms end up? They end up in machines without firewalls or AV software. Worms either include a tiny e-mail server to send themselves out—usually with a spoofed sender address obtained from address lists—or search for unprotected shared network drives where they can unload themselves.

Once malware hits your PC, the damage can take many forms. A true virus attaches itself to a file and replicates itself when you launch the file. A Trojan horse hides on your system to do its damage, which may involve sending private data to its creator. One particularly obnoxious type of Trojan horse is a dialer, which uses your modem to call a pay number, sticking you with the bill.

A worm will often send mail to everyone on your e-mail address lists or propagate itself on shared network drives. Even viruses that don't destroy your data can wreak havoc by slowing Internet service to a crawl or hogging system resources.

Some people couldn't care less about malware and Internet security, claiming they have nothing personal or valuable stored on their hard drives. But such attitudes actually contribute to the larger problem, as these people let their machines become overrun by malware. Although you may notice only a slowdown in performance of your unprotected PC, you could actually be helping to cause massive damage on the Internet: Many viruses take part in launching denial-of-service attacks on prominent Web sites. Silently, unprotected systems in homes and offices are doing the bidding of malware that works alone or is controlled remotely by its miscreant authors, attacking other sites and systems in the process.…"

http://www.pcmag.com/article2/0,4149,1373605,00.asp

Thursday, November 13, 2003

O'Reilly Network Weblogs: PTO Director Orders Re-Exam for '906 Patent:
"In what could be good news for the Web, the Director of the US Patent and Trademark Office has ordered a re-examination of the '906 patent, which was the subject of a patent infringement lawsuit this summer brought by Eolas against Microsoft.

Issued in 1998 to Michael Doyle of Eolas Technologies, the patent (#5,838,906) covers the ability to embed and control applications (or objects) in a web browser. Doyle succeeded in obtaining a $500M judgement against Microsoft. In the aftermath, Microsoft said that changes to the browser were necessary to work around paying royalties on the patent, and that these changes would impact developers who create and maintain web pages. Many believe that the patent would also affect other technologies such as Flash and Java as well, which are launched from a browser. "



http://www.oreillynet.com/lpt/wlg/3969
Holes Found in Online Job Search Privacy:
"Some career Web sites, recruitment services and automated job-application kiosks offer flimsy privacy protections and might even violate employment and credit laws, a report released Tuesday asserts."

Many job sites still let too much information from resumes posted online get into the hands of third parties through online "cookies" that monitor Web surfing, according to the report, led by Pam Dixon, formerly of the University of Denver's Privacy Foundation and now head of her own group, the World Privacy Forum.

The report also faults self-service job application computers commonly used by chain stores. It says they almost always demand social security numbers and perform background checks on applicants without clearly stating who will see the information.

Dixon is urging job seekers to demand more stringent privacy protections. She also wants the Federal Trade Commission and the Equal Employment Opportunity Commission to look more closely at how job sites and recruitment services handle information.

"Technology is in such a place right now where it really is at odds with Title 7," the employment-discrimination section of the Civil Rights Act, Dixon said. "I don't want to see that eroded at all."

Other prominent Internet watchdogs also participated in the investigation, including members of the Electronic Privacy Information Center and the Privacy Rights Clearinghouse.

The report says that even people who don't hunt for jobs online should be aware that many resumes, no matter how they are submitted, are processed through vast databases.

For example, Eliyon Technologies Corp., a private company in Cambridge, Mass., has a file of 16 million executives that it sells to headhunters, employers and companies seeking leads for sales pitches. Eliyon's Web site says its customers include IBM Corp., Microsoft Corp. and Time Warner Inc.

Eliyon's advanced software mines information about people from Web sites, press releases, Securities and Exchange Commission filings and other public sources. Dixon said she was surprised at the level of detail in an Eliyon search about her sister. Though the sister is not a public figure, the names of her children and husband were listed.

Dixon alleged that Eliyon has no clear method for people to correct or remove erroneous data. That makes it "an end-run around the Fair Credit Reporting Act," which requires that consumers be able to examine adverse information maintained about them in commercial files, she said.…

http://www.eweek.com/article2/0,4149,1379992,00.asp?kc=EWNWS111203DTX1K0000599
Microsoft Issues Security Patches:
"Hardest hit in this month's batch of patches is IE, which contains five newly discovered vulnerabilities. Three of the flaws are related to the cross-domain security model in the browser. This mechanism is meant to prevent windows in different domains from sharing information. However, these weaknesses allow an attacker to run script in the browser's My Computer zone, which typically does not carry the same level of security as the Internet zone might."

