Tuesday, May 04, 2004

Symantec Security Response - W32.Sasser.B.Worm:
"W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011. This worm spreads by scanning randomly selected IP addresses of vulnerable systems.… "

Notes:
The MD5 hash value of this worm is 0x1A2C0E6130850F8FD9B9B5309413CD00.

Symantec Security Response has developed a removal tool to clean the infections of W32.Sasser.B.Worm.

Block TCP ports 5554, 9996, and 445 at the perimeter firewall and install the appropriate Microsoft patch (MS04-011) to prevent the remote exploitation of the vulnerability.

--------------------------------------------------------------------------------

W32.Sasser.B.Worm can run on, but not infect, Windows 95/98/Me computers. Although these operating systems cannot be infected, they can still be used to infect the vulnerable systems to which they are able to connect. In this case, the worm will waste a lot of resources so that programs cannot properly run, including our removal tool. (On Windows 95/98/Me computers, the tool should be run in Safe mode.)

http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html
Keyboard Shortcuts with Windows XP Home Edition:
"When speed counts, the keyboard is still king. Almost all the actions and commands you can perform with a mouse you can perform faster using combinations of keys on your keyboard. These simple keyboard shortcuts can get you where you want to go faster than several clicks of a mouse. You'll work faster on spreadsheets and similar documents, too, because you won't lose your place switching back and forth between mouse and keys.

Here are some of the most useful keyboard shortcuts:"

http://www.microsoft.com/windowsxp/home/using/tips/personalize/keyboardsc.asp

Monday, May 03, 2004

ZDNet: Printer Friendly - Alarm growing over bot software:
"Known as bot software, the remote attack tools can seek out and place themselves on vulnerable computers, then run silently in the background, letting an attacker send commands to the system while its owner works away, oblivious. The latest versions of the software created by the security underground let attackers control compromised computers through chat servers and peer-to-peer networks, command the software to attack other computers and steal information from infected systems.

News.context

What's new:
Internet security watchers warn that the most common kind of bot software has been upgraded. A new variant incorporates publicly available code for breaching security through a vulnerability on almost every Windows system sold in the past five years.

Bottom line:
Bot software has spread widely--just how quickly is difficult even for security experts to evaluate. Symantec puts the number of computers compromised in the hundreds of thousands. Other security experts have put the number in the millions. Moreover, with source code commonly available, bot software gets quickly updated to take advantage of the latest flaws.…"

http://zdnet.com.com/2100-1105_2-5202236.html?tag=adnews
URLScan Security Tool:
"UrlScan version 2.5 is a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan security tool helps prevent potentially harmful requests from reaching the server. UrlScan 2.5 will now install as a clean installation on servers running IIS 4.0 and later.…"

http://www.microsoft.com/technet/security/tools/urlscan.mspx

Saturday, May 01, 2004

Spam Report Card 2004 - TechUpdate - ZDNet:
"More than 50 percent of e-mail is spam. Billions of spam attacks are launched each month. Spam costs U.S. companies at least $1 billion per year in security and human resources expenditures, as well as lost productivity. Increasingly, virus-infected machines are used to distribute spam and perpetuate additional fraud, such as phishing. Is combating spam a losing battle?"

http://techupdate.zdnet.com/special_report/Spam_Report_Card_2004.html

Friday, April 30, 2004

Crypto-Gram: April 15, 2004:
"In this issue:

National ID Cards
TSA-Approved Locks
Crypto-Gram Reprints
Stealing an Election
Counterpane News
Security Notes from All Over: Man-in-the-Middle Attack

Bluetooth BeepCard
Privacy Hack
News
Virus Wars "

http://www.schneier.com/crypto-gram-0404.html
Signs Point to Worm Attack on SSL Vulnerability:
"Security experts on Tuesday said they are seeing evidence of what appears to be a worm exploiting the recently announced vulnerability in the Windows implementation of the Secure Sockets Layer (SSL) protocol.

During the morning and early afternoon Tuesday, specialists at VeriSign Inc.'s security operations center observed a large-scale exploitation of the vulnerability. While there are a number of software tools available on the Internet to attack the vulnerability, experts said the volume of activity is too great for the attacks to be manual."

http://www.eweek.com/article2/0,1759,1573827,00.asp
Microsoft Confirms Bug In SSL Patch:
"The knowledge base article goes by the unusually long name: 'Your computer stops responding, you cannot log on to Windows, or your CPU usage for the System process approaches 100 percent after you install the security update that is described in Microsoft Security Bulletin MS04-011.'

The problem occurs, according to the article, because Windows tries repeatedly to load drivers that fail to load. Microsoft acknowledges that the problem is a bug in the patch and that the company is investigating solutions."

http://www.eweek.com/article2/0,1759,1578752,00.asp
Scams, Lies, Deceit, and Offshoring:
"Someone has to take the jobs that, as President Bush and others say, 'Americans don't want.' There appear to be a large number of these jobs. In fact, it seems that our fastest-growing business segment is the creation of more and more jobs that Americans don't want. Often, American companies will lay people off, only to train newcomers to replace them."

Here is how the real scam works. You are a programmer at one of the big IT or computer companies. You're 55 and nearing a retirement plateau; in fact, you're a liability. You're making, say, $80,000 as a program designer. You have various responsibilities. The company eliminates your position in the process of downsizing.

To be fair to you, it creates a new position, Associate Program Designer, that pays $35,000 a year. Its responsibilities coincidentally match those of your old job. You can take this job, doing what you did before but at a huge cut in pay, or look elsewhere. If the latter, it's apparent that this new job is one that "Americans don't want." The company can then hire a "body shop" to drop in a foreign H-1B or L1 visa holder, who will not be quite as good but will work for a lot less.


This is a bait-and-switch scheme that is designed to screw older and more experienced workers out of their retirement benefits, plain and simple. This sort of thing, unfortunately, is nothing new to corporate America:

http://www.pcmag.com/article2/0,1759,1573102,00.asp

Wednesday, April 28, 2004

Phishing Scams Increase 1,200% in 6 Months:
"Beware your email.

In the last six months, the number of phishing email scams has increased 1,200 percent, putting end users and major companies at an even greater risk, according to a report from MessageLabs Inc., a managed email security firm based in New York.

MessageLabs reports that last September its analysts had only seen 279 phishing emails. But that number had risen nearly 800-fold to 215,643. Phishing emails peaked in January with 337,050.… "

Phishing is the latest online scam financial scam. It's a con game based on posing.

Spammers send out millions of emails claiming to be from legitimate organizations, such as major U.S. banks or credit card companies. The spammers even fake the senders address so it appears to be from the company they're posing to be. The message in the email often says there is a problem with the recipient's account and it has been shut down. To reinstate the account, or deal with whatever fictional problem the email refers to, the user is instructed to click on a link that then takes them to a phony Web site.

The users are then led to what is often a perfect replica of the Web site that the spammer is pretending to be. At this point, the victim is asked to 'update' his personal security information, passwords, Social Security numbers, addresses and bank account information. The information is then used to siphon money out of the victim's bank account or to make financial transactions with their money.

http://www.esecurityplanet.com/trends/article.php/3344141

Tuesday, April 27, 2004

AntiOnline - Windows XP Security Guide (phase one):
"This guide will take you from a FRESH install of XP, to the high level of security … Note that this is more intended for singular computer use (and possibly work office) and not for mission critical server usage. While yes, … use XP for server usages, because it can handle it with the proper settings, a mission critical server requires a primary focus on the 'Server' portion, rather than being evently distrubuted between server, desktop, and game machine. … when it comes down to mission critical servers, it isn't about bending tools to work, it's about how well they work. Windows XP as a *mission* critical server is not recommended because of latency issues, forced RAM on the GUI, and process handling meant for low latency on the GUI responcivness, instead of packet and server process stability handling."

http://www.antionline.com/showthread.php?s=&threadid=255353

Saturday, April 24, 2004

Fonts in Cyberspace:
"A guide to finding language fonts on the Internet. Containing more than 400 sources for 123 languages"

http://www.sil.org/computing/fonts/

Tuesday, April 20, 2004

Getting a Job in CG: Real Advice from Reel People, Chapter 3: What to Learn. By Sybex - WebReference.com-:
"This book excerpt is from 'Getting a Job in CG: Real Advice from Reel People' ISBN 0-7821-4257-5. All rights reserved. Chapter 3: What to Learn., is posted with permission from Sybex.

