DoS Flaw in SOAP DTD Parameter:
"Technology heavyweights IBM and Microsoft have released fixes for a potentially serious vulnerability in various Web Services products that could be exploited to trigger denial-of-service attacks (define).
In separate alerts, the companies said the vulnerability was caused by an error in the XML parser when parsing the DTD (Document Type Definition) part of XML documents. Independent security researcher Secunia has tagged the flaw with a 'moderately critical' rating."
Affected software include the IBM WebSphere 5.0.0 and Microsoft ASP.NET Web Services (.NET framework 1.0, .NET framework 1.1).
According to IBM, the security patch fixes a flaw that could be exploited by sending a specially crafted SOAP request. "This can cause the WebSphere XML Parser to consume an excessive amount of CPU resources," Big Blue warned.
An advisory from Microsoft confirmed the DTD error parsing vulnerability in its Web Services products, included with the .NET Framework 1.1.
Document Type Definition (DTD) provides a way DTDs provide a way to write markup rules that describe the structure of XML documents and can be used to validate the structure of those documents. When the XML 1.0 specification was originally created, the DTD syntax, which is not XML-based, was inherited from earlier markup languages, such as Standard Generalized Markup Language (SGML) and HTML, Microsoft explained.…
http://www.internetnews.com/dev-news/article.php/3289191
Wednesday, December 17, 2003
W32/Sobig.F-mm is Still a Big Threat:
"On the virus and worm front, not much has changed in the lineup of top threats. W32/Swen.A-mm, W32/Dumaru.A-mm and several Mimail variations are still infecting hundreds worldwide every day. Also on the top list is W32/Sobig.F-mm, a tenacious multi-vector worm that has been around since August. Sobig.F, like Swen.A, spoofed the 'from' address field of e-mail it sent out, to make it look like someone else was sending the infected messages. The worm was very prolific by itself, but it ended up generating more incidental Internet traffic because automated IT antivirus systems were sending virus notifications back to the senders. Unfortunately, many of the apparent senders had nothing to do with the original e-mail message. In the days of slower moving viruses, the notifications were helpful, but with fast moving worms, it had to be scrapped. In a recent newsletter, ThreatFocus estimated that 'Spam from PC's hijacked by the Sobig virus now accounts for more than half of all email sent across the Internet.' "
First discovered in August 2003, mass mailing worm W32/Sobig.F-mm caused a lot of grief in a short amount of time, and is still in the top 10 viruses plaguing users. W32/Sobig.F-mm was supposed to terminate its propagation on September 10th, 2003, and was downgraded in threat level by several antivirus companies. Though "deactivated", it is still listed as one of the top infectors, and it is attributed to spreading spam across the Internet. After the deactivation date, it can still be used to propagate spam and update itself, making it important to remove the infection.
One of the fastest moving viruses, Sobig.F usually spreads as an e-mail attachment (usually a PIF or SCR file), though it also attempts to spread through network shares, leaving open the possibility of re-infection even if the original infected machines have been cleaned. For a user to catch Sobig.F, they must run or view the e-mail attachment. Once running, Sobig.F will send copies of itself out using its own SMTP engine to addresses harvested from text, database, html and e-mail files on the victim's machine. The virus also uses the harvested addresses to spoof the "From" field to disguise the origin of the e-mail. This feature caused major headaches, as many innocent users were being blamed for sending out infected traffic, and the bounced back e-mail in itself clogged the Internet.
Once running, the virus will attempt get the current date and time through one of several Network Timer Protocol (NTP) servers. If the time is between 19:00 and 22:00 UTC (Universal Time Code) or 8pm – 11pm UK time, on a Friday or Sunday, it sends a UDP packet to a remote server on port 8998. It is suspected that it is being used to download an update file, which is a behavior shown by earlier versions of Sobig. Blocking outgoing UDP connections on port 8998 with a firewall is recommended as a workaround for this feature.
When a user runs an infected attachment, Sobig creates a copy of itself called winppr32.exe in the Windows folder (C:\Windows or C:\Winnt). It then adds the value "TrayX"="%Windir%\winppr32.exe /sinc" to the following registry keys, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run . This means that the virus will run when the machine is booted. Sobig also creates a file called winstt32.dat in the Windows folder (%windir% is the Windows folder as noted above), which is used to store e-mail addresses gathered from the victim's machine.
The virus will also look for any accessible network shares for which the PC has write access. Symantec reports though that due to a bug in the code, Sobig cannot copy over network shares. Sobig.F can download arbitrary files from server addresses stored in the virus, and execute them. Also according to the Symantec, "The author of the worm has used this functionality to steal confidential system information and to set up spam relay servers on infected computers". This is in line with ThreatFocus's estimate that over 50% of the spam on the web comes from Sobig infected zombie computers. It is suspected that Sobig.F attempts to contact a master server that its author controls and downloads a URL where it goes to download a Trojan to run on the local PC.…
Full article (printable version) at http://www.pcmag.com/print_article/0,3048,a=114580,00.asp
http://www.pcmag.com/article2/0,4149,1414899,00.asp
"On the virus and worm front, not much has changed in the lineup of top threats. W32/Swen.A-mm, W32/Dumaru.A-mm and several Mimail variations are still infecting hundreds worldwide every day. Also on the top list is W32/Sobig.F-mm, a tenacious multi-vector worm that has been around since August. Sobig.F, like Swen.A, spoofed the 'from' address field of e-mail it sent out, to make it look like someone else was sending the infected messages. The worm was very prolific by itself, but it ended up generating more incidental Internet traffic because automated IT antivirus systems were sending virus notifications back to the senders. Unfortunately, many of the apparent senders had nothing to do with the original e-mail message. In the days of slower moving viruses, the notifications were helpful, but with fast moving worms, it had to be scrapped. In a recent newsletter, ThreatFocus estimated that 'Spam from PC's hijacked by the Sobig virus now accounts for more than half of all email sent across the Internet.' "
First discovered in August 2003, mass mailing worm W32/Sobig.F-mm caused a lot of grief in a short amount of time, and is still in the top 10 viruses plaguing users. W32/Sobig.F-mm was supposed to terminate its propagation on September 10th, 2003, and was downgraded in threat level by several antivirus companies. Though "deactivated", it is still listed as one of the top infectors, and it is attributed to spreading spam across the Internet. After the deactivation date, it can still be used to propagate spam and update itself, making it important to remove the infection.
One of the fastest moving viruses, Sobig.F usually spreads as an e-mail attachment (usually a PIF or SCR file), though it also attempts to spread through network shares, leaving open the possibility of re-infection even if the original infected machines have been cleaned. For a user to catch Sobig.F, they must run or view the e-mail attachment. Once running, Sobig.F will send copies of itself out using its own SMTP engine to addresses harvested from text, database, html and e-mail files on the victim's machine. The virus also uses the harvested addresses to spoof the "From" field to disguise the origin of the e-mail. This feature caused major headaches, as many innocent users were being blamed for sending out infected traffic, and the bounced back e-mail in itself clogged the Internet.
Once running, the virus will attempt get the current date and time through one of several Network Timer Protocol (NTP) servers. If the time is between 19:00 and 22:00 UTC (Universal Time Code) or 8pm – 11pm UK time, on a Friday or Sunday, it sends a UDP packet to a remote server on port 8998. It is suspected that it is being used to download an update file, which is a behavior shown by earlier versions of Sobig. Blocking outgoing UDP connections on port 8998 with a firewall is recommended as a workaround for this feature.
When a user runs an infected attachment, Sobig creates a copy of itself called winppr32.exe in the Windows folder (C:\Windows or C:\Winnt). It then adds the value "TrayX"="%Windir%\winppr32.exe /sinc" to the following registry keys, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run . This means that the virus will run when the machine is booted. Sobig also creates a file called winstt32.dat in the Windows folder (%windir% is the Windows folder as noted above), which is used to store e-mail addresses gathered from the victim's machine.
The virus will also look for any accessible network shares for which the PC has write access. Symantec reports though that due to a bug in the code, Sobig cannot copy over network shares. Sobig.F can download arbitrary files from server addresses stored in the virus, and execute them. Also according to the Symantec, "The author of the worm has used this functionality to steal confidential system information and to set up spam relay servers on infected computers". This is in line with ThreatFocus's estimate that over 50% of the spam on the web comes from Sobig infected zombie computers. It is suspected that Sobig.F attempts to contact a master server that its author controls and downloads a URL where it goes to download a Trojan to run on the local PC.…
Full article (printable version) at http://www.pcmag.com/print_article/0,3048,a=114580,00.asp
http://www.pcmag.com/article2/0,4149,1414899,00.asp
Judge OKs Internet Company's Pop-Up Ads:
"A federal judge ruled Monday that a California company can send 'pop-up' Internet ads that regulators have called 'high-tech extortion"—at least until the matter is decided at trial.
U.S. District Judge Andre Davis said there was insufficient evidence for him to grant a preliminary injunction sought by the Federal Trade Commission. Regulators wanted to stop San Diego-based D-Squared Solutions LLC from selling its ad-blocking software."
"It's not clear to me ... if there's substantial injury to consumers," said Davis, who set a trial for March 8. "The case had the odor of extortion as it was originally prosecuted ... but it certainly doesn't look like extortion to me."
The FTC said D-Squared improperly used a technology built into most versions of Microsoft's Windows operating software to display intrusive messages on computer screens.
The messages offered software to block the same types of ads the company was sending. The FTC said D-Squared unlawfully exploited Microsoft's Windows Messenger Service feature by sending the unwanted ads to Internet users as frequently as once every 10 minutes.
FTC attorney Mona Spivack said D-Squared's advertisements caused "substantial injury" to consumers, citing lost data, crashed computers, frustration, annoyance and harassment.
"They clearly knew that this practice was in fact causing consumers' computers to crash," Spivack said. "The defendant's own marketing material said this."
http://www.eweek.com/article2/0,4149,1414497,00.asp?kc=EWNWS121603DTX1K0000599
"A federal judge ruled Monday that a California company can send 'pop-up' Internet ads that regulators have called 'high-tech extortion"—at least until the matter is decided at trial.
U.S. District Judge Andre Davis said there was insufficient evidence for him to grant a preliminary injunction sought by the Federal Trade Commission. Regulators wanted to stop San Diego-based D-Squared Solutions LLC from selling its ad-blocking software."
"It's not clear to me ... if there's substantial injury to consumers," said Davis, who set a trial for March 8. "The case had the odor of extortion as it was originally prosecuted ... but it certainly doesn't look like extortion to me."
The FTC said D-Squared improperly used a technology built into most versions of Microsoft's Windows operating software to display intrusive messages on computer screens.
The messages offered software to block the same types of ads the company was sending. The FTC said D-Squared unlawfully exploited Microsoft's Windows Messenger Service feature by sending the unwanted ads to Internet users as frequently as once every 10 minutes.
FTC attorney Mona Spivack said D-Squared's advertisements caused "substantial injury" to consumers, citing lost data, crashed computers, frustration, annoyance and harassment.
"They clearly knew that this practice was in fact causing consumers' computers to crash," Spivack said. "The defendant's own marketing material said this."
http://www.eweek.com/article2/0,4149,1414497,00.asp?kc=EWNWS121603DTX1K0000599
Monday, December 15, 2003
News: Google delivers parcel search:
"Google has introduced a new search feature that turns up shipping information from Federal Express and United Parcel Service, the company's latest move to expand beyond keyword searches.
Google takes people directly to the FedEx or UPS Web page containing the location of a particular package when they type in their parcel tracking number into its search site. The new 'Search by Number' feature, announced Friday, also brings up information linked to other kinds of numbers, such as patent numbers, equipment identification numbers issued by the Federal Communications Commission, and airplane registration numbers from the Federal Aviation Administration.… "
Google also has tweaked the way it displays search results for specific products for sale on the Web. A search for "Hulk Hands," for instance, will display the top listings from Google's online shopping guide, Froogle, above its regular search results.…
http://zdnet.com.com/2100-1104_2-5121824.html
"Google has introduced a new search feature that turns up shipping information from Federal Express and United Parcel Service, the company's latest move to expand beyond keyword searches.
Google takes people directly to the FedEx or UPS Web page containing the location of a particular package when they type in their parcel tracking number into its search site. The new 'Search by Number' feature, announced Friday, also brings up information linked to other kinds of numbers, such as patent numbers, equipment identification numbers issued by the Federal Communications Commission, and airplane registration numbers from the Federal Aviation Administration.… "
Google also has tweaked the way it displays search results for specific products for sale on the Web. A search for "Hulk Hands," for instance, will display the top listings from Google's online shopping guide, Froogle, above its regular search results.…
http://zdnet.com.com/2100-1104_2-5121824.html
ZDNet AnchorDesk: How to stop spam? Don't look to legislation:
"After months of debate, Congress has approved an antispam bill, known as the Controlling the Assault of Non-Solicited Pornography and Marketing Act, or the CAN-SPAM Act of 2003. President Bush has indicated he will sign it before the end of the year. That sounds like good news for anyone who uses e-mail. But once you look beyond the spin, you'll find there's much less here than meets the eye. "
IN A NUTSHELL, CAN-SPAM prohibits the use of fraudulent e-mail headers, the use of robotic means to collect e-mail addresses from Web sites, and the sending of unsolicited adult advertising. It requires e-mail marketers to provide a working URL in messages so recipients can remove themselves from any future mailings.
Down the road, the law also calls for the creation of a federal Do Not Spam list, much like the FTC's Do Not Call list, which gives you the ability to remove your phone number from telemarketers' databases. The law also prohibits unwanted commercial messages via mobile services on mobile phones and PDAs.…
SO WHY DID the attorneys general from California, Kansas, Maryland, Nevada, Texas, Vermont, and Washington urge the House of Representatives to vote against the act? Because CAN-SPAM ignores and supercedes any existing or pending junk e-mail laws in 30 states--including the toughest, California's--with a decidedly weaker federal law.
The state laws, which are now obsolete, were more stringent than the federal one in several ways. For example, the laws in Utah and California would allow recipients to sue spammers who use false e-mail headers. One provision of a California law would even use the penalties claimed from such cases to help fund the state's high-tech crime task forces. However, under CAN-SPAM, while recipients can still sue spammers, the burden of proof has been extended beyond showing that the e-mail header was false and now requires that plaintiffs show the sender also knew it was false.
It's the opinion of several state attorneys general that this is a much higher standard of proof than other consumer protection laws, and that spam recipients will now tie up the legal system with new cases without being able to stop unsolicited e-mails in the meantime. That is what the direct-marketing associations wanted: judicial gridlock.
ANOTHER SHORTCOMING of the law: According to Spamhaus.org, an antispam clearinghouse, CAN-SPAM allows 23 million U.S. businesses to spam U.S. e-mail addresses legally as long as they also provide a means for users to opt-out of future mailings.
It turns out the direct marketers got their way this time around. With telemarketing restricted by the Do Not Call list, direct-marketing associations now see e-mail advertising as their last and best option, since automatically sending hundreds of thousands of e-mails is much cheaper than maintaining call centers. These groups made the rounds in Washington D.C. and managed to get this muted federal antispam bill passed quickly. For the legislators in Congress, CAN-SPAM allows them to say, "Look, we did something about spam," when, in reality, the act does little to actually solve the problem.…
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5113118.html?tag=ns
"After months of debate, Congress has approved an antispam bill, known as the Controlling the Assault of Non-Solicited Pornography and Marketing Act, or the CAN-SPAM Act of 2003. President Bush has indicated he will sign it before the end of the year. That sounds like good news for anyone who uses e-mail. But once you look beyond the spin, you'll find there's much less here than meets the eye. "
IN A NUTSHELL, CAN-SPAM prohibits the use of fraudulent e-mail headers, the use of robotic means to collect e-mail addresses from Web sites, and the sending of unsolicited adult advertising. It requires e-mail marketers to provide a working URL in messages so recipients can remove themselves from any future mailings.
Down the road, the law also calls for the creation of a federal Do Not Spam list, much like the FTC's Do Not Call list, which gives you the ability to remove your phone number from telemarketers' databases. The law also prohibits unwanted commercial messages via mobile services on mobile phones and PDAs.…
SO WHY DID the attorneys general from California, Kansas, Maryland, Nevada, Texas, Vermont, and Washington urge the House of Representatives to vote against the act? Because CAN-SPAM ignores and supercedes any existing or pending junk e-mail laws in 30 states--including the toughest, California's--with a decidedly weaker federal law.
