Flaw pops up in Linux kernel - News - ZDNet:
"Linux users have been urged to fix a flaw in the core component of the open-source operating system, following the public release of code that could be used to crash Linux systems.
The flaw, found by two software programmers, could give a user with access to a Linux system the ability to crash the system using two dozen lines of code written in the C programming language, said an advisory posted over the weekend on linuxreviews."
"Assume your kernel is (vulnerable) unless you have good reason to believe it is safe," Oyvind Saether, one of the discoverers of the flaw, said in the advisory.
The program, dubbed "evil.c," causes problems with the code sent to the floating-point unit, the part of the processor that handles noninteger calculations, according to a note in a source code patch published by Linux founder Linus Torvalds.
The open-source Linux operating system has fallen prey to its share of flaws and attacks this year. Several flaws were found in the Concurrent Versions System, CVS, a commonly used application for managing open-source code under development. In March and April, online attackers targeted Linux and Solaris systems at many academic high-performance computing centers.…
http://zdnet.com.com/2100-1105_2-5235028.html
Thursday, June 17, 2004
Wednesday, June 16, 2004
Yahoo Mail Popped Instead of Pumped.
Yahoo Chokes Upon Offering Additional User Storage:
"Yahoo Inc., which on Tuesday meant to pump up users' free e-mail accounts to 100MB, popped instead.
On the morning of its splashy debut, Yahoo users were greeted with notices of the upgrade, which boosted standard accounts from 4MB of e-mail storage to 100MB.
However, the vastly popular e-mail service was sluggish, if it worked at all. Starting Tuesday morning, users began complaining about the site's groggy response time—if, in fact, they could even get the www.yahoo.com site to load at all.
Predictably enough, postings on Slashdot show that Yahoo users are looking the gift horse in the mouth.…"
http://www.eweek.com/article2/0,1759,1612683,00.asp?kc=ewnws061504dtx1k0000599
"Yahoo Inc., which on Tuesday meant to pump up users' free e-mail accounts to 100MB, popped instead.
On the morning of its splashy debut, Yahoo users were greeted with notices of the upgrade, which boosted standard accounts from 4MB of e-mail storage to 100MB.
However, the vastly popular e-mail service was sluggish, if it worked at all. Starting Tuesday morning, users began complaining about the site's groggy response time—if, in fact, they could even get the www.yahoo.com site to load at all.
Predictably enough, postings on Slashdot show that Yahoo users are looking the gift horse in the mouth.…"
http://www.eweek.com/article2/0,1759,1612683,00.asp?kc=ewnws061504dtx1k0000599
Tuesday, June 15, 2004
Yahoo Expands E-Mail Storage
Yahoo Expands E-Mail Storage, in Nod to Google:
"Starting today, Yahoo will offer users of its free e-mail service 100 megabytes of storage. That is one-tenth of what Google offers but is still far more than the four megabytes Yahoo previously offered. It will also introduce a premium e-mail service, called Yahoo Mail Plus, with two gigabytes of storage for $19.99 a year.…"
http://www.nytimes.com/2004/06/15/technology/15mail.html
"Starting today, Yahoo will offer users of its free e-mail service 100 megabytes of storage. That is one-tenth of what Google offers but is still far more than the four megabytes Yahoo previously offered. It will also introduce a premium e-mail service, called Yahoo Mail Plus, with two gigabytes of storage for $19.99 a year.…"
http://www.nytimes.com/2004/06/15/technology/15mail.html
A bug in fully patched versions of Microsoft's Internet Explorer Invites Phishing Attacks
URL Parsing Bug in IE Invites Phishing Attacks:
"A bug in fully patched versions of Microsoft's Internet Explorer Web browser allows violations of the browser's security zones, with the result that an unknown malicious site could assume the privileges of more trusted zones.
Researchers on several security mailing lists have been discussing the bug since yesterday and appear still to be learning about it.… "
http://www.eweek.com/article2/0,1759,1611102,00.asp?kc=ewnws061404dtx1k0000599
"A bug in fully patched versions of Microsoft's Internet Explorer Web browser allows violations of the browser's security zones, with the result that an unknown malicious site could assume the privileges of more trusted zones.
Researchers on several security mailing lists have been discussing the bug since yesterday and appear still to be learning about it.… "
http://www.eweek.com/article2/0,1759,1611102,00.asp?kc=ewnws061404dtx1k0000599
ZDNet AnchorDesk: Is your antivirus app working? Are you sure?
Is your antivirus app working? Are you sure?:
"You have a desktop antivirus app installed now, and you know the signature file subscription is current with the vendor, but still you're seeing viruslike symptoms or perhaps you actually know that you have a virus. Since the first of this year, many new viruses have been shutting down antivirus and firewall apps, or, in other cases, disabling the software's automatic update feature, leaving your system vulnerable to future attack.
It's actually an old trick. The virus MTX, for example, released in 2000, blocks access to antivirus software Web sites. But these recent antivirus-disabling attacks are more effective because of their sheer volume: with some 30-odd variations of Bagle appearing within a 10-week period, each one better than the last, you might have been hit and not even realized it."
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5138927.html?tag=adss
"You have a desktop antivirus app installed now, and you know the signature file subscription is current with the vendor, but still you're seeing viruslike symptoms or perhaps you actually know that you have a virus. Since the first of this year, many new viruses have been shutting down antivirus and firewall apps, or, in other cases, disabling the software's automatic update feature, leaving your system vulnerable to future attack.
It's actually an old trick. The virus MTX, for example, released in 2000, blocks access to antivirus software Web sites. But these recent antivirus-disabling attacks are more effective because of their sheer volume: with some 30-odd variations of Bagle appearing within a 10-week period, each one better than the last, you might have been hit and not even realized it."
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5138927.html?tag=adss
Friday, June 11, 2004
How Much Is Spam Costing Your Company?
How Much Is Spam Costing Your Company?:
"Two research firms' recent reports say spam is costing your company mucho bucks. Security Center Editor Larry Seltzer sees whether the numbers add up."
By now, you've probably seen the stories about the outrageous cost of spam to businesses. Most of it came from research firm Nucleus Research.
eWEEK's story also cited research from MessageLabs, a respected mail security service.
The report from Nucleus, here in PDF form, made some electrifying claims, the big one being that spam is costing an average of $1,934 per employee a year of lost productivity. The cost in July 2003 was $874 per employee a year.