Knowing the job descriptions in 3D and effects described in the first two chapters can help you find the kind of job that fits your skills and interests. Perusing the descriptions and sample listings, you might have realized that there are skills you lack.

This chapter explains the skills involved in 3D and effects and gives you direction on how to acquire them.…"

http://www.webreference.com/3d/cg/
Security issues move Linksys routers off the short list:
"As more companies adopt a telecommuting-friendly culture, more employees are taking the plunge for cable or DSL-based Internet access. In many cases, their households have more than one Internet user and are installing turnkey connection-sharing appliances. The two companies that most often come to mind for me as providers of these appliances are the recently Cisco-acquired Linksys and the as-of-yet-to-be acquired NetGear. Linksys is apparently having some engineering difficulties that are leaving its customers exposed to potential security problems.… "

http://techupdate.zdnet.com/techupdate/stories/main/Linksys_routers_and_DDoS.html
ZDNet AnchorDesk: What's wrong with Internet phones:
"The best thing about the traditional phone system is what people take for granted: Any phone on the planet can connect to any other. Some Internet telephone systems, such as Vonage, can also connect to any other phone. But except in extremely rare cases, two people on different VoIP systems can't connect to each other directly over the Internet--they have to use the public phone system as a go-between.… "

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5130570.html?tag=adss

Monday, April 19, 2004

Training:
"This set of labs will help you learn how to design and deploy Extensible Markup Language (XML)-based forms in Microsoft® Office InfoPath® 2003 SP-1."

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/odc_2003_ta/html/odc_landinfo03_tr.asp

Saturday, April 17, 2004

The New York Times > National > 9/11 Panel Calls Policies on Immigration Ineffective:
"The commission investigating the 9/11 attacks has concluded that immigration policies promoted as essential to keeping the country safe from future attacks have been largely ineffective, producing little, if any, information leading to the identification or apprehension of terrorists."

http://www.nytimes.com/2004/04/17/national/17IMMI.html?pagewanted=all&position=
EMediaLive.com Review: Editor's Choice-Ulead DVD Workshop 2.0:
"Compared to its peers, we found DVD Workshop much more accessible than Adobe Encore, while offering a greater range of design options. Workshop stands up well even if you throw Photoshop and After Effects into the creative mix, especially if you consider development efficiency."

http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=152#9
Understanding and Choosing File Formats in Photoshop CS and Illustrator CS:
"Peter Bauer discusses file formats and their various capabilities, including information on which format to select for which purpose. "

regitration required

http://www.informit.com/articles/printerfriendly.asp?p=169496

Thursday, April 15, 2004

Data Recovery Software. NTFS Reader for DOS NTFS DOS. Freeware & Shareware.:
"NTFS Reader DOS Boot Disk provides read access to NTFS drives from the MS DOS environment. It supports long filenames as well as compressed and fragmented files. NTFS Reader for DOS allows you to preview the files on NTFS and copy them from NTFS to FAT volumes or network drives. In order to use the software you need to copy the readntfs.exe file to a bootable floppy disk and boot from it."

http://www.ntfs.com/products.htm
12 Short Steps Go a Long Way Toward Safeguarding Your Business:
"SMALL BUSINESS SECURITY CHECKLIST

Before you begin, make sure these recommendations concur with your security policy. If you don't have a security policy, learn why you should consider adopting one. "

http://www.microsoft.com/smallbusiness/gtm/securityguidance/hub.mspx
Manipulate the User Agent for Accurate Site Stats:
"If you implement any sort of hit monitoring or tracking on your Website, you probably don't want to include any of your own hits."

Ordinarily, you could set a "self-specific" cookie. Then, when the tracking script was called, you could simply check to see if that cookie existed, and, if it did, exit the tracking script.

However, if, like me, you're frankly scared of cookies on the grounds that they:

are difficult to test with,

are called something silly and

aren't 100% reliable

Furthermore, many Webmasters exclude from tracking certain browsers that are known not to work on their Websites. For example, many sites block any non-Internet Explorer or Netscape browsers, such as Mozilla's excellent new Firebird and a whole heap of others. Being able to manipulate the user agent to fool the Website into thinking we're using Internet Explorer 6.0 when we're really running Firebird 0.7 could be quite handy!

http://www.sitepoint.com/print/site-stats-user-agent

Wednesday, April 14, 2004

ZDNet: Printer Friendly - Attackers infiltrating supercomputer networks:
"Unknown attackers have compromised a large number of Linux and Solaris machines in high-speed computing networks at Stanford University and other academic research facilities, according to an advisory.

The attacks, which apparently compromised servers as recently as April 3, are currently being investigated, according to an advisory posted April 6 by the Information Technology Systems and Services (ITSS) group at Stanford. "

The attacks start with the compromise of an unprivileged local user account. Usually this is because the attacker's captured the password from somewhere else: it's been sniffed off the network (through the use of insecure protocols like telnet), it's been collected when the user signs on to or from another compromised machine, it's been harvested from the password file on a compromised system.

If the target machine is behind on its patches, the attacker then uses one of a number of public exploits to elevate the unprivileged account to root status. Exploits target the Linux mremap() vulnerabilities, the Solaris kernel module loading vulnerability (for which an attack was made public on 8 Apr), and a Solaris priocntl() issue.

http://zdnet.com.com/2102-1105_2-5191024.html?tag=printthis
New Bugbear Virus finds New IE Hole:
"This has been a busy week for virus writers and antivirus vendors. We've seen some more Netsky and Bagle variants, as well as a number of new Trojans. However, the most prevalent has been last week's top threat Netsky.P, followed by Netsky.C and Netsky.D. While we haven't seen a wide distribution yet, a new Bugbear variety is starting to make the rounds?4Bugbear.C or Bugbear.E (depending on antivirus company reporting it). Bugbear.C attacks through an HTML attachment, and an unpatched Internet Explorer vulnerability. See our top threat for more information. "

Compared with PC users, Apple users have been fairly immune to viruses. However, a new "concept" Trojan is making waves in the Mac community. Intego, a security company announced the appearance of a new Trojan, MP3Concept. While Indego's press release describes potentially malicious payload the Trojan can have such as file deletion, sending e-mail, or infecting other MP3, Jpeg, GIF or QuickTime files, the MP3 Concept only shows a text message, and plays an MP3 of a man laughing. According to Symantec, the Trojan is not in the wild yet. Codemonkey takes a bit more of a swipe at Intego saying they are spreading FUD. The famous Nigerian 419 scam (also known as the advance payment scam) was in the news this week, with the conviction of one of the scammers. According to UK newspaper AllAfrica.com , Peter Okoeguale, a Nigerian living in Wales, was arrested for committing fraud. He was sentenced to 20 months, and faces deportation to Nigeria once freed. Unfortunately, this perpetrator is only one of probably hundreds or thousands of scammers preying on victims looking to make a fast buck. The Nigerian 419 scam, named after the Nigerian penal code covering fraud, comes in a number of varieties. Some offer a victim an investment in a Nigerian company, or a share of a large sum of money being spirited out of the country by an exiled high official. They often send the victim a forged or stolen check that the victim is to hold while they put up their own money. There are many web sites that explain and fight the scam. A quick search on Google for Nigerian Scam will bring up hundreds results. Peter Ferrie and Frederic Perriot, researchers at Symantec have just published an analysis of the Welchia.B (Nachi.B) worm in Virus Bulletin called "The Wormpire Strikes Back". Welchia.B attempts to be a good worm by removing other worm infections. The analysis is a terrific look under the hood of the virus, with a little Star Wars humor tossed in. If you're interested in a deeper understanding of worms in general, and Welchia in particular, take a look at Peter's whitepaper.

http://www.pcmag.com/print_article/0,1761,a=124102,00.asp
Cheaper Shared Hosting Imperils Security:
"How secure is that $16.95-a-month hosted Web account? Hosted servers, especially shared accounts, can pose real security problems. Some hosts are better than others, but with shared hosting, you basically have to keep your fingers crossed. "

http://www.eweek.com/article2/0,1759,1565792,00.asp

Tuesday, April 13, 2004

833786 - Steps that you can take to help identify and to help protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks:
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.