The state laws, which are now obsolete, were more stringent than the federal one in several ways. For example, the laws in Utah and California would allow recipients to sue spammers who use false e-mail headers. One provision of a California law would even use the penalties claimed from such cases to help fund the state's high-tech crime task forces. However, under CAN-SPAM, while recipients can still sue spammers, the burden of proof has been extended beyond showing that the e-mail header was false and now requires that plaintiffs show the sender also knew it was false.
It's the opinion of several state attorneys general that this is a much higher standard of proof than other consumer protection laws, and that spam recipients will now tie up the legal system with new cases without being able to stop unsolicited e-mails in the meantime. That is what the direct-marketing associations wanted: judicial gridlock.
ANOTHER SHORTCOMING of the law: According to Spamhaus.org, an antispam clearinghouse, CAN-SPAM allows 23 million U.S. businesses to spam U.S. e-mail addresses legally as long as they also provide a means for users to opt-out of future mailings.
It turns out the direct marketers got their way this time around. With telemarketing restricted by the Do Not Call list, direct-marketing associations now see e-mail advertising as their last and best option, since automatically sending hundreds of thousands of e-mails is much cheaper than maintaining call centers. These groups made the rounds in Washington D.C. and managed to get this muted federal antispam bill passed quickly. For the legislators in Congress, CAN-SPAM allows them to say, "Look, we did something about spam," when, in reality, the act does little to actually solve the problem.…
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5113118.html?tag=ns
Saturday, December 13, 2003
Security Troubleshoot and Maintain:
Find what you need to respond to current security issues.
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/Default.asp
Find what you need to respond to current security issues.
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/Default.asp
Security Pipeline | News | Spam-Virus Marriage Seen As Leading 2004 Internet Threat:
"The use of viruses to commandeer personal computers on the Internet for relaying spam is a trend that started this year and is expected to escalate in 2004, an e-mail security company said Friday.
In the last six months, MessageLabs Inc. has seen a steady rise in the use of spam and virus techniques in sending out junk e-mail hawking drugs, pornography and sexual enhancements. "
The Minneapolis-based company, which filters corporate e-mail for spam and viruses, intercepts about 27 spam messages a second today, up from two per second at the same time last year. Sixty-six percent of those messages are generated from PCs that have been taken over by spammers without the knowledge of the computers' owners, Mark Sunner, chief technology officer for MessageLabs, said.
The number of PCs commandeered by spammers is expected to increase next year. "Spammers are taking advantage of the flaw in traditional anti-virus software people are running on their desktops today," Sunner said.
Traditional anti-virus software requires users to download code capable of detecting a virus after it's released on the Internet.
Until this year, people seeking a thrill from the chaos they could cause on the Internet accounted for most of the viruses. The malevolent code is hidden in an e-mail attachment that the sender tries to trick a person into opening by pretending the message is from a legitimate vendor or someone who can be trusted, like a friend.
Spammers are now using the same techniques to get PC users to unknowingly install applications that allow the machines to be used later to relay spam. The pre-eminent example of this kind of malevolent code was the Sobig.F virus, which had such an effective mass-mailing engine that it managed to shut down some corporate and government networks.
"The authors behind Sobig were definitely spammers using the virus to harvest lots of machines to blast spam," Sunner said.
Relaying spam through other computers enables spammers to remain anonymous and avoid law enforcement agencies. In addition, by hiding the original source of the mass-mailings, spammers can avoid black lists used by filtering software to separate spam from legitimate messages.…
http://informationweek.securitypipeline.com/news/showArticle.jhtml;jsessionid=F1K3ID3UJ3UQIQSNDBCSKHQ?articleId=16600263
"The use of viruses to commandeer personal computers on the Internet for relaying spam is a trend that started this year and is expected to escalate in 2004, an e-mail security company said Friday.
In the last six months, MessageLabs Inc. has seen a steady rise in the use of spam and virus techniques in sending out junk e-mail hawking drugs, pornography and sexual enhancements. "
The Minneapolis-based company, which filters corporate e-mail for spam and viruses, intercepts about 27 spam messages a second today, up from two per second at the same time last year. Sixty-six percent of those messages are generated from PCs that have been taken over by spammers without the knowledge of the computers' owners, Mark Sunner, chief technology officer for MessageLabs, said.
The number of PCs commandeered by spammers is expected to increase next year. "Spammers are taking advantage of the flaw in traditional anti-virus software people are running on their desktops today," Sunner said.
Traditional anti-virus software requires users to download code capable of detecting a virus after it's released on the Internet.
Until this year, people seeking a thrill from the chaos they could cause on the Internet accounted for most of the viruses. The malevolent code is hidden in an e-mail attachment that the sender tries to trick a person into opening by pretending the message is from a legitimate vendor or someone who can be trusted, like a friend.
Spammers are now using the same techniques to get PC users to unknowingly install applications that allow the machines to be used later to relay spam. The pre-eminent example of this kind of malevolent code was the Sobig.F virus, which had such an effective mass-mailing engine that it managed to shut down some corporate and government networks.
"The authors behind Sobig were definitely spammers using the virus to harvest lots of machines to blast spam," Sunner said.
Relaying spam through other computers enables spammers to remain anonymous and avoid law enforcement agencies. In addition, by hiding the original source of the mass-mailings, spammers can avoid black lists used by filtering software to separate spam from legitimate messages.…
http://informationweek.securitypipeline.com/news/showArticle.jhtml;jsessionid=F1K3ID3UJ3UQIQSNDBCSKHQ?articleId=16600263
Windows XP Professional File Sharing:
"The file system in Windows XP is based on Windows NT and Windows 2000, so many of its features are new to users of Windows 95, 98, and Me. "
In Windows 95/98/Me, you can assign a password to a shared disk or folder, so that only people who know the password can gain access. That works well in a small home network where, for example, Mom and Dad know the password to the family's financial data, but Junior doesn't. But it isn't practical in a large corporate network, where Windows XP Professional is likely to be used. It's hard to keep a password secret in a large company, and changing to a new password requires giving it to everyone who needs to use it.
Windows XP Professional replaces password-based security with two alternatives:
http://www.practicallynetworked.com/sharing/xp_filesharing/index.htm
"The file system in Windows XP is based on Windows NT and Windows 2000, so many of its features are new to users of Windows 95, 98, and Me. "
In Windows 95/98/Me, you can assign a password to a shared disk or folder, so that only people who know the password can gain access. That works well in a small home network where, for example, Mom and Dad know the password to the family's financial data, but Junior doesn't. But it isn't practical in a large corporate network, where Windows XP Professional is likely to be used. It's hard to keep a password secret in a large company, and changing to a new password requires giving it to everyone who needs to use it.
Windows XP Professional replaces password-based security with two alternatives:
- Simple File Sharing is enabled by default on Windows
XP Professional systems that are members of a workgroup (typically
used in small networks) rather than a domain (typically used in
large corporate networks). For full details, see our article
on Simple
File Sharing. There are no passwords or access restrictions
and, with one exception described in the article, everything that's
shared is accessible by everyone on the network. Simple File
Sharing is the only type of sharing available in Windows XP Home
Edition. - By disabling Simple File Sharing, you can specify an Access
Control List (ACL) for each shared
disk or folder. The ACL specifies which users are allowed to
have access.
http://www.practicallynetworked.com/sharing/xp_filesharing/index.htm
Thursday, December 11, 2003
Eureka! Mac's Are Not Invulnerable:
"The truth is that the Mac OS is just as vulnerable as Microsoft Windows. Overall, maybe OS X is better than Windows, but that's not the point. Panther, for example, is a great OS, but it's also complex, and complexity leaves room for gaps—some small, some not.
OS X 10.x may not be as widely used as Windows (let's face it, it isn't) but some of its devotees seem far more fanatical than Windows users. Those who toil in Windows—me, for instance—care about their OS to a certain degree, but hardly feel the need to jump to its defense or come up with ridiculous conspiracy theories to explain why, say, Bob bombed or Windows Me stank."
When Microsoft released Windows 95 three years and some months later, for the first time there was a degree of parity between the graphical interfaces. I found things to grumble about, but they were minor. Microsoft's less-than-stellar OS security took a while to become apparent. In fact, the problem wasn't epidemic until a few years after the Internet took off. Windows' market domination makes it a target for the virus authoring community. The OS also bears the burden of user wrath because those who depend on Windows so often feel let down. But nothing drives me crazier than Mac true believers shaking their heads and grinning at me every time another Windows virus hits. This past summer was particularly difficult. As Blaster and SoBig wreaked havoc across the Internet and with millions of Windows PCs, Mac users would tell me with mock sympathy, "This wouldn't happen if we all ran Macs".
We don't, of course, and again, that's the point. The discovery of this OS X security hole will be like a tree falling in a particularly remote forest. So few people actually use Macs (notwithstanding, of course, what you see in the alternate universe of movies, where everyone appears to use them), that I think it's unlikely this problem will have any long-term effect. Hackers are unlikely to exploit this hole the way they have Windows failings.
If the Macintosh OS ever became dominant, the tables would turn, and there would be just as many reports of viruses, security holes, and attacks on it as we currently have with Windows. As one Macophile I spoke with noted, no one has even bothered to exploit this security flaw. I doubt anyone will. Meanwhile, we can already see what happens when Apple has a broadly popular product that cuts across platforms. The Apple iPod is the number one MP3 player, and now that its companion computer utility, iTunes, is available for both the Mac and the PC, it has become a hack target. In fact, Jon Lech Johansen, the same Norwegian who cracked the DVD security code, recently circumvented the iTunes music protection scheme. An event like that occurring makes sense to me, since iTunes' popularity makes it a target worth hacking—and whatever mystical Mac mojo there may be, it didn't go far in protecting a popular Apple product.…
http://www.pcmag.com/article2/0,4149,1408924,00.asp
"The truth is that the Mac OS is just as vulnerable as Microsoft Windows. Overall, maybe OS X is better than Windows, but that's not the point. Panther, for example, is a great OS, but it's also complex, and complexity leaves room for gaps—some small, some not.
OS X 10.x may not be as widely used as Windows (let's face it, it isn't) but some of its devotees seem far more fanatical than Windows users. Those who toil in Windows—me, for instance—care about their OS to a certain degree, but hardly feel the need to jump to its defense or come up with ridiculous conspiracy theories to explain why, say, Bob bombed or Windows Me stank."
When Microsoft released Windows 95 three years and some months later, for the first time there was a degree of parity between the graphical interfaces. I found things to grumble about, but they were minor. Microsoft's less-than-stellar OS security took a while to become apparent. In fact, the problem wasn't epidemic until a few years after the Internet took off. Windows' market domination makes it a target for the virus authoring community. The OS also bears the burden of user wrath because those who depend on Windows so often feel let down. But nothing drives me crazier than Mac true believers shaking their heads and grinning at me every time another Windows virus hits. This past summer was particularly difficult. As Blaster and SoBig wreaked havoc across the Internet and with millions of Windows PCs, Mac users would tell me with mock sympathy, "This wouldn't happen if we all ran Macs".
We don't, of course, and again, that's the point. The discovery of this OS X security hole will be like a tree falling in a particularly remote forest. So few people actually use Macs (notwithstanding, of course, what you see in the alternate universe of movies, where everyone appears to use them), that I think it's unlikely this problem will have any long-term effect. Hackers are unlikely to exploit this hole the way they have Windows failings.
If the Macintosh OS ever became dominant, the tables would turn, and there would be just as many reports of viruses, security holes, and attacks on it as we currently have with Windows. As one Macophile I spoke with noted, no one has even bothered to exploit this security flaw. I doubt anyone will. Meanwhile, we can already see what happens when Apple has a broadly popular product that cuts across platforms. The Apple iPod is the number one MP3 player, and now that its companion computer utility, iTunes, is available for both the Mac and the PC, it has become a hack target. In fact, Jon Lech Johansen, the same Norwegian who cracked the DVD security code, recently circumvented the iTunes music protection scheme. An event like that occurring makes sense to me, since iTunes' popularity makes it a target worth hacking—and whatever mystical Mac mojo there may be, it didn't go far in protecting a popular Apple product.…
http://www.pcmag.com/article2/0,4149,1408924,00.asp
Don't Let These Security Gotcha's Get Your Database:
"Securing the database is top of mind at most organizations now more than ever. How not? As it is, Slammer slapped us last winter, Microsoft had yet another SQL Server Hotfix patch out as of Friday, and Oracle on Friday put out a high-severity security alert warning of Secure Sockets Layer (SSL) vulnerabilities that require immediate attention."
No matter how locked-down-by-default Oracle 10g gets …, no matter how automated SQL Server security patches get, database administrators and security officers are still making mistakes that can easily be avoided.
http://www.eweek.com/print_article/0,3048,a=114260,00.asp
"Securing the database is top of mind at most organizations now more than ever. How not? As it is, Slammer slapped us last winter, Microsoft had yet another SQL Server Hotfix patch out as of Friday, and Oracle on Friday put out a high-severity security alert warning of Secure Sockets Layer (SSL) vulnerabilities that require immediate attention."
No matter how locked-down-by-default Oracle 10g gets …, no matter how automated SQL Server security patches get, database administrators and security officers are still making mistakes that can easily be avoided.
http://www.eweek.com/print_article/0,3048,a=114260,00.asp
Secunia - Advisories - Internet Explorer URL Spoofing Vulnerability:
"A vulnerability has been identified in Internet Explorer, which can be exploited by malicious people to display a fake URL in the address and status bars.
The vulnerability is caused due to an input validation error, which can be exploited by including the '%01' and '%00' URL encoded representations after the username and right before the '@' character in an URL.
Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address and status bars, which is different from the actual location of the page. "
This can be exploited to trick users into divulging sensitive information or download and execute malware on their systems, because they trust the faked domain in the two bars.
Example displaying only "http://www.trusted_site.com" in the two bars when the real domain is "malicious_site.com":
http://www.trusted_site.com%01%00@malicious_site.com/malicious.html
A test is available at:
http://www.secunia.com/internet_explorer_address_bar_spoofing_test/
The vulnerability has been confirmed in version 6.0. However, prior versions may also be affected.…
http://www.secunia.com/advisories/10395
"A vulnerability has been identified in Internet Explorer, which can be exploited by malicious people to display a fake URL in the address and status bars.
The vulnerability is caused due to an input validation error, which can be exploited by including the '%01' and '%00' URL encoded representations after the username and right before the '@' character in an URL.
Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address and status bars, which is different from the actual location of the page. "
This can be exploited to trick users into divulging sensitive information or download and execute malware on their systems, because they trust the faked domain in the two bars.
Example displaying only "http://www.trusted_site.com" in the two bars when the real domain is "malicious_site.com":
http://www.trusted_site.com%01%00@malicious_site.com/malicious.html
A test is available at:
http://www.secunia.com/internet_explorer_address_bar_spoofing_test/
The vulnerability has been confirmed in version 6.0. However, prior versions may also be affected.…
http://www.secunia.com/advisories/10395
On 'Seamless Computing' and Other Microspeak:
"You can tell a lot about a company by the phrases it coins. And Microsoft continues to mint some telltale ones.
More than a few Microsoft-spawned terms have made their way into the wider tech lexicon. Think 'dogfooding,' 'show stopper,' 'three-finger salute,' etc.
(Hats off to the MicroNews crew, the folks who produce Microsoft's internal company newsletter, for keeping tabs on the latest lingo from Redmond, documenting everything from 'blibbets' to 'Lake Bill.')"
Check a Partial Guide to Microspeak (from MicroNews)
But Microspeak is always morphing. Just this past week, we heard Chairman Bill Gates toss around his seeming new favorite: "Seamless Computing." Gates used the term in both his Comdex keynote and subsequent press interviews, ad nauseum.
Microsoft execs first began talking about seamless computing (no "TM," but Microsoft is using initial caps when referring to the term) back in 2001, when the company rolled out Windows XP.
Microsoft seems to be equating Seamless Computing with interoperability. But Redmond's kind of Seamless Computing isn't focused interoperability among heterogeneous systems and software from different vendors (which is what most folks mean when they talk interoperability). Instead, Seamless Computing, according to Microsoft, is all about interconnecting Windows-based systems, from the Auto PC, to the Media Center PC, to the data-center hub.…
http://www.gisuser.co.nz/pdfs/MicroSpeak.pdf
http://www.microsoft-watch.com/article2/0,4248,1394053,00.asp
"You can tell a lot about a company by the phrases it coins. And Microsoft continues to mint some telltale ones.
