Thursday, February 05, 2004

Do Web search engines suppress controversy?:
"Do Web search engines suppress controversy? by Susan L. Gerhart

Web behavior depends upon three interlocking communities: (1) authors whose Web pages link to other pages; (2) search engines indexing and ranking those pages; and (3) information seekers whose queries and surfing reward authors and support search engines. Systematic suppression of controversial topics would indicate a flaw in the Web’s ideology of openness and informativeness. This paper explores search engines’ bias by asking: Is a specific well–known controversy revealed in a simple search? Experimental topics include: distance learning, Albert Einstein, St. John’s Wort, female astronauts, and Belize. The experiments suggest simple queries tend to overly present the "sunny side" of these topics, with minimal controversy. A more "Objective Web" is analyzed where: (a) Web page authors adopt research citation practices; (b) search engines balance organizational and analytic content; and, (c) searchers practice more wary multi–searching."

http://www.firstmonday.dk/issues/issue9_1/gerhart/

Wednesday, February 04, 2004

Microsoft shrugs off MyDoom attack - News - ZDNet:
"Microsoft has created an alternate Web site for people whose PCs are infected with MyDoom.B and who want to get security information but cannot contact the main site because of a mechanism in the virus that blocks some 65 Web sites, including Microsoft's home page. The alternate site, which starts with 'information' rather than 'www,' lets people see the regular home page content."

http://information.microsoft.com/

http://zdnet.com.com/2100-1105_2-5152702.html
Halting MyDoom Is a Free Download Away:
"MyDoom.A has 'DoS-ed' SCO.com out of commission, forcing the company to establish thescogroup.com in order to maintain its presence on the Internet. Microsoft, thus far, has fared better as MyDoom.B has yet to cripple the software giant's considerable defenses.

But where are individual PC users supposed to turn for relief? "

http://www.enterpriseitplanet.com/security/news/article.php/3307751
Google Ultimate Interface - Fagan Finder

If you want all of Google's tools and options conveniently displayed on a single screen, try FaganFinder.…It even has handy links for typing non-English letters.

http://www.faganfinder.com/google.html
Hidden Google Tools:
"Even if you consider yourself a Google expert, these 'hidden' tools and resources let you push the search engine's capabilities to the max. "

http://searchenginewatch.com/searchday/article.php/3304771
The Search Engine Report - Number 87:
"

+ Search Engine Watch News

+ Preview Of SES New York

+ Search Engine Articles By Danny Sullivan

+
SearchDay Articles

+ Search Engine Articles

+ Search Engine Resources

+ About The Newsletter

"


http://searchenginewatch.com/sereport/print.php/34721_3308131
Microsoft Patches Serious IE Flaw:
"Microsoft Corp. on Monday finally released a patch for a dangerous vulnerability that lets attackers trick Internet users into visiting malicious sites. The flaw has been public knowledge for some time, but Microsoft failed to include a fix for it with January's scheduled patch releases."

http://www.eweek.com/article2/0,4149,1485698,00.asp
IT Losing Ground in Virus Battle:
"After years of success deploying more effective and smarter defenses, anti-virus researchers contacted last week in the wake of the MyDoom outbreak acknowledged for one of the first times that the battle may be getting away from them.

The MyDoom virus, which hit Jan. 26 and infected several-hundred-thousand machines, is the fastest-spreading virus in the history of the Internet, experts said. At its peak late last week, MyDoom had infected one in every 12 pieces of e-mail, according to MessageLabs Inc., a New York-based e-mail security company. MyDoom also is the latest in a line of recent viruses that, while not particularly innovative, have been maddeningly effective."

http://www.eweek.com/print_article/0,3048,a=117996,00.asp

Tuesday, February 03, 2004

Accessible Website Menu: Ultimate Drop Down Menu by Brothercake:
"Ultimate Drop Down Menu v4.0 [beta] by Brothercake

UDM is a lightweight and accessible javascript menu, which provides useable content to all browsers - including screenreaders, search-engines and text-only browsers. But accessibility shouldn't mean compromise, and so UDM has a sophisticated range of design and usability controls, many of which are unique to this script. "

http://af.brothercake.com/dropdown/

Saturday, January 31, 2004

Another IE Spoofing Hole Found — sigh!:
"Security researchers are warning of another spoofing vulnerability in Internet Explorer, this time one that allows an attacker to mask the true file extension of malicious downloads.

The file-extension spoof means that an attacker could lull a user into opening a malicious file from a Web site by making the file appear as a legitimate extension, such as a PDF or MPEG, researchers said on Wednesday.… "

Users can avoid the vulnerability by first saving a download to a folder, rather than directly opening it, when prompted by IE. Saving the file reveals its true file name.

A Microsoft Corp. spokeswoman said the company is investigating the file-name spoofing vulnerability but could not say whether a fix would be ready at the same time as a planned patch for another IE spoofing vulnerability.

The other vulnerability, disclosed in December, could allow attackers to fake URLs in the Web browser's address bar and convince users to disclose sensitive information.

Microsoft officials have said they have a patch ready to fix that vulnerability but are testing it for multiple versions of IE on various platforms and for various languages.

http://www.eweek.com/article2/0,4149,1473145,00.asp

Friday, January 30, 2004

Antivirus feature creates a burden - News - ZDNet:
"A common antivirus feature that automatically replies to e-mails infected with a virus--to inform the senders that they are infected--is obsolete and should be disabled, because it creates almost as much trouble as the virus itself, according to security experts.

When an antivirus application detects malware in an e-mail, such as the recent MyDoom worm, it can automatically reply to senders of messages to inform them that they have been infected. However, virtually all modern e-mail viruses disguise the original senders' addresses by spoofing the 'to' field of the reply message with stolen, but valid, e-mail addresses. This means that users receive e-mails telling them that they are infected when they are not, resulting in significant quantities of unnecessary traffic. "

This additional traffic is a further burden on administrators, because it occurs when companies are trying to clean their systems from the virus attack. Jack Clark, technology consultant at McAfee, an antivirus division of Network Associates, estimates that "bounce-back" e-mails play a significant part in slowing down corporate networks and says the feature should be disabled immediately.

http://zdnet.com.com/2100-1105_2-5148995.html

Wednesday, January 28, 2004

Breaking Virus News: MyDoom Hobbles Internet E-mail:
"Removing/Blocking MyDoom

The easiest way to remove MyDoom and Novarg is to update your antivirus program. As of 1/27, most antivirus vendors have added at least beta detection and deletion to their pattern definition updates. If you don't have an antivirus, we have confirmation that TrendMicro's freely available Housecall http://housecall.trendmicro.com, has been updated to detect the virus, but you'll have to manually remove the registry entries as outlined below. Panda Software also has a free removal utility (registry required) for MyDoom, http://www.pandasoftware.com/ virus_info/encyclopedia/

overview.aspx?idvirus=44140. McAfee's stinger http://vil.nai.com/vil/stinger/ has also been updated to detect and remove MyDoom. Note that you need to reboot after running Stinger to completely repair your system."

http://www.pcmag.com/print_article/0,3048,a=117496,00.asp
Chicago Tribune | Computer users worldwide fall victim to worm:
"A rapidly spreading worm has infected personal computers worldwide, clogging e-mail traffic at an unprecedented pace.

Known as MyDoom, the worm is sent as an attachment and is contained in about one of every 12 e-mails sent, according to one security firm. Other experts said the message accounts for one in nine sent globally."

That volume makes MyDoom the most prolific worm or virus ever, according to security firm MessageLabs, surpassing last year's SoBig virus. SoBig was detected on one out of every 17 e-mails.

The worm propagates through cleverly written e-mail, Internet security analysts say. When opened, the worm replicates itself on e-mail addresses it finds and is sent on to new potential victims.

The worm doesn't exploit any flaws in the Windows operating system, but once inside a computer it releases a virus that allows the attackers to gain access and use the computer to launch an attack.…

The worm and its variant strains all have the same target: software firm SCO Group, of Lindon, Utah.

Infected computers are set to swamp SCO's Web site beginning Sunday in what is known as a denial-of-service attack. A successful denial-of-service attack causes a Web site to become inaccessible, effectively shutting it down. The attack is scheduled to start Sunday and continue until Feb. 12.