However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL."

http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
Magical Jelly Bean Software - Magical Jelly Bean Keyfinder v1.41:
"The Magical Jelly Bean Keyfinder is a freeware utility that retrieves your Product Key (cd key) used to install windows from your registry. It has the options to copy the key to clipboard, save it to a text file, or print it for safekeeping. It works on Windows 95, 98, ME, NT4, 2000, XP, Server 2003, Office 97, and Office XP. This version is a quick update to make it work with Windows Server 2003."

http://www.magicaljellybean.com/keyfinder.shtml

Monday, April 12, 2004

Internet Explorer 6 Security and Privacy Essentials:
"Protect your privacy and the security of your computer on the Web. The following topics are packed with information and easy-to-follow, practical instructions that explain how features in Internet Explorer 6 help make your Web browsing experience better. "

http://www.microsoft.com/windows/ie/using/howto/privacy/secprivessntl.asp

Friday, April 09, 2004

RealPlayer 10 Release Supports More Formats:
"RealNetworks Inc. on Wednesday released the latest version of its digital media player with support for all of the major Internet media formats, including those from competitors Microsoft Corp. and Apple Computer Inc.

RealNetworks of Seattle first announced RealPlayer 10 for Windows in January and said it would include support for playing music purchased through Apple's iTunes, working around Apple's digital rights management technology. "

http://www.eweek.com/article2/0,1759,1563416,00.asp
Researcher Claims Online Anti-virus Scanners Buggy:
"Online scanners from Symantec, McAfee and Panda all contain buffer overflows. One researcher claims an attacker could execute arbitrary code, another just that they could crash the browser. Panda reports their software has been fixed and Symantec denies there is a problem at all. "

http://www.eweek.com/article2/0,1759,1563092,00.asp
Authorama - Public Domain Books:
"Authorama.com, featuring completely free books from a variety of different authors, collected here for you to read online or offline. The books may have been published before, but not in this form, which I hope you find enjoyable to read and print."

http://www.authorama.com/

Thursday, April 08, 2004

Tax Center:
"American Express has created a Web site to help small-business owners learn about new tax developments and interact with other entrepreneurs on tax issues."

http://home3.americanexpress.com/smallbusiness/Landing/tax_center_main.asp?openvan=taxcenter

Wednesday, April 07, 2004

Attrition Security Rant: Anti-Virus Companies: Tenacious Spammers:
"For roughly three years, the Internet has seen worms that spread via e-mail, often taking addresses out of the infected machine's web cache, user addressbook or other sources. Some of these worms will also forge/spoof the 'From:' line so the mail appears to be from someone else, in an attempt to make the mail more 'trusted'. To be clear, here is a sample timeline of how these work:

EvilGuy01 writes and releases a new worm.

Fred is a moron and clicks on an attachment from a stranger, infecting his machine.

The worm mails a copy of itself to everyone in Fred's addressbook.

The mail sent out spoofs the headers of the mail so it may be 'From: George' or 'From: Sally'.

Tom gets a copy of the mail 'From: Sally' and clicks on the attachment, infecting himself.

Tom sends mail to Sally complaining about her evil shenanigans.

Sally replies to Tom with 'd00d WTF?! lol' since she never sent the mail. "

How enterprise AV systems add to the Internet traffic

But wait, it gets worse. Even if friends and family understand that I likely did not send them a virus, some enterprise antivirus program with built-in return messages will state emphatically that I have a virus. Here's how that works: As the forged e-mail enters their enterprise system, that system bounces it back to the apparent sender with a message that authoritatively states, "You are infected with XXX virus." I have hundreds of these bounced e-mail messages claiming that I am infected with MyDoom.f, Netsky.d, or Bagle.c. I'm not.

In the middle of an e-mail virus outbreak, messages such as these--originally intended to provide a useful service--only add to the Internet traffic jam. Brian Martin, a.k.a. Jericho at Attrition.org, wrote a thorough critique of the current methods being used, complete with examples. His conclusion? System administrators need to turn off this "helpful" feature if they haven't already.

Unfortunately, the spoofing problem itself lies deep under the hood of the Internet, within SMTP, Simple Mail Transfer Protocol, the Internet protocol used for sending e-mail. SMTP was created many years ago and lacks a modern method for verifying the authenticity of the sender. With a little finesse, almost anyone can manipulate the header information on an e-mail message to disguise its true origin and make it appear as though someone else sent you a message.

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5128975.html?tag=adss

http://www.attrition.org/security/rant/av-spammers.html
Microsoft Releases Source Code on SourceForge:
"On Monday, Microsoft released some of its code under an open-source license, and posted it on SourceForge, the open-source code repository.

To date, Microsoft has made its source code available under a variety of licensing mechanisms, all under its 'shared source' umbrella. But until today, the company had not released code under what is commonly considered a true open-source license."

Microsoft made available an internally-developed product called the "Windows Installer XML" (WiX) to SourceForge. The code is downloadable here.

WiX is a toolset for building Windows installation packages from XML source code. It runs on Windows NT and Windows 2000.…

http://sourceforge.net/projects/wix/

http://www.microsoft-watch.com/article2/0,1995,1561953,00.asp

Tuesday, April 06, 2004

Microsoft Security Newsletter For Home Users- Current Edition

http://www.microsoft.com/security/home/secnews/current.asp
Executive E-Mail: Current Edition:
"Microsoft Progress Report: Security

Malicious software code has been around for decades. But only in the last few years have the Internet, high-speed connections and millions of new computing devices converged to create a truly global computing network in which a virus or worm can circle the world in a matter of minutes.

Meanwhile, criminal hackers have become more sophisticated, creating and distributing digital epidemics like Slammer, Blaster, Sobig and Mydoom that spread almost instantaneously, threatening the potential of technology to advance business productivity, commerce and communication.

The kinds of threats are evolving too. Blaster, for example, hijacked individual computers, turning innocent users into unknowing and innocent worm propagators. These kinds of attacks – "swarming" attacks that are coordinated to cause multiplied, cascading effects – change the landscape of security threats. They put new demands on IT professionals and consumers to take preventative measures, and on the technology industry to continue to innovate and develop new solutions.…

Given human nature, evolving threat models and the increasing interconnectedness of computers, the number of security exploits will never reach zero. But we can dramatically blunt the impact of cybercriminals, and are dedicating a major portion of our R&D investments to security advances.…"

http://www.microsoft.com/mscorp/execmail/
HOAXBUSTERS Home Page:
"Interspersed among the junk mail and spam that fills our Internet e-mail boxes are dire warnings about devastating new viruses, Trojans that eat the heart out of your system, and malicious software that can steal the computer right off your desk. Added to that are messages about free money, children in trouble, and other items designed to grab you and get you to forward the message to everyone you know. Most all of these messages are hoaxes or chain letters. While hoaxes do not automatically infect systems like a virus or Trojan, they are still time consuming and costly to remove from all the systems where they exist. At CIAC, we find that we spend much more time de-bunking hoaxes than handling real virus and Trojan incidents. These pages describe some of the warnings, offers, and pleas for help that are filling our mailboxes, clogging our mailservers, and that generally do not have any basis in fact.…"

http://hoaxbusters.ciac.org/

Monday, April 05, 2004

MSBlast epidemic far larger than believed - News - ZDNet:
"New data from Microsoft suggests that at least 8 million Windows computers have been infected by the MSBlast, or Blaster, worm since last August--many times more than previously thought.… "

http://zdnet.com.com/2100-1105_2-5184439.html
A Heretical View of File Sharing:
"But what if the industry is wrong, and file sharing is not hurting record sales?