My goodness, that's a lot of money. "What will we do?" some might ask. But I ask, "Where did they get that number?"
Fortunately, the report answers the question. It assumes that an employee makes $30 per hour and works 2,080 hours per year, stating that employees in May got 29 spam messages per day. The increase from July 2003 comes from the average number of spam messages increasing from 13 to 29.
I don't know where they get those last two numbers on the increase in messages; maybe they're accurate, maybe not. Seems like more of a jump than I've seen, but it could be right.
They also assume 30 seconds per spam message. This is where I have a real problem. It seems like an awful lot of time to me. The average spam message that gets through my filtering takes me a second at most to delete.
I'm probably also on the phone while I do this, further complicating the productivity calculation. Let's assume it takes three seconds to dispose of a spam message, quite a long time if you ask me; that cuts the cost per employee from $1,934 to $193.40, nothing to sneeze at but a whole lot less.…
http://www.eweek.com/article2/0,1759,1609427,00.asp
"Two research firms' recent reports say spam is costing your company mucho bucks. Security Center Editor Larry Seltzer sees whether the numbers add up."
By now, you've probably seen the stories about the outrageous cost of spam to businesses. Most of it came from research firm Nucleus Research.
eWEEK's story also cited research from MessageLabs, a respected mail security service.
The report from Nucleus, here in PDF form, made some electrifying claims, the big one being that spam is costing an average of $1,934 per employee a year of lost productivity. The cost in July 2003 was $874 per employee a year.
My goodness, that's a lot of money. "What will we do?" some might ask. But I ask, "Where did they get that number?"
Fortunately, the report answers the question. It assumes that an employee makes $30 per hour and works 2,080 hours per year, stating that employees in May got 29 spam messages per day. The increase from July 2003 comes from the average number of spam messages increasing from 13 to 29.
I don't know where they get those last two numbers on the increase in messages; maybe they're accurate, maybe not. Seems like more of a jump than I've seen, but it could be right.
They also assume 30 seconds per spam message. This is where I have a real problem. It seems like an awful lot of time to me. The average spam message that gets through my filtering takes me a second at most to delete.
I'm probably also on the phone while I do this, further complicating the productivity calculation. Let's assume it takes three seconds to dispose of a spam message, quite a long time if you ask me; that cuts the cost per employee from $1,934 to $193.40, nothing to sneeze at but a whole lot less.…
http://www.eweek.com/article2/0,1759,1609427,00.asp
Thursday, June 10, 2004
Adware purveyor used security flaws to install a toolbar on Internet Explorer
Pop-up toolbar spreads via IE flaws - News - ZDNet:
"An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week.
One flaw lets an attacker run a program on a victim's machine, while the other enables malicious code to 'cross zones,' or run with privileges higher than normal. Together, the two issues allow for the creation of a Web site that, when visited by victims, can upload and install programs to the victim's computer, according to two analyses of the security holes.… "
http://zdnet.com.com/2100-1105_2-5229707.html
"An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week.
One flaw lets an attacker run a program on a victim's machine, while the other enables malicious code to 'cross zones,' or run with privileges higher than normal. Together, the two issues allow for the creation of a Web site that, when visited by victims, can upload and install programs to the victim's computer, according to two analyses of the security holes.… "
http://zdnet.com.com/2100-1105_2-5229707.html
833786 - Identify and to protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks
833786 - Steps that you can take to help identify and to help protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks:
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.
However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL.… "
http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.
However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL.… "
http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
Friday, June 04, 2004
Yahoo Anti-Spy Doesn't Default to Detect Adware
Yahoo Plays Favorites with Some Adware:
"When it comes to blocking intrusive Internet software, Yahoo Inc.'s new Anti-Spy gives adware the benefit of the doubt.
The beta version of the spyware-fighting toolbar add-on, which Yahoo released last week, doesn't default to detect adware—a category of software in which Yahoo's paid search division has a financial stake.
Instead, users who want to identify adware in their systems via Anti-Spy must check a box each time they conduct a scan.…"
http://www.eweek.com/article2/0,1759,1606054,00.asp
"When it comes to blocking intrusive Internet software, Yahoo Inc.'s new Anti-Spy gives adware the benefit of the doubt.
The beta version of the spyware-fighting toolbar add-on, which Yahoo released last week, doesn't default to detect adware—a category of software in which Yahoo's paid search division has a financial stake.
Instead, users who want to identify adware in their systems via Anti-Spy must check a box each time they conduct a scan.…"
http://www.eweek.com/article2/0,1759,1606054,00.asp
Thursday, June 03, 2004
New Windows Media DRM Announced!
Microsoft Windows Media - Digital Rights Management (DRM):
"Windows Media digital rights management (DRM) is a proven platform to protect and securely deliver content for playback on a computer, portable device, or network device. It's flexible to support a range of business models from single downloads or physical format delivery. The latest version of Windows Media DRM enables new scenarios and provides consumers even greater access to protected audio and video content."
http://www.microsoft.com/windows/windowsmedia/drm/default.aspx
"Windows Media digital rights management (DRM) is a proven platform to protect and securely deliver content for playback on a computer, portable device, or network device. It's flexible to support a range of business models from single downloads or physical format delivery. The latest version of Windows Media DRM enables new scenarios and provides consumers even greater access to protected audio and video content."
http://www.microsoft.com/windows/windowsmedia/drm/default.aspx
Wednesday, June 02, 2004
The Search Engine Report - Number 91 - May 27, 2004
A worm that uses seven mechanisms to spread itself.
Kibuv Worm, Bobax Trojan Try Many Methods:
"Security experts are tracking two new threats that have emerged in the past few days, including a worm that uses seven mechanisms to spread itself.
The worm is known as Kibuv, and researchers first noticed its presence Friday. Kibuv affects all versions of Windows from 98 through Windows Server 2003 and attempts to spread through a variety of methods, including exploiting five Windows vulnerabilities and connecting to the FTP server installed by the Sasser worms. "
Once it's installed on a PC, Kibuv starts its own FTP server that can be used to distribute copies of the worm. It also connects to a remote IRC chat server and listens for commands, according to an analysis done by Symantec Corp. Kibuv also listens on TCP port 420 for commands.