SCO owns the Unix computer operating system and maintains that Linux, a popular free operating system, infringes on its copyright by incorporating Unix features. SCO has gone to court to assert its ownership rights, angering some computer hackers who see Linux as an alternative to Microsoft's Windows.…

This is a pretty darned sophisticated worm," said David Perry, global education director for Trend Micro, a computer security company. "It is very well socially engineered."

Social engineering is a way of saying the worm is adept at getting users to open e-mail and activate the program.

The worm was first noticed Monday on the computer networks of major corporations, Perry said. That means the person who created MyDoom knows that corporate users can have hundreds or thousands of e-mail addresses on their computers, while home users typically have far fewer.

"If a corporate desktop gets infected, it can send out 5,000 or 6,000 e-mails in a tenth of a second," Perry said. He said that hundreds of thousands of computers have since become infected, in part because of MyDoom's rapid reproduction.

Many people know not to open suspicious e-mail or to click on e-mail attachments from strangers. But MyDoom "spoofs" its recipients by sometimes using the return e-mail address of an individual known to the target.

And the e-mail's message can be deceptive.

The subject line in some e-mails reads "Mail Transaction Failed," and the message includes "Partial message is available" and an icon to click.

Perry said such e-mail is a lot more likely to be opened than a typical spam message.

http://www.chicagotribune.com/technology/chi-0401280318jan28,1,1664606.story?coll=chi-newsnationworld-hed

Tuesday, January 27, 2004

HANDWRITING FONTS TO LOAD:
"How about borrowing somebody else's handwriting (especially if yours isn't all that neat to begin with)?"

Download the font you like, unzip the .zip file, and copy the .ttf file to your Fonts folder in your Windows directory.

http://pro.wanadoo.fr/dephitro/telechf1.htm

Friday, January 23, 2004

Easily and Safely Installing a Motherboard:
"Without a motherboard, your CPU is a very expensive silicon and plastic keychain accessory. Without a motherboard, that Radeon 9700 graphics card makes a great doorstop. Without a motherboard, there is no PC.

Motherboards used to be a pain in the derriere to install. A typical motherboard had zillions of jumper settings for different CPU clocks, frontside bus speeds, floating point coprocessors and memory module sizes. That time passed long ago, as chronology of technology is measured. Today's motherboards are more complex than ever, in terms of features sets, but are easier to install and simpler to set up than ever before. "

http://www.extremetech.com/print_article/0,3998,a=34474,00.asp

Thursday, January 22, 2004

Easing of Internet Regulations Challenges Surveillance Efforts:
"In a series of unpublicized meetings and heated correspondence in recent weeks, officials from the Justice Department, the Federal Bureau of Investigation and the Drug Enforcement Administration have repeatedly complained about the commission's decision in 2002 to classify high-speed Internet cable services under a looser regulatory regime than the phone system.

The Justice Department recently tried to block the commission from appealing a decision by a federal appeals court two months ago that struck down major parts of its 2002 deregulatory order. Justice Department officials fear that the deregulatory order impedes its ability to enforce wiretapping orders. "

The department ultimately decided to permit the F.C.C. to appeal, but took the highly unusual step of withdrawing from the lawsuit, officials involved in the case said.

As a result of the commission's actions, said John G. Malcolm, a deputy assistant attorney general who has played a lead role for the Justice Department, some telecommunications carriers have taken the position in court proceedings that they do not need to make their networks available to federal agents for court-approved wiretapping.

"I am aware of instances in which law enforcement authorities have not been able to execute intercept orders because of this uncertainty," Mr. Malcolm said in an interview last Friday. He declined to provide further details.

The clash between the commission and officials from the Justice Department and other law enforcement agencies pits two cherished policies of the Bush administration against each other. On one side stand those who support deregulation of major industries and the nurturing of emerging technologies; on the other are those who favor more aggressive law enforcement after the Sept. 11 terrorist attacks.

The outcome of the debate has far- reaching consequences.…

David Fiske, the commission's chief spokesman, said that he could not respond to Mr. Malcolm's statement that the F.C.C.'s interpretation of the rules was making it more difficult to execute surveillance orders.

A senior official at the F.C.C. said the commission was not unsympathetic to the concerns of the law enforcement agencies. "We're an economic regulatory agency as well as a law enforcement agency and we have to look at the interests of everyone," the official said.

Some industry experts say that their biggest worry is that law enforcement demands may reshape the technical specifications of the new Internet voice services, an accusation that officials at the Justice Department and the F.B.I. deny.

"What's most scary for industry and perhaps some people at the F.C.C. is the notion that the architecture of the Internet will depend on the permission of the F.B.I.," said Stewart A. Baker, a former general counsel of the National Security Agency, which monitors foreign communications. Mr. Baker now represents a number of telecommunications companies as a partner at the law firm of Steptoe & Johnson.

But law enforcement officials say they are not seeking uniform technical standards but requirements that the new companies offering so-called "voice over Internet" services build into their systems easy ways for agents to tap into conversations between suspects.

In a strange-bedfellows twist, officials from the F.B.I. and other agencies have found themselves the unlikely allies of groups like the American Civil Liberties Union, which have also argued that the new Internet services offered by cable companies should be under a regulatory regime like the phone system — but for different reasons. The A.C.L.U. prefers that approach because it would prohibit cable companies from discriminating against Internet service providers, and as such would assure a greater diversity of voices.

http://www.nytimes.com/2004/01/22/technology/22VOIC.html?pagewanted=all&position=

Wednesday, January 21, 2004

Report Says Internet Voting System Is Too Insecure to Use:
"A new $22 million system to allow soldiers and other Americans overseas to vote via the Internet is inherently insecure and should be abandoned, according to a panel of computer security experts asked by the government to review the program.

The system, Secure Electronic Registration and Voting Experiment, or SERVE, was developed with financing from the Department of Defense and will first be used in this year's primaries and general election."

The authors of the new report noted that computer security experts had already voiced increasingly strong warnings about the reliability of electronic voting systems, but they said the new voting program, which allows people overseas to vote from their personal computers over the Internet, raised the ante on such systems' risks.

The system, they wrote, "has numerous other fundamental security problems that leave it vulnerable to a variety of well-known cyber attacks, any one of which could be catastrophic." Any system for voting over the Internet with common personal computers, they noted, would suffer from the same risks.

The trojans, viruses and other attacks that complicate modern life and allow such crimes as online snooping and identity theft could enable hackers to disrupt or even alter the course of elections, the report concluded. Such attacks "could have a devastating effect on public confidence in elections," the report's authors wrote, and so "the best course to take is not to field the SERVE system at all."

http://www.nytimes.com/2004/01/21/technology/23CND-INTE.html?pagewanted=all&position=

Saturday, January 17, 2004

Schneier.com: Crypto-Gram: January 15, 2004 — Color-Coded Terrorist Threat Levels:
"… the threat levels are largely motivated by politics. There are two possble reasons for the alert.

Reason 1: CYA. Governments are naturally risk averse, and issuing vague threat warnings makes sense from that perspective. Imagine if a terrorist attack actually did occur. If they didn't raise the threat level, they would be criticized for not anticipating the attack. As long as they raised the threat level they could always say 'We told you it was Orange,' even though the warning didn't come with any practical advice for people. "

Reason 2: To gain Republican votes. The Republicans spent decades running on the "Democrats are soft on Communism" platform. They've just discovered the "Democrats are soft on terrorism" platform. Voters who are constantly reminded to be fearful are more likely to vote Republican, or so the theory goes, because the Republicans are viewed as the party that is more likely to protect us.

(These reasons may sound cynical, but I believe that the Administration has not been acting in good faith regarding the terrorist threat, and their pronouncements in the press have to be viewed under that light.)

I can't think of any real security reasons for alerting the entire nation, and any putative terrorist plotters, that the Administration believes there is a credible threat.

http://www.schneier.com/crypto-gram-0401.html#1

Friday, January 16, 2004

News: Report: Spam claims two-thirds of e-mail:
"MessageLabs, an e-mail filtering company, claims 65 percent of e-mail sent to its users is spam, according to data it collected during December and released Monday.