It might seem counterintuitive, but that is the conclusion reached by two economists who released a draft last week of the first study that makes a rigorous economic comparison of directly observed activity on file-sharing networks and music buying.

'Downloads have an effect on sales which is statistically indistinguishable from zero, despite rather precise estimates,' write its authors, Felix Oberholzer-Gee of the Harvard Business School and Koleman S. Strumpf of the University of North Carolina at Chapel Hill. "

http://www.nytimes.com/2004/04/05/technology/05music.html

Saturday, April 03, 2004

Kinja, the weblog guide:
"Kinja is a weblog portal, collecting news and commentary from some of the best sites on the web. Visitors can browse items on topics, everything from food to sex. Or they can create a convenient personal digest, to track their favorite writers.

Weblogs are much talked about, but still challenging to navigate for the average web user. Kinja is designed to bring weblog writers to a broader audience, by making it easier to explore topics, posts and writers.

Kinja is not aimed at early adopters. Users wanting to analyze patterns of meme propagation, and other sophisticated data, should try the excellent Technorati."

http://www.kinja.com/
Google to offer gigabyte of free e-mail - News - ZDNet:
"Google, the company that made off with the search market, is setting its sights on free e-mail.

The company, based in Mountain View, Calif., on Thursday launched a test with about 1,000 invited guests set to try out a new e-mail service called 'Gmail.'

Google, which made its name in search but has added numerous services, such as a news aggregation page and a newsgroup interface, says that Gmail is search-based e-mail."

Like Yahoo Mail and MSN Hotmail, Gmail will let users search through their e-mail. Unlike those competitors, though, Google will offer enough storage so that the average e-mail account holder will never have to delete messages.

Hotmail currently offers 2MB of free e-mail storage. Yahoo offers 4MB. Gmail will dwarf those offerings with a 1GB storage limit.…

http://zdnet.com.com/2100-1104_2-5182805.html

Thursday, April 01, 2004

PC Magazine: Top 100 Web Sites:
"Top 100 Web Sites - April 2004

You'll wonder how you ever got along without these little-known gems. We've also updated our Top 100 Classics."

http://www.pcmag.com/category2/0,1738,7488,00.asp
Top 100 Favorites Download:
"2004 100 Top Websites You Didn't Know You Couldn't Live Without "

http://www.pcmag.com/article2/0,1759,1558426,00.asp

Wednesday, March 31, 2004

DOS on Its Death Bed?:
"DeviceLogics, keeper of the DR-DOS code base, released this week what might be the final upgrade to the 17-year-old DOS operating-system variant.

At the Embedded Systems Conference in San Francisco, DeviceLogics took the wraps off DR-DOS 8.0, the first update to DR-DOS since 1999."

The primary new feature of the 8.0 release is FAT32/large-partition support, which DeviceLogics is targeting at customers with DOS-based embedded applications that are built atop FAT32 platforms.…

While Microsoft's now-defunct MS-DOS is the probably the best known of the DOS flavors (Microsoft buried MS-DOS inside Windows, as of Windows 95), DR-DOS has had its share of backers through the years.

http://www.eweek.com/article2/0,1759,1558362,00.asp

Tuesday, March 30, 2004

DDoS Attacks for the Common Man:
"Ask not why the DDoS bell tolls for thee.

You might ask why you, who monopolized your industry or sued customers for using someone else's product, should be the target of a DDoS attack? You might as well ask why there's random street crime. The answer is that the Internet is a rough neighborhood, and even little guys have disgruntled former employees and customers who feel cheated, not to mention ex-spouses and competitors. Trust me, it really could happen."

Most Web sites don't have or need the resources that Microsoft or even The SCO Group put in theirs for normal business, and it doesn't take an army of zombied clients to bring them down. Just a few clients, focused on the job, can cause problems for a Web site. Froutan says that at his company they've seen such attacks go on for days at a time. Experience with the MyDoom worms certainly bears that out.

http://www.eweek.com/print_article/0,1761,a=122636,00.asp
This summary is not available. Please click here to view the post.
Online Merchants Find Problems With Google:
"Google may be popular, but it gets its share of complaints. Merchants quibble when their sites rank poorly, while some users say the popularity-based ranking system shuts out useful, but little-known sites. "

Because a site scores higher the more other sites link to it—an indication of popularity—independent films are less likely than Hollywood blockbusters to appear in results, said Dragomir Radev, an information studies professor at the University of Michigan.

Newer and foreign sites may also be difficult to find because they are not as well known by the U.S.-centric Internet population.…

as Google's popularity grew, so did attempts to fool it. A cottage industry developed around search engine optimization to share tricks for ranking higher.

One early trick involved buying hundreds of domain names and having them link to one another to mimic popularity. As Google closed one loophole, webmasters found others.

Pranksters have figured out that they, too, could game the system, so that typing "miserable failure" gets you President Bush's biography, even though neither word appears on the page.…

http://www.eweek.com/article2/0,1759,1556008,00.asp?kc=EWNWS032904DTX1K0000599

Saturday, March 27, 2004

Crafty Syntax Live support Help - Free download and open source:
"A multi-user, multi-operator, multi-department live Help support chat system that allows the operators of the websites to monitor their visitors as they are browsing the site and proactively open a chat session with the visitor. Is in PHP and uses either Mysql or Text based database . Other features include AUTO INVITE!, referer tracking, page tracking, chat notification, user is typing message, multiple chat sessions, sound alert, leave a message if offline, push urls, quick responses, and multiple operators. runs on your server and is open source GPL."

http://www.craftysyntax.com/CSLH/

Thursday, March 25, 2004

Online Swindlers, Called 'Phishers,' Lure Unwary:
"EarthLink, the big Internet access provider, went hunting for phishers.

It started a campaign to track down people who were sending e-mail messages that pretended to be from EarthLink but were actually fraudulent attempts to steal customers' passwords, credit card numbers and other information. What it found was that of the dozen or so people it could clearly identify as engaged in the practice known as phishing, more than half were under 18."

http://www.nytimes.com/2004/03/24/technology/24PHIS.html?pagewanted=all&position=
Hotmail, Yahoo Users at Risk of PC Takeover:
"A potentially serious security flaw found in Web-based e-mail services offered by Microsoft and Yahoo could put millions of PCs at risk of takeover, an Internet security research firm warned Tuesday.…"

The vulnerability only affects Hotmail and Yahoo running on Microsoft's Internet Explorer (IE) browser.

"When the victim attempts to read this email, the code executes and may result in severe consequences," the company said. Successful exploit could lead to theft of a user's login and password, disclosure of the content of any e-mail in the mailbox and disclosure of all contacts within the address book.

Additionally, GreyMagic said the attacker could manipulate the system to automatically send e-mails from the mailbox and to exploit vulnerabilities in IE to access the user's file system and eventually take over his or her machine.

The company said Microsoft reacted to its warning with a fix for the flaw. However, GreyMagic said all attempts to contact Yahoo's security department failed, meaning that Yahoo's users are still vulnerable. Efforts by internetnews.com to contact Yahoo at press time were unsuccessful.

…the vulnerability makes use of an IE technology called HTML+TIME (based on SMIL), which is meant to add timing and media synchronization support to HTML pages.