In order to exploit this flaw, the attacker would either need to entice the user into visiting a malicious Web site or opening an HTML mail message containing the attack code. This would let the attacker access data from other Web sites that the user has visited and read files on the user's machine, Microsoft said in its bulletin.

Another flaw in IE concerns the manner in which the browser passes zone data to XML objects. Like the other three vulnerabilities, this one also can be exploited via Web sites and HTML mail messages. However, the attack also requires that users agree to download an HTML file, which would let the attacker read local files on the user's machine, if he knows the exact location of the files.

The final weakness in IE affects drag-and-drop operations during dynamic HTML events. If a user clicked on a link supplied by an attacker, the attacker could save a file on a user's machine in an arbitrary location. All of these flaws affect IE 5.01, 5.5 and 6, including IE 6, Service Pack 1.

The batch of patches also addresses a buffer overrun flaw in Windows 2000 and XP that could allow an attacker to run arbitrary code on remote machines. The vulnerability is in the Workstation service in Windows and a successful exploitation would give the attacker complete control of the compromised PC, Microsoft said.

Windows XP users who have installed the patch for MS03-043 are already protected against this vulnerability, but all Windows 2000 users would still need to apply this latest patch.…

The patches are at Microsoft's Security and Privacy Page.
http://www.microsoft.com/security/

http://www.eweek.com/article2/0,4149,1379656,00.asp?kc=EWNWS111203DTX1K0000599

Wednesday, November 12, 2003

Mimail Can Capture Keystrokes:
"Top 10 E-Mail Viruses as Reported by MessageLabs
These are the latest threats as of Monday Nov 10, 2003 as listed by MessageLabs:
  • W32/Swen.A-mm

  • W32/Dumaru.A-mm

  • W32/Sobig.F-mm

  • W32/Klez.H-mm

  • W32/Mimail.A-mm

  • W32/Mimail.C-mm

  • W32/Mimail.E-mm

  • W32/Holar.L-mm

  • W32/Yaha.P-mm

  • W32/Yaha.E-mm

For MessageLabs's complete list of email viruses, click here."


http://www.messagelabs.com/viruseye/threats/

http://www.pcmag.com/print_article/0,3048,a=111807,00.asp
Messaging and Collaboration News, Product Reviews, Trends and Analysis:
"More IM technology is enterprise-ready, but security and other issues still loom large."

http://www.eweek.com/category2/0,4148,1237933,00.asp
154036 - How to Disable Active Content in Internet Explorer:
"This article lists troubleshooting steps to help you troubleshoot problems with active content such as ActiveX scripts, ActiveX controls, and Java programs in Internet Explorer. "

Configure Internet Explorer so that it does not run Active scripts automatically:

Configure Internet Explorer so that it does not automatically use items that show active content, such as vertical marquees or animations.

Verify that Internet Explorer's internal Java Just-In-Time (JIT) compiler is disabled:

Configure Internet Explorer so that it does not run Java programs automatically.

While most active content contained in Web pages is safe, some Web pages contain active content that can potentially cause security problems on your computer. For example, an ActiveX control that runs automatically when you load a particular Web page might damage your data or cause your computer to become infected with a virus. Internet Explorer uses safety levels for active content to help prevent this situation from occurring.…

http://support.microsoft.com/default.aspx?scid=kb;en-us;154036

Tuesday, November 11, 2003

AntiSpam: Up Close and Personal:
"A feature of Norton AntiSpam is its log of statistics. Here are my spam statistics since I began using the software on September 25, 2003, through Sunday November 9, 2003. Let's call that 44 days."

  • E-mail scanned: 14,737 messages

  • Average (over the 44 days): 335 per day

  • Sent e-mail: 781 messages

  • Valid e-mail: 6,023 messages(40.87%)

  • Mail correctly identified: 5,996 messages (99.55%)

  • >Spam: 8,714 messages (59.13%)

  • Spam correctly identified: 8,103 messages (92.99%)



The most stunning number in this list is the sheer quantity of mail I receive. Something is clearly wrong with me—I must make a note to get myself an actual life (actually, a lot of it is security mailing lists that I don't read thoroughly). Maybe this weekend.

Still, it looks like I had 27 false positives (0.45% of valid mail), and that sounds like what I remember from my use of the product. NAS counts false positives when I manually scan the Spam folder in Outlook and mark non-spam messages with the "This is not Spam" button. Conversely, when I mark a message in the Inbox with the "This is Spam" button, it gets tracked as a false negative. The difference between the "Spam" and "Spam correctly identified" results totaled 611 messages or a hair over 7 percent of spam.

Now, I'm pretty happy with the ability of the product to find spam and reaching 93 percent is pretty good. At the same time, my instincts are that the 0.45 percent figure for false positives seems like a small number.