The worm has not spread too widely as of yet, but with its variety of infection methods, experts say the potential exists for it to infect a large number of machines.
The second piece of malware that has surfaced is a Trojan that is capable of spreading semi-automatically. Known as Bobax, the Trojan can only infect machines running Windows XP and seems to exist solely for the purpose of sending out large amounts of spam, according to an analysis by LURHQ Corp., a managed security services provider.
http://securityresponse.symantec.com/avcenter/venc/data/w32.kibuv.b.html
http://www.eweek.com/article2/0,1759,1594848,00.asp?kc=ewnws051904dtx1k0000599
"Security experts are tracking two new threats that have emerged in the past few days, including a worm that uses seven mechanisms to spread itself.
The worm is known as Kibuv, and researchers first noticed its presence Friday. Kibuv affects all versions of Windows from 98 through Windows Server 2003 and attempts to spread through a variety of methods, including exploiting five Windows vulnerabilities and connecting to the FTP server installed by the Sasser worms. "
Once it's installed on a PC, Kibuv starts its own FTP server that can be used to distribute copies of the worm. It also connects to a remote IRC chat server and listens for commands, according to an analysis done by Symantec Corp. Kibuv also listens on TCP port 420 for commands.
The worm has not spread too widely as of yet, but with its variety of infection methods, experts say the potential exists for it to infect a large number of machines.
The second piece of malware that has surfaced is a Trojan that is capable of spreading semi-automatically. Known as Bobax, the Trojan can only infect machines running Windows XP and seems to exist solely for the purpose of sending out large amounts of spam, according to an analysis by LURHQ Corp., a managed security services provider.
http://securityresponse.symantec.com/avcenter/venc/data/w32.kibuv.b.html
http://www.eweek.com/article2/0,1759,1594848,00.asp?kc=ewnws051904dtx1k0000599
unless they're shut down by the company that installed them, RFID tags can be read
Zombie RFID tags may never die - News - ZDNet:
"Item-level tagging is some way off yet, mainly due to cost rather than retailers' lack of enthusiasm but, when it does kick off in earnest, it's worth putting money on consumers being at loggerheads with retailers over when exactly to switch off and kill the chips.
RFID tags can be read--either by a store or by an unrelated third party--unless they're shut down by the company that installed them in the product. "
While a consumer might quite fancy the idea of walking up to the checkout and having his new $9,000 plasma-screen TV scanned instantaneously, he might not be so pleased that any passer-by with a reader can find out what he's got in the back of his car. He may also just not like the idea of a supermarket being able to scan his goods after he's left the store.
But when should the tag's tracking powers be turned off? Kill commands, as they're known, do exist. The idea is that when a shopper passes a certain point, any active RFID chip essentially shuts itself down (German supermarket Metro tried similar technology with its RFID rollout and was rather red-faced to find its kill commanders were more like a nasty-kick-in-the-shins commands).
The question remains: why would we want to keep the tags active once we've left our local Tesco and should retailers be allowed to?…
http://zdnet.com.com/2100-1103_2-5214648.html?tag=zdaresources
"Item-level tagging is some way off yet, mainly due to cost rather than retailers' lack of enthusiasm but, when it does kick off in earnest, it's worth putting money on consumers being at loggerheads with retailers over when exactly to switch off and kill the chips.
RFID tags can be read--either by a store or by an unrelated third party--unless they're shut down by the company that installed them in the product. "
While a consumer might quite fancy the idea of walking up to the checkout and having his new $9,000 plasma-screen TV scanned instantaneously, he might not be so pleased that any passer-by with a reader can find out what he's got in the back of his car. He may also just not like the idea of a supermarket being able to scan his goods after he's left the store.
But when should the tag's tracking powers be turned off? Kill commands, as they're known, do exist. The idea is that when a shopper passes a certain point, any active RFID chip essentially shuts itself down (German supermarket Metro tried similar technology with its RFID rollout and was rather red-faced to find its kill commanders were more like a nasty-kick-in-the-shins commands).
The question remains: why would we want to keep the tags active once we've left our local Tesco and should retailers be allowed to?…
http://zdnet.com.com/2100-1103_2-5214648.html?tag=zdaresources
Friday, May 28, 2004
Security Watch Letter: Dangerous Bobax Worm Hits System Files
Security Watch Letter: Dangerous Bobax Worm Hits System Files:
"Since Sasser opened the door, we've seen over a half a dozen new names, and several versions of each-- Cycle, Gaobot, Bobax, Korgo, Kibuv, and Sdbot. Gaobot and Wallon worms also attempt to exploit Windows vulnerabilities from earlier security bulletins. However, the most prolific threats are still the e-mail viruses Netsky.P, Bagel.X, and Dumaru. Sasser.B is also still at the top of the active infector lists, even though Microsoft reports that the number downloads of the MS04-011 update (which could block a Sasser infection) is four times the amount of previous ones. If you haven't updated and haven't gotten Sasser, you're lucky. Update now."
Our top threat of the week is the Bobax.D worm. The fourth in the family, Bobaxuses the same LSASS vulnerability that the Sasser family did. It hasn't had a Sasser-sized impact, but it has the potential (if Sasser doesn't infect the un-patched systems first). Bobax is a little more dangerous than Sasser, as it deletes and changes system files, and sets up an open e-mail relay to send spam from a victim's machine. It even checks the speed of the victim's connection, presumably to cherry-pick the best spam-sending systems.…
http://www.pcmag.com/article2/0,1759,1600125,00.asp
"Since Sasser opened the door, we've seen over a half a dozen new names, and several versions of each-- Cycle, Gaobot, Bobax, Korgo, Kibuv, and Sdbot. Gaobot and Wallon worms also attempt to exploit Windows vulnerabilities from earlier security bulletins. However, the most prolific threats are still the e-mail viruses Netsky.P, Bagel.X, and Dumaru. Sasser.B is also still at the top of the active infector lists, even though Microsoft reports that the number downloads of the MS04-011 update (which could block a Sasser infection) is four times the amount of previous ones. If you haven't updated and haven't gotten Sasser, you're lucky. Update now."