One of the features of HTML+TIME is the ability to manipulate any attribute on an element via special control elements.

http://www.internetnews.com/dev-news/print.php/3329821
MSDN Flash:
"Volume 8, Number 6 March 23, 2004"

http://msdn.microsoft.com/flash/currentissue.htm

Wednesday, March 24, 2004

Netsky.P Spreads Through Ancient Security Hole:
"McAfee's Avert labs is reporting that a new variant of the Netsky worm, Netsky.P, is spreading quickly. Both McAfee and Trend Micro Inc. rate Netsky.P as a 'medium' threat and Symantec Corp. has rated it a '2' (for 'Low,' on a scale of 1 to 5). This is the first new variant of Netsky seen in about a week, a long hiatus for recent times. "

This new variant is very much like other Netsky versions with two differences, according to Vincent Gullotto, vice president of the McAfee Avert Virus and Vulnerability Emergency Response Team. The initial seeding of the worm, referring to the initial group of users to whom the virus author distributed it, appears to have been in Australia. It's not clear whether or how this would facilitate spreading of the worm, but it is unusual.

The other interesting and unusual characteristic of this worm is that is utilizes a very old vulnerability in Internet Explorer, the Incorrect MIME Header (MS01-020) bug. This bug, patched almost three years ago, allowed a hostile HTML e-mail to execute arbitrary code if viewed in the preview pane of a mail client.

Once very much in vogue among virus writers, it has fallen into disuse in recent times.

http://www.eweek.com/article2/0,1759,1552315,00.asp?kc=EWNWS032204DTX1K0000599
Fast-Moving Worm Crashes Computers:
"Witty, a new worm that hit the Internet Saturday, looked late Monday to be running down. It corrupts the hard drives of machines running vulnerable versions of ISS' BlackIce products."

The Witty worm, which took hold of the Internet for a short time during the weekend, appears to have peaked thanks to its habit of destroying the machines it infects.

Witty made a dramatic entrance Saturday morning, quickly infecting more than 6,000 computers, which then began scanning the Internet for other machines to attack. But within 24 hours, the number of Witty-infected PCs scanning the Internet had dropped to around 2,000. That number dropped even further, to around 1,000 machines by Monday morning, according to data compiled by The SANS Institute, based in Bethesda, Md.

Unlike most worms, which exist for the lone purpose of spreading themselves, Witty is capable of corrupting the hard drives of infected machines, preventing normal operation of the PC and eventually causing it to crash. The worm attacks via random UDP ports; however, it always comes from UDP source port 4000, according to various analyses of the code by security experts. Infected machines will begin sending out large amounts of UDP traffic as the worm attempts to infect other machines.

Rebooting an infected machine appears to remove the worm, experts said on the weekend.

The main reason for the drop-off seems to be that Witty gradually corrupts the hard drives of infected machines, eventually causing them to crash and preventing them from scanning any longer. At the peak of the outbreak Saturday, SANS was seeing as many as 300,000 Witty-related packets per hour. Witty exploits a flaw in a component of Internet Security Systems Inc.'s BlackIce protection software. The vulnerable component also is found in several other ISS products, but the Atlanta-based company said they are not susceptible to the worm.

Once it infects a given machine, the worm generates a random IP address and sends its payload to that PC. It repeats this process 20,000 times, then turns its attention back to the local machine it's on. Witty opens a random drive on the PC and writes 65 kb of data to a random location.

http://www.eweek.com/article2/0,1759,1552000,00.asp?kc=EWNWS032204DTX1K0000599

Saturday, March 20, 2004

Use JavaScript to Create a Scrolling Grid - WebReference.com-:
"A problem often encountered in web design is condensing large tables of data into a standard 800x600 web page. If the table is too big, the user will need to scroll the browser window to see all of the data, which means that the surrounding text and any row or header columns cannot be seen."

http://www.webreference.com/programming/javascript/gr/column4/index.html

Friday, March 19, 2004

Experts Debate Danger of Phatbot Worm:
"Security discussion lists and reports were abuzz Wednesday with talk of a new worm, named 'Phatbot,' that had spread to as many as hundreds of thousands of systems. But not all security experts agreed that the worm was widespread.

As of late Wednesday afternoon, no major antivirus company had listed the worm as more than a 'low' risk. "

http://www.eweek.com/article2/0,1759,1550393,00.asp?kc=EWNWS031804DTX1K0000599
New Bagle Worm Variant Can Run Without Launching Attachment:
"A series of new variants of the prolific Bagle worm has raised alarms in the security community through an innovative infection mechanism: The e-mail message in which the variants arrive may have no file attachment, and it's possible for a user to become infected without having to launch one. "

The message includes a Windows ActiveX control and uses a vulnerability announced and patched by Microsoft Corp. in August and another problem from last October. The most recent Cumulative Security Update for Internet Explorer also includes a fix for the more recently discovered flaw.

The ActiveX control does not contain the actual worm, according to McAfee Security. Instead, it creates and runs a VBScript on the system, which downloads and executes the worm from one of a list of IP addresses. According to McAfee, as of 06:45 PST on March 18, "The majority of the 590 IP addresses seen have been closed down. At the time of writing, 39 were still responding."

http://www.eweek.com/article2/0,1759,1550835,00.asp?kc=EWNWS031804DTX1K0000599

Thursday, March 18, 2004

New Homeland Security Guidelines Called Vendor-Driven:
"A task force formed by the Department of Homeland Security is set to unveil a set of security recommendations this week for both enterprises and home users, but many industry observers say the guidelines are too little, too late. "

The guidelines are the work of the Awareness for Home Users and Small Businesses task force, formed late last year by DHS and private industry at the National Cybersecurity Summit. The group and several others formed at the same event are designed to help foster better cooperation between government and industry and to tackle topics such as creating early warning systems, writing secure software and bolstering security in corporate governance.

The groups mainly comprise executives from security and software vendors such as Oracle Corp., Microsoft Corp., RSA Security Inc. and Internet Security Systems Inc., as well as government officials and security experts in academia.

The recommendations, scheduled to be released Thursday, are intended as a follow-up to the National Strategy to Secure Cyberspace, released in early 2003 and widely panned in the industry for being long on platitudes and short on definitive action. The new offering reportedly centers on increasing users' awareness about security issues through education and communication.

"Because this is driven mainly by the vendors, it will be about blaming the users," said Alan Paller, research director at The SANS Institute in Bethesda, Md. "Private industry isn't doing its part to fix the problems we have with software and processes. It's like telling drivers to drive safely and not fixing the bumpers and the seat belts."

http://www.eweek.com/article2/0,1759,1549954,00.asp?kc=EWNWS031704DTX1K0000599
Microsoft Renews Its Commitment to Security Education:
"If you lead customers to the security trough, will they drink?

Microsoft seems convinced they will. And the company is pulling out all the stops to continue to educate its users, reasoning that a more educated customer base will be a more secure customer base.…"

Microsoft will release for download on Wednesday, March 17, a new scripting capability for its Microsoft Baseline Security Analyzer 1.2, a product which performs scans of Windows systems for security misconfigurations. The new scripting tool will allow users to scan an unlimited number of computers or IP addresses from a single input file.

http://www.microsoft-watch.com/article2/0,1995,1549876,00.a

Wednesday, March 17, 2004

Help Yourself:
"Although it's easy to pick up the phone and call that friend who always has an answer, or post a message to your favorite tech forum, you might want to take a few steps to try to solve the problem on your own—or at least be prepared with the information your geek in shining armor will need to troubleshoot the problem for you. Here are ten steps that can help you solve your problems faster."

http://www.pcmag.com/article2/0,1759,1544176,00.asp
Java(TM) Boutique - Using FOP with Java:
"In data-centric applications, you are often required to produce reports and documents in various formats. One of the challenges facing the developer world is to find a generic and consistent way of manipulating a structurally diverse data set to produce formatted reports. For example, if you write a program to accept a certain data set and produce a PDF formatted report, than in order to produce an HTML report on the same data set you might have to write a different program. In this article, we will see a relatively new technology involving W3C standard named XSL-FO. FOP gives us the flexibility to operate on XML structured data, apply an XSL Stylesheet, do the XSLT transformation and publish the data in various formats such as PDF, PCL, SVG, TXT and many other…"

http://javaboutique.internet.com/tutorials/FOP/

Tuesday, March 16, 2004

The Hidden Power of Photoshop CS: Chapter 2: Color Separations. Pt. 2. By Sybex - WebReference.com-:
"A second way to achieve manual duotoning is to create the effect using spot color channels. This creates an image with the spot color built in, and essentially it will be press ready as a separation. In the following techniques you will use both the manual layer method just described in the previous section and Photoshop’s duotone interface to create duotone results."

http://www.webreference.com/graphics/ps2/
Office update clogs spam filters - News - ZDNet:
"A recent update for Microsoft's Office software is blocking several popular spam filters, and software makers are scrambling to find a fix to the fixes.