More than a few Microsoft-spawned terms have made their way into the wider tech lexicon. Think 'dogfooding,' 'show stopper,' 'three-finger salute,' etc.
(Hats off to the MicroNews crew, the folks who produce Microsoft's internal company newsletter, for keeping tabs on the latest lingo from Redmond, documenting everything from 'blibbets' to 'Lake Bill.')"
Check a Partial Guide to Microspeak (from MicroNews)
But Microspeak is always morphing. Just this past week, we heard Chairman Bill Gates toss around his seeming new favorite: "Seamless Computing." Gates used the term in both his Comdex keynote and subsequent press interviews, ad nauseum.
Microsoft execs first began talking about seamless computing (no "TM," but Microsoft is using initial caps when referring to the term) back in 2001, when the company rolled out Windows XP.
Microsoft seems to be equating Seamless Computing with interoperability. But Redmond's kind of Seamless Computing isn't focused interoperability among heterogeneous systems and software from different vendors (which is what most folks mean when they talk interoperability). Instead, Seamless Computing, according to Microsoft, is all about interconnecting Windows-based systems, from the Auto PC, to the Media Center PC, to the data-center hub.…
http://www.gisuser.co.nz/pdfs/MicroSpeak.pdf
http://www.microsoft-watch.com/article2/0,4248,1394053,00.asp
Wednesday, December 10, 2003
News: Developers take Linux attacks to heart:
"During the last four months, unknown intruders have breached the security around servers hosting programs and code published by the Linux kernel development team, the Debian Project, the Gentoo Linux Project and the GNU Project, which manages the development of many important programs used by Linux and other Unix-like systems. The attacks have convinced open-source project leaders to take another look at their security. "
"It is a definite eyebrow raiser that there has been this targeting of open-source servers and core open-source development servers," said Corey Shields, a member of the infrastructure team that overseas the distribution system for Gentoo Linux's code. "The worry is that if someone wanted to be malicious, they could change core software and users could be using corrupted packages."
Although the open-source model has led to immense progress in developing a competing operating system to Microsoft's Windows--long a target of hackers--it now seems to be a magnet for attackers itself. In a sort of backhanded compliment, attackers are aiming at the Linux OS and other open-source applications because of the software's popularity. Even developers who believe they've adequately secured their development systems are looking at the trend with some trepidation.
"It is one of those things where you have to hope you are not next and try to be one step ahead of the bad guys," said Jeremy Allison, co-founder and developer of the Samba Project, the programming effort for the popular open-source file server that seamlessly fits into Windows networks.
On Dec. 1, an attack on Gentoo Linux compromised one of 105 volunteer-run servers that make copies of Gentoo's source code available to users. The attack, however, didn't threaten the main source-code database. Moreover, security software on the targeted server detected the attack quickly and kept a detailed record of it.
The incident followed a November attack on the Linux kernel, which similarly happened because another system--this time a developer's--had been breached and used as a stepping-stone. The attacker used the developer's machine to submit code to a secondary server, code that could have been used by a later attacker to gain access to any systems that installed it. That attack also was detected within 24 hours.
Other incidents in the rash of attacks have been more serious.
Intruders gained access to the GNU Project's development system, Savannah, and in a separate incident, to four Debian Project servers used to manage development and community efforts for that Linux distribution.
Both attacks were similarly executed: An attacker managed to garner a legitimate user's log-in name and password and then used a recently discovered vulnerability in the Linux kernel to gain the rights and privileges of the system's owners. Both Debian and GNU Project leaders continue to keep the systems offline--and inaccessible to developers--until they can ensure they're secure.
The GNU Project said the latest attack, and another one that compromised the project's file transfer servers last March, had prompted its leadership to make changes.…
http://zdnet.com.com/2100-1105_2-5117271.html
"During the last four months, unknown intruders have breached the security around servers hosting programs and code published by the Linux kernel development team, the Debian Project, the Gentoo Linux Project and the GNU Project, which manages the development of many important programs used by Linux and other Unix-like systems. The attacks have convinced open-source project leaders to take another look at their security. "
"It is a definite eyebrow raiser that there has been this targeting of open-source servers and core open-source development servers," said Corey Shields, a member of the infrastructure team that overseas the distribution system for Gentoo Linux's code. "The worry is that if someone wanted to be malicious, they could change core software and users could be using corrupted packages."
Although the open-source model has led to immense progress in developing a competing operating system to Microsoft's Windows--long a target of hackers--it now seems to be a magnet for attackers itself. In a sort of backhanded compliment, attackers are aiming at the Linux OS and other open-source applications because of the software's popularity. Even developers who believe they've adequately secured their development systems are looking at the trend with some trepidation.
"It is one of those things where you have to hope you are not next and try to be one step ahead of the bad guys," said Jeremy Allison, co-founder and developer of the Samba Project, the programming effort for the popular open-source file server that seamlessly fits into Windows networks.
On Dec. 1, an attack on Gentoo Linux compromised one of 105 volunteer-run servers that make copies of Gentoo's source code available to users. The attack, however, didn't threaten the main source-code database. Moreover, security software on the targeted server detected the attack quickly and kept a detailed record of it.
The incident followed a November attack on the Linux kernel, which similarly happened because another system--this time a developer's--had been breached and used as a stepping-stone. The attacker used the developer's machine to submit code to a secondary server, code that could have been used by a later attacker to gain access to any systems that installed it. That attack also was detected within 24 hours.
Other incidents in the rash of attacks have been more serious.
Intruders gained access to the GNU Project's development system, Savannah, and in a separate incident, to four Debian Project servers used to manage development and community efforts for that Linux distribution.
Both attacks were similarly executed: An attacker managed to garner a legitimate user's log-in name and password and then used a recently discovered vulnerability in the Linux kernel to gain the rights and privileges of the system's owners. Both Debian and GNU Project leaders continue to keep the systems offline--and inaccessible to developers--until they can ensure they're secure.
The GNU Project said the latest attack, and another one that compromised the project's file transfer servers last March, had prompted its leadership to make changes.…
http://zdnet.com.com/2100-1105_2-5117271.html
EasyRGB - Color harmonies, complements and themes.:
"Search for colors complements to your RGB values.
Create color harmonies, combinations and themes.
From your main (or background) color select trim and accents tones."
http://www.easyrgb.com/harmonies.php
"Search for colors complements to your RGB values.
Create color harmonies, combinations and themes.
From your main (or background) color select trim and accents tones."
http://www.easyrgb.com/harmonies.php
Tuesday, December 09, 2003
CSS Design: Creating Custom Corners & Borders: A List Apart:
http://www.alistapart.com/articles/customcorners/
We’ve all heard the rap:
“Sites designed with CSS tend to be boxy and hard-edged. Where are the rounded corners?”
Answer: the rounded corners are right here. In this article, we’ll show how customized borders and corners can be applied to fully fluid and flexible layouts with dynamic
content, using sound and semantically logical markup.
http://www.alistapart.com/articles/customcorners/
News: U.N. confab to see tussle over Net control:
"Leaders from nearly 200 countries will convene in Geneva for the World Summit on the Information Society (WSIS) on Dec. 10-12, an inaugural conference with lofty goals to discuss bridging the digital divide and fostering press freedoms.
But a contentious political move to grant an international governing body such as the U.N.'s International Telecommunication Union (ITU) control over Internet governance issues--from distributing Web site domains to the public to fighting spam--has all but obscured the more virtuous aspects of the event. "
…the Internet has become a thriving global marketplace since being fully turned over to the private business community in the early 1990s.
But many in the developing world believe a new approach is needed as the medium enters its teen years, one that will see poorer countries harness new technologies to improve their competitive stance.
The most recognizable Internet governance body is a California-based nonprofit company, the International Corporation for Assigned Names and Numbers (ICANN). Under the new plan, it has the most to lose. Incorporated in 1998, ICANN oversees management of the Internet's crucial addressing system which matches numerical addresses to familiar Web site addresses such as www.google.com.
While ICANN's oversight has been confined to the decidedly technical matters behind doling out domain names and establishing a system for resolving domain name disputes, the group has been criticized roundly for adopting a probusiness approach that neglects the developing world.
The ITU, a 138-year-old trade body that among other things established country code rules for international telephone dialing, has been put forth by the developing world as the governing body that will best address its needs.…
So far, a change in leadership has been bogged down by fractious discussion with a definitive resolution not expected until 2005 when the second WSIS summit is held in Tunisia.
But many believe the new guard has already arrived.…
http://zdnet.com.com/2100-1104_2-5113744.html?tag=adnews
"Leaders from nearly 200 countries will convene in Geneva for the World Summit on the Information Society (WSIS) on Dec. 10-12, an inaugural conference with lofty goals to discuss bridging the digital divide and fostering press freedoms.
But a contentious political move to grant an international governing body such as the U.N.'s International Telecommunication Union (ITU) control over Internet governance issues--from distributing Web site domains to the public to fighting spam--has all but obscured the more virtuous aspects of the event. "
…the Internet has become a thriving global marketplace since being fully turned over to the private business community in the early 1990s.
But many in the developing world believe a new approach is needed as the medium enters its teen years, one that will see poorer countries harness new technologies to improve their competitive stance.
The most recognizable Internet governance body is a California-based nonprofit company, the International Corporation for Assigned Names and Numbers (ICANN). Under the new plan, it has the most to lose. Incorporated in 1998, ICANN oversees management of the Internet's crucial addressing system which matches numerical addresses to familiar Web site addresses such as www.google.com.
While ICANN's oversight has been confined to the decidedly technical matters behind doling out domain names and establishing a system for resolving domain name disputes, the group has been criticized roundly for adopting a probusiness approach that neglects the developing world.
The ITU, a 138-year-old trade body that among other things established country code rules for international telephone dialing, has been put forth by the developing world as the governing body that will best address its needs.…
So far, a change in leadership has been bogged down by fractious discussion with a definitive resolution not expected until 2005 when the second WSIS summit is held in Tunisia.
But many believe the new guard has already arrived.…
http://zdnet.com.com/2100-1104_2-5113744.html?tag=adnews
Fighting Phishing:
"Phishing, e-mail and Web-based efforts by online scammers to hijack personal information from unsuspecting users, faces a new obstacle. A group of global banks and technology companies have joined forces to fight the scams. The group is running a Web site, Anti-Phishing.Org (www.antiphishing.org), where those who have received phishing messages can report them, and personnel will follow up by trying to track down the originators of the scams."
http://www.pcmag.com/article2/0,4149,1407031,00.asp
"Phishing, e-mail and Web-based efforts by online scammers to hijack personal information from unsuspecting users, faces a new obstacle. A group of global banks and technology companies have joined forces to fight the scams. The group is running a Web site, Anti-Phishing.Org (www.antiphishing.org), where those who have received phishing messages can report them, and personnel will follow up by trying to track down the originators of the scams."
http://www.pcmag.com/article2/0,4149,1407031,00.asp
Could The Bad Guys Win on Spam?: http://eletters.eweek.com/zd1/cts?d=79-356-2-3-13145-42538-1
"Spam and mail-based attacks are coming to dominate Internet e-mail. Nothing seems able to stop them, and some days it's rare to find real mail among the spam. Could it come to the point that it's not worth dealing with e-mail's problems?"
On some days, life in the security business is more depressing than on others. My recent reading about Mimail.L, the latest in a long line of sociopathic worms, tipped me into the blues.
Mimail.L is particularly vile. Here are some of the actions it takes:
So, not only is this a particularly offensive worm, but it specifically attacks anti-spam sites! Do the authors of the worm have a particular problem with these groups? Perhaps, or maybe it's just more anti-social behavior. They also attack Register.com, but I doubt they're opposed to domain name registration on principal
After reading about this I'm tempted to agree with a poster on a Slashdot thread on Mimail.L: "They won't stop 'til they've destroyed e-mail." We keep hearing about the ever-increasing percentage of Internet e-mail that is composed of spam. The latest consensus I hear is "over 50 percent," but you can bet your last "F_R_E_E whatever" that the number will continue to climb.…
http://www.eweek.com/article2/0,4149,1403354,00.asp?kc=EWNWS120903DTX1K0000599
"Spam and mail-based attacks are coming to dominate Internet e-mail. Nothing seems able to stop them, and some days it's rare to find real mail among the spam. Could it come to the point that it's not worth dealing with e-mail's problems?"
On some days, life in the security business is more depressing than on others. My recent reading about Mimail.L, the latest in a long line of sociopathic worms, tipped me into the blues.
Mimail.L is particularly vile. Here are some of the actions it takes:
- It arrives as a pornographic e-mail with an attached ZIP file purporting to contain dirty pictures. That file contains a file with a .jpg.exe extension, so if someone runs it to see the picture they actually infect themselves. As always, this subterfuge works far more often than I'd like to think, but so far it's just a run of the mill worm.
- It scours the hard disk for e-mail addresses and stores them in a file named xu298da.tmp in the Windows folder. It then mails itself out with the same porno message to these addresses.
- If there's a problem sending that mail, it instead tries to send a different message without the attachment. This fallback message says that the recipient's credit card has been charged for a purchase of child pornography. It directs the reader, if they want to cancel, to contact security@europe.spamhaus.org.
- The message also lists more than a half a dozen sites as places you can get more kiddy porn, including Disney.go.com, Spamcop.net and Spews.org, and attempts to perform a denial of service attack on these sites..
So, not only is this a particularly offensive worm, but it specifically attacks anti-spam sites! Do the authors of the worm have a particular problem with these groups? Perhaps, or maybe it's just more anti-social behavior. They also attack Register.com, but I doubt they're opposed to domain name registration on principal
After reading about this I'm tempted to agree with a poster on a Slashdot thread on Mimail.L: "They won't stop 'til they've destroyed e-mail." We keep hearing about the ever-increasing percentage of Internet e-mail that is composed of spam. The latest consensus I hear is "over 50 percent," but you can bet your last "F_R_E_E whatever" that the number will continue to climb.…
http://www.eweek.com/article2/0,4149,1403354,00.asp?kc=EWNWS120903DTX1K0000599
News: Worm hits Windows-based ATMs:
"An unknown number of ATMs running Windows XP Embedded were shut down during the spread of the so-called Nachi worm, said executives at Diebold, which made the ATMs and refused to name the customers affected.
The Nachi worm, also dubbed 'Welchia,' was written to clean up after the MSBlast, or Blaster, worm. Instead it crippled or congested networks around the world, including the check-in system at Air Canada. Both worms spread through a hole in Windows XP, 2000, NT and Server 2003. "
"It's a harbinger of things to come," said Bruce Schneier, chief technical officer of network monitoring company Counterpane Internet Security.
"Specific-purpose machines, like microwave ovens and until now ATM machines, never got viruses," said Schneier, author of "Beyond Fear: Thinking Sensibly About Security in an Uncertain World." "Now that they are using a general purpose operating system, Diebold should expect a lot more of this in the future," he said.
John Pescatore, an analyst at Gartner, agreed.
"It's a horrendous security mistake," he said of specific-purpose machines like ATMs running Windows, which is written for general-purpose computers and for which Microsoft releases security fixes on a regular basis. "I'm a lot more worried about my money than I was before this."
Diebold switched from using IBM's OS/2 on its ATMs because banks were requesting Windows, said Steve Grzymkowski, senior product marketing manager at Diebold.
To help prevent future problems Diebold is shipping ATMs with firewall software designed to block out viruses and other attacks, he said.
"As far as it happening again, I wouldn't want to speculate on that," Grzymkowski said.
Schneier and Pescatore said they were worried about the security of other Windows-based Diebold appliances--voting machines, which run Windows CE.…
http://zdnet.com.com/2100-1105_2-5117285.html
"An unknown number of ATMs running Windows XP Embedded were shut down during the spread of the so-called Nachi worm, said executives at Diebold, which made the ATMs and refused to name the customers affected.
The Nachi worm, also dubbed 'Welchia,' was written to clean up after the MSBlast, or Blaster, worm. Instead it crippled or congested networks around the world, including the check-in system at Air Canada. Both worms spread through a hole in Windows XP, 2000, NT and Server 2003. "
"It's a harbinger of things to come," said Bruce Schneier, chief technical officer of network monitoring company Counterpane Internet Security.