Our top threat of the week is the Bobax.D worm. The fourth in the family, Bobaxuses the same LSASS vulnerability that the Sasser family did. It hasn't had a Sasser-sized impact, but it has the potential (if Sasser doesn't infect the un-patched systems first). Bobax is a little more dangerous than Sasser, as it deletes and changes system files, and sets up an open e-mail relay to send spam from a victim's machine. It even checks the speed of the victim's connection, presumably to cherry-pick the best spam-sending systems.…
http://www.pcmag.com/article2/0,1759,1600125,00.asp
Borland to make software development kits available for .Net services, designed by eBay and PayPal, to Delphi developers
Borland to distribute tool kits for eBay, PayPal - News - ZDNet:
"Borland Software will provide developers access to development tools for creating Web services applications for eBay and PayPal.
Through a joint distribution agreement announced Wednesday, Borland will make software development kits designed by eBay and PayPal available to Delphi developers for creating .Net services. These applications will allow developers to access the eBay marketplace and PayPal's online payment services, the companies said.
eBay and PayPal had enhanced their Web services offerings to attract enterprise customers and Web services developers earlier this year. Thousands of developers have already created customized applications using these tools. Web services technology allows developers to more easily link computers, software and networks through standard interfaces."
http://zdnet.com.com/2100-1104_2-5220867.html
"Borland Software will provide developers access to development tools for creating Web services applications for eBay and PayPal.
Through a joint distribution agreement announced Wednesday, Borland will make software development kits designed by eBay and PayPal available to Delphi developers for creating .Net services. These applications will allow developers to access the eBay marketplace and PayPal's online payment services, the companies said.
eBay and PayPal had enhanced their Web services offerings to attract enterprise customers and Web services developers earlier this year. Thousands of developers have already created customized applications using these tools. Web services technology allows developers to more easily link computers, software and networks through standard interfaces."
http://zdnet.com.com/2100-1104_2-5220867.html
Thursday, May 27, 2004
A patch issued by Apple Computer last week failed to fix the underlying problem
Mac OS fix fails to plug security hole - News - ZDNet:
"A security hole still threatens Mac OS X users after a patch issued by Apple Computer last week failed to fix the underlying problem, security experts said on Tuesday.
The security issue could allow an attacker to transfer and then run a malicious program on a Mac, if the Mac's user can be enticed to go to a fake Web page on which the program has been placed.… "
http://zdnet.com.com/2100-1105_2-5220285.html
"A security hole still threatens Mac OS X users after a patch issued by Apple Computer last week failed to fix the underlying problem, security experts said on Tuesday.
The security issue could allow an attacker to transfer and then run a malicious program on a Mac, if the Mac's user can be enticed to go to a fake Web page on which the program has been placed.… "
http://zdnet.com.com/2100-1105_2-5220285.html
Microsoft will now guarantee a minimum of 10 years of support
Microsoft pledges longer support for products - News - ZDNet:
"Speaking at TechEd, the software giant's annual conference for information technology administrators, Andy Lees, vice president of the company's server and tools business, said Microsoft will now guarantee a minimum of 10 years of support for all business and developer products.
Microsoft currently cuts off its most basic level of support after eight years. The company has been widely criticized for dropping support for older products that are still widely used, including versions of the Windows operating system. "
Lees said the new policy would provide more reliability for corporate customers. "From the time of shipment, you can guarantee a much more predictable level of support," he said.…
http://zdnet.com.com/2100-1104_2-5220041.html
"Speaking at TechEd, the software giant's annual conference for information technology administrators, Andy Lees, vice president of the company's server and tools business, said Microsoft will now guarantee a minimum of 10 years of support for all business and developer products.
Microsoft currently cuts off its most basic level of support after eight years. The company has been widely criticized for dropping support for older products that are still widely used, including versions of the Windows operating system. "
Lees said the new policy would provide more reliability for corporate customers. "From the time of shipment, you can guarantee a much more predictable level of support," he said.…
http://zdnet.com.com/2100-1104_2-5220041.html
Wednesday, May 26, 2004
Ulead Launches Partnership with Neptune.com with VideoStudio 8 Summertime Video Editing Contest
Summertime Video Editing Contest:
"With Ulead's recent launch of VideoStudio 8, its flagship consumer video editing software, Ulead partnered with Neptune to incorporate an upload feature that lets users immediately post edited movies to a personal Neptune.com Mediashare site for instant playback. To complement the launch of VideoStudio 8, Ulead and Neptune has announced the VideoStudio 8 'Summertime Video Editing Contest' where VideoStudio 8 users and trial users are invited to upload their best movies to their Mediashare account (http://ulead.neptune.com). Ulead and Neptune will continue to collaborate in developing integrated products, hosting digital media contests, and joint marketing activities.
Winners of the VideoStudio 8 'Summertime Video Contest' can receive thousands of dollars in prizes. First place will receive a Special Edition NVIDIA Editing System; second place a Pioneer DVR-A07XL 8X speed DVD recordner with Ulead DVD Workshop 2, Ulead's EMedia Editor's Choice-winning DVD authoring software; and third place an Audio-Technica Pro Microphone Set (3 and 1) designed for camcorders. In addition to these prizes, each winner along with nine honorable mentions will receive three subscriptions to Neptune.com MediaShare with 1GB each of storage."
http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=162#1
"With Ulead's recent launch of VideoStudio 8, its flagship consumer video editing software, Ulead partnered with Neptune to incorporate an upload feature that lets users immediately post edited movies to a personal Neptune.com Mediashare site for instant playback. To complement the launch of VideoStudio 8, Ulead and Neptune has announced the VideoStudio 8 'Summertime Video Editing Contest' where VideoStudio 8 users and trial users are invited to upload their best movies to their Mediashare account (http://ulead.neptune.com). Ulead and Neptune will continue to collaborate in developing integrated products, hosting digital media contests, and joint marketing activities.
Winners of the VideoStudio 8 'Summertime Video Contest' can receive thousands of dollars in prizes. First place will receive a Special Edition NVIDIA Editing System; second place a Pioneer DVR-A07XL 8X speed DVD recordner with Ulead DVD Workshop 2, Ulead's EMedia Editor's Choice-winning DVD authoring software; and third place an Audio-Technica Pro Microphone Set (3 and 1) designed for camcorders. In addition to these prizes, each winner along with nine honorable mentions will receive three subscriptions to Neptune.com MediaShare with 1GB each of storage."
http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=162#1
Dual-Layer DVD Burner Reviewed
Sony DRU-700A Dual-Layer DVD Burner:
"DVD burners have dropped rapidly in price over the past twelve months, while performance has steadily increased. Such is the march of technology, and having the capability to burn DVDs has been a boon for amateur videographers. But one fly has remained in the ointment: dual layer DVDs. Until recently, all DVD recordable drives on the market could only burn to a single layer disc, which limits capacity to 4.7GB.