While the statistics point to a dramatic upswing in the ratio of spam to legitimate e-mails--up from 43.7 percent in September, 50.5 percent in October and 55.1 percent in November--the figures only take into account e-mails being sent to MessageLabs' clients, many of whom signed up to the service because they received a high volume of spam, MessageLabs Australia's technical director David Banes conceded. "

http://zdnet.com.com/2100-1105_2-5139469.html

Thursday, January 15, 2004

The Ten Immutable Laws of Security Administration :
"As in the case of the immutable laws for users, the laws on this list reflect the basic nature of security, rather than any product-specific issue. Don't look for a patch from a vendor, because these laws don't result from a technology flaw. Instead, use common sense and thorough planning to turn them to your advantage."

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/columns/security/essays/10salaws.asp

Wednesday, January 14, 2004

News: Wi-Fi testing finds weak links:
"At least one in every four Wi-Fi products examined by the Wi-Fi Alliance has failed its certification test--a sign that many pieces of wireless equipment on the market are incapable of working as well as users might expect. "

Products that sport the Alliance's seal of approval are certified to work with each other and provide the performance expected from the 802.11a, b or g standards. This means that users can buy certified 802.11x routers, access points and cards knowing that they should all be compatible.

But while a great many Wi-Fi products have been approved by the Alliance, several hundred did not pass its tests.

"Based on testing of more than 1,000 products over several IEEE 802.11 standards, products that are prepared for Wi-Fi certification testing fail 25 (percent) to 30 percent of the time--or more depending on the technology being tested," said Wi-Fi Alliance managing director Frank Hanzlik.

"Products that do not go through the rigorous testing preparation process have an even higher failure rate. Without Wi-Fi certification, these product failures would have been experienced by the technology consumer," Hanzlik added.

A product that fails Wi-Fi certification can still be launched, though, and a manufacturer could still label its wireless products as "802.11b compatible" even if they only work with its own range of equipment and not with those from another company.

The Wi-Fi Alliance says that certification is becoming increasingly important as the wireless-networking market grows and matures.

http://zdnet.com.com/2100-1103_2-5139499.html

Tuesday, January 13, 2004

Calendar Of Updates (Powered by Invision Power Board):
"Keep Your Security Software Current
Upgrades, Updates & Definitions"

… hard working people have put together a web site that deals with software updates, especially security updates. It is a free site where members can help with the updates.

Thanks to WinXPnews
http://www.winxpnews.com/issues.cfm

http://www.dozleng.com/updates/

Monday, January 12, 2004

Microsoft Bows to Pressure, Extends Support for Older Windows Versions:
"Microsoft Corp. on Monday capitulated to customer pressure and announced that it would now continue extended support for Windows 98, Windows 98 Second Edition and for Windows Millennium Edition (ME) until June 30, 2006. "

… on Monday a company spokesman told eWEEK that the decision to extend support for the products was "part of Microsoft's ongoing effort to respond to customers' needs around the world." During this time, Microsoft will continue to offer paid phone support and will continue to review any critical security issues and take appropriate steps.

"Microsoft made this decision to accommodate customers worldwide who are still dependent upon these operating systems and to provide Microsoft more time to communicate its product lifecycle support guidelines in a handful of markets—particularly smaller and emerging markets," he said.

According to officials, Microsoft also wanted to bring Windows 98 SE into compliance with the company's current lifecycle policy for new products, which provides for support for seven years instead of the original four.

"Microsoft made the decision to also lengthen support for Windows 98 and Windows Me customers through the same date in order to provide a clear and consistent date for support conclusion for all of these older products," the spokesman said.

The move is expected to bring relief to some IT users, and particularly consumers, given the millions who still use the products.

http://www.eweek.com/article2/0,4149,1434318,00.asp
News: Windows 98 support shifts to CD:
"When Microsoft pulls the plug on Windows 98 support next Friday, it will offer a free CD designed to help users 'make the most' of the aging operating system, without any further assistance from the software giant.

Six years after its launch, Windows 98 is still used by about a fourth of Web surfers. Microsoft announced last year that it would stop supporting Windows 98 on Jan. 15, meaning that millions of users will soon be left exposed when new exploits and vulnerabilities are discovered. "

Lars Ahlgren, senior marketing manager at Microsoft, told ZDNet UK that the CD, which the software giant created with Future Publishing, will provide hints and tips, technical content and exclusive Knowledge Base articles. The content will also be published on Microsoft's support Web sites.


"We have made an arrangement with Future Publishing so we get Windows 98 content that is not just technical; it is also about how to get more from your Windows 98 machine. For those who have difficulties getting on the Web or want the content on a CD, we will ship them the CD for free, if they call us or register on the Web," Ahlgren said.

Ahlgren also acknowledged that Microsoft is hoping to keep Windows 98 users' expectations low, so that if there is a serious security breach the company decides to patch, they will be pleasantly surprised.

http://zdnet.com.com/2100-1104_2-5138328.html

Friday, January 09, 2004

Phishing: Spam that can’t be ignored:
"If you haven’t already heard about phishing, then get ready. Like a lot spam, phishing is a form of unsolicited commercial email. Whereas all spam is not a scam, all attempts at phishing are scams, and the potential losses to corporations and consumers alike is stunning"

Phishing: Spam that can’t be ignored
By David Berlind, Tech Update
January 7, 2004

If you haven’t already heard about phishing, then get ready. Like a lot spam, phishing is a form of unsolicited commercial email. Whereas all spam is not a scam, all attempts at phishing are scams, and the potential losses to corporations and consumers alike is stunning.

Phishing, as the name implies, is when spam is used as means to “fish” for the credentials that are necessary to access and manipulate financial accounts. Invariably, the e-mail will ask the recipient for an account number and the related password using an explanation that their records need updating or a security procedure is being changed that requires confirming an account. Unsuspecting e-mail recipients that supply the information don’t know it, but within hours or even minutes, unauthorized transactions will begin to appear on whatever account was compromised.

By now, most people know that giving this information away on the Internet is a no-no. With phishing, however, it’s almost impossible to tell that the e-mail is a fraud. Like spam, e-mail from phishers usually contains spoofed FROM or REPLY TO addresses to make the e-mail look as though it came from a legitimate company.

In addition to the spoofed credentials, the e-mail is usually HTML-based. To an undiscerning eye, the e-mail bears the authentic trademarks, logos, graphics, and URLs of the spoofed company. In many cases, the HTML page is coded to retrieve and use the actual graphics of the site being spoofed. Most of the phishing I’ve received pretends to come from PayPal and contains plainly visible URLs that make it look as though clicking on them will take me to PayPal’s domain. Upon quick examination of the HTML tags behind the authentic looking link, the actual URL turns out to be an unrecognizable and cryptic looking IP address rather than an actual page within PayPal’s domain.

PayPal, the payment subsidiary of EBay, is a common target of phishing. If you get one and you’ve never joined PayPal, then you obviously know it’s a fraud. But if you are a PayPal member, as I am, the phisher has at that point broken through the unofficial security-by-obscurity layer that once protected you. It not difficult to see how PayPal members could be victimized by this technique.

According to Antiphishing Working Group Chairman David Jevans, PayPal isn’t the only target of phishers. “In about 35 percent of all reported phishing attacks, Ebay’s PayPal service is the biggest victim. But just about any financial institution, credit card issuer, retailer, or other business can be targeted. UK-based NatWest was phished badly in October 2003 and then even worse in December. The December attack was so bad that NatWest had to take down its site. Visa was another organization that was targeted over the holidays.”