But those 27 false positives over 43 days may be non-trivial. This figure tells me I still should check the Spam folder periodically, and even relatively often, because if I don't I'll be intimidated by the amount of mail in it.

I was also struck by the fact that the statistics page reported that the last Antispam update was released on 8/29/2003. If they can go a month and a half without an update (and yes, I do run LiveUpdate frequently), Symantec can't be following the spam business the way they follow the virus business.…

One more bit of perspective on the amount of spam I receive. It's actually a lot more than that 59 percent figure presented by Norton. Some of my e-mail accounts are already filtered at the servers. Note the difference in the handling of three addresses of mine that are filtered through FrontBridge's server-based spam filtering. In the last month, that product found 523 spam messages and only one of them was a false positive.

Perhaps the answer is to switch to Outlook 2003. The numbers showed that it had not a single false positive, although it found far less spam. Oh well, the products get better, but the decisions we have to make continue to get harder.

http://www.eweek.com/article2/0,4149,1378794,00.asp?kc=EWNWS111103DTX1K0000599
Internet Tax Ban Stops Dead in Senate:
"A push to permanently ban taxes on Internet access came to an abrupt halt in the Senate on Friday amid concern that state and local governments could lose millions in taxes from phones, music and movies that are migrating to the Internet."

State and local governments collect more than $20 billion every year on telecommunications and fear the permanent ban will wipe out a large part of that revenue. A core group of senators pressing for a permanent end to taxes on Internet access said those fears are unfounded.

"All the bill says is you cannot discriminate against electronic commerce, and not one state has come forward and given an example of how they have been hurt by their inability to discriminate against electronic commerce," said Sen. Ron Wyden, D-Ore.

An analysis by the Congressional Budget Office said the bill could hit state and local governments in three ways. About 10 states that imposed a tax on Internet access charges before the original ban, and who were permitted to keep collecting those taxes, would lose $80 million to $120 million each year.

http://www.eweek.com/article2/0,4149,1376712,00.asp
Google Unveils Web-Searching Software:
"Internet search engine Google has unveiled free software that lets people search the Web quickly—without launching a Web browser.

Google Deskbar, released Thursday, appears as a search box in the Windows toolbar. After the search words are entered, a resizable mini-viewer pops up with the results. Users can jump to the site within the mini-viewer or launch their browser."


Beyond Google's main search, the box can be set to search Google non-U.S. sites, Google News, Google Images and others. There are options to find stock quotes, movie reviews, word definitions and synonyms. Users can add custom sites to search, too.

The software, which is about 400 kilobytes, requires a PC with Windows XP or Windows 2000, at least Internet Explorer 5.5 and an Internet connection. Windows 95, 98 and ME are not supported. Google Deskbar also does not run on Macintosh or Linux computers.

http://www.eweek.com/article2/0,4149,1376294,00.asp
Carriers Unprepared for Wireless Number Portability Deadline:
"Number portability is drawing near, but because many wireless carriers aren't ready for the flood of customers looking to make the switch, experts advise waiting to change contracts."

In fact, customers should wait until at least March before trying to change carriers, according to a new study from Mobile Competency Inc., a consultancy in Providence, R.I.

The study focused on six major carriers, all of which have established WNP (wireless number portability) call centers: Verizon Wireless Inc., Sprint, Nextel Communications Inc., T-Mobile USA Inc. and Cingular Wireless Inc. Of these, only Verizon, Sprint, Nextel and Cingular have call centers designed for enterprise ports. And only Sprint and Nextel have published enterprise WNP guidelines.

The study also found that only two carriers are prepared for porting from wire line to wireless: Verizon, which stands to gain wireless business from its own wire-line customers, and Nextel, which has no wire-line business.

As of last week, none of the top six carriers had completed carrier-to-enterprise service-level agreements nor had any completed intercarrier testing with the other five carriers to make sure that porting would work smoothly. While the FCC has issued loose guidelines that say a port should take no more than 2.5 hours, there is no penalty for carriers that don't meet that time limit.

http://www.eweek.com/article2/0,4149,1376512,00.asp
Microsoft: Virtual PC Will Run Linux:
"Carla Huffman, Microsoft's product manager for the Virtual PC, told eWEEK that the software will be available by the end of the year, through Microsoft's existing retail and volume licensing channels, for an estimated retail price of $129, $100 less than the Connectix price of $229.

'We have not removed any technical features that supported other non-Microsoft operating systems. So there is no negative impact to customers to running non-Microsoft operating systems on Virtual PC,' she said.

The confusion around the product has been around official Microsoft product support services, Huffman said, adding that Microsoft is treating the use of Linux the same way it treats the use of any third-party application on a Windows operating system. "


http://www.eweek.com/article2/0,4149,1378286,00.asp