Last fall, the DVD RW Alliance finalized its spec for DVD R DL. The 'DL' stands for 'dual layer.' Currently, only DVD R DL support is available, but dual layer DVD-R drives will likely appear later in the year."
http://www.extremetech.com/article2/0,1558,1594142,00.asp
"DVD burners have dropped rapidly in price over the past twelve months, while performance has steadily increased. Such is the march of technology, and having the capability to burn DVDs has been a boon for amateur videographers. But one fly has remained in the ointment: dual layer DVDs. Until recently, all DVD recordable drives on the market could only burn to a single layer disc, which limits capacity to 4.7GB.
Last fall, the DVD RW Alliance finalized its spec for DVD R DL. The 'DL' stands for 'dual layer.' Currently, only DVD R DL support is available, but dual layer DVD-R drives will likely appear later in the year."
http://www.extremetech.com/article2/0,1558,1594142,00.asp
Tuesday, May 25, 2004
Server Side Coding with PHP & MySQL
PHP & MySQL Tutorials:
"Server Side Coding : PHP & MySQL Tutorials"
http://www.sitepoint.com/subcat/php-tutorials
"Server Side Coding : PHP & MySQL Tutorials"
http://www.sitepoint.com/subcat/php-tutorials
PHP and PEAR, Instant XML with PHP and PEAR::XML_Serializer
Instant XML with PHP and PEAR::XML_Serializer:
"These days, XML has become part of landscape in most all areas of software development -- none more so than on the Web. Those using common XML applications, such as RSS and XML-RPC, will probably find public domain libraries geared specifically to help them work with the formats, eliminating the need for wheel re-invention."
But for "ad-hoc" XML documents, you may be on your own, and you may well wind up spending valuable time building code to parse it. You may also find yourself needing to expose data as XML, in order to make it available to some other system or application, and while XML, in the end, is just text, generating a document that obeys XML's rules for well-formedness can be trickier than it seems. Enter: PEAR::XML_Serializer, the "Swiss Army Knife" for XML…
http://www.sitepoint.com/article/1336
"These days, XML has become part of landscape in most all areas of software development -- none more so than on the Web. Those using common XML applications, such as RSS and XML-RPC, will probably find public domain libraries geared specifically to help them work with the formats, eliminating the need for wheel re-invention."
But for "ad-hoc" XML documents, you may be on your own, and you may well wind up spending valuable time building code to parse it. You may also find yourself needing to expose data as XML, in order to make it available to some other system or application, and while XML, in the end, is just text, generating a document that obeys XML's rules for well-formedness can be trickier than it seems. Enter: PEAR::XML_Serializer, the "Swiss Army Knife" for XML…
http://www.sitepoint.com/article/1336
Caller ID for E-Mail: The Next Step to Deterring Spam
Caller ID for E-Mail Technical Specification:
"'Caller ID for E-Mail: The Next Step to Deterring Spam' is the Microsoft draft specification to address the widespread problem of domain spoofing. Domain spoofing refers specifically to the use of someone else's domain name when sending a message, and is part of the larger spoofing problem, the practice of forging the sender's address on e-mail messages.
Caller ID for e-mail would verify that each e-mail message originates from the Internet domain it claims to come from. Eliminating domain spoofing will help legitimate senders protect their domain names and reputations, and help recipients more effectively identify and filter junk e-mail.…"
http://www.microsoft.com/mscorp/twc/privacy/spam_callerid.mspx
"'Caller ID for E-Mail: The Next Step to Deterring Spam' is the Microsoft draft specification to address the widespread problem of domain spoofing. Domain spoofing refers specifically to the use of someone else's domain name when sending a message, and is part of the larger spoofing problem, the practice of forging the sender's address on e-mail messages.
Caller ID for e-mail would verify that each e-mail message originates from the Internet domain it claims to come from. Eliminating domain spoofing will help legitimate senders protect their domain names and reputations, and help recipients more effectively identify and filter junk e-mail.…"
http://www.microsoft.com/mscorp/twc/privacy/spam_callerid.mspx
Spam now 83 percent of messages in the United States
Spam now two thirds of all e-mail - News - ZDNet:
"There is no sign of relief for companies already overwhelmed by the sheer volume of unsolicited and unwanted e-mail messages clogging their mail systems. E-mail security firm MessageLabs' filtering statistics for April, which were published on Monday, show that 67.6 percent of all global e-mail traffic is spam.
MessageLabs said it scanned 840 million e-mail messages in April and found that 97 percent of spam is aimed at five countries: the United States, the U.K., Germany, Australia and Hong Kong. The United States has the worst problem, with 83 percent of messages being classified as spam, while in the U.K. that figure stands at 53 percent.… "
http://zdnet.com.com/2100-1105-5219078.html
"There is no sign of relief for companies already overwhelmed by the sheer volume of unsolicited and unwanted e-mail messages clogging their mail systems. E-mail security firm MessageLabs' filtering statistics for April, which were published on Monday, show that 67.6 percent of all global e-mail traffic is spam.
MessageLabs said it scanned 840 million e-mail messages in April and found that 97 percent of spam is aimed at five countries: the United States, the U.K., Germany, Australia and Hong Kong. The United States has the worst problem, with 83 percent of messages being classified as spam, while in the U.K. that figure stands at 53 percent.… "
http://zdnet.com.com/2100-1105-5219078.html
Monday, May 24, 2004
Has your PC made you a spammer?
Is your PC spewing spam?:
"Putting a price on a viral network
But wait, it gets worse. Once upon a time, the only way spam operators spread their junk mail was by opening an e-mail account, queuing up a few thousand e-mail messages, then moving on. But Internet service providers got savvy to this practice, and now they look for abnormal spikes in outbound mail traffic, then immediately block or shut down spam-sending accounts.
So the spammers had to get even savvier. With last summer's Sobig virus, it became clear that someone was building viral networks to relay spam messages.
By using open proxies on virus-compromised Windows computers, a spam operator, who may be on some ISP's block list, sends direct marketing e-mail via someone else's compromised PC. Doesn't matter if the infected PC's ISP shuts them down; there are thousands of other PCs relaying the same spam. Viruses are moving targets, so as one system is disinfected or blocked, another system becomes infected."
To illustrate that point, the Sobig virus self-terminated every two weeks or so, allowing the virus writer to sell his or her list of currently infected PCs, then, after the virus expired, author another version, infecting different PCs, and sell that list at a later date. As individual PCs on a given virus network keep changing, the effort to identify and stop spam operators gets much harder.
Yet this open proxy method isn't perfect. To work, the spam operator still contacts each and every infected PC in the virus network. This requires bandwidth, almost as much as if the operator were using a single account to send the spam.
The self-contained spam factory method
Enter the Bobax worm. Security company Lurhq describes Bobax as a self-propagating Trojan horse and a self-contained spam factory. The worm carries with it a template and a list of e-mail addresses, so it's able to create spam on the fly.
This evolution suggests that the virus writers and the spam operators are working closely. No longer is a rogue virus writer selling his or her networks of infected computers created by off-the-shelf viruses and worms to spammers. Now, the spammers are ordering up custom-designed viruses and worms. Perhaps the virus writers are employees, working solely for the spam operators.…
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5136207.html?tag=adss
"Putting a price on a viral network
But wait, it gets worse. Once upon a time, the only way spam operators spread their junk mail was by opening an e-mail account, queuing up a few thousand e-mail messages, then moving on. But Internet service providers got savvy to this practice, and now they look for abnormal spikes in outbound mail traffic, then immediately block or shut down spam-sending accounts.
So the spammers had to get even savvier. With last summer's Sobig virus, it became clear that someone was building viral networks to relay spam messages.
By using open proxies on virus-compromised Windows computers, a spam operator, who may be on some ISP's block list, sends direct marketing e-mail via someone else's compromised PC. Doesn't matter if the infected PC's ISP shuts them down; there are thousands of other PCs relaying the same spam. Viruses are moving targets, so as one system is disinfected or blocked, another system becomes infected."
To illustrate that point, the Sobig virus self-terminated every two weeks or so, allowing the virus writer to sell his or her list of currently infected PCs, then, after the virus expired, author another version, infecting different PCs, and sell that list at a later date. As individual PCs on a given virus network keep changing, the effort to identify and stop spam operators gets much harder.
Yet this open proxy method isn't perfect. To work, the spam operator still contacts each and every infected PC in the virus network. This requires bandwidth, almost as much as if the operator were using a single account to send the spam.
The self-contained spam factory method
Enter the Bobax worm. Security company Lurhq describes Bobax as a self-propagating Trojan horse and a self-contained spam factory. The worm carries with it a template and a list of e-mail addresses, so it's able to create spam on the fly.
This evolution suggests that the virus writers and the spam operators are working closely. No longer is a rogue virus writer selling his or her networks of infected computers created by off-the-shelf viruses and worms to spammers. Now, the spammers are ordering up custom-designed viruses and worms. Perhaps the virus writers are employees, working solely for the spam operators.…
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5136207.html?tag=adss
Sunday, May 23, 2004
Paper Trails for Electronic Votes
Demand Grows to Require Paper Trails for Electronic Votes:
"A coalition of computer scientists, voter groups and state officials, led by California's secretary of state, Kevin Shelley, is trying to force the makers of electronic voting machines to equip those machines with voter-verifiable paper trails.
Following the problems of the 2000 election in Florida, a number of states and hundreds of counties rushed to dump their punch card ballot systems and to buy the electronic touch screens. Election Data Services, a consulting firm that specializes in election administration, estimates that this November 50 million Americans - about 29 percent of the electorate - may be voting on touch screens, up from 12 percent in 2000.
But in the last year election analysts have documented so many malfunctions, including the disappearance of names from the ballot, and computer experts have shown that the machines are so vulnerable to hackers, that critics have organized to counter the rush toward touch screens with a move to require paper trails."
Paper trails - ballot receipts - would let voters verify that they had cast their votes as they intended and let election officials conduct recounts in close races.
Not everyone agrees that paper trails are necessary, or even advisable. Numerous local election officials - the ones who actually conduct elections - argue that paper trails could create worse problems than the perceived ones that they are intended to cure. They warn of paper jams, voter confusion and delays in the voting booth while voters read their receipts.
There are no national standards to help resolve the disputes. The federal commission that Congress created after 2000 to guide states is behind schedule, and the research body that was supposed to set standards for November 2004 has not even been appointed. So states, prompted by voter organizations, are taking matters into their own hands.
Nevada, which is using touch screens in all its voting precincts this November, has become the first state to require the manufacturer to attach printers in time for Election Day.…
http://www.nytimes.com/2004/05/23/politics/campaign/23vote.html?pagewanted=all&position=
"A coalition of computer scientists, voter groups and state officials, led by California's secretary of state, Kevin Shelley, is trying to force the makers of electronic voting machines to equip those machines with voter-verifiable paper trails.
Following the problems of the 2000 election in Florida, a number of states and hundreds of counties rushed to dump their punch card ballot systems and to buy the electronic touch screens. Election Data Services, a consulting firm that specializes in election administration, estimates that this November 50 million Americans - about 29 percent of the electorate - may be voting on touch screens, up from 12 percent in 2000.
But in the last year election analysts have documented so many malfunctions, including the disappearance of names from the ballot, and computer experts have shown that the machines are so vulnerable to hackers, that critics have organized to counter the rush toward touch screens with a move to require paper trails."
Paper trails - ballot receipts - would let voters verify that they had cast their votes as they intended and let election officials conduct recounts in close races.
Not everyone agrees that paper trails are necessary, or even advisable. Numerous local election officials - the ones who actually conduct elections - argue that paper trails could create worse problems than the perceived ones that they are intended to cure. They warn of paper jams, voter confusion and delays in the voting booth while voters read their receipts.
There are no national standards to help resolve the disputes. The federal commission that Congress created after 2000 to guide states is behind schedule, and the research body that was supposed to set standards for November 2004 has not even been appointed. So states, prompted by voter organizations, are taking matters into their own hands.