At first blush, phishing appears to be sort of buyer-beware consumer issue since the e-mails themselves are prospecting for potential account holders to the spoofed institutions. Indeed, depending on the spoofed institution’s policies, a consumer could end up eating a loss. “So far,” said Jevans, “most of the transgressions against individuals have been in the hundreds of dollars because smaller transactions will sometimes go unnoticed for a while. But they go higher. The largest one on record so far is for $16,000. If the credentials obtained by a phisher are for a credit card account, then the risk is usually absorbed by either card issuer or a merchant.” This is when the hard dollar cost of phishing, which Jevans considers a form of identity theft, begins to be recognized by corporations and businesses instead of individuals.

http://techupdate.zdnet.com/techupdate/stories/main/Phishing_Spam_that_cant_be_ignored.html
Novell's Linux Makeover:
"Ximian Desktop Boosts SuSE Linux Support
Ximian, now part of Novell, enhances its desktop offering to run with SuSE Linux's latest versions as Novell's SuSE purchase nears completion."


http://www.eweek.com/article2/0,4149,1428558,00.asp

http://www.eweek.com/category2/0,4148,1375052,00.asp

Thursday, January 08, 2004

Tenacious W32/Sober.c-mm Attacks:
"Top Virus: W32/Sober.C-mm …

W32/Sober.C-mm is a variation of Sober.A, which hit in late October, 2003. Like its cousin, Sober.C spreads as an email attachment, and uses its own SMTP engine to propagate. The worm harvests email addresses from various files on the victim's system, and can spoof the 'from' field as well, when sending copies of itself. The attachment name is randomly chosen from over two dozen different English or German names, and can have a .bat, .pif, .cmd, .scr, .exe, or .com extension. The message and subject line varies, and can be in either German or English. TrendMicro's analysis of Sober.C has a comprehensive list of the subject, attachment name, and message possibilities. The virus infects when the recipient opens the attachment, making it fairly preventable. "

When Sober.C executes, it creates two copies of itself in the %system% folder (by default is C:\windows\system for Windows 9x, C:\Winnt\system32 for Windows 2000/NT or C:\windows\system32 for Windows XP.) The file names are randomly generated, and the files themselves may be appended with random garbage data to inhibit antivirus detection. It then adds the these names to the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

These entries allow the virus to automatically start when they victim's machine is booted.

The virus scans the victim's hard disk for email addresses within database or text based files, and stores them in the %system% folder under the name savesyss.dll. As an indicator of infection, when Sober.C runs for the first time, it displays a fake error message box with the message:

"First" as caused an unknown error. Stop: 00000010x08.

Sober.C guards its position greedily by running two memory processes that watch out for each other. Terminating a virus process is a standard procedure to do before removing the virus. However, if a user terminates only one of the processes, the other process of Sober.C recognizes its mate is gone, and restarts it, making removal difficult.

http://www.pcmag.com/print_article/0,3048,a=115641,00.asp
News: Microsoft publishes program to blast MSBlast:
"Microsoft released a removal tool for the MSBlast worm on Monday after Internet service providers complained that home users' PCs infected with the malicious program are still causing network congestion.

The MSBlast worm, also commonly called the Blaster worm, started spreading last August and is believed to have spread to hundreds of thousands of systems. While most corporations have cleaned up the worm, Microsoft has found that a large number of home users are still unknowingly infected, the software giant said in a statement. "

"For many users in this situation, there is little indication that they are infected other than possible performance degradation," Microsoft said. "And those infected are still actively transmitting the worm, causing Internet congestion in the process."

Microsoft's aim in releasing the latest tool is to reduce the amount of traffic being borne by ISPs by cleaning up a significant number of home computers.

The tool can be found on Microsoft's download site.



http://www.microsoft.com/downloads/details.aspx?FamilyID=e70a0d8b-fe98-493f-ad76-bf673a38b4cf&displaylang=en

http://zdnet.com.com/2100-1104_2-5136260.html

Wednesday, January 07, 2004

The Search Engine Report - Number 86:
"The Search Engine Report - Number 86"

+ Search Engine Watch News
+ SES Returns To The Big Apple!
+ Search Engine Articles By Danny Sullivan
+ SearchDay Articles
+ Search Engine Articles
+ Search Engine Resources
+ SES Coverage

http://searchenginewatch.com/sereport/article.php/3296121
20 Tips for Taking Better Pictures Today:

http://www.pcmag.com/category2/0,4148,2461,00.asp
Security Highlights and Lowlights of 2003:
"The consensus among security professionals is solid: 2003 was a lousy year for computer security. And the news won't be much better in the year ahead; things are trending for the worse.… "

http://www.eweek.com/print_article/0,3048,a=114506,00.asp
News: Security flaws force Linux kernel upgrade:
"Open-source developers released a new version of the Linux kernel Monday in a move aimed at quickly fixing several bugs--among them two serious security flaws.

The 2.4.24 upgrade to the Linux kernel comes a month after the release of the previous version of the core system software and only includes patches for six software issues, including the two flaws.

The release is intended to prompt users to upgrade quickly, said Marcelo Tosatti, the maintainer of the 2.4 kernel series and a Linux developer for data center management company Cyclades.… "

The most serious flaw, which occurs in a function used by virtual memory, resembles a vulnerability fixed in late November that had been exploited by unknown attackers to control several key Linux servers open-source developers use. Both flaws allow an intruder to increase the privileges of a normal user account to the same level as the system's owner.

Tosatti said that once it became clear that the latest flaw could be used to circumvent security on Linux systems, he and other developers decided to immediately release the fixes. The move follows decisions by the kernel developers to curtail new features in the 2.4 kernel series in order to get developers and users to move to the next generation of core Linux software, the 2.6 kernel. The final set of features that had been intended for this release of the kernel have been postponed until the next version, he said.

http://zdnet.com.com/2100-1105_2-5135129.html?tag=zdfd.newsfeed
Using Microsoft eBook technology to create portable documentation - Builder.com


http://builder.com.com/5100-6373-5129225.html?tag=e055

Tuesday, January 06, 2004

Symantec Security Response - W32.Jitux.Worm:
"W32.Jitux.Worm is a worm that attempts to spread through MSN Messenger.

This threat is written in the Visual Basic (VB) programming language. The VB runtime libraries are required for it to be executed."

http://securityresponse.symantec.com/avcenter/venc/data/w32.jitux.worm.html
Ten Steps for Cleaning Up Information Pollution (Jakob Nielsen's Alertbox):
"Our knowledge environment is getting ever more contaminated by information pollution. Things we need to know are drowning in irrelevant information. Symptoms include:

  • In most companies, employees squander an hour or more each day simply 'doing email.'

  • Employees fritter away 48 hours each year trying to unearth job-related information on bad intranets compared to the time they would need on an intranet with usability in the top 25%. The resulting productivity loss amounts to millions of dollars for mid-sized companies.

  • Many websites alienate users by burying answers to basic questions in useless corporatese.

  • Email messages that customers actually want, such as useful newsletters or customer-service confirmations, don't survive overflowing inboxes -- often because senders ignore the principles of good email design.
"
What Individuals Can Do

All time-management courses boil down to one basic piece of advice: set priorities and allocate the bulk of your time to tasks that are crucial to meeting your goals. Minimize interruptions and spend big chunks of your time in productive and creative activity.

Unfortunately, current information systems encourage the opposite approach, leading to an interrupt-driven workday and reduced productivity. Here are six steps to regaining control of your day

http://www.useit.com/alertbox/20040105.html
Free newsletter - HFI's UI Design Update:
"HFI's December newsletter reviews the findings of the research presented in our Putting Research into Practice course. In preparing this course, recent research from various disciplines (including Human Computer Interaction / Ergonomics, Cognitive & Social Psychology, Computer Science, Marketing, Economics...) that might have implications for usability professionals is systematically reviewed. The most interesting, important, and applicable papers are summarized for presentation in our 3 day seminar – essentially a "Cliff Notes" course for usability research, updated annually.

The list below differs slightly from that of previous years. Rather than presenting design "dos" and "don'ts", this year we present key findings of many of the papers presented in the 2003 PRP course. As such, in addition to providing design guidance, this list provides you recent research references to directly justify your analysis, design, and testing decisions."

http://www.humanfactors.com/downloads/dec03.asp#susan
Rapid Application Development with Mozilla: Navigation. Pt. 2 - WebReference.com -

http://www.webreference.com/programming/mozilla/2/index.html
The XML Schema Companion - WebReference.com -:
"Although the XML Schema language has a large number of built-in data types that can be used, restricted, and extended, some requirements demand much finer con­trol over the exact structure of a value. For example, a simple code might need to consist of three lowercase letters:"

abc

ABC

abcd

Similarly, when an element or attribute contains an ISBN (International Standard Book Number), it should be possible to apply constraints that reflect the nature of ISBN codes. All ISBN codes are composed of three identifiers (location, pub­lisher, and book) and a check digit, separated by hyphens (or spaces). Valid values would include ‘0-201-41999-8’ and ‘963-9131-21-0’. The schema processor should detect any error in an ISBN attribute:





Some programming languages, such as Perl, include a regular expression lan­guage, which defines a pattern against which a series of characters can be com­pared. Typically, this feature is used to search for fragments of a text document, but the XML Schema language has co-opted it for sophisticated validation of ele­ment content and attribute values.

http://www.webreference.com/programming/awxml1/index.html

Monday, January 05, 2004

O'Reilly Network: PHP Foundations [Feb. 28, 2001]:
"A programmers guide to learning PHP for people with no PHP experience."

http://www.oreillynet.com/pub/ct/29
Can-Spam Law: More Harm than Good? - Tech Update - ZDNet:
"Fans say CAN SPAM--set to become the first federal law against digital junk mail--would serve notice to spammers. But critics say that by overriding stronger state laws, it would actually tell spammers they can."

http://zdnet.com.com/html/z/tu/sr/canspam.html

Friday, January 02, 2004

Security Vendor Issues Dec. Vulnerabilities List:
"Central Command Inc. on Thursday released its so-called Dirty Dozen list of top twelve viruses for December, 2003. The report is based on virus incidents confirmed through the Medina, Ohio-based company's Emergency Virus Response Team."