"Specific-purpose machines, like microwave ovens and until now ATM machines, never got viruses," said Schneier, author of "Beyond Fear: Thinking Sensibly About Security in an Uncertain World." "Now that they are using a general purpose operating system, Diebold should expect a lot more of this in the future," he said.
John Pescatore, an analyst at Gartner, agreed.
"It's a horrendous security mistake," he said of specific-purpose machines like ATMs running Windows, which is written for general-purpose computers and for which Microsoft releases security fixes on a regular basis. "I'm a lot more worried about my money than I was before this."
Diebold switched from using IBM's OS/2 on its ATMs because banks were requesting Windows, said Steve Grzymkowski, senior product marketing manager at Diebold.
To help prevent future problems Diebold is shipping ATMs with firewall software designed to block out viruses and other attacks, he said.
"As far as it happening again, I wouldn't want to speculate on that," Grzymkowski said.
Schneier and Pescatore said they were worried about the security of other Windows-based Diebold appliances--voting machines, which run Windows CE.…
http://zdnet.com.com/2100-1105_2-5117285.html
Welcome to TechBuilder.org:
"Secure wireless networking can be a reality, but only if you employ some very straightforward techniques."
http://www.techbuilder.org./article.htm?ArticleID=46364
"Secure wireless networking can be a reality, but only if you employ some very straightforward techniques."
http://www.techbuilder.org./article.htm?ArticleID=46364
Monday, December 08, 2003
Op-Ed Contributor: A Million Miles From the Green Zone to the Front Lines:
"The other day I told General Petraeus about a young specialist fourth class I had met while waiting for a military flight out of Baghdad. The specialist was a college student from Iowa whose National Guard unit had been called up for the war. He had told me about a prolonged firefight that took place the week before, outside Camp Anaconda on the outskirts of the city of Balad, 40 miles from Baghdad.
'We began taking small arms fire about 8 a.m., from Abu Shakur, the village just north of the base camp's gate,' the specialist told me. 'Our guys responded with small arms and then mortars. Someone on patrol outside the wire got wounded, and they sent Bradley Fighting Vehicles out, and they hit the Bradleys pretty hard, and by 10 a.m., they were firing 155-millimeter howitzers, and attack helicopters were firing missiles into the village, and you could see tracers and smoke everywhere.
'I had just gotten off a night shift, and I was sitting outside my tent about 100 meters from the gate in my pajamas reading a book. Right near me, guys were doing laundry and standing in line for chow. I was sitting there thinking: `Have we had wars like this before? Shouldn't we drop everything and help? I mean, we were spectators! What kind of war is this, sir?' '"
General Petraeus, who graduated from West Point in 1974, just in time to witness the ignominious end to the war in Vietnam, didn't say anything. But slowly, and it seemed, unconsciously, his head began to nod, and his mind seemed far, far away. It seemed clear he knew the answer: yes, specialist, we have had wars like this before.
Commanding generals have had lavishly appointed offices before, as well. My grandfather, Gen. Lucian K. Truscott Jr., occupied the Borghese Palace when his VI Corps swept into Rome in 1943. His aide kept a record of the meals prepared for him by his three Chinese cooks, while every day dozens — and on some days, hundreds — of his soldiers perished on the front lines at Anzio, only a few miles away from his villa on the beach.
So there may be nothing new about this war and the way we are fighting it — with troops on day and night patrols from base camps being hit by a nameless, faceless enemy they cannot see and whose language they do not speak. However, the disconnect between the marbled hallways of the Coalition Provisional Authority palaces in Baghdad and the grubby camp in central Mosul where I spent last week as a guest of Bravo Company, First Battalion, 502nd Infantry Regiment, is profound, and perhaps unprecedented.
An colonel in Baghdad (who will go nameless here for obvious reasons) told me just after I arrived that senior Army officers feel every order they receive is delivered with next November's election in mind, so there is little doubt at and near the top about who is really being used for what over here. The resentment in the ranks toward the civilian leadership in Baghdad and back in Washington is palpable. Another officer described the two camps, military and civilian, inhabiting the heavily fortified, gold-leafed presidential palace inside the so-called Green Zone in Baghdad, as "a divorced couple who won't leave the house."
Meanwhile in Mosul, the troops of Bravo Company bunker down amid smells of diesel fuel and burning trash and rotting vegetables and dishwater and human waste from open sewers running though the maze of stone and mud alleyways in the Old City across the street. Bravo Company's area of operations would be an assault on the senses even without the nightly rattle of AK-47 fire in the nearby streets, and the two rocket-propelled grenade rounds fired at the soldiers a couple of weeks ago.
It is difficult enough for the 120 or so men of Bravo Company to patrol their overcrowded sector of this city of maybe two million people and keep its streets safe and free of crime. But from the first day they arrived in Mosul, Bravo Company and the rest of the 101st Airborne Division were saddled with dozens of other missions, all of them distinctly nonmilitary, and most of them made necessary by the failure of civilian leaders in Washington and Baghdad to prepare for the occupation of Iraq.
The 101st entered Mosul on April 22 to find the city's businesses, civil ministries and utilities looted and its people rioting in the streets. By May 5, the soldiers had supervised elections for mayor and city council. On May 11, they oversaw the signing of harvest accords and the division of wheat profits among the region's frequently warring factions of Arabs, Kurds, Turkmen and Assyrians. On May 14, a company commander of Alpha Company, Third Battalion, 187th Infantry Regiment of the 101st re-opened the Syrian border for trade, and by May 18, soldiers had largely restored the flow of automobile gas and cooking propane, shortages of which had been causing riots.
Since that time, soldiers from the 101st have overseen tens of millions of dollars worth of reconstruction projects: drilling wells for villages that had never had their own water supply; rebuilding playgrounds and schools; repairing outdated and broken electrical systems; installing satellite equipment needed to get the regional phone system up and running; restoring the city's water works; repairing sewers and in some cases installing sewage systems in neighborhoods that had never had them; policing, cleaning and reorganizing the ancient marketplace in the Old City; setting up a de facto social security system to provide "retirement" pay to the 110,000 former Iraqi soldiers in the area; screening and, in most cases, putting back to work most of the former Baath Party members who fled their jobs at the beginning of the war.
So many civil projects were reported on at a recent battle update briefing I attended that staff officers sometimes sounded more like board members of a multinational corporation than the combat-hardened infantry soldiers they are.…The Coalition Provisional Authority nominally has the job of "rebuilding" Iraq — using $20 billion or so of the $78 billion that recently flew out of America's deficit-plagued coffers. But during the time the 101st has been in Mosul, three regional coalition authority directors have come and gone. Only recently, long after the people of Mosul elected their mayor and city council, was a civilian American governance official sent to the area. And, according to the division leadership, not a nickel of the $20 billion controlled by the provisional authority has reached them.
"First they want a planning contractor to come in here, and even that step takes weeks to get approved," one officer in Mosul complained of the civilian leadership. "The planners were up here for months doing assessments, and then more weeks go by because everything has to be approved by Baghdad. If we sat around waiting for the C.P.A. and its civilian contractors to do it, we still wouldn't have electricity and running water in Mosul, so we just took our own funds and our engineers and infantry muscle and did it ourselves. We didn't have the option of waiting on the guys in the Green Zone."
But the guys in the Green Zone seem to have plenty of time on their hands. The place is something to behold, surrounded on one side by the heavily patrolled Tigris River, and on the three others by a 15-foot-high concrete wall backed by several rows of concertina razor wire and a maze of lesser concrete barriers. There's only one way in and out, through a heavily fortified checkpoint near the Jumhiriya Bridge guarded by tanks and Bradley Fighting Vehicles from the First Armored Division and an invisible array of British commando teams. More tanks guard key intersections inside the walls, machine gun towers line the wide boulevards, snipers man firing positions atop palaces great and small.
In all, hundreds of uniformed soldiers and heavily armed civilian security guards stand watch all day, every day over a display of grim garishness that would have given Liberace nightmares. If you're curious about how your tax dollars are being spent in Baghdad, you should get one of the many colonels strolling about the Green Zone to take you on a tour of the rebuilt duck pond across the road from the marble and gold-leafed palace serving as headquarters of an Army brigade. As I went to sleep one night a couple of weeks ago in the Green Zone, listening to the gurgle of the duck pond fountain and the comforting roar of Black Hawk helicopters patrolling overhead, it occurred to me that it was the safest night I've spent in about 25 years.
Which was a blessing for me, but a curse on the war effort. The super-defended Green Zone is the biggest, most secure American base camp in Iraq, but there is little connection between the troops in the field and the bottomless pit of planners and deciders who live inside the palace. Soldiers from the 101st tell me that they waited months for the Bechtel Corporation to unleash its corporate might in northern Iraq. "Then one of the Bechtel truck convoys got ambushed on the way up here three weeks ago, and one of the security guys got wounded," an infantryman told me. "They abandoned their trucks on the spot and pulled out, and we haven't seen them since."
"It's really not helpful when people down in Baghdad and politicians back in Washington refer to the `disorganized and ineffective' enemy we supposedly face," said one young officer, as we walked out of a battalion battle briefing that had been concerned largely with the tactics of an enemy force that is clearly well organized and very, very effective. After spending more than a week with the soldiers of Bravo Company, I know that they resent not only the inaccuracy of such statements, but the implication that soldiers facing a disorganized and ineffective enemy have an easy job.
No matter what you call this stage of the conflict in Iraq — the soldiers call it a guerrilla war while politicians back home often refer to it misleadingly and inaccurately as part of the amorphous "war on terror" — it is without a doubt a nasty, deadly war. And the people doing the fighting are soldiers, not the civilian employees of Kellogg, Brown & Root, or the officials of the Coalition Provisional Authority, or the visiting bigwigs from the Defense Department.
The troops in Bravo Company don't pay much attention to the rear-guard political wars being waged back in Washington, but they loved President Bush's quick visit to Baghdad on Thanksgiving. While it was clearly a political stunt, they were quick to credit the risks he took. I can confirm that flying in and out of Baghdad — even at night, when it's safest — is not for the faint of heart. A C-130 on approach takes a nervous, dodgy route, banking this way and that, gaining and losing altitude. Hanging onto one of those web-seats by only a seat belt (no shoulder harnesses), you're nearly upside down half the time — it would feel like the ultimate roller-coaster ride, except it's very much for real.
When Bravo Company troops roll out of the rack at 2 a.m. for street patrols, they walk the broad boulevards and narrow alleyways spread out as if they're walking a jungle trail — wheeling to the rear, sideways, back to the front; their eyes searching doorways, alleys, windows, rooftops, passing cars, even donkey carts — trying to keep one another alive for another day, another week, another month, whatever it takes to get home.
Meanwhile, two soldiers armed with M-4 carbines and fearsome M-249 Saws machine guns stand guard inside concrete and sandbag bunkers atop the Bravo Company camp's roof, while squads of soldiers patrol alleys with no names in Mosul's Old City, and everyone prays.
http://www.nytimes.com/2003/12/07/opinion/07TRUS.html?pagewanted=all&position=
"The other day I told General Petraeus about a young specialist fourth class I had met while waiting for a military flight out of Baghdad. The specialist was a college student from Iowa whose National Guard unit had been called up for the war. He had told me about a prolonged firefight that took place the week before, outside Camp Anaconda on the outskirts of the city of Balad, 40 miles from Baghdad.
'We began taking small arms fire about 8 a.m., from Abu Shakur, the village just north of the base camp's gate,' the specialist told me. 'Our guys responded with small arms and then mortars. Someone on patrol outside the wire got wounded, and they sent Bradley Fighting Vehicles out, and they hit the Bradleys pretty hard, and by 10 a.m., they were firing 155-millimeter howitzers, and attack helicopters were firing missiles into the village, and you could see tracers and smoke everywhere.
'I had just gotten off a night shift, and I was sitting outside my tent about 100 meters from the gate in my pajamas reading a book. Right near me, guys were doing laundry and standing in line for chow. I was sitting there thinking: `Have we had wars like this before? Shouldn't we drop everything and help? I mean, we were spectators! What kind of war is this, sir?' '"
General Petraeus, who graduated from West Point in 1974, just in time to witness the ignominious end to the war in Vietnam, didn't say anything. But slowly, and it seemed, unconsciously, his head began to nod, and his mind seemed far, far away. It seemed clear he knew the answer: yes, specialist, we have had wars like this before.
Commanding generals have had lavishly appointed offices before, as well. My grandfather, Gen. Lucian K. Truscott Jr., occupied the Borghese Palace when his VI Corps swept into Rome in 1943. His aide kept a record of the meals prepared for him by his three Chinese cooks, while every day dozens — and on some days, hundreds — of his soldiers perished on the front lines at Anzio, only a few miles away from his villa on the beach.
So there may be nothing new about this war and the way we are fighting it — with troops on day and night patrols from base camps being hit by a nameless, faceless enemy they cannot see and whose language they do not speak. However, the disconnect between the marbled hallways of the Coalition Provisional Authority palaces in Baghdad and the grubby camp in central Mosul where I spent last week as a guest of Bravo Company, First Battalion, 502nd Infantry Regiment, is profound, and perhaps unprecedented.
An colonel in Baghdad (who will go nameless here for obvious reasons) told me just after I arrived that senior Army officers feel every order they receive is delivered with next November's election in mind, so there is little doubt at and near the top about who is really being used for what over here. The resentment in the ranks toward the civilian leadership in Baghdad and back in Washington is palpable. Another officer described the two camps, military and civilian, inhabiting the heavily fortified, gold-leafed presidential palace inside the so-called Green Zone in Baghdad, as "a divorced couple who won't leave the house."
Meanwhile in Mosul, the troops of Bravo Company bunker down amid smells of diesel fuel and burning trash and rotting vegetables and dishwater and human waste from open sewers running though the maze of stone and mud alleyways in the Old City across the street. Bravo Company's area of operations would be an assault on the senses even without the nightly rattle of AK-47 fire in the nearby streets, and the two rocket-propelled grenade rounds fired at the soldiers a couple of weeks ago.
It is difficult enough for the 120 or so men of Bravo Company to patrol their overcrowded sector of this city of maybe two million people and keep its streets safe and free of crime. But from the first day they arrived in Mosul, Bravo Company and the rest of the 101st Airborne Division were saddled with dozens of other missions, all of them distinctly nonmilitary, and most of them made necessary by the failure of civilian leaders in Washington and Baghdad to prepare for the occupation of Iraq.
The 101st entered Mosul on April 22 to find the city's businesses, civil ministries and utilities looted and its people rioting in the streets. By May 5, the soldiers had supervised elections for mayor and city council. On May 11, they oversaw the signing of harvest accords and the division of wheat profits among the region's frequently warring factions of Arabs, Kurds, Turkmen and Assyrians. On May 14, a company commander of Alpha Company, Third Battalion, 187th Infantry Regiment of the 101st re-opened the Syrian border for trade, and by May 18, soldiers had largely restored the flow of automobile gas and cooking propane, shortages of which had been causing riots.
Since that time, soldiers from the 101st have overseen tens of millions of dollars worth of reconstruction projects: drilling wells for villages that had never had their own water supply; rebuilding playgrounds and schools; repairing outdated and broken electrical systems; installing satellite equipment needed to get the regional phone system up and running; restoring the city's water works; repairing sewers and in some cases installing sewage systems in neighborhoods that had never had them; policing, cleaning and reorganizing the ancient marketplace in the Old City; setting up a de facto social security system to provide "retirement" pay to the 110,000 former Iraqi soldiers in the area; screening and, in most cases, putting back to work most of the former Baath Party members who fled their jobs at the beginning of the war.
So many civil projects were reported on at a recent battle update briefing I attended that staff officers sometimes sounded more like board members of a multinational corporation than the combat-hardened infantry soldiers they are.…The Coalition Provisional Authority nominally has the job of "rebuilding" Iraq — using $20 billion or so of the $78 billion that recently flew out of America's deficit-plagued coffers. But during the time the 101st has been in Mosul, three regional coalition authority directors have come and gone. Only recently, long after the people of Mosul elected their mayor and city council, was a civilian American governance official sent to the area. And, according to the division leadership, not a nickel of the $20 billion controlled by the provisional authority has reached them.
"First they want a planning contractor to come in here, and even that step takes weeks to get approved," one officer in Mosul complained of the civilian leadership. "The planners were up here for months doing assessments, and then more weeks go by because everything has to be approved by Baghdad. If we sat around waiting for the C.P.A. and its civilian contractors to do it, we still wouldn't have electricity and running water in Mosul, so we just took our own funds and our engineers and infantry muscle and did it ourselves. We didn't have the option of waiting on the guys in the Green Zone."