Nevada, which is using touch screens in all its voting precincts this November, has become the first state to require the manufacturer to attach printers in time for Election Day.…
http://www.nytimes.com/2004/05/23/politics/campaign/23vote.html?pagewanted=all&position=
Saturday, May 22, 2004
200 Articles and Columns on PC Troubleshooting
PC Troubleshooting:
"200 Articles & Columns for 'pc troubleshooting' "
Free registration required. Top quality information.
http://techrepublic.com.com/5048-22-0.html?SearchThis=pc troubleshooting&nodeIds=all&tag=e099.0521&queryType=2&tag=search
"200 Articles & Columns for 'pc troubleshooting' "
Free registration required. Top quality information.
http://techrepublic.com.com/5048-22-0.html?SearchThis=pc troubleshooting&nodeIds=all&tag=e099.0521&queryType=2&tag=search
Friday, May 21, 2004
Skype Creator Promises Official VOIP Program Release:
"The peer-to-peer phone program Skype, which allows computer users to talk to each other globally for free, will soon be expanded to include a paid service that will connect Skype calls to regular phones, the program's co-creator said Wednesday.
Skype Technologies SA founder Niklas Zennstrom, who also co-developed the Internet file-sharing program Kazaa, made the announcement at an Internet-phone conference Wednesday in Markham, north of Toronto.
He said final bugs were being worked out of the Skype software's 'beta' or trial version, which already has at least 5.5 million users worldwide. An official release is scheduled for the summer.…"
http://www.eweek.com/article2/0,1759,1595770,00.asp
"The peer-to-peer phone program Skype, which allows computer users to talk to each other globally for free, will soon be expanded to include a paid service that will connect Skype calls to regular phones, the program's co-creator said Wednesday.
Skype Technologies SA founder Niklas Zennstrom, who also co-developed the Internet file-sharing program Kazaa, made the announcement at an Internet-phone conference Wednesday in Markham, north of Toronto.
He said final bugs were being worked out of the Skype software's 'beta' or trial version, which already has at least 5.5 million users worldwide. An official release is scheduled for the summer.…"
http://www.eweek.com/article2/0,1759,1595770,00.asp
Thursday, May 20, 2004
Phishing Attacks on the Rise:
"…'The red flag should be any request for personal information, especially from someone who says they need it right now or there will be dire consequences,' said Patricia Poss, an attorney with the Federal Trade Commission's bureau of consumer protection.
Consumers who think they've received a phishing e-mail should not click on any Web links contained in the e-mail and, instead, forward it to the FTC's collection site at uce@ftc.gov.
If they've responded to such e-mails, they should contact their banks or credit card companies immediately to try to prevent account information from being misused, Poss said.
'Then, if you're worried about identity theft, get a copy of your credit report and make sure nothing is going on,' she added.… "
http://www.eweek.com/article2/0,1759,1595710,00.asp?kc=ewnws052004dtx1k0000599
"…'The red flag should be any request for personal information, especially from someone who says they need it right now or there will be dire consequences,' said Patricia Poss, an attorney with the Federal Trade Commission's bureau of consumer protection.
Consumers who think they've received a phishing e-mail should not click on any Web links contained in the e-mail and, instead, forward it to the FTC's collection site at uce@ftc.gov.
If they've responded to such e-mails, they should contact their banks or credit card companies immediately to try to prevent account information from being misused, Poss said.
'Then, if you're worried about identity theft, get a copy of your credit report and make sure nothing is going on,' she added.… "
http://www.eweek.com/article2/0,1759,1595710,00.asp?kc=ewnws052004dtx1k0000599
Wednesday, May 19, 2004
Essential Utilities from PC Magazine
2004 Utility Guide: "You won't find firewall, antispam, antispyware, or traditional antivirus tools in here—they're essential utilities, but we've covered them recently; see our current favorites in the Editors' Choices section. But with new viruses coming at us faster than AV companies can write signatures to stop them, we take a hard look at alternative detection methods that attempt to root out new threats based on their behavior, not just their signatures.
Some utilities are less fun than important—yes, you do have to back up your data regularly, and your Registry probably could use a good cleaning. The following pages present a mix of tools that taste good and are good for you.…"
http://www.pcmag.com/article2/0,1759,1594001,00.asp
Some utilities are less fun than important—yes, you do have to back up your data regularly, and your Registry probably could use a good cleaning. The following pages present a mix of tools that taste good and are good for you.…"
http://www.pcmag.com/article2/0,1759,1594001,00.asp
Cisco Source Code Reportedly Stolen:
"According to a Russian security Web site, criminal hackers broke into Cisco Systems' corporate network last week and stole 800MB of source code for IOS 12.3 and 12.3t (an early deployment version of the operating system containing features not found in the vanilla 12.3 version). In addition, a 2.5MB sample of what is supposedly IOS code was released on an Internet Relay Chat channel as proof of the alleged theft.
'Cisco is aware that a potential compromise of its proprietary information occurred and was reported on a public website just prior to the weekend,' said Cisco spokesman Robert Barlow. 'Cisco is fully investigating what happened. As a matter of policy, we take security very seriously and we continue to take every measure to protect our intellectual property, employee and customer information.' "
IOS 12.3 is the newest main version of San Jose, Calif.-based Cisco's popular operating system. It's used across the company's networking line, including in home office routers (the 800 Series); those for branch offices (the 3700 Series); and those that comprise the Internet backbone (the 7000 Series). Other routers that use the operating system include the 1700, 2500, 2600 and 3600 Series.
This could represent a major security threat not just for Cisco users, but for the entire Internet. According to the Dell'Oro Group, a market research firm that specializes in the networking and telecommunications industries, Cisco owns 62 percent of the core router market.…
http://www.eweek.com/article2/0,1759,1594322,00.asp
"According to a Russian security Web site, criminal hackers broke into Cisco Systems' corporate network last week and stole 800MB of source code for IOS 12.3 and 12.3t (an early deployment version of the operating system containing features not found in the vanilla 12.3 version). In addition, a 2.5MB sample of what is supposedly IOS code was released on an Internet Relay Chat channel as proof of the alleged theft.
'Cisco is aware that a potential compromise of its proprietary information occurred and was reported on a public website just prior to the weekend,' said Cisco spokesman Robert Barlow. 'Cisco is fully investigating what happened. As a matter of policy, we take security very seriously and we continue to take every measure to protect our intellectual property, employee and customer information.' "
IOS 12.3 is the newest main version of San Jose, Calif.-based Cisco's popular operating system. It's used across the company's networking line, including in home office routers (the 800 Series); those for branch offices (the 3700 Series); and those that comprise the Internet backbone (the 7000 Series). Other routers that use the operating system include the 1700, 2500, 2600 and 3600 Series.
This could represent a major security threat not just for Cisco users, but for the entire Internet. According to the Dell'Oro Group, a market research firm that specializes in the networking and telecommunications industries, Cisco owns 62 percent of the core router market.…
http://www.eweek.com/article2/0,1759,1594322,00.asp
Tuesday, May 18, 2004
Crypto-Gram: May 15, 2004:
"In this issue:
Warrants as a Security Countermeasure
Counterterrorism in Airports
Crypto-Gram Reprints
News
Counterpane News
Security Notes from All Over: Bypassing the USPS
The Doghouse: Markland Technologies
The Doghouse: IQ Networks
National Security Consumers "
http://www.schneier.com/crypto-gram-0405.html
"In this issue:
Warrants as a Security Countermeasure
Counterterrorism in Airports
Crypto-Gram Reprints
News
Counterpane News
Security Notes from All Over: Bypassing the USPS
The Doghouse: Markland Technologies
The Doghouse: IQ Networks
National Security Consumers "
http://www.schneier.com/crypto-gram-0405.html
Saturday, May 15, 2004
How to Create A JavaScript Windows Interface - WebReference.com-:
"When windows first appeared on computer screens around the world it revolutionized the way programs interfaced with the user. Multiple programs could be run at the same time without much confusion. Even within a single program, multiple windows could be used to separate unrelated bits of information or data entry forms and much more."
http://www.webreference.com/programming/javascript/gr/column6/index.html
"When windows first appeared on computer screens around the world it revolutionized the way programs interfaced with the user. Multiple programs could be run at the same time without much confusion. Even within a single program, multiple windows could be used to separate unrelated bits of information or data entry forms and much more."
http://www.webreference.com/programming/javascript/gr/column6/index.html
ZDNet: Printer Friendly - Search engines take the stand:
"Fifteen years after his trial, a convicted drug dealer in New York state belatedly got a chance to clear his name--thanks in part to an Internet search.
A federal judge last November threw out Manuel Rodriguez's conviction and granted him a new trial after discovering evidence of potential jury tampering in a review of court records and queries on Web search engine Google. U.S. Magistrate Judge Frank Maas said that his review of the 1988 court transcript, coupled with looking up jurors' names in Google, had revealed that the assistant district attorney had 'improperly' removed Hispanics.… "
Some judges call Web search a crucial research tool, but critics of the trend are warning that searches on Google and its rivals are no substitute for the painstaking process of evidence and testimony.
"A Google search that I conducted" suggested that a removed juror had "a Hispanic name," Maas wrote in the court decision overturning the conviction.
Rodriguez finished his sentence before his new trial could take place. But his case nevertheless offers a striking illustration of the growing clout of Internet search engines among the judiciary--a controversial trend that's so far garnered little attention outside legal circles.
In the United States and abroad, judges are turning to search engines such as Google to check facts, to look up information about companies embroiled in litigation, and to challenge statistics presented by attorneys in court. Dozens of judges have penned opinions describing Google as a valuable--and sometimes crucial--source of knowledge.
To be sure, Google has no monopoly in the legal system. Yahoo's search engine popped up in the landmark Napster copyright case four years ago, and Oregon police tried to track a criminal defendant accused of firearm violations through Yahoo searches. When AltaVista was in its heyday, it also was mentioned in a handful of cases.
But in the last few years, Google appears to have become the courts' favorite search engine. The Mountain View, Calif.-based company--which announced its plans for an initial public offering last month--accounts for 41 percent of U.S. search referrals, according to statistics compiled by research company WebSideStory.
In one case in Ohio, a judge who ordered a mother not to smoke near her 8-year-old daughter cited medical journals and a Google search that lists 60,000-plus links for "secondhand smoke" and 30,000-plus links for "secondhand smoke children." In addition, the California Supreme Court has Googled for evidence showing that stun belts, which jolt prisoners with 50,000-volt electric shocks, can be harmful and should not have been used in a criminal trial. And an enterprising federal judge in New York did his own Google search to demonstrate that a watch, jeans and handbag retailer named Alfredo Versace was infringing the trademarks of the famous Gianni Versace design house.
Some legal experts warn that Google searches are no substitute for the painstaking process of evidence and testimony. "If a judge is taking as proof facts that are reported in any public medium that pertain to individual actions by persons involved in a case, that is troubling," said George Fisher, a Stanford University law professor. "Those are the sorts of facts that are supposed to be proved in the courtroom under the rules of evidence.…"
http://zdnet.com.com/2102-1104_2-5211658.html?tag=printthis
"Fifteen years after his trial, a convicted drug dealer in New York state belatedly got a chance to clear his name--thanks in part to an Internet search.
A federal judge last November threw out Manuel Rodriguez's conviction and granted him a new trial after discovering evidence of potential jury tampering in a review of court records and queries on Web search engine Google. U.S. Magistrate Judge Frank Maas said that his review of the 1988 court transcript, coupled with looking up jurors' names in Google, had revealed that the assistant district attorney had 'improperly' removed Hispanics.… "
Some judges call Web search a crucial research tool, but critics of the trend are warning that searches on Google and its rivals are no substitute for the painstaking process of evidence and testimony.
"A Google search that I conducted" suggested that a removed juror had "a Hispanic name," Maas wrote in the court decision overturning the conviction.
Rodriguez finished his sentence before his new trial could take place. But his case nevertheless offers a striking illustration of the growing clout of Internet search engines among the judiciary--a controversial trend that's so far garnered little attention outside legal circles.
In the United States and abroad, judges are turning to search engines such as Google to check facts, to look up information about companies embroiled in litigation, and to challenge statistics presented by attorneys in court. Dozens of judges have penned opinions describing Google as a valuable--and sometimes crucial--source of knowledge.
To be sure, Google has no monopoly in the legal system. Yahoo's search engine popped up in the landmark Napster copyright case four years ago, and Oregon police tried to track a criminal defendant accused of firearm violations through Yahoo searches. When AltaVista was in its heyday, it also was mentioned in a handful of cases.
But in the last few years, Google appears to have become the courts' favorite search engine. The Mountain