According to the company, the Gibe.C worm, with its HTML e-mail message that impersonated a Microsoft Web site, retained the top spot for December, a position that Klez.E held five times during the year.

Gibe.C—21.4 percent
Klez.E—14.7 percent
MiMail.I—12.8 percent
MiMail.J—5.9 percent
BugBear.B—5.2 percent
MiMail.K—5.1 percent
MiMail.A—3.7 percent
Sober.C—1.9 percent
Nachi—1.6 percent
MiMail.C—1.6 percent
Hawawi.G—1.2 percent
Dumaru.A—1.1 percent
Others—23.8 percent

http://www.eweek.com/article2/0,4149,1425300,00.asp?kc=EWNWS010204DTX1K0000599
New Worm Spreads Via MSN Messenger:
"Anti-virus experts are watching a new worm that spreads through Microsoft Corp.'s MSN Messenger client. The worm is not harmful to infected machines and has infected only a few PCs at this point, according to an analysis by Trend Micro Inc.

Known as Jitux, the worm is self-propagating and contains a link to a Web site that automatically downloads an executable file named 'jituxramon.exe' to the PC. Once the file runs, the worm begins sending out copies of itself to all of the names in the user's Messenger contact list. The worm, first discovered Tuesday, is capable of spawning multiple instances of itself on one PC. "

http://www.eweek.com/article2/0,4149,1424692,00.asp?kc=EWNWS010204DTX1K0000599
Top Technologies of 2003:
"Anti-Spam Software and Services

As junk e-mail reached epidemic proportions this year, spam blockers rushed in to rescue ailing e-mail in-boxes."

Centralized Patch Management
Patches were the bane of IT managers' existence this year, and many have turned or are turning to centralized patch management to ease the burden (if not their ire over having to patch in the first place).

http://www.eweek.com/article2/0,4149,1420259,00.asp?kc=EWNWS123103DTX1K0000599

Wednesday, December 31, 2003

An Unrepentant Spammer Considers the Risks:
"Alan Ralsky, according to experts in the field, has long been one of the most prolific senders of junk e-mail messages in the world. But he has not sent a single message over the Internet in the last few weeks.

He stopped sending e-mail offers for everything from debt repayment schemes to time-share vacations even before President Bush, on Dec. 16, signed the new Can Spam Act, a law meant to crack down on marketers like Mr. Ralsky.

He plans to resume in January, he said, after he overcomes some computer problems, and only after he changes his practices to include in his messages a return address and other information required by the law, the title of which stands for Controlling the Assault of Non-Solicited Pornography and Marketing. "

That is quite a switch for Mr. Ralsky, who has earned a reputation as a master of cyberdisguise. By his own admission, he once produced more than 70 million messages a day from domains registered with fake names, largely by way of foreign countries - or sometimes even by way of hijacked computers - so that the recipients could not trace the mail back to him.

Most experts in junk e-mail, known as spam, have dismissed the new federal law as largely ineffectual. And many high-volume e-mailers say the law may even improve the situation for them because it wipes away a handful of tougher state laws.

But Mr. Ralsky, who lives in a Detroit suburb, says the law's potential penalties - fines of up to $6 million and up to five years in jail - are making him rethink his business.

"Of course I'm worried about it," he said after the law was signed. "You would have to be stupid to try to violate this law."

No one is saying that e-mail in-boxes will be clean of spam any time soon. But the world is getting to be a much more hostile place for spammers, particularly those who send some of the most offensive messages. The biggest threat is not so much the new law, though it is expected to play a role in stepped-up enforcement, as the increased willingness of prosecutors to go after spammers.

http://www.nytimes.com/2003/12/30/technology/30spam.html?pagewanted=all&position=

Monday, December 29, 2003

Download details: Security Update for Windows XP (KB823980):
"This update addresses the vulnerability addressed in Microsoft Security Bulletin 03-026. Find out about more recent critical updates in the Overview section."

http://www.microsoft.com/downloads/details.aspx?FamilyID=2354406c-c5b6-44ac-9532-3de40f69c074&displaylang=en
Revamping the Security Bulletin Release Process:
"Security Bulletins Expanded and Summarized by Product

Tools & Resources

The most significant change that the new security bulletin process will introduce for customers will be in the number and timing of security patches. Consequently, customers may need to revisit some of the processes they use for deploying patches. The following tools and resources will help customers evaluate, plan, manage and deploy security patches:"

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/revsbwp.asp
Security Bulletin Search:
"Microsoft Releases Enhanced Security Bulletin Search Tool"

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/current.asp

Saturday, December 27, 2003

The Best Products of 2003
"PC Magazine's Best Products List is out."

• Desktops & Notebooks
• Processors
• Digital Imaging
• Printers
• Productivity Software
• Utilities
• Audio
• Video
• Peripherals
• Home Entertainment
• Mobile Devices & Services
• Open-Source Tools
• Networking
• Development Tools
• Games
• Education & Reference

http://www.pcmag.com/article2/0,4149,1421871,00.asp
InformIT.com : Design & Creative Media > Web Design:
"Web Design Reference Guide"

The Guide is broken into several sections, as follows:

  • Web Design Reference Guide

  • Articles and sample chapters

  • Books and e-books

  • Online resources



The Web Design Reference Guide is continuously updated. Each
week, you can expect new content with the latest news and information from the
world of Web design.

Table of Contents
http://www.informit.com/isapi/guide~webdesign/seq_id~3/guide/content.asp

http://www.informit.com/topics/index.asp?guide=webdesign

Friday, December 26, 2003

The Law of War in the War on Terror:
"What are the boundaries of the Bush administration's 'war on terrorism?' The recent battles fought against the Afghan and Iraqi governments were classic wars between organized military forces. But President George W. Bush has suggested that his campaign against terrorism goes beyond such conflicts; he said on September 29, 2001, 'Our war on terror will be much broader than the battlefields and beachheads of the past. The war will be fought wherever terrorists hide, or run, or plan.'

This language stretches the meaning of the word 'war.' If Washington means 'war' metaphorically, as when it speaks about a 'war' on drugs, the rhetoric would be uncontroversial, a mere hortatory device intended to rally support for an important cause. Bush, however, seems to think of the war on terrorism quite literally -- as a real war -- and this concept has worrisome implications. The rules that bind governments are much looser during wartime than in times of peace. The Bush administration has used war rhetoric precisely to give itself the extraordinary powers enjoyed by a wartime government to detain or even kill suspects without trial. In the process, the administration may have made it easier for itself to detain or eliminate suspects. But it has also threatened the most basic due process rights."

http://www.nytimes.com/cfr/international/20040101faessay_v83n1_roth.html?pagewanted=all&position=
ZDNet AnchorDesk: Greatest hits: The top columns of 2003

http://reviews-zdnet.com.com/4520-7298-5114689.html
Of Dying Viruses and Dangerous Xmas Cards:
"While antivirus vendors have reported several new viruses and malicious attackers in the past week, we have not seen any new large scale outbreaks. However, the ghosts of virus past are still with us -- Klez, Blaster, Swen, Bugbear, Dumaru, Mimail, and Welchia\Nachi all haunt the top ten. According to virus analysts, the Welchia\Nachi worm has only another week or so to live, as it is supposed to remove itself in 2004. Despite this fact, it is still infecting at a good rate…"

2003 may go down in history as the year of the spammer, as there has been more spam sent and received than in any other year. eWeek reported Monday Dec 15th that a judge in California ruled to allow pop up spammers to continue to operate for the time being. One spammer, in particular, was sending Windows Messenger Service popups to PCs that were not running a firewall or had the service turned on (it's on by default in Windows XP/2000). The ruling may trigger more spammers to try their hand at that kind of advertising.…

http://www.pcmag.com/print_article/0,3048,a=115069,00.asp

Wednesday, December 24, 2003

Microsoft Security FAQ :
"TOP Frequently Asked Questions

Note that this is NOT a complete list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. If your question is not listed below, you may want to see the complete table of contents at: http://securityadmin.info/faq.htm#contents "

http://securityadmin.info/faq.asp
Top Ten Web Design Mistakes of 2003 (Jakob Nielsen's Alertbox):
"Sites are getting better at using minimalist design, maintaining archives, and offering comprehensive services. However, these advances entail their own usability problems, as several prominent mistakes from 2003 show. "

http://www.useit.com/alertbox/20031222.html
Rapid Application Development with Mozilla: Navigation. Pt. 1 - WebReference.com -:
"This chapter is from the book 'Rapid Application Development with Mozilla' Nigel McFarlane. (ISBN 0131423436). "

http://www.webreference.com/programming/mozilla/

Tuesday, December 23, 2003

Threat From Sober Variant Grows:
"A variant of the Sober mass-mailing worm appears to be gaining more traction as leading security vendors increase their threat levels.

Increasing prevalence of the W32/Sober.C worm prompted Network Associates Inc. on Sunday to raise its risk assessment to medium from low. Sober.C is most active in Germany, where e-mail security vendor MessageLabs Inc. said 83 percent of samples had originated."

Other security vendors all have rated Sober.C's threat as low or medium. F-Secure Corp. tagged it a medium threat, ranking it a level 2 threat out of three. Symantec Corp. rated it as a level 2 threat out of five, or a low threat. MessageLabs also consider the risk "low," while saying that it has intercepted a "significant number of copies" of the worm.

Sober.C first appeared on Saturday, and New York-based MessageLabs reported its highest number of interceptions of the worm on Sunday.

Sober.C, once activated, e-mails itself to a user's Microsoft Outlook address book and sends outgoing messages through its own SMTP engine, said Network Associates, of Santa Clara, Calif. Along with e-mail, Sober.C can spread through peer-to-peer filing sharing networks.…

Sober.C, written in Visual Basic, can infect systems running Windows 2000, Windows 95, Windows 98, Windows NT and Windows Server 2003.

http://www.eweek.com/article2/0,4149,1420314,00.asp
In 1998, President Clinton noted that "information technology now accounts for more than a third of our economic growth, and government should follow one guiding principle: First, do no harm."

News: New threat to Net's future?:
"In complex political systems, the objective of an action can be honorable, but the impact of an action can be completely at odds with the objective. This is largely because the tools we use to encourage behavior in such systems are often crude and imprecise.

On Oct. 6, the 9th U.S. Circuit Court of Appeals issued an opinion in the case of Brand X Internet v. the Federal Communications Commission that has the potential to delay the progress of the Internet in the United States by certainly years and potentially decades. Through its actions, the 9th Circuit has 'invited' the 50 independent and natural bureaucratic state-based public utility commissions directly into the fold of the Internet. "

How the 9th Circuit accomplished this feat is both curious and confusing. The case in question deals with whether cable lines that deliver Internet service can be considered a "telecommunications service." This wording is critical, because Congress and the FCC have made it clear that states can regulate "telecommunications services," but must keep their hands off "information services."

In 1998, the same year Clinton made his declaration, the city of Portland mandated that AT&T, as a requirement for approval of its acquisition of TCI, open up its broadband lines to competitive carriers. Ruling on this in 2000, the 9th Circuit stated that the city of Portland could not mandate this behavior, as its jurisdiction was over cable franchises, and these broadband connections did not technically represent a cable franchise.

But the 9th Circuit did not stop there. It made one more historical but seemingly unnecessary step. It declared cable modem service a "telecommunications service."

The FCC was compelled to react to the 9th Circuit Court's assertion, as it flew in the face of the FCC position on this matter, as well as the clear intent of Congress and the Executive Branch. (Both had echoed a desire to keep the Internet unregulated.) In 2002, in an effort to clarify and correct the decision in Portland, the FCC ruled that cable modem services are "interstate information services" and not "telecommunication services." Seven different petitions for review of the FCC's "information services" ruling were filed in the 3rd, 9th and D.C. Circuits. Under the multicircuit rules, a judicial lottery was held, and the 9th Circuit was ironically elected to rule on the FCC's ruling.


http://zdnet.com.com/2100-1107_2-5130490.html
SecurityFocus HOME Infocus: Firewall Evolution - Deep Packet Inspection:
"Deep Packet Inspection is a term used to describe the capabilities of a firewall or an Intrusion Detection System (IDS) to look within the application payload of a packet or traffic stream and make decisions on the significance of that data based on the content of that data. The engine that drives deep packet inspection typically includes a combination of signature-matching technology along with heuristic analysis of the data in order to determine the impact of that communication stream. While the concept of deep packet inspection sounds very nice it is not so simple to achieve in practice. The inspection engine must use a combination of signature-based analysis techniques as well as statistical, or anomaly analysis, techniques. Both of these are borrowed directly from intrusion detection technologies. In order to identify traffic at the speeds necessary to provide sufficient performance newer ASICs will have to be incorporated into existing firewall designs. These ASICs, or Network Processors Units (NPUs), provide for fast discrimination of content within packets while also allowing for data classification. Deep Packet Inspection capable firewalls must not only maintain the state of the underlying network connection but also the state of the application utilizing that communication channel."

http://www.securityfocus.com/infocus/1716
FAQ: Firewall Forensics (What am I seeing?):
"This document explains what you see in firewall logs, especially what port numbers means. You can use this information to help figure out what hackers are up to.

This document is intended for both security-experts maintaining corporate firewalls as well as home users of personal firewalls. "

http://www.secinf.net/firewalls_and_VPN/FAQ_Firewall_Forensics_What_am_I_seeing_.html
News: IE fix mends flawed open-source patch:
"A Web site that published a third-party patch to fix a security hole in Microsoft's Internet Explorer has had to reissue the patch, after the original was found to be flawed.

Openwares.org published the second patch Saturday, after the first was found to contain a buffer overflow exploit. This exploit, which allowed an attacker to take control of the patched PC, might have been far more damaging than the flaw the patch aimed to fix."

The IE vulnerability, which was first reported in late November, allows a browser to display one URL in the address bar while the page that's being viewed is actually hosted elsewhere, making the user more susceptible to ruses like "phishing," in which spoof e-mails direct people to fake Web sites that seem to belong to legitimate companies. However, Openwares' first fix, which worked by filtering out any URLs containing suspicious characters, would work only with addresses that had less than 256 bytes. Larger addresses produced a buffer overflow.

Openwares' administrator said: "The new version has been rewritten and tested by dozens of users who helped out. If you're unsure, look at the new source code for yourself."

By early morning Monday, there had been 2,500 downloads of the new patch. However, this is a minute fraction of IE users, who make up more than 90 percent of the Internet population.

Microsoft has still not released a fix for the IE problem or given any indication as to when one might be available. In October, the Redmond, Wash., software maker adopted a policy of releasing only one patch each month, but it has already announced that it will be skipping its December release; IE is expected to remain vulnerable until at least mid-January.

Earlier in December, weeks after the IE flaw was discovered, Iain Mulholland, a security program manager at Microsoft, said the company was putting heavy emphasis on increasing the quality of its patches and that the approach has had an effect on the timing of releases.…

http://zdnet.com.com/2100-1105_2-5130708.html

Monday, December 22, 2003

Op-Ed Contributors: Good Nukes, Bad Nukes:
"The Nuclear Nonproliferation Treaty is arguably the most popular treaty in history: except for five states, every nation in the world is part of it. For more than three decades, it has helped curb the spread of nuclear weapons.

Since 9/11, however, and especially in the last several months, the viability of the treaty has been called into question. Some say it is obsolete. Others say it is merely ineffective. In support of its argument each side cites the situation in Iran, which has been able to advance a nuclear weapons program despite being a member of the treaty."
Early Word on Amazon ‘Stores’:
"AS in other recent holiday seasons, Amazon.com Inc. this year has successfully peddled the staples - books, music and videos - of online gift shoppers. But how about those alligator tenderloins, Callaway drivers and Mikimoto pearls? Amazon.com is wrapping up its first holiday season in which it has featured such goods and others in distinct 'stores,' or categories. Since September it has opened four stores: gourmet food, sporting goods, jewelry and watches, and (just last week) health and personal care. Retailers who are participating in the new stores and analysts who have watched them closely said Amazon.com's sales in those categories had shown promise."

"We're hearing that sales are good, not great," said Carrie A. Johnson, an analyst with Forrester Research, a technology consulting firm. "But they're good enough, and that's the key for retailers who've spent a lot of time integrating with Amazon."

Amazon.com's new stores collect items from other merchants, occasionally alongside goods already sold by Amazon. For instance, the jewelry-and-watches store features items from Mondera, Fortunoff and Ross-Simons, with pearl necklaces and other goods stocked and sold by Amazon.com.

When customers make purchases on Amazon.com from another merchant, Amazon.com sends the order to the merchant, which then ships the items. In exchange for offering their goods to Amazon.com's shoppers - more than 15 million visitors a week during the holiday season, according to Media Metrix - merchants typically pay Amazon.com a commission of 7 percent to 15 percent on each sale, according to Forrester. If an item fails to satisfy a customer, it is the responsibility of the merchant that shipped the product to receive the customer service call.

Amazon.com's senior vice president for worldwide retail, Diego Piacentini, would not disclose sales goals for the new stores. But the merchants that have joined Amazon.com have high hopes, if not for sales directly from the partnership, then for increased awareness and acceptance of their goods among mainstream shoppers. The gourmet food category may stand to benefit most from Amazon.com's participation.

"Beyond the big names like Harry & David or Omaha Steaks, this category is incredibly fragmented by small mom-and-pop businesses," Ms. Johnson of Forrester said. "Now the small players have the opportunity to reach many more customers online, and customers can find all of them in one place."

http://www.nytimes.com/2003/12/22/technology/22ecom.html?pagewanted=all&position=
New Economy: Offshore Jobs in Technology: Opportunity or a Threat?:
"The United States economy is finally getting stronger, but there seems to be one unsettling weakness: the apparent wholesale flight of technology jobs like computer programming and technical support to lower-cost nations, led by India.

The trend is typically described in ungainly terms - as 'offshore outsourcing' or 'offshoring.' But that rhetorical hurdle has done nothing to lessen the recent public debate and expressions of angst over this kind of job migration. There are some early signs of political reaction. Last month, for example, the State of Indiana pulled out of a $15 million contract with an Indian company to provide technology services. And a proposed bill in New Jersey would restrict the use of offshore workers by companies doing work for the state."

Forrester Research, a technology consulting firm, published a report this month pointing out that the movement abroad is only gradual. The firm bemoaned "the rising tide of offshore hype." Yet Forrester itself played a significant role in framing the debate on offshore outsourcing, as well as stirring fears, with a report last year. That report, published in November 2002, predicted that 3.3 million services jobs in America would move offshore by 2015, and added that the information technology industry will "lead the initial overseas exodus."

So what is really happening? Is the offshore outsourcing of technology jobs a cataclysmic jolt or a natural evolution of the economy?

The short answer is that the trend is real, irreversible and another step in the globalization of the American economy. It does present a challenge to industry, government and individual workers. But the shifting of some technology jobs abroad fits into a well-worn historical pattern of economic change and adjustment in the United States.

"To be competitive and to maintain and improve American living standards, we have to move up the technology food chain," said Craig R. Barrett, the chief executive of Intel.

That may seem like easy advice from someone perched at the top of the food chain, but Intel represents a good example of a company that successfully navigated an earlier round of threats from international competition, from Japan in the 1980's.

In the early 1980's, Japanese chip makers appeared to be taking the semiconductor industry by storm, supported by their banks and their government. The Japanese were focused on the market for memory chips, which store data. At the time, Intel was getting battered and still received much of its revenues from memory chips. It made a bet-the-company decision, abandoned the memory-chip business and focused on microprocessors, the bit-processing engines in personal computers.

The bet, of course, paid off as the personal computer business blossomed. In retrospect, Intel's triumph might seem to be a foregone conclusion. But it did not necessarily look that way back then. Remember, those were the days when the term Japan Inc. struck fear in corporate boardrooms across America, and there was a resonant ring to the bleak prognosis of the nation's economic future by the former vice president, Walter F. Mondale: "What are our kids supposed to do? Sweep up around Japanese computers and sell McDonald's hamburgers the rest of their lives?"

It did not quite work out that way, did it? Today, the overseas challenge in technology services comes from linking nations with strong education systems like China, India and Russia with the global economy. The Internet is a big part of the phenomenon. The spread of high-speed Internet connections in the last few years has meant that Indian programmers are a mouse-click away from American corporations that are eager to cut their software development costs.

The salary comparisons are striking. A programmer in the United States would earn about $80,000 a year on average, compared with $20,000 or less in India. But analysts say the actual cost savings on a development project are not proportionate. Whole stages of a project - analysis, design and deployment - typically require face-to-face meetings. Communications and cultural differences add to costs and sometimes reduce effectiveness.

On a typical corporate software project, employing 40 programmers for a year, the savings from offshore outsourcing in India would be more in the range of 20 to 40 percent less than employing higher priced labor in the United States, estimates Joseph Feiman, an analyst at Gartner Inc., a research firm. Sometimes, American services firms with special expertise are the preferred choice, despite higher labor costs.

"The math of looking only at salaries is just wrong," Mr. Feiman said. "And it is a prevalent misconception."

http://www.nytimes.com/2003/12/22/technology/22neco.html?pagewanted=all&position=

Saturday, December 20, 2003

Electronic Voting:

"Electronic voting has garnered significant attention in recent months. Controversy abounds over whether e-voting machines are secure and reliable, while strong movements toward expanding their use have arisen. India, for instance, announced in July 2003 that it would use exclusively electronic polls in its future elections. This trend and its associated security risks are examined in this Topic in Depth."

The NSDL Scout Report for Mathematics Engineering and Technology-- Volume 2, Number 25 Topic in Depth

1. The Free E-Democracy Project


http://www.free-project.org/learn/


2. Caltech-MIT/Voting Technology Project [pdf, RealOne Player]


http://web.mit.edu/voting/


3. Electronic Voting and Counting [pdf]


http://www.elections.act.gov.au/Elecvote.html


4. The Open Voting Consortium


http://www.openvotingconsortium.org/


5. Election Reform and Electronic Voting Systems (DREs): Analysis of Security Issues [pdf]


http://www.epic.org/privacy/voting/crsreport.pdf


6. Electronic Voting: What You Need to Know


http://www.truthout.org/docs_03/102003A.shtml


7. Can Voting Machines Be Trusted?


http://www.cbsnews.com/stories/2003/11/11/politics/main583042.shtml


From The NSDL Scout Report for Math, Engineering, & Technology, Copyright Internet Scout Project 1994-2003. http://www.scout.wisc.edu/

http://scout.wisc.edu/Reports/NSDL/MET/2003/met-031219-topicindepth.php#1
Deep Content: Guide to Effective Searching of the Internet:
"Your ability to find the information you seek on the Internet is a function of how precise your queries are and how effectively you use search services. Poor queries return poor results; good queries return great results. Contrary to the hype surrounding 'intelligent agents' and 'artificial intelligence,' the fact remains that search results are only as good as the query you pose and how you search. There is no silver bullet.

There are very effective ways to 'structure' a query and use special operators to target the results you seek. Absent these techniques, you will spend endless hours looking at useless documents that do not contain the information you want. Or you will give up in frustration after search-click-download-reviewing long lists of documents before you find what you want."