The problems have occurred since the release earlier this week of Service Pack 3 for Office XP and 2000, which are recent versions of Microsoft's widespread productivity package. The patches and big fixes in SP3 included a number of security fixes for Office's widely used e-mail client, Outlook.

Shortly after SP3 was released, users started reporting problems to the makers of several popular products for filtering out junk e-mail. They said every time their spam filter tried to intercept a message, Outlook would pop up a warning message that another application was trying to access Outlook's address book. …"

"If they were to click, 'yes,' 'yes,' 'yes' (in Outlook), it would work for them," Fahey said. "It's just a pain."

http://zdnet.com.com/2100-1105_2-5172968.html

Monday, March 15, 2004

Building ASP.NET Applications with C#Builder for Microsoft .NET:
"Among the many features of C#Builder is an ASP.NET application development environment. With full support for WYSIWYG design and access to HTML and C# code, C#Builder is an excellent tool for building entire Web sites."

http://www.informit.com/articles/article.asp?p=169672

Saturday, March 13, 2004

Video Codec Shootout:
"There are a great many considerations when it comes to digital video -- such as streaming capabilities, server software and processor load, and licensing costs for packaged media -- that are of more concern to businesses than home users. For the most part, we're not going to focus on these enterprise-oriented issues.

Rather, this is an article for those who want to compress video for home use: to e-mail to family members, put up on a Web site, burn onto a CD, re-compress to fit on a PDA or portable video player, or just archive for later use. Our focus is on middle-of-the-road bitrates suitable for download or CD archives, not extremely low bitrates for streaming over the Internet or very high bitrates for DVD-ROM based packaged media. "

http://www.extremetech.com/print_article/0,1583,a=121163,00.asp
Microsoft Raises Threat Level of Outlook Hole:
"The Redmond, Wash., software maker increased the threat level of the Outlook security vulnerability to its highest level of four — "critical." The Outlook 2002 hole could let an attacker run malicious code on a user's machine.

Microsoft originally had labeled the vulnerability as "important" and believed that attackers could only exploit the hole if users had set the Outlook Today folder as the default view for Outlook 2002, said Mike Reavey, a Microsoft security program manager.

After issuing a fix for the Outlook hole, as part of Microsoft's March security bulletin releases, the company learned from the researcher who discovered the vulnerability that attackers could reach a wider number of users by forcing them into the view in order to run an exploit, Reavey said."

"It has the potential to affect users that are in any (Outlook 2002) view at all," he said.

http://www.eweek.com/article2/0,1759,1546968,00.asp?kc=EWNWS031104DTX1K0000599
The ASP.NET Resource Kit is available:
"The ASP.NET Resource Kit is available for download free of charge from http://www.msdn.microsoft.com/asp.net/asprk. Developers can also order a copy of the Resource Kit on CD for a small shipping and handling fee.

The MSDN ASP.NET Migration Center and the ASP to ASP.NET and PHP to ASP.NET Migration Guides are located at http://www.msdn.microsoft.com/asp.net/using/migrating/."

http://www.msdn.microsoft.com/asp.net/asprk

Friday, March 12, 2004

Advanced Placement Digital Library in Biology, Physics, and Chemistry:
"Advanced Placement (AP) teachers and students will find resources linked to the AP content outlines, published by the College Board, in biology, physics, and chemistry."

http://apdl.rice.edu/DesktopDefault.aspx

Tuesday, March 09, 2004

Symantec Security Response - W32.Netsky@mm Removal Tool:
"Symantec Security Response has developed a removal tool to clean infections of the following Netsky variants.

W32.Netsky.B@mm
W32.Netsky.C@mm
W32.Netsky.D@mm
W32.Netsky.E@mm
W32.Netsky.K@mm"

http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky@mm.removal.tool.html
The Hidden Power of Photoshop CS: Chapter 2: Color Separations. Pt. 1. By Sybex - WebReference.com-:
"Photoshop provides many tools that seem to produce some magic behind the scenes. Channels, one of the most prominent of these tools, allow you to work directly with components of a color model, such as RGB or CMYK. But, as we saw in the previous chapter, channels can actually be simulated using some simple light theory. Understanding what the channels represent can help you make more intelligent color and correction decisions, and can very much change the way you work with images. "

http://www.webreference.com/graphics/ps1/
Linux Privilege Escalation Hole Detected:
"For the second time in as many months, security researchers have uncovered a privilege escalation security flaw in the Linux kernel.…"

The flaw carries a "critical" rating and affects Linux versions 2.2 up to and including 2.2.25; it also impacts versions 2.4 up to and including 2.4.24 as well as versions 2.6 up to and including 2.6.2.

"Proper exploitation of this vulnerability leads to local privilege escalation giving an attacker full super-user privileges. The vulnerability may also lead to a denial-of-service attack on the available system memory," iSEC warned.

Linux distributor Gentoo confirmed its implementation of the open source operating system was susceptible to the flaw and strongly urged uses to upgrade to newer, more secure versions.

According to Gentoo, arbitrary code with normal non-superuser privileges may be able to exploit this vulnerability and may disrupt the operation of other parts of the kernel memory management subroutines.

Proper exploitation of this vulnerability may lead to local privilege escalation allowing for the execution of arbitrary code with kernel level root access," Gentoo warning, noting that proof-of-concept exploit code has been created and successfully tested.

The flaw was discovered in the memory subsystem which allows for shrinking, growing, and moving of chunks of memory along any of the allocated memory areas which the kernel possesses. iSEC Security Research found that the code doesn't check the return value of the memory function.

http://www.internetnews.com/dev-news/article.php/3322911
How to Use Command Line Shortcuts:
"How to Use Command Line Shortcuts"

http://www.microsoft.com/WindowsXP/expertzone/columns/ballew/commandline.asp
Windows XP Support Secrets:
"Windows XP Support Secrets"

http://www.microsoft.com/WindowsXP/expertzone/columns/bott/suppsec.asp
Finding Help Online for New Users:
"Finding Help Online for New Users"

http://www.microsoft.com/windowsxp/expertzone/columns/ballew/02august19.asp
Worms Are For Suckers Page 2:
"BE VERY SKEPTICAL OF ANY ATTACHMENT IN E-MAIL. This doesn't mean that you shouldn't trust any attachment at all, but unless you know the sender and were expecting the file, you should scrutinize it and not open it unless you can determine that it's legitimate.

Keep your antivirus software and firewall up to date. They aren't perfect, but they help a lot.

If your mail client can block all executables, let it. Most worms, including NetSky, will be blocked just by this. If not, find some other way to do it. It's just not worth being able to mail executables around. Incidentally, both Outlook and Outlook Express have done this for years, and therefore their users have been immune to these worms. "

http://www.eweek.com/article2/0,1759,1543635,00.asp
Worm Masquerades as MyDoom Patch:
"A new worm purporting to contain a patch to defend against MyDoom is attacking Windows machines throughout Europe and parts of North America.