But the guys in the Green Zone seem to have plenty of time on their hands. The place is something to behold, surrounded on one side by the heavily patrolled Tigris River, and on the three others by a 15-foot-high concrete wall backed by several rows of concertina razor wire and a maze of lesser concrete barriers. There's only one way in and out, through a heavily fortified checkpoint near the Jumhiriya Bridge guarded by tanks and Bradley Fighting Vehicles from the First Armored Division and an invisible array of British commando teams. More tanks guard key intersections inside the walls, machine gun towers line the wide boulevards, snipers man firing positions atop palaces great and small.
In all, hundreds of uniformed soldiers and heavily armed civilian security guards stand watch all day, every day over a display of grim garishness that would have given Liberace nightmares. If you're curious about how your tax dollars are being spent in Baghdad, you should get one of the many colonels strolling about the Green Zone to take you on a tour of the rebuilt duck pond across the road from the marble and gold-leafed palace serving as headquarters of an Army brigade. As I went to sleep one night a couple of weeks ago in the Green Zone, listening to the gurgle of the duck pond fountain and the comforting roar of Black Hawk helicopters patrolling overhead, it occurred to me that it was the safest night I've spent in about 25 years.
Which was a blessing for me, but a curse on the war effort. The super-defended Green Zone is the biggest, most secure American base camp in Iraq, but there is little connection between the troops in the field and the bottomless pit of planners and deciders who live inside the palace. Soldiers from the 101st tell me that they waited months for the Bechtel Corporation to unleash its corporate might in northern Iraq. "Then one of the Bechtel truck convoys got ambushed on the way up here three weeks ago, and one of the security guys got wounded," an infantryman told me. "They abandoned their trucks on the spot and pulled out, and we haven't seen them since."
"It's really not helpful when people down in Baghdad and politicians back in Washington refer to the `disorganized and ineffective' enemy we supposedly face," said one young officer, as we walked out of a battalion battle briefing that had been concerned largely with the tactics of an enemy force that is clearly well organized and very, very effective. After spending more than a week with the soldiers of Bravo Company, I know that they resent not only the inaccuracy of such statements, but the implication that soldiers facing a disorganized and ineffective enemy have an easy job.
No matter what you call this stage of the conflict in Iraq — the soldiers call it a guerrilla war while politicians back home often refer to it misleadingly and inaccurately as part of the amorphous "war on terror" — it is without a doubt a nasty, deadly war. And the people doing the fighting are soldiers, not the civilian employees of Kellogg, Brown & Root, or the officials of the Coalition Provisional Authority, or the visiting bigwigs from the Defense Department.
The troops in Bravo Company don't pay much attention to the rear-guard political wars being waged back in Washington, but they loved President Bush's quick visit to Baghdad on Thanksgiving. While it was clearly a political stunt, they were quick to credit the risks he took. I can confirm that flying in and out of Baghdad — even at night, when it's safest — is not for the faint of heart. A C-130 on approach takes a nervous, dodgy route, banking this way and that, gaining and losing altitude. Hanging onto one of those web-seats by only a seat belt (no shoulder harnesses), you're nearly upside down half the time — it would feel like the ultimate roller-coaster ride, except it's very much for real.
When Bravo Company troops roll out of the rack at 2 a.m. for street patrols, they walk the broad boulevards and narrow alleyways spread out as if they're walking a jungle trail — wheeling to the rear, sideways, back to the front; their eyes searching doorways, alleys, windows, rooftops, passing cars, even donkey carts — trying to keep one another alive for another day, another week, another month, whatever it takes to get home.
Meanwhile, two soldiers armed with M-4 carbines and fearsome M-249 Saws machine guns stand guard inside concrete and sandbag bunkers atop the Bravo Company camp's roof, while squads of soldiers patrol alleys with no names in Mosul's Old City, and everyone prays.
http://www.nytimes.com/2003/12/07/opinion/07TRUS.html?pagewanted=all&position=
IE 6.0 - QuirksMode - for all your browser quirks:
"QuirksMode.org is the personal and professional site of Peter-Paul Koch, freelance web developer in Amsterdam, the Netherlands. It contains more than 150 pages with CSS and JavaScript tips and tricks, and is one of the best sources on the WWW for studying and defeating browser incompatibilities.
It is free of charge and ads, and largely free of copyrights."
This site is quite large. The table of contents mostly leads to other tables of contents.
http://www.quirksmode.org/
"QuirksMode.org is the personal and professional site of Peter-Paul Koch, freelance web developer in Amsterdam, the Netherlands. It contains more than 150 pages with CSS and JavaScript tips and tricks, and is one of the best sources on the WWW for studying and defeating browser incompatibilities.
It is free of charge and ads, and largely free of copyrights."
This site is quite large. The table of contents mostly leads to other tables of contents.
http://www.quirksmode.org/
Friday, December 05, 2003
Warning: Look Out for the eBay Scam:
"The trick message arrived with a very official looking header featuring eBay's logo. It was signed 'Thank you, Accounts Management.' The text read: 'Dear eBay Member, We at eBay are sorry to inform you that we are having problems with the billing information of your account. We would appreciate it if you would visit our website, eBay Billing Center, and fill out the proper information that we are needing to keep you as an eBay member.' The 'eBay Billing Center' referenced was a link to a Web page asking for a credit card number, a social security number, and more. The message also contained an 'ebay.com' suffix, just as a real message from an eBay employee might."
As is often true in spoof messages and phishing efforts, the trick e-mail contained telltale signs that it did not come from eBay. The subject line of the message read "eBay Member Billing Information Uptade" with the word "update" misspelled. The text string "fill out the proper information that we are needing" also had suspicious syntax.…
http://www.pcmag.com/article2/0,4149,1402431,00.asp
"The trick message arrived with a very official looking header featuring eBay's logo. It was signed 'Thank you, Accounts Management.' The text read: 'Dear eBay Member, We at eBay are sorry to inform you that we are having problems with the billing information of your account. We would appreciate it if you would visit our website, eBay Billing Center, and fill out the proper information that we are needing to keep you as an eBay member.' The 'eBay Billing Center' referenced was a link to a Web page asking for a credit card number, a social security number, and more. The message also contained an 'ebay.com' suffix, just as a real message from an eBay employee might."
As is often true in spoof messages and phishing efforts, the trick e-mail contained telltale signs that it did not come from eBay. The subject line of the message read "eBay Member Billing Information Uptade" with the word "update" misspelled. The text string "fill out the proper information that we are needing" also had suspicious syntax.…
http://www.pcmag.com/article2/0,4149,1402431,00.asp
News: Antispammers again targeted by worm:
"Antispam organizations are the target of a new Internet worm outbreak that tries to knock them offline with a crippling data barrage, computer security experts said Tuesday.
Virus experts believe the worm, W32/Mimail-L, is the work of a vengeful spam e-mail peddler bent on paralyzing organizations that try to deal with spam, the torrents of get-rich-quick schemes and body-enhancement deals that clog in-boxes daily.
'It's the third Mimail variation to come after us, except this one is trying to do more,' said Steve Linford, founder of The Spamhaus Project, a British-based group that singles out spammers. Spamhaus was hit by Mimail late Monday. "
According to anti-virus and spam-filtering company Sophos Plc, the Mimail-L program comes as an attachment to an e-mail purporting to be from a woman named Wendy who details an erotic encounter and then offers naked photographs.
Clicking on the attachment activates the virus. Once triggered, the worm forwards itself to other e-mail users.
The worm can also turn the affected PC into a "zombie," which can then be remotely commanded to bombard one of a select group of targets, such as Spamhaus, with a disabling blizzard of data--a so-called denial-of-service attack.
In a new twist, a follow-up e-mail is sent to the infected user stating that an order for a CD containing images of child pornography will be delivered to their postal address.
To stop the order, the e-mail advises, they should respond to what appears to be an e-mail address for billing complaints, but which is actually an e-mail for one of the eight targets.…
http://zdnet.com.com/2100-1105_2-5112997.html
"Antispam organizations are the target of a new Internet worm outbreak that tries to knock them offline with a crippling data barrage, computer security experts said Tuesday.
Virus experts believe the worm, W32/Mimail-L, is the work of a vengeful spam e-mail peddler bent on paralyzing organizations that try to deal with spam, the torrents of get-rich-quick schemes and body-enhancement deals that clog in-boxes daily.
'It's the third Mimail variation to come after us, except this one is trying to do more,' said Steve Linford, founder of The Spamhaus Project, a British-based group that singles out spammers. Spamhaus was hit by Mimail late Monday. "
According to anti-virus and spam-filtering company Sophos Plc, the Mimail-L program comes as an attachment to an e-mail purporting to be from a woman named Wendy who details an erotic encounter and then offers naked photographs.
Clicking on the attachment activates the virus. Once triggered, the worm forwards itself to other e-mail users.
The worm can also turn the affected PC into a "zombie," which can then be remotely commanded to bombard one of a select group of targets, such as Spamhaus, with a disabling blizzard of data--a so-called denial-of-service attack.
In a new twist, a follow-up e-mail is sent to the infected user stating that an order for a CD containing images of child pornography will be delivered to their postal address.
To stop the order, the e-mail advises, they should respond to what appears to be an e-mail address for billing complaints, but which is actually an e-mail for one of the eight targets.…
http://zdnet.com.com/2100-1105_2-5112997.html
Wednesday, December 03, 2003
'Critical' IE Security Warning Released:
"A Chinese security researcher has warned of five serious vulnerabilities in Microsoft's (Quote, Chart) Internet Explorer browser, warning that a successful exploit could lead to system takeover.
Liu Die Yu released details of the flaws on the Bugtraq mailing list and issued a warning that the vulnerabilities could lead to system access, exposure of sensitive information, cross site scripting and security bypass.
Yu also released proof-of-concept exploits on the popular mailing list, noting that the flaws affect Internet Explorer versions 5.0, 5.5 and 6.0."
Independent security consultant Secunia has rated the flaws 'Extremely Critical' and urged IE users to disable Active Scripting as a workaround until Microsoft issues a fix.
The flaws related to a redirection feature in the browser using the "mhtml:" URI handler. The researcher warned that it could be exploited to bypass a security check in Internet Explorer which normally blocks web pages in the "Internet" zone from parsing local files.
Yu said the redirection feature could also be exploited to download and execute a malicious file on a user's system. Successful exploitation requires that script code can be executed in the "MyComputer" zone, he explained.
The security alert also included a cross-site scripting vulnerability that could allow a malicious attacker to execute script code in the security zone associated with another Web page if it contains a subframe.
A variant of a previously fixed flaw can still be exploited to hijack a user's clicks and perform certain actions without the user's knowledge, the researcher explained.
Microsoft late Wednesday confirmed it was investigating Lu's warnings. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," said Stephen Toulouse, Security Program Manager, Microsoft Security Response Center.
Toulouse told internetnews.com Microsoft would take the "appropriate action to protect our customers" and hinted that a fix could come via an out-of-cycle patch, depending on the seriousness of its findings.
He said Microsoft was concerned that Lu's warnings were not disclosed responsibly, potentially putting computer users at risk. "We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality patches for security vulnerabilities with no exposure to malicious attackers while the patch is being developed," Toulouse declared.
In the interim, Toulouse is recommending that IE users install the cumulative patch issued earlier this month (MS03-048).…
http://www.internetnews.com/dev-news/print.php/3114171
"A Chinese security researcher has warned of five serious vulnerabilities in Microsoft's (Quote, Chart) Internet Explorer browser, warning that a successful exploit could lead to system takeover.
Liu Die Yu released details of the flaws on the Bugtraq mailing list and issued a warning that the vulnerabilities could lead to system access, exposure of sensitive information, cross site scripting and security bypass.
Yu also released proof-of-concept exploits on the popular mailing list, noting that the flaws affect Internet Explorer versions 5.0, 5.5 and 6.0."
Independent security consultant Secunia has rated the flaws 'Extremely Critical' and urged IE users to disable Active Scripting as a workaround until Microsoft issues a fix.
The flaws related to a redirection feature in the browser using the "mhtml:" URI handler. The researcher warned that it could be exploited to bypass a security check in Internet Explorer which normally blocks web pages in the "Internet" zone from parsing local files.
Yu said the redirection feature could also be exploited to download and execute a malicious file on a user's system. Successful exploitation requires that script code can be executed in the "MyComputer" zone, he explained.
The security alert also included a cross-site scripting vulnerability that could allow a malicious attacker to execute script code in the security zone associated with another Web page if it contains a subframe.
A variant of a previously fixed flaw can still be exploited to hijack a user's clicks and perform certain actions without the user's knowledge, the researcher explained.
Microsoft late Wednesday confirmed it was investigating Lu's warnings. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," said Stephen Toulouse, Security Program Manager, Microsoft Security Response Center.
Toulouse told internetnews.com Microsoft would take the "appropriate action to protect our customers" and hinted that a fix could come via an out-of-cycle patch, depending on the seriousness of its findings.
He said Microsoft was concerned that Lu's warnings were not disclosed responsibly, potentially putting computer users at risk. "We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality patches for security vulnerabilities with no exposure to malicious attackers while the patch is being developed," Toulouse declared.
In the interim, Toulouse is recommending that IE users install the cumulative patch issued earlier this month (MS03-048).…
http://www.internetnews.com/dev-news/print.php/3114171
Tuesday, December 02, 2003
Webmasters Wary of Latest Google Tweaks:
"Some sites have fallen from high rankings to the nether reaches, while others have gained better slots. While such shifts are nothing new, this time around some observers say it appears that Google is trying to penalize sites using the most aggressive search-engine-optimization techniques with keywords and links to rank well on Google results. "
The problem is that along with these abusers of search engine optimization, many more innocent sites have fallen as well, said Barry Lloyd, CEO of Clogher, Ireland-based search-engine marketing company Microchannel Technologies Ltd.
"It's gone from a Google love fest to some of the most vitriolic attacks I've ever heard," he said of the reaction to the latest tweaks. "My genuine belief is that there's been too much collateral damage. A lot of people not deliberately gaming the system have been affected."
Google, as a matter of policy, does not discuss changes to its search engine algorithm. A spokesman said that the Mountain View, Calif., regularly tweaks its algorithms to improve the relevancy of search results.
"This is why it is common to see movement in the ranking of sites on Google search results pages," he said.
It remains to be seen to what extent the common user of Google has noticed the shifting positions of sites in search results. Search-engine marketers and optimizers readily admit that they watch the results with hawk eyes, noticing the slightest shifts in rank.
To Danny Sullivan, editor of SearchEngineWatch.com, the current spat of debate filling Webmaster and search-engine message boards is part of the regular cycle of complaints that follows a Google change. Quantifying whether the latest shifting is producing better or worse results is difficult since the results vary depending on the search query.
"If your job is to optimize a site for a particular term, then you know intimately what site comes up for that term," Sullivan said. "For a typical Google user, they probably won't notice anything."
Along with link tricks, some sites and search-engine optimizers have created doorway pages. The pages are designed specifically for search engine spiders indexing Web pages and are optimized to match coveted keywords. They are often invisible to actual users or appear as a quick introductory page that leads into the main site.
"(Google) had to come up with a way of overcoming the gaming of their algorithm because it was becoming so corrupted," Lloyd said.
In the course of combating techniques what Google and others consider search-engine spam, Google's algorithm changes also appear to have caught other sites in the crosshairs, Lloyd said. The changes appear to be affecting the rank of commercial-oriented search terms the most, ones where over-optimization is often common, and to be hurting sites that use a given keyword term frequently in the site or in the domain, Lloyd said.
At the same time, Lloyd and others have noticed that the results for some search terms seem more focused on directory listings or non-commercial sites rather than commercial sites. On one example, Lloyd tried searching for "Web design Calgary," expecting to find Web design companies in Calgary, Canada. Instead the first result was the site for the Calgary Flames hockey team.
More than anything, the most recent brouhaha over Google algorithm changes points to the danger of relying too heavily on search-result positioning for one's business, experts say.…
http://www.eweek.com/print_article/0,3048,a=113607,00.asp
"Some sites have fallen from high rankings to the nether reaches, while others have gained better slots. While such shifts are nothing new, this time around some observers say it appears that Google is trying to penalize sites using the most aggressive search-engine-optimization techniques with keywords and links to rank well on Google results. "
The problem is that along with these abusers of search engine optimization, many more innocent sites have fallen as well, said Barry Lloyd, CEO of Clogher, Ireland-based search-engine marketing company Microchannel Technologies Ltd.
"It's gone from a Google love fest to some of the most vitriolic attacks I've ever heard," he said of the reaction to the latest tweaks. "My genuine belief is that there's been too much collateral damage. A lot of people not deliberately gaming the system have been affected."
Google, as a matter of policy, does not discuss changes to its search engine algorithm. A spokesman said that the Mountain View, Calif., regularly tweaks its algorithms to improve the relevancy of search results.
"This is why it is common to see movement in the ranking of sites on Google search results pages," he said.
It remains to be seen to what extent the common user of Google has noticed the shifting positions of sites in search results. Search-engine marketers and optimizers readily admit that they watch the results with hawk eyes, noticing the slightest shifts in rank.
To Danny Sullivan, editor of SearchEngineWatch.com, the current spat of debate filling Webmaster and search-engine message boards is part of the regular cycle of complaints that follows a Google change. Quantifying whether the latest shifting is producing better or worse results is difficult since the results vary depending on the search query.
"If your job is to optimize a site for a particular term, then you know intimately what site comes up for that term," Sullivan said. "For a typical Google user, they probably won't notice anything."
Along with link tricks, some sites and search-engine optimizers have created doorway pages. The pages are designed specifically for search engine spiders indexing Web pages and are optimized to match coveted keywords. They are often invisible to actual users or appear as a quick introductory page that leads into the main site.
"(Google) had to come up with a way of overcoming the gaming of their algorithm because it was becoming so corrupted," Lloyd said.
In the course of combating techniques what Google and others consider search-engine spam, Google's algorithm changes also appear to have caught other sites in the crosshairs, Lloyd said. The changes appear to be affecting the rank of commercial-oriented search terms the most, ones where over-optimization is often common, and to be hurting sites that use a given keyword term frequently in the site or in the domain, Lloyd said.
At the same time, Lloyd and others have noticed that the results for some search terms seem more focused on directory listings or non-commercial sites rather than commercial sites. On one example, Lloyd tried searching for "Web design Calgary," expecting to find Web design companies in Calgary, Canada. Instead the first result was the site for the Calgary Flames hockey team.
More than anything, the most recent brouhaha over Google algorithm changes points to the danger of relying too heavily on search-result positioning for one's business, experts say.…
http://www.eweek.com/print_article/0,3048,a=113607,00.asp
News: Flaw in Linux kernel allows attack:
"The Debian Project warned on Monday that a flaw in the Linux kernel helped attackers compromise four of the open-source software project's development servers.
During several intrusions Nov. 19, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.
Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released Friday, eight days after the Debian breach."
The unknown attacker compromised at least four servers. The systems--known as Master, Murphy, Gluck and Klecker--had maintained the open-source project's bug tracking system, source code database, mailing lists, Web site and security patches.
The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published Friday. When the programmer logged into the klecker system, the attacker recorded his password.
Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw--in a part of the kernel that manages memory--allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.
The attacks have been the latest leveled at open-source software. In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open-source projects.
http://zdnet.com.com/2100-1104_2-5112427.html
"The Debian Project warned on Monday that a flaw in the Linux kernel helped attackers compromise four of the open-source software project's development servers.
During several intrusions Nov. 19, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.
Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released Friday, eight days after the Debian breach."
The unknown attacker compromised at least four servers. The systems--known as Master, Murphy, Gluck and Klecker--had maintained the open-source project's bug tracking system, source code database, mailing lists, Web site and security patches.
The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published Friday. When the programmer logged into the klecker system, the attacker recorded his password.
Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw--in a part of the kernel that manages memory--allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.
The attacks have been the latest leveled at open-source software. In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open-source projects.
http://zdnet.com.com/2100-1104_2-5112427.html
Economy & Business: I.R.S. Set to Resolve Disputes Online:
"The I.R.S. is testing a system called Electronic Account Resolution with a handful of tax professionals. Lawyers, accountants and enrolled agents - a kind of preparer who is authorized to represent taxpayers before the I.R.S. - will be able to use the system; they can go online now to register. But individuals and other paid preparers will not have access.
James Leimbach, an enrolled agent in Panama City, Fla., who is one of the testers, is enthusiastic. 'Through a simple three-step process,' Mr. Leimbach said, 'I will be able to electronically access my client's tax records and then resolve problems.'
Under the present nonelectronic system, tax professionals must show the agency a power of attorney from the taxpayer before the I.R.S. will talk to them. While I.R.S. clerks will sometimes accept a faxed form, getting approval to represent a client can take days."
With the new system, a taxpayer fills out the power of attorney form and gives it to the tax adviser. Then the adviser logs on to an I.R.S. computer, using a secure Internet connection, punching in the client's adjusted gross income from any of the three previous years, the year of the return and the taxpayer's birth date. The taxpayer also gives a self-selected personal identification number.
"You get disclosure authorization almost instantly," Mr. Leimbach said. Immediately, a request can be made for the taxpayer's records, known as a transcript.
"Typically, getting a transcript took 5 to 10 days when ordered through the mail," he said. "With the new system, I will be able to pull transcripts up electronically."
Such speedy gathering of information and problem resolution - in contrast to hours or days of work - should hold down the fees taxpayers pay their advisers.
At first, the system can be used to resolve simple problems, like tracing payments, tracking refunds and entering into installment agreements to pay taxes.
The agency has not begun to work on more complex problems, like proposals to settle a tax debt for less than the full amount…
http://www.nytimes.com/2003/12/01/business/01taxx.html
"The I.R.S. is testing a system called Electronic Account Resolution with a handful of tax professionals. Lawyers, accountants and enrolled agents - a kind of preparer who is authorized to represent taxpayers before the I.R.S. - will be able to use the system; they can go online now to register. But individuals and other paid preparers will not have access.
James Leimbach, an enrolled agent in Panama City, Fla., who is one of the testers, is enthusiastic. 'Through a simple three-step process,' Mr. Leimbach said, 'I will be able to electronically access my client's tax records and then resolve problems.'
Under the present nonelectronic system, tax professionals must show the agency a power of attorney from the taxpayer before the I.R.S. will talk to them. While I.R.S. clerks will sometimes accept a faxed form, getting approval to represent a client can take days."
With the new system, a taxpayer fills out the power of attorney form and gives it to the tax adviser. Then the adviser logs on to an I.R.S. computer, using a secure Internet connection, punching in the client's adjusted gross income from any of the three previous years, the year of the return and the taxpayer's birth date. The taxpayer also gives a self-selected personal identification number.
"You get disclosure authorization almost instantly," Mr. Leimbach said. Immediately, a request can be made for the taxpayer's records, known as a transcript.
"Typically, getting a transcript took 5 to 10 days when ordered through the mail," he said. "With the new system, I will be able to pull transcripts up electronically."
Such speedy gathering of information and problem resolution - in contrast to hours or days of work - should hold down the fees taxpayers pay their advisers.
At first, the system can be used to resolve simple problems, like tracing payments, tracking refunds and entering into installment agreements to pay taxes.
The agency has not begun to work on more complex problems, like proposals to settle a tax debt for less than the full amount…
http://www.nytimes.com/2003/12/01/business/01taxx.html
News: Sobig lingers despite shutdown date:
"Sobig is still rampaging around the Internet, two months after the virus was supposed to have terminated itself. "
E-mail security firm MessageLabs said Friday that Sobig was the third most active virus in November, with some 264,000 copies being detected by its e-mail virus-scanning servers.
Although this activity is well below the virus's peak, it is still surprising as Sobig--like several other members of the Sobig family--contained a built-in shutdown date that was supposed to prevent it propagating after Sept. 10. Sobig.F's continued proliferation is due to a combination of factors, including the successful efforts that prevented it wreaking even more havoc and the fact that many PCs are set to the wrong date, according to MessageLabs.
http://zdnet.com.com/2100-1104_2-5112207.html
"Sobig is still rampaging around the Internet, two months after the virus was supposed to have terminated itself. "
E-mail security firm MessageLabs said Friday that Sobig was the third most active virus in November, with some 264,000 copies being detected by its e-mail virus-scanning servers.
Although this activity is well below the virus's peak, it is still surprising as Sobig--like several other members of the Sobig family--contained a built-in shutdown date that was supposed to prevent it propagating after Sept. 10. Sobig.F's continued proliferation is due to a combination of factors, including the successful efforts that prevented it wreaking even more havoc and the fact that many PCs are set to the wrong date, according to MessageLabs.
http://zdnet.com.com/2100-1104_2-5112207.html
Score one for the spammers: CAN SPAM bill to become law - TechUpdate - ZDNet:
"For the umpteenth time: Anti-spam laws are a bad idea as long as they're written by those out of touch with the underpinnings of Internet e-mail. For example, writing into law anything that ventures down the path of 'opting out' (short-hand for 'optioning out,' deselecting, or unsubscribing yourself from membership in a mailing list) --- which CAN SPAM does --- creates a virtually unenforceable law since there are a million and one reasons (most of which would not be due to negligence on behalf of mailing list operators) that an opt-out mechanism may not work at some given point in time. Before opt-out language can be included in a law, there needs to exist an opt-out standard under the guise of what I call a relationship termination protocol over which dissimilar email clients and servers can interoperate. "
Perhaps you think I'm on the lunatic fringe, an ultraconservative who refuses to see the good in legislation that clearly has the welfare of the spam-afflicted in mind? OK ignore me. But don't ignore the following warning, reported in a recent CNET News.com story about the CAN SPAM bill, that was sent from the National Association of Attorneys General to Congress: "The bill creates so many loopholes, exceptions, and high standards of proof, that it provides minimal consumer protections and creates too many burdens for effective enforcement...We respectfully request that you not move forward."
Lack of enforceability has been my main point all along and it's refreshing to see the very folks chartered with upholding the CAN SPAM bill saying to Congress "Hey, you're all off your rockers if you move forward with this law." Still not convinced? Assuming that the law's effectiveness is dependent on the fact that all evil spammers fall within its jurisdiction (a very bad assumption considering the mounting tide of spam from China and South Korea), then you, as a concerned Netizen, should consider its definition of spam. To the relief of e-mail marketers everywhere, spam will not be the first unsolicited commercial email you get from someone you consider to be a spammer. It's one of the subsequent ones. That's right. It's the second, third, fourth, or later one and it is only such if, after receiving the first one, you issued an objection according to a method the sender, not you, says you are permitted to do so (the vaulted "opt-out" for which no standard method exists and no auditable test for proven functionality has been created).
Are you getting ill yet?
Despite the fact that the Attorneys General will be reluctant to expend the resources necessary to prosecute given the loopholes it envisions, Senators Burns and Wyden cited the financial implications in their declarations of victory. Sen. Ron Wyden, D-Ore., said that "when this bill takes effect, the big-time spammers who up until now have faced virtually no penalties will suddenly be at risk of criminal prosecution, (Federal Trade Commission) prosecution and million-dollar lawsuits." Sen. Conrad Burns, R-Mont., said: "In cases where e-mail marketers don't comply with the CAN-SPAM bill, the penalties are very severe...Spammers are actually on the hook for (per e-mail) damages, with a cap of $2 million."
Newsflash. The big time spammers --- at least the ones who are intentionally sidestepping all sense of Internet decorum in order to invade the sanctity of your inbox --- have about a hundred dollars in their checking accounts--collectively. It was only about six months ago, at the now infamous Federal Trade Commission three-day workshop on spam, that we heard from several Attorneys General and Internet Service Providers about how their investments in certain investigations, indictments, prosecutions, and lawsuits were disproportionate to the final outcome: one or two bad apples (out of an ocean-sized apple orchard) with little or no money to their names shut down. My inbox didn't notice. Did yours? Despite efforts to publicly draw, quarter, flog, and hang the offenders, the rest of the orchard didn't appear to flinch. It may have yawned, though. We'll never know. They're a secretive bunch. It's not like they have offices on Madison Avenue.
http://techupdate.zdnet.com/techupdate/stories/main/Score_one_for_the_spammers.html
"For the umpteenth time: Anti-spam laws are a bad idea as long as they're written by those out of touch with the underpinnings of Internet e-mail. For example, writing into law anything that ventures down the path of 'opting out' (short-hand for 'optioning out,' deselecting, or unsubscribing yourself from membership in a mailing list) --- which CAN SPAM does --- creates a virtually unenforceable law since there are a million and one reasons (most of which would not be due to negligence on behalf of mailing list operators) that an opt-out mechanism may not work at some given point in time. Before opt-out language can be included in a law, there needs to exist an opt-out standard under the guise of what I call a relationship termination protocol over which dissimilar email clients and servers can interoperate. "
Perhaps you think I'm on the lunatic fringe, an ultraconservative who refuses to see the good in legislation that clearly has the welfare of the spam-afflicted in mind? OK ignore me. But don't ignore the following warning, reported in a recent CNET News.com story about the CAN SPAM bill, that was sent from the National Association of Attorneys General to Congress: "The bill creates so many loopholes, exceptions, and high standards of proof, that it provides minimal consumer protections and creates too many burdens for effective enforcement...We respectfully request that you not move forward."
Lack of enforceability has been my main point all along and it's refreshing to see the very folks chartered with upholding the CAN SPAM bill saying to Congress "Hey, you're all off your rockers if you move forward with this law." Still not convinced? Assuming that the law's effectiveness is dependent on the fact that all evil spammers fall within its jurisdiction (a very bad assumption considering the mounting tide of spam from China and South Korea), then you, as a concerned Netizen, should consider its definition of spam. To the relief of e-mail marketers everywhere, spam will not be the first unsolicited commercial email you get from someone you consider to be a spammer. It's one of the subsequent ones. That's right. It's the second, third, fourth, or later one and it is only such if, after receiving the first one, you issued an objection according to a method the sender, not you, says you are permitted to do so (the vaulted "opt-out" for which no standard method exists and no auditable test for proven functionality has been created).
Are you getting ill yet?
Despite the fact that the Attorneys General will be reluctant to expend the resources necessary to prosecute given the loopholes it envisions, Senators Burns and Wyden cited the financial implications in their declarations of victory. Sen. Ron Wyden, D-Ore., said that "when this bill takes effect, the big-time spammers who up until now have faced virtually no penalties will suddenly be at risk of criminal prosecution, (Federal Trade Commission) prosecution and million-dollar lawsuits." Sen. Conrad Burns, R-Mont., said: "In cases where e-mail marketers don't comply with the CAN-SPAM bill, the penalties are very severe...Spammers are actually on the hook for (per e-mail) damages, with a cap of $2 million."
Newsflash. The big time spammers --- at least the ones who are intentionally sidestepping all sense of Internet decorum in order to invade the sanctity of your inbox --- have about a hundred dollars in their checking accounts--collectively. It was only about six months ago, at the now infamous Federal Trade Commission three-day workshop on spam, that we heard from several Attorneys General and Internet Service Providers about how their investments in certain investigations, indictments, prosecutions, and lawsuits were disproportionate to the final outcome: one or two bad apples (out of an ocean-sized apple orchard) with little or no money to their names shut down. My inbox didn't notice. Did yours? Despite efforts to publicly draw, quarter, flog, and hang the offenders, the rest of the orchard didn't appear to flinch. It may have yawned, though. We'll never know. They're a secretive bunch. It's not like they have offices on Madison Avenue.
http://techupdate.zdnet.com/techupdate/stories/main/Score_one_for_the_spammers.html
Friday, November 28, 2003
Beware the Worm in Your Handset:
"As more consumers begin surfing the Web and sending e-mail messages on cellphone and hand-held devices, along comes a new worry: worms and viruses spread via Internet-enabled handsets."
The problem is still small, with only a few cases reported globally. But as operating systems in cellphones become standardized, hackers will probably begin focusing on vulnerabilities in those systems as they have with personal computers. And as cellphones and personal digital assistants connect to the Internet at ever faster speeds, more users will be able to download files with attachments - some of which may be infected.
Asia, where high-speed networks and text messaging on mobile phones are common, is the most vulnerable to these threats. As carriers in Europe and North America adopt similar technology, they will confront the same kinds of hazards.
Telecommunications companies currently spend as much as $8 billion a year fixing handsets with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business.
"The danger to mobile phone networks is probably five times bigger than with personal computers because very few people are focused on this problem now," said Andrew Cole, senior vice president at Adventis, a Boston-based consultant specializing in telecommunications issues. "The dominant form of messaging is going to be cell-to-cell, so this could escalate very rapidly and overload phone networks. What if viruses phone 911 randomly?"
That, in fact, is what happened in Japan in 2000 and 2001. NTT DoCoMo, the country's largest cellular phone provider, received complaints from customers who were being sent messages that froze their screens and automatically dialed 110, the emergency line to the police in Japan.…
That event was a shock because the company is spending billions of dollars introducing its high-speed third-generation, or 3G, network that allows users to download data up to 40 times faster than conventional mobile phone networks. A rash of viruses might turn off users to the new network before it was released. Eventually, DoCoMo dealt with the problem by installing special security software on its servers and new handsets, which were also being bombarded with unwanted commercial e-mail and text messages from advertisers, dating clubs and other marketers. DoCoMo blocks about 55 percent of the one billion text messages that reach its servers each day because of suspicious return addresses or attachments. Another 26 percent of those messages are blocked by DoCoMo users who have programmed their handsets to turn back unwanted mail or spam.
http://www.nytimes.com/2003/11/28/technology/28cell.html
"As more consumers begin surfing the Web and sending e-mail messages on cellphone and hand-held devices, along comes a new worry: worms and viruses spread via Internet-enabled handsets."
The problem is still small, with only a few cases reported globally. But as operating systems in cellphones become standardized, hackers will probably begin focusing on vulnerabilities in those systems as they have with personal computers. And as cellphones and personal digital assistants connect to the Internet at ever faster speeds, more users will be able to download files with attachments - some of which may be infected.
Asia, where high-speed networks and text messaging on mobile phones are common, is the most vulnerable to these threats. As carriers in Europe and North America adopt similar technology, they will confront the same kinds of hazards.
Telecommunications companies currently spend as much as $8 billion a year fixing handsets with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business.
"The danger to mobile phone networks is probably five times bigger than with personal computers because very few people are focused on this problem now," said Andrew Cole, senior vice president at Adventis, a Boston-based consultant specializing in telecommunications issues. "The dominant form of messaging is going to be cell-to-cell, so this could escalate very rapidly and overload phone networks. What if viruses phone 911 randomly?"
That, in fact, is what happened in Japan in 2000 and 2001. NTT DoCoMo, the country's largest cellular phone provider, received complaints from customers who were being sent messages that froze their screens and automatically dialed 110, the emergency line to the police in Japan.…
That event was a shock because the company is spending billions of dollars introducing its high-speed third-generation, or 3G, network that allows users to download data up to 40 times faster than conventional mobile phone networks. A rash of viruses might turn off users to the new network before it was released. Eventually, DoCoMo dealt with the problem by installing special security software on its servers and new handsets, which were also being bombarded with unwanted commercial e-mail and text messages from advertisers, dating clubs and other marketers. DoCoMo blocks about 55 percent of the one billion text messages that reach its servers each day because of suspicious return addresses or attachments. Another 26 percent of those messages are blocked by DoCoMo users who have programmed their handsets to turn back unwanted mail or spam.
http://www.nytimes.com/2003/11/28/technology/28cell.html
Wednesday, November 26, 2003
News: The computer virus--no cures to be found:
"Of all the accomplishments in the annals of technology, Fred Cohen's contribution is undeniably unique: He introduced the term 'virus' to the lexicon of computers."
The University of New Haven professor used the phrase in a 1984 research paper, in which he described threats self-propagating programs pose and explored potential defenses against them. When he asked for funding from the National Science Foundation three years later to further explore countermeasures, the agency rebuffed him.
"They turned it down," said Cohen, who is also principal analyst for research firm Burton Group. "They said it wasn't of current interest."
Two decades later, countless companies and individuals are still paying for that mistake. The technology industry has yet to find a blanket solution to the ever-growing list of viruses and worms that constitute the greatest risk to computers on the Internet. Every year, companies lose billions of dollars when forced to halt work and deal with infectious digital diseases, such as Sobig and Slammer.
While much attention has been paid to the malicious online attackers who exploit technology's vulnerabilities, little has been documented about the origins of the virus. Its early iterations were not created by malcontent teenagers or antisocial geeks but by campus researchers, system administrators and a handful of old-school hackers who thought that the ability to reproduce their programs automatically was a neat trick.
http://zdnet.com.com/2100-1105_2-5111442.html
"Of all the accomplishments in the annals of technology, Fred Cohen's contribution is undeniably unique: He introduced the term 'virus' to the lexicon of computers."
"The design of the Internet facilitates the distribution of information--all sorts of information; it's a double-edged sword," Gordon said in a recent e-mail interview. "Even if (viruses) are not designed to be intentionally malicious or dangerous, if they get outside of a controlled environment, there can be unexpected results."
The University of New Haven professor used the phrase in a 1984 research paper, in which he described threats self-propagating programs pose and explored potential defenses against them. When he asked for funding from the National Science Foundation three years later to further explore countermeasures, the agency rebuffed him.
"They turned it down," said Cohen, who is also principal analyst for research firm Burton Group. "They said it wasn't of current interest."
Two decades later, countless companies and individuals are still paying for that mistake. The technology industry has yet to find a blanket solution to the ever-growing list of viruses and worms that constitute the greatest risk to computers on the Internet. Every year, companies lose billions of dollars when forced to halt work and deal with infectious digital diseases, such as Sobig and Slammer.
While much attention has been paid to the malicious online attackers who exploit technology's vulnerabilities, little has been documented about the origins of the virus. Its early iterations were not created by malcontent teenagers or antisocial geeks but by campus researchers, system administrators and a handful of old-school hackers who thought that the ability to reproduce their programs automatically was a neat trick.
http://zdnet.com.com/2100-1105_2-5111442.html
Domain Theft is Still a Little Too Easy:
"Do you ever get spam offering to sell you fake IDs? Here's one reason why some people want to buy one: a fake ID, a fax machine, and an absence of morals are all that's needed to hijack any domain name. "
Yes, stealing a domain name from its rightful owners still appears to be child's play. A reader contacted me about his case involving the domain name DVDMovies.com. Several weeks ago Arnold Jones of Visionario Inc., a storage consulting firm and owner of dvdmovies.com, discovered that this domain had been transferred to someone else.
This person had sent in to Network Solutions, the registrar holding the registry of dvdmovies.com, a request by fax to change the e-mail contacts on the registration to a free yahoo.com address. Even though his identification information had been forged, including a copy of a fake Florida drivers license with Jones's work address on it, Network Solutions happily obliged and did not scrutinize the license.
Once the e-mail contact had been changed, the domain pirate simply sent a request to reset the password on the account, and he replied from the new address. Now that he had control over the account, he could transfer the registration to another registrar.
However, according to Jones' account, there were many other glaring red flags that should have alerted Network Solutions to a possible hijacking:
The fax requesting the e-mail change came from area code 530, in California, but all registrant information was for Florida.
The key administrative contact e-mail address was changed to a free, untraceable yahoo.com address.
The fake Florida drivers license lacked all the major characteristics of a legitimate Florida drivers license.
Jones required two weeks of time and effort before he got his domain back. If he was less sophisticated about these matters, it might have taken him much longer to take control of the domain. To compensate him for the two weeks of time and the lack of his domain, Network Solutions extended his registration by a year, a $35 value. Gosh, I hope he declares this on his taxes.…
http://www.eweek.com/article2/0,4149,1384450,00.asp
"Do you ever get spam offering to sell you fake IDs? Here's one reason why some people want to buy one: a fake ID, a fax machine, and an absence of morals are all that's needed to hijack any domain name. "
Yes, stealing a domain name from its rightful owners still appears to be child's play. A reader contacted me about his case involving the domain name DVDMovies.com. Several weeks ago Arnold Jones of Visionario Inc., a storage consulting firm and owner of dvdmovies.com, discovered that this domain had been transferred to someone else.
This person had sent in to Network Solutions, the registrar holding the registry of dvdmovies.com, a request by fax to change the e-mail contacts on the registration to a free yahoo.com address. Even though his identification information had been forged, including a copy of a fake Florida drivers license with Jones's work address on it, Network Solutions happily obliged and did not scrutinize the license.
Once the e-mail contact had been changed, the domain pirate simply sent a request to reset the password on the account, and he replied from the new address. Now that he had control over the account, he could transfer the registration to another registrar.
However, according to Jones' account, there were many other glaring red flags that should have alerted Network Solutions to a possible hijacking:
The fax requesting the e-mail change came from area code 530, in California, but all registrant information was for Florida.
The key administrative contact e-mail address was changed to a free, untraceable yahoo.com address.
The fake Florida drivers license lacked all the major characteristics of a legitimate Florida drivers license.
Jones required two weeks of time and effort before he got his domain back. If he was less sophisticated about these matters, it might have taken him much longer to take control of the domain. To compensate him for the two weeks of time and the lack of his domain, Network Solutions extended his registration by a year, a $35 value. Gosh, I hope he declares this on his taxes.…
http://www.eweek.com/article2/0,4149,1384450,00.asp
Creating Interactive Video With MPEG4:
"MPEG4 is finally starting to gain some traction. The allure of platform and vendor independence and ubiquitous players on all kinds of devices is strong. But in many areas, MPEG4 is still a 'bleeding-edge' technology. You'll quickly feel the pain when you try to do any but the most basic audio/video delivery using it. Today, all the major streaming players support MPEG4, mostly through the EnvivioTV plugin. And Apple's Quicktime lets you convert all kinds of movies to MPEG4 using the best-$30-you-ever-spent-on-software Quicktime Pro. But to really unlock the promise of MPEG4 – universal and reliable authoring and playback of complex interactive multimedia – you still have to go out on the edge."
Profiles and Compatibility
MPEG4 is designed to be useful for video playback across a wide variety of devices, from cell phones to powerful desktop computers; from pocket sized handhelds to TV set top boxes. To support this flexibility, the spec is divided into different profiles and levels, each defining a subset of MPEG4's total feature set. An MPEG player will support a particular profile by implementing all of that profile's features. IBM's SamplesForMPEG4 (also available at alphaWorks) includes dozens of examples of varied XMT and MPEG4 features. Many of these play in the QT and Real players, while others do not. (Of course, they all play in IBM's M4Play, part of the Toolkit.)
http://www.streamingmedia.com/article.asp?id=8544
"MPEG4 is finally starting to gain some traction. The allure of platform and vendor independence and ubiquitous players on all kinds of devices is strong. But in many areas, MPEG4 is still a 'bleeding-edge' technology. You'll quickly feel the pain when you try to do any but the most basic audio/video delivery using it. Today, all the major streaming players support MPEG4, mostly through the EnvivioTV plugin. And Apple's Quicktime lets you convert all kinds of movies to MPEG4 using the best-$30-you-ever-spent-on-software Quicktime Pro. But to really unlock the promise of MPEG4 – universal and reliable authoring and playback of complex interactive multimedia – you still have to go out on the edge."
Profiles and Compatibility
MPEG4 is designed to be useful for video playback across a wide variety of devices, from cell phones to powerful desktop computers; from pocket sized handhelds to TV set top boxes. To support this flexibility, the spec is divided into different profiles and levels, each defining a subset of MPEG4's total feature set. An MPEG player will support a particular profile by implementing all of that profile's features. IBM's SamplesForMPEG4 (also available at alphaWorks) includes dozens of examples of varied XMT and MPEG4 features. Many of these play in the QT and Real players, while others do not. (Of course, they all play in IBM's M4Play, part of the Toolkit.)
http://www.streamingmedia.com/article.asp?id=8544
Tuesday, November 25, 2003
washingtonpost.com: On the Web, Research Work Proves Ephemeral:
"It was in the mundane course of getting a scientific paper published that physician Robert Dellavalle came to the unsettling realization that the world was dissolving before his eyes.
The world, that is, of footnotes, references and Web pages."
Dellavalle, a dermatologist with the Veterans Affairs Medical Center in Denver, had co-written a research report featuring dozens of footnotes -- many of which referred not to books or journal articles but, as is increasingly the case these days, to Web sites that he and his colleagues had used to substantiate their findings.
Problem was, it took about two years for the article to wind its way to publication. And by that time, many of the sites they had cited had moved to other locations on the Internet or disappeared altogether, rendering useless all those Web addresses -- also known as uniform resource locators (URLs) -- they had provided in their footnotes.
"Every time we checked, some were gone and others had moved," said Dellavalle, who is on the faculty at the University of Colorado Health Sciences Center. "We thought, 'This is an interesting phenomenon itself. We should look at this.' "
He and his co-workers have done just that, and what they have found is not reassuring to those who value having a permanent record of scientific progress. In research described in the journal Science last month, the team looked at footnotes from scientific articles in three major journals -- the New England Journal of Medicine, Science and Nature -- at three months, 15 months and 27 months after publication. The prevalence of inactive Internet references grew during those intervals from 3.8 percent to 10 percent to 13 percent.
"I think of it like the library burning in Alexandria," Dellavalle said, referring to the 48 B.C. sacking of the ancient world's greatest repository of knowledge. "We've had all these hundreds of years of stuff available by interlibrary loan, but now things just a few years old are disappearing right under our noses really quickly."
http://www.washingtonpost.com/ac2/wp-dyn/A8730-2003Nov23
"It was in the mundane course of getting a scientific paper published that physician Robert Dellavalle came to the unsettling realization that the world was dissolving before his eyes.
The world, that is, of footnotes, references and Web pages."
Dellavalle, a dermatologist with the Veterans Affairs Medical Center in Denver, had co-written a research report featuring dozens of footnotes -- many of which referred not to books or journal articles but, as is increasingly the case these days, to Web sites that he and his colleagues had used to substantiate their findings.
Problem was, it took about two years for the article to wind its way to publication. And by that time, many of the sites they had cited had moved to other locations on the Internet or disappeared altogether, rendering useless all those Web addresses -- also known as uniform resource locators (URLs) -- they had provided in their footnotes.
"Every time we checked, some were gone and others had moved," said Dellavalle, who is on the faculty at the University of Colorado Health Sciences Center. "We thought, 'This is an interesting phenomenon itself. We should look at this.' "
He and his co-workers have done just that, and what they have found is not reassuring to those who value having a permanent record of scientific progress. In research described in the journal Science last month, the team looked at footnotes from scientific articles in three major journals -- the New England Journal of Medicine, Science and Nature -- at three months, 15 months and 27 months after publication. The prevalence of inactive Internet references grew during those intervals from 3.8 percent to 10 percent to 13 percent.
"I think of it like the library burning in Alexandria," Dellavalle said, referring to the 48 B.C. sacking of the ancient world's greatest repository of knowledge. "We've had all these hundreds of years of stuff available by interlibrary loan, but now things just a few years old are disappearing right under our noses really quickly."
http://www.washingtonpost.com/ac2/wp-dyn/A8730-2003Nov23
Debian: Attack Didn't Harm Source Code:
"Despite a cracker incursion into Debian Project servers this week, representatives of the Debian Linux distribution said the open-source code behind it remains untouched."
This is not the first time an open-source site has been attacked by crackers. In March of this year, the Free Software Foundation Inc.'s GNU Project ftp servers were attacked. This assault, which caused no damage to the code, was only discovered months afterwards.
In the Debian case, though, the break-in was discovered within 24 hours. The cracker had gained access to four machines: "master," the bug-tracking system; "murphy," the mailing-list manager; "gluck," the Web server and Concurrent Versions System (CVS) system; and "klecker," which houses security, quality assurance and search-engine code. Martin Schulze, a Debian spokesman, reported that the Debian source code archives themselves were "not affected by this compromise."
"This kind of attack is inevitable in open source," Murdoch said. "We've increased security. At the beginning of Debian, becoming a developer was as easy as sending me an e-mail, but these days there are checks and balances in place to make sure that only real developers get in and that the code stays clean."
http://www.eweek.com/article2/0,4149,1394420,00.asp?kc=EWNWS112403DTX1K0000599
But Open Source is Safer?
"Despite a cracker incursion into Debian Project servers this week, representatives of the Debian Linux distribution said the open-source code behind it remains untouched."
This is not the first time an open-source site has been attacked by crackers. In March of this year, the Free Software Foundation Inc.'s GNU Project ftp servers were attacked. This assault, which caused no damage to the code, was only discovered months afterwards.
In the Debian case, though, the break-in was discovered within 24 hours. The cracker had gained access to four machines: "master," the bug-tracking system; "murphy," the mailing-list manager; "gluck," the Web server and Concurrent Versions System (CVS) system; and "klecker," which houses security, quality assurance and search-engine code. Martin Schulze, a Debian spokesman, reported that the Debian source code archives themselves were "not affected by this compromise."
"This kind of attack is inevitable in open source," Murdoch said. "We've increased security. At the beginning of Debian, becoming a developer was as easy as sending me an e-mail, but these days there are checks and balances in place to make sure that only real developers get in and that the code stays clean."
http://www.eweek.com/article2/0,4149,1394420,00.asp?kc=EWNWS112403DTX1K0000599
Monday, November 24, 2003
Take note of critical Office 2003 update and MiMail worm - TechRepublic:
"Fix
Symantec has posted a free tool for removing MiMail variants A through E, which will:
End the W32.Mimail viral processes.
Remove the W32.Mimail files.
Delete dropped files.
Delete the worm’s registry values."
http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.removal.tool.html
http://techrepublic.com.com/5100-6264_11-5104786.html
"Fix
Symantec has posted a free tool for removing MiMail variants A through E, which will:
End the W32.Mimail viral processes.
Remove the W32.Mimail files.
Delete dropped files.
Delete the worm’s registry values."
http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.removal.tool.html
http://techrepublic.com.com/5100-6264_11-5104786.html
Chicago Tribune | Survey: 31 Percent of U.S. Tech-Savvy:
"Technology geeks, unite. There are more of you than you might have realized. A study released Sunday found that 31 percent of Americans are 'highly tech-savvy' people for whom the Internet, cell phones and handheld organizers are more indispensable than TVs and old-fashioned wired phones. "
John Horrigan, author of the report by the Pew Internet & American Life Project, said the size of this "tech elite" was somewhat surprising. And while this group is predominantly young, the Pew researchers found plenty of baby boomers and seniors who are equally ardent about using technology.
The difference, though, is that techies in their late teens and 20s are more likely to create online content, like Web logs, or "blogs." Generation Xers are more likely to pay for content on the Web, while wired boomers and seniors generally plumb the Internet for news or to do work-related research.
So are you part of the "tech elite"? Consider these other Pew findings about how they live:…
http://www.chicagotribune.com/technology/sns-ap-tech-elite.story
"Technology geeks, unite. There are more of you than you might have realized. A study released Sunday found that 31 percent of Americans are 'highly tech-savvy' people for whom the Internet, cell phones and handheld organizers are more indispensable than TVs and old-fashioned wired phones. "
John Horrigan, author of the report by the Pew Internet & American Life Project, said the size of this "tech elite" was somewhat surprising. And while this group is predominantly young, the Pew researchers found plenty of baby boomers and seniors who are equally ardent about using technology.
The difference, though, is that techies in their late teens and 20s are more likely to create online content, like Web logs, or "blogs." Generation Xers are more likely to pay for content on the Web, while wired boomers and seniors generally plumb the Internet for news or to do work-related research.
So are you part of the "tech elite"? Consider these other Pew findings about how they live:…
http://www.chicagotribune.com/technology/sns-ap-tech-elite.story
Chicago Tribune | Questions, answers on cell phone changes:
"Questions and answers for consumers about changes in telecommunications rules:"
http://www.chicagotribune.com/technology/sns-ap-cell-phone-qa,1,1844433.story
"Questions and answers for consumers about changes in telecommunications rules:"
http://www.chicagotribune.com/technology/sns-ap-cell-phone-qa,1,1844433.story
Friday, November 21, 2003
Apple Plugs Vulnerabilities in Panther, Jaguar:
"The software updates a number of libraries, services and programs, including Personal File Sharing and QuickTime for Java. While described as the Security Update 2003-11-19 for Jaguar 10.2.8, the update is also recommended for Mac OS X 10.3, called Panther through Apple's automatic Software Update program. "
The update comes after Apple in October had been criticized for fixing some security problems in Mac OS X within its latest Panther release but not providing patches for earlier versions of the operating system. Later, the company indicated that it planned to offer patches for Jaguar.
http://www.eweek.com/article2/0,4149,1393307,00.asp?kc=EWNWS112103DTX1K0000599
"The software updates a number of libraries, services and programs, including Personal File Sharing and QuickTime for Java. While described as the Security Update 2003-11-19 for Jaguar 10.2.8, the update is also recommended for Mac OS X 10.3, called Panther through Apple's automatic Software Update program. "
The update comes after Apple in October had been criticized for fixing some security problems in Mac OS X within its latest Panther release but not providing patches for earlier versions of the operating system. Later, the company indicated that it planned to offer patches for Jaguar.
http://www.eweek.com/article2/0,4149,1393307,00.asp?kc=EWNWS112103DTX1K0000599
AeANET : 11/19/2003 - U.S. High-Tech Industry Sheds More than One-Half Million Jobs in 2002, AeA Report Says:
"However, Decline in 2003 Has Slowed Dramatically"
A study released today by AeA shows that in 2002 the U.S. high-tech industry lost 540,000 jobs, dropping from 6.5 million to 6.0 million. A preliminary look at data for 2003 shows that the decline in high-tech employment slowed considerably in 2003. The report, AeA’s annual Cyberstates 2003: A State-by-State Overview of the High-Technology Industry, details national and state trends in high-tech employment, wages, exports, and other economic indicators.
The sector with the largest decrease in jobs was electronics manufacturing, accounting for more than half of all tech jobs lost between 2001 and 2002. For the first time in the seven years of publishing Cyberstates, the software sector recorded a loss of nearly 150,000 jobs last year. Indeed, the once-thriving software sector posted large increases in employment in all previous editions of Cyberstates. The communications services sector posted a similar loss of jobs. The engineering and tech services sector lost 15,000 jobs in 2002. The one bright spot was in R&D and testing labs, where employment increased by 7,000 in 2002.
"While high-tech employment fell by eight percent last year, preliminary 2003 data show a significant slowdown in high-tech job losses, with a decline of four percent," said AeA’s President and CEO William T. Archey. "We project that the 2003 high-tech job losses will total 234,000--down 57 percent from the 540,000 decline in 2002."
Archey further stated, "However, these declines have caused us to pause about two important issues. We are aware of current budget constraints, but now is not the time to cut back on education, particularly in math and science. We need a world class workforce to deal with world class challenges. Our second concern is the decline in basic research, particularly in technology, by the federal government. We worry that we have eaten the seed corn of federal research of 20 and 30 years ago that is not being replenished."
For the first time, Cyberstates 2003 is based on the newly implemented North American Industry Classification System (NAICS). AeA selected 49 NAICS codes to define the high-tech industry. They fall into four broad categories: electronics manufacturing, communications services, software, and engineering and tech services. This more current and comprehensive system allows us to capture several sectors which we could not with the previous system. These include fiber optic cable manufacturers, semiconductor machinery manufacturers, and web search portals.
This new industry classification system is fundamentally different from the old Standard Industrial Classification (SIC) system. Every sector of the economy has been restructured and redefined by the NAICS. Consequently, the data presented in this report are not comparable in any way to previous editions of Cyberstates. In this edition, however, 2001, 2002, and 2003 data use the NAICS system and are therefore comparable.
Cyberstates 2003 found that all but three states lost high-tech jobs in 2002. California lost the greatest number of tech jobs, shedding some 123,000 jobs. Texas was second with tech jobs down by 61,000 jobs. Interestingly, the District of Columbia, Wyoming, and Montana were the only three cyberstates to add technology jobs between 2001 and 2002.
http://www.aeanet.org/PressRoom/idmk_cs2003_US.asp
"However, Decline in 2003 Has Slowed Dramatically"
A study released today by AeA shows that in 2002 the U.S. high-tech industry lost 540,000 jobs, dropping from 6.5 million to 6.0 million. A preliminary look at data for 2003 shows that the decline in high-tech employment slowed considerably in 2003. The report, AeA’s annual Cyberstates 2003: A State-by-State Overview of the High-Technology Industry, details national and state trends in high-tech employment, wages, exports, and other economic indicators.
The sector with the largest decrease in jobs was electronics manufacturing, accounting for more than half of all tech jobs lost between 2001 and 2002. For the first time in the seven years of publishing Cyberstates, the software sector recorded a loss of nearly 150,000 jobs last year. Indeed, the once-thriving software sector posted large increases in employment in all previous editions of Cyberstates. The communications services sector posted a similar loss of jobs. The engineering and tech services sector lost 15,000 jobs in 2002. The one bright spot was in R&D and testing labs, where employment increased by 7,000 in 2002.
"While high-tech employment fell by eight percent last year, preliminary 2003 data show a significant slowdown in high-tech job losses, with a decline of four percent," said AeA’s President and CEO William T. Archey. "We project that the 2003 high-tech job losses will total 234,000--down 57 percent from the 540,000 decline in 2002."
Archey further stated, "However, these declines have caused us to pause about two important issues. We are aware of current budget constraints, but now is not the time to cut back on education, particularly in math and science. We need a world class workforce to deal with world class challenges. Our second concern is the decline in basic research, particularly in technology, by the federal government. We worry that we have eaten the seed corn of federal research of 20 and 30 years ago that is not being replenished."
For the first time, Cyberstates 2003 is based on the newly implemented North American Industry Classification System (NAICS). AeA selected 49 NAICS codes to define the high-tech industry. They fall into four broad categories: electronics manufacturing, communications services, software, and engineering and tech services. This more current and comprehensive system allows us to capture several sectors which we could not with the previous system. These include fiber optic cable manufacturers, semiconductor machinery manufacturers, and web search portals.
This new industry classification system is fundamentally different from the old Standard Industrial Classification (SIC) system. Every sector of the economy has been restructured and redefined by the NAICS. Consequently, the data presented in this report are not comparable in any way to previous editions of Cyberstates. In this edition, however, 2001, 2002, and 2003 data use the NAICS system and are therefore comparable.
Cyberstates 2003 found that all but three states lost high-tech jobs in 2002. California lost the greatest number of tech jobs, shedding some 123,000 jobs. Texas was second with tech jobs down by 61,000 jobs. Interestingly, the District of Columbia, Wyoming, and Montana were the only three cyberstates to add technology jobs between 2001 and 2002.
http://www.aeanet.org/PressRoom/idmk_cs2003_US.asp
Customers rage at Google tweak | CNET News.com:
"In a rare sign of trouble for the booming search marketing business, Google is fending off complaints from angry customers who say recent changes to the company's advertising program are costing them sales.
The search engine giant tweaked its AdWords service in late October, saying it was making the move to better identify successful ads--those that get clicks--and to increase their visibility. It also took steps to reduce the number of unsuccessful ads that show up on its search results pages. A company representative said overall ad response rates have improved since the changes took effect. "
As keyword marketing grows in popularity, providers will likely face a tough balancing act to satisfy advertisers intent on bidding up prices and fighting for visibility on increasingly crowded lists.
But the new system hasn't improved results for everyone, leading to an outcry from those on the losing end. Disgruntled customers say the new system pits smaller companies against bigger ones, ultimately favoring deep-pocketed advertisers that can afford to outbid rivals for coveted keywords. In addition, some customers say the changes may be responsible for decreased conversion rates--the crucial sales that come after someone clicks on a Web advertisement.
"We would love to spend more with Google, but we're not going to overpay on (search) terms, when the surfer will click on terms and be frustrated and go elsewhere," said Daniel Mardorf, the Webmaster at Cellphonecarriers.com, who said he's seen response rates and sales from his Google ads drop since last month's changes took effect
http://news.com.com/2102-1024_3-5107406.html?tag=st_util_print
"In a rare sign of trouble for the booming search marketing business, Google is fending off complaints from angry customers who say recent changes to the company's advertising program are costing them sales.
The search engine giant tweaked its AdWords service in late October, saying it was making the move to better identify successful ads--those that get clicks--and to increase their visibility. It also took steps to reduce the number of unsuccessful ads that show up on its search results pages. A company representative said overall ad response rates have improved since the changes took effect. "
As keyword marketing grows in popularity, providers will likely face a tough balancing act to satisfy advertisers intent on bidding up prices and fighting for visibility on increasingly crowded lists.
But the new system hasn't improved results for everyone, leading to an outcry from those on the losing end. Disgruntled customers say the new system pits smaller companies against bigger ones, ultimately favoring deep-pocketed advertisers that can afford to outbid rivals for coveted keywords. In addition, some customers say the changes may be responsible for decreased conversion rates--the crucial sales that come after someone clicks on a Web advertisement.
"We would love to spend more with Google, but we're not going to overpay on (search) terms, when the surfer will click on terms and be frustrated and go elsewhere," said Daniel Mardorf, the Webmaster at Cellphonecarriers.com, who said he's seen response rates and sales from his Google ads drop since last month's changes took effect
http://news.com.com/2102-1024_3-5107406.html?tag=st_util_print
Thursday, November 20, 2003
ZDNet AnchorDesk: It wasn't me, it was the Trojan horse:
"Remember the Twinkie defense? Well, now there's the Trojan horse defense. That's right: In three recent court cases in the United Kingdom, defendants pleaded not guilty on the basis that someone else put code on their computer (via a Trojan horse) that caused their machines to break the law. "
While these cases have no direct bearing on U.S. court cases, they could lead to creative defenses for computer-related crimes in this country as well.
THE FIRST TWO cases involved the downloading of child pornography, while the third concerned a denial-of-service attack that caused real-world economic damage. All three defendants were acquitted.
In one of the child pornography cases, Karl Schofield of Whitley, England was cleared of processing 14 images of child pornography on his home PC. In the other, Julian Green of Devon, England, who was acquitted of storing 172 images of child pornography on his system.
In both cases, computer forensics experts found evidence of Trojan horses on the suspects' hard drives. The rogue code was allegedly deposited there via pop-up advertisements, banner ads, or Internet worms.
The third case involved a U.K. teenager named Aaron Caffrey. U.S. police discovered that his computer was responsible for the denial-of-service attack that crashed servers at the Port of Houston in October. However, Caffrey claimed that someone else put a Trojan horse on his PC that allowed his system to be controlled remotely. When investigators were unable to find evidence of such a remote-control Trojan, Caffrey claimed the Trojan had automatically erased itself.
THIS SEEMS suspicious to me, if only because Microsoft Windows (the operating system on Caffrey's computer) is notorious for creating duplicates or logs of all data. So either Caffrey was lying, or the authorities who investigated him were inept, as evidence of a Trojan horse should be relatively easy to find. Computer forensics tools, such as Guidance Software's EnCase, can quickly reveal hidden, partial, or even deleted files.…
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5107486.html?tag=adss
"Remember the Twinkie defense? Well, now there's the Trojan horse defense. That's right: In three recent court cases in the United Kingdom, defendants pleaded not guilty on the basis that someone else put code on their computer (via a Trojan horse) that caused their machines to break the law. "
While these cases have no direct bearing on U.S. court cases, they could lead to creative defenses for computer-related crimes in this country as well.
THE FIRST TWO cases involved the downloading of child pornography, while the third concerned a denial-of-service attack that caused real-world economic damage. All three defendants were acquitted.
In one of the child pornography cases, Karl Schofield of Whitley, England was cleared of processing 14 images of child pornography on his home PC. In the other, Julian Green of Devon, England, who was acquitted of storing 172 images of child pornography on his system.
In both cases, computer forensics experts found evidence of Trojan horses on the suspects' hard drives. The rogue code was allegedly deposited there via pop-up advertisements, banner ads, or Internet worms.
The third case involved a U.K. teenager named Aaron Caffrey. U.S. police discovered that his computer was responsible for the denial-of-service attack that crashed servers at the Port of Houston in October. However, Caffrey claimed that someone else put a Trojan horse on his PC that allowed his system to be controlled remotely. When investigators were unable to find evidence of such a remote-control Trojan, Caffrey claimed the Trojan had automatically erased itself.
THIS SEEMS suspicious to me, if only because Microsoft Windows (the operating system on Caffrey's computer) is notorious for creating duplicates or logs of all data. So either Caffrey was lying, or the authorities who investigated him were inept, as evidence of a Trojan horse should be relatively easy to find. Computer forensics tools, such as Guidance Software's EnCase, can quickly reveal hidden, partial, or even deleted files.…
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5107486.html?tag=adss
Subscribe to:
Posts (Atom)