This outstanding website is, without question, one of the most comprehensive online resources for learning efficient Internet search techniques. The guide begins with some fairly non-technical background about the Internet and explains why searching such a massive amount of information is more complex than it seems. The general process used by search engines to rank webpages is described. After covering the fundamentals of search engine operation, the guide discusses some best practices to use when conducting a search. Keyword selection, phrasing, and Boolean operators are just a few of the concepts discussed to help users make their searching more effective. The guide also compares many top search engines, noting the supported features, coverage, and type of indexing associated with each. From The NSDL Scout Report for Math, Engineering, & Technology, Copyright Internet Scout Project 1994-2003. http://www.scout.wisc.edu/

http://scout.wisc.edu/Reports/NSDL/MET/2003/met-031219-printable.html#12

http://www.brightplanet.com/deepcontent/tutorials/search/index.asp

Friday, December 19, 2003

Record Industry May Not Subpoena Online Providers:
The industry's argument that the subpoena power could be applied to an Internet service provider "regardless of what function it performs," even if songs are only momentarily passing through its data pipes, "borders upon the silly."

"The recording industry cannot compel an Internet service provider to give up the names of customers who trade music online without judicial review, a federal appeals court in Washington ruled today.

The sharply worded ruling, which dismissed one industry argument by saying that it 'borders on the silly,' is a blow to the music companies in the online music wars. It overturns a decision in federal district court that favored the industry and ordered Verizon Communications to disclose the identity of a subscriber based on simple subpoenas submitted to a court clerk. "

The music industry has been struggling to counter an army of downloaders tens of millions strong who, beginning with the advent of Napster in the 1990's, have swapped songs online on so-called "peer-to-peer" networks without regard to the property rights of artists, composers and the companies that make the music.

In September, the industry began suing large-scale file swappers. In doing so, it used a controversial provision of the Digital Millennium Copyright Act of 1998, section 512 (h), to demand that the service providers reveal the identities of customers whose activities could otherwise be linked by the industry only to an identifier known as an Internet Protocol number.

The opinion, written by Chief Judge Douglas H. Ginsburg of the United States Court of Appeals for the District of Columbia Circuit, did not strike down the new provisions of the copyright act on constitutional grounds. Instead, it said that the statute was applied incorrectly by the recording industry.

Under the terms of the law, the court said, subpoenas that the industry sent to Verizon demanding the identity of the file trader and the removal of infringing files could not be applied to the company when its customers were trading files on a peer-to-peer network. As an Internet service provider, or I.S.P., Verizon was "acting merely as a conduit" for the music files and did not store the data on its own computer network, Judge Ginsburg wrote. "A subpoena may be issued only to an I.S.P. engaged in storing on its servers material that is infringing or the subject of infringing activity."

Since the law requires a "takedown notice" that identifies the material that must be removed from the Internet, and since the material in question is not on the Internet service provider's own servers, "the R.I.A.A.'s notification identifies absolutely no material Verizon could remove or access to which it could disable," Judge Ginsburg wrote.

Although the recording industry argued that an Internet service provider can, in fact, remove the offending material by cutting off the subscriber's account, Judge Ginsburg wrote that "this argument is undone by the terms of the act," which clearly distinguished between blocking access to copyrighted files and cutting off the accounts of infringing users.

The industry's argument that the subpoena power could be applied to an Internet service provider "regardless of what function it performs," even if songs are only momentarily passing through its data pipes, "borders upon the silly," the judge wrote.

Such attempts by the industry to broaden the definition and role of Internet service provider, Judge Ginsburg wrote, must fail under the harsh light of careful statutory analysis. "Define all the world as an I.S.P. if you like, the validity of a 512(h) subpoena still depends upon the copyright holder having given the I.S.P., however defined, a notification" that is effective under other crucial provisions of the law, he wrote.…

http://www.nytimes.com/2003/12/19/technology/19CND-MUSI.html?pagewanted=all&position=
ZDNet AnchorDesk: The safe way to move your data to a new PC:
"This column is about something that every reasonably advanced PC user faces at one time or another, an exercise that's fraught with peril. "

Specifically: How do you make sure your PC is safe to hand down to someone else or perhaps to sell on eBay for a dollar or two? By "safe," I mean that all your personal data has been safely removed.

Real paranoiacs will remove the hard drive, run it past a demagnetizer, smash it with a 20-pound sledge hammer, and then soak the remains in circuit board etching solution before they pass along a PC. If you should actually catch somebody doing this, however, do us all a favor and notify Tom Ridge immediately.

If you'd rather preserve the drive, and don't care about the apps and operating system, there are a number of utilities that will completely wipe the drive. If you have a copy of Norton SystemWorks, for example, you can boot from the CD and use it to wipe the machine's hard drive.

Not all data wiping programs are created equal, however. Whatever app you use, try to make sure it makes three or more passes of the hard drive, replacing the old data with random characters each time. Such a hard drive will be clean enough for the Defense Department's purposes, whatever those might be.

BUT SUPPOSE you want to leave most or all of the applications and operating system in a condition that someone else could still use. And (to be even more realistic), let's say you'd also like to migrate all your data and settings from the old machine to one you've just purchased or received as a holiday present.…

http://reviews-zdnet.com.com/AnchorDesk/4520-7298_16-5114407.html?tag=adss

Thursday, December 18, 2003

No MS Security Issues In December? Think Again!:
"Mozilla not immune.

…there's is a particular problem in Internet Explorer which allows a malicious coder to make it appear as if the user is viewing a different Web site than they actually are viewing. The bug involved the use of a feature of Uniform Resource Identifiers (browser addresses) that is more often abused than used legitimately used: the '@' character.

When an '@' is part of the domain in a Web address, the browser treats the string to the left of it as a user name to fill in any userid prompts, and everything on the right side as the domain name. This is perfectly legitimate syntax. Click here for the actual standard document about URIs.

Malicious coders, such as phishers, often will use this technique to obscure the actual address of the site they send you to. For example, they might send you a message that appears to be from Paypal and include a link that looks something like this:

http://www.paypal.com@64.225.264.128/accounts/validate.htm (The IP address I used is illegal for the same reason they use 555 phone numbers on TV shows.)
Notice, the numeric string to the right of the '@' mark. This link will not take you to www.paypal.com, but to 64.225.264.128. But most unsophisticated users won't notice the difference. Still, all of this monkey business is perfectly legal (if immoral) under the URI standard.

The latest bug adds a twist: If you put ASCII 00 and 01 characters (designated as %00%01 in the spec.) just prior to the '@' character, then Internet Explorer won't display the rest of the URL when the user views the page. In Javascript you must use just the %01 character and also decode the string with the unescape() function..

There are many variations of this particular scheme, and surprisingly some of them partially work on Mozilla as well.

The anchor link version of this vulnerability also results in the partial, incorrect address being displayed in the status line as the user hovers the mouse over the link. Versions of Mozilla I tested (Versions 1.0 and 1.5) also showed the partial address in the status line, although they displayed the full address in the address bar. Just for fun, I tried Netscape 4.7 as well. Despite being one of worst programs ever written, it handled this situation properly, displaying the full URL in the address and status lines. "

http://www.eweek.com/print_article/0,3048,a=114456,00.asp

Wednesday, December 17, 2003

ASP 101 - Using the Google APIs to Spell Check:
"The Developers at Google have been kind enough to offer a web API for developers using the SOAP protocol. When you do a search using Google, you may have noticed that you are prompted with possible alternatives to any words you may have misspelled.

The Google web API 'spell check' allows you to send a string of text and receive alternatives for misspelled words. The power in this web API is that the Google dictionary includes technology words that are used in website searches, but may not have been included in a Standard English dictionary. "

Setting up the Google SDK on your server is as simple as downloading the API from http://www.google.com/apis/. You'll need to register with the website which will give you your own key. You'll need the key for Google to accept SOAP connections from your server.

There are some limitations to be mentioned as well. The Google web API allows 10 words to be sent at a time and a limit of 1000 connections per key per day. The following script works around the 10 word limit, however is still limited by the 1000 connections.…

http://www.asp101.com/articles/jeremy/googlespell/default.asp
PCMag.com Shareware Library: Freeware and Shareware Downloads:
"This one's for everyone who complained about being forced to pay $5 a month (or $20 a year) to get award-winning PC Magazine Utilities.

…an extensive (and I mean extensive) shareware library full of thousands of programs you can download and try -- without spending a dime! Utilities, music, multimedia, programming, business, and more "

http://shareware.pcmag.com/welcome.php?&SiteID=pcmag