Sober.D appeared Sunday and began spreading in Germany and the United Kingdom. The worm arrives in an e-mail message with a subject line of 'Microsoft Alert: Please Read!' and carries a sending address with a Microsoft domain. The domain extension on the messages are typically from Germany, Israel, Switzerland or Austria. "

The new worm comes a week after the largest, most concentrated onslaught of virus activity in recent memory, which included the appearances of 16 new viruses within about 10 days. Most of those new threats were variants of existing viruses, including MyDoom. The original version of Sober hit the Internet last October and never amounted to much.

Many of the samples of the new variant that antivirus vendors have seen so far have been written in German. The body of the infected message reads:

"New MyDoom Virus Variant Detected! A new variant of the W32.Mydoom (W32.Novarg) worm spread rapidly through the Internet. Anti-virus vendor Central Command claims that 1 in 45 e-mails contains the MyDoom virus. The worm also has a backdoor Trojan capability. By default, the Trojan component listens on port 13468. Protection: Please download this digitally signed attachment. This Update includes the functionality of previously released patches."

The message includes a file attachment that is either an executable or a Zip archive, according to Network Associates Inc.'s analysis of Sober.D. Once installed on a machine, the virus will display a phony error message indicating either that the fake patch has been installed or does not need to be installed on the PC.

Sober.D then scours the machine's hard drive for e-mail addresses and begins mailing itself out.

http://www.eweek.com/article2/0,1759,1544482,00.asp?kc=EWNWS030804DTX1K0000599

Monday, March 08, 2004

mezzoblue revised image replacement:
"Plenty of new and interesting revisions to the original Fahrner Image Replacement technique have sprouted up recently. This is an attempt to consolidate them, so that perhaps we can decide on the official replacement.

Requirements: the replacement must solve the screen reader problem, and it must address the 'images off, css on' problem. It is also hoped that a solution will be found that reduces the need for empty elements. The successful technique must work in browsers back to 5.x, but as of the time of writing none of these appear to fail so browser support matrices will be spared.

The two most promising techniques, Phrak and Gilder/Levin are available on a reduced page for screenreader testing."

http://www.mezzoblue.com/tests/revised-image-replacement/
ZDNet AnchorDesk: Virus 'gangs' to blame for recent epidemic:
"It's a busy time for computer viruses and worms. Over the last three weeks, we've seen nearly two dozen variations of Bagle, Netsky, and MyDoom circulate the Net. What gives? It looks like gang warfare is responsible, drive-by shootings on the information highway."

YOU HEARD ME right. "Gangs" of virus writers are currently trying to outdo one another and protect their turf. What they're fighting for is control of thousands of Trojan horses that create stealth peer-to-peer networks out of virus-infected computers worldwide. Such networks can be used to launch next-generation computer viruses or distributed denial-of-service attacks. They can also be sold to spammers who use them to anonymously send messages to our inboxes. Because of all their uses, virus writers consider these networks worth fighting for.

Unfortunately, you and I aren't just bystanders, we're the targets. And the only solution I can offer is what I've been saying for years: Update your antivirus software and don't open unsolicited e-mail messages. I wish there were a magic fix I could offer that would inoculate us all from these viruses, but, unfortunately, I can't. These infections aren't even very original. They use good old-fashioned social engineering, and not a software flaw, to spread.

There appear to be three distinct gangs: the MyDoomers, who are using source code from the MyDoom.b worm to set up stealth networks; the Bagles, who wrote their own unique viral code to establish the same sorts of networks; and the Netskys, who seem to have started the whole imbroglio by thwarting the plans laid down by MyDoom and Bagle.

THE FIGHT seems to have broken out on Feb. 18, when Netsky.b appeared on the Net and began removing traces of MyDoom and Bagle from infected computers. Netsky.b not only removed the viral code, but also the Trojan horse "back doors." These are the tunnels of communication that allow the MyDoom and Bagle gangs to communicate with infected systems and thus set up the valuable peer-to-peer networks. Needless to say, the authors of the Bagle and MyDoom variants took offense--as Netsky spread, their networks began to shrink in size and thus their ability to do harm online diminished.

One week later, on Feb. 25, the Netsky.c variant appeared a hidden message embedded in the code: "We are the skynet--you can't hide yourself---we kill malware...MyDoom.f is a thief of our idea!" (Such messages are known as "greetz.") A few days later, Bagle.J and MyDoom.G responded: "Hey, NetSky...Don't ruin our business, wanna start a war?" and "To NetSky's creator(s): imho, skynet is a decentralized peer-to-peer neural network. We have seen P2P in Slapper in Sinit only. They may be called skynets, but not your...app." (Slapper is a Linux worm that established its own P2P network starting in August 2002; Sinit is a common Trojan horse that also established its own P2P network, starting in October 2003.)

Greetz are not new; often they are directed at rival Internet gangs or antivirus researchers. In December of 2001, rival members of Israeli script kiddie gangs unwittingly released the Goner virus. In that case, the virus (which they called Pentagone) contained greetz with Internet nicknames of the authors: "Pentagone coded by: suid, tested by: ThE_SkuLL and Isatanl." Originally, the authors named in the greetz denied their involvement; shortly thereafter, however, they took credit for the virus when the news media started saying the code was cut and pasted from elsewhere. A short time later, the Israeli youths were arrested and sentenced to 2.5 years in jail.

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5124832.html?tag=adss

Saturday, March 06, 2004

Alias Reduces Educational Pricing on Alias SketchBook Pro: "
Alias, a Silicon Graphics Inc. company, announced special educational pricing for Alias SketchBook Pro, the sketching, annotation and presentation software for Tablet PCs and Wacom tablets. Following a restructuring of its education program in July 2003 to provide affordable and accessible Maya and StudioTools learning packages, Alias is now expanding the program to include reduced pricing on Alias SketchBook Pro for both students and faculty.

Alias SketchBook Pro provides the latest in accurate digital sketching technology for industries such as industrial and product design, architecture, computer graphics, animation, game development and fashion design. Students looking to break into these industries can benefit from combining tools like Alias SketchBook Pro and a Tablet PC or Wacom tablet to hone their skills and develop a portfolio of exceptional creative work.…"

www.alias.com
www.journeyed.com

http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=140#4
Paid Inclusion Under Fire at Search Engine Shindig:
"The debate over the fairness and relevancy of paid search spilled onto the stage at the Jupitermedia's Search Engine Strategies 2004 conference here on Wednesday.

On one side: Google Inc., which objects to any commingling of paid search with its Web index. On the other: Yahoo Inc., which embraced this week a program for letting Web sites pay to be included in its recently launched Web index. "

And in the middle: Ask Jeeves Inc., which has dropped one paid program, where Web sites could provide XML feeds into its index, while maintaining another for paying to submit sites for crawling.

The varying positions demonstrate the evolving field of Web search. The battle to deliver the most relevant results, and to make money, has intensified now that Yahoo has switched from Google's search results to its own technology and as Microsoft Corp. builds its own technology.

The latest shift was Ask Jeeves discontinuation of its Index Express program for direct XML feeds into its Teoma search engine index. Paul Gardi, Ask Jeeves senior vice president of operations and planning, said the company was not denouncing the practice of paid inclusion but dropped that form because it didn't return relevant results for users.…

Ask Jeeves, of Emeryville, Calif., is continuing its Site Submit program, where sites pay to guarantee that their pages get crawled, Gardi said.

But Google and Yahoo, in a far-reaching panel discussion here on the future of search, did stake out clear opinions on whether Web sites should be able to pay to ensure their pages are indexed.

Google will continue to ban any paid inclusion into its Web search index, said Craig Silverstein, Google's director of technology, which drew applause from the audience. The Mountain View, Calif., company follows a strict division between its advertising business for sponsored search links and its ranking of regular results, he said.

http://www.eweek.com/article2/0,1759,1541921,00.asp

http://www.eweek.com/article2/0,1759,1542441,00.asp?kc=EWNWS030404DTX1K0000599

Wednesday, March 03, 2004

Microsoft Sparks Web Services for eBay:
"Specifically, developers may use Microsoft Office Excel 2003 spreadsheet and Microsoft Office FrontPage Web design applications to write services where eBay users could automate pricing and bid changes as needed. "

Participants in the eBay Developers Program can use XML application programming interfaces (APIs) with FrontPage 2003 to design Web sites that display custom information on items for sale on eBay. FrontPage 2003 includes Web design and maintenance tools and customized data views for listing multiple auction items.

With Excel 2003, users can: use XML to integrate with the eBay API to customize list views, graphs and charts; catalog bulk items online or offline; and submit item listings. The software allows eBay buyers and sellers to create a transaction record, analyze buying or selling history, and use automated uploading processes to submit listings.

To try the solution, users can download sample code with the eBay listing management capabilities within Microsoft Office from the eBay Developer site here.
http://developer.ebay.com/DevProgram/sign_in.asp?URL=/devzone/docs/samplecode.asp

http://www.internetnews.com/ec-news/article.php/3319641

Saturday, February 28, 2004

Netsky causing billions in damages - News - ZDNet:
"Despite requiring the computer user to actively run an attachment, Netsky.C seems to be spreading fast, with anti-virus vendor Central Command claiming it had discovered 1,500 infections of the virus within 40 minutes of its discovery. Like Netsky.B the latest virus uses its own SMTP engine to e-mail itself to addresses found on the computer, and copies itself into any folder it finds whose name includes 'shar'. "

UK security company mi2g estimated the economic damage done by Netsky.B worldwide to be at least US$3.12 billion. This was calculated "on the basis of helpdesk support costs, overtime payments, contingency outsourcing, loss of business, bandwidth clogging, productivity erosion, management time reallocation, cost of recovery, and software upgrades".…

http://zdnet.com.com/2100-1105_2-5165642.html

Thursday, February 26, 2004

Caller ID for E-Mail Technical Specification:
"'Caller ID for E-Mail: The Next Step to Deterring Spam' is the Microsoft draft specification to address the widespread problem of domain spoofing. Domain spoofing refers specifically to the use of someone else's domain name when sending a message, and is part of the larger spoofing problem, the practice of forging the sender's address on e-mail messages.

Caller ID for e-mail would verify that each e-mail message originates from the Internet domain it claims to come from. Eliminating domain spoofing will help legitimate senders protect their domain names and reputations, and help recipients more effectively identify and filter junk e-mail."

http://www.microsoft.com/mscorp/twc/privacy/spam_callerid.mspx
Fresh Worms Attack E-Mail, Internet Explorer, User Data:
"A series of new worms spread on the Internet on Wednesday, spreading through conventional e-mail methods. The new versions have escalated their attacks and destructiveness. "

On the prowl is MyDoom.F worm, which began action on Monday. It is the latest version one of most successful worms on record; earlier MyDoom variants in January launched a series of distributed denial of service attacks (DDoS) against Microsoft Corp. and The SCO Group. The new version retains its predecessors' capability to perform a DDoS attack.

"What is interesting about these latest worm trends is that they are very politically motivated. More than your curious teenage hacker at work; these attacks are stemming from groups seeking to make a statement on some of today's most controversial technology issues," said Scott Chasin, chief technology officer of MX Logic Inc., in a statement.

Beyond its DDoS target, MyDoom.F is also more destructive. A PC Magazine analysis of MyDoom.F, said the worm attempts to delete files on the system based on a probabilistic formula, adding an element of destructiveness rarely seen in such worms.

The worm also attempts to spread to file sharing users. For all these reasons, antivirus vendors are giving it a higher threat ranking than usual.

The latest threat is NetSky.C, which arrived on Wednesday. The worm is a variant of NetSky.B, which spread rapidly earlier this month, according to security vendors. It is also called Moodown.C.

According to F-Secure Corp.'s analysis of the worm, the new version is compressed with a different program. It also behaves differently in several ways than its predecessor, such as searching far more files for e-mail addresses that it can use to spread itself.

The worm arrives in a ZIP file attachment to an e-mail message. The file inside the ZIP will have two file extensions, the first for an innocuous file type such as .RTF and the second for an executable file type, such as .SCR.

http://www.eweek.com/article2/0,4149,1538954,00.asp?kc=EWNWS022604DTX1K0000599
Security Guru Unmoved by Gates' RSA Remarks:
"Schneier's Gates comments followed some anecdotes about how everyone can help solve the security problems facing all enterprises. 'Get involved,' he said. 'That's how we make changes. Otherwise security is something done to us.'

Most security systems affect multiple parties, he explained, but usually only one person makes the decision about how security is implemented. 'At this point it's a negotiation. The players with most power are the ones who get to decide what the final answer is,' Schneier said. 'The best way to effect security is to gain power in negotiations. The best way is to change the environment in which security decisions are being made. Change the agenda of the players. Change the outcome.'

Every person has to make security work for himself, he said. 'The goal of security systems is the most security for the least amount of trade-offs. The way to do that is to make the party who is best able to mitigate the risk responsible for the risk,' he said, saying that computer software companies at this point do not share in the risks of software security or insecurity. "

Schneier said one of the best and simplest "security systems" he's seen is the local convenience store or fast food restaurant that displays a sign at the cash register that says, "Purchase free if you don't get a receipt." The system is not designed as a customer service, as it may appear, he said. Rather, it's a means of co-opting the customer into keeping an eye on the store employee who may be suspected of skimming from the cash register. Nevertheless, the customer will be watching if he knows he could get something for free.

"Good security systems are in line with their capabilities," he said. "The store manager is hiring you, aligning your interests with your capabilities. Very cheap security system. For the money it's really good. That's what we should strive for in security systems. The goal is to make them as effective as possible and work with the natural tendencies of people already there."

http://www.eweek.com/print_article/0,3048,a=120200,00.asp
News: Special Reports:
"RSA Conference: New lines of defense

The security companies and experts gathering at the RSA Conference 2004 in San Francisco are showing off smarter ways to ward off attacks. The problem is that hackers are becoming more sophisticated, too. At best, it's hoped that damage can be kept to a minimum."

http://zdnet.com.com/2251-1110-5163906.html

Wednesday, February 25, 2004

Service-Oriented Architecture: Chapter 13: Thirty best practices for integrating Web services. Pt. 1. - WebReference.com -:
"Service-Oriented Architecture: Chapter 13: Thirty best practices for integrating Web services, Pt. 1.

'This chapter is from the book 'Service-Oriented Architecture: A Field Guide to Integrating XML and Web Services' by Thomas Erl. (ISBN 0131428985)."

http://www.webreference.com/programming/soa/index.html

Tuesday, February 24, 2004

Download details: Office 2003/XP Add-in: Remove Hidden Data:
"With this add-in you can permanently remove hidden data and collaboration data, such as change tracking and comments, from Microsoft Word, Microsoft Excel, and Microsoft PowerPoint files."

Thanks to WinXPnews at http://www.winxpnews.com

http://www.microsoft.com/downloads/details.aspx?FamilyID=144e54ed-d43e-42ca-bc7b-5446d34e5360&displaylang=en

Monday, February 23, 2004

Order the Windows Security Update CD:
"Order the Windows Security Update CD
Updated Date: February 23, 2004

The Windows Security Update CD will be shipped to you free of charge. This CD includes Microsoft critical updates released through October 2003 and information to help you protect your PC. In addition, you will also receive a free antivirus and firewall trial software CD.

This CD is only available for Windows XP, Windows Me, Windows 2000, Windows 98, and Windows 98 Second Edition (SE).
Please allow 2-4 weeks for delivery."

http://www.microsoft.com/security/protect/cd/order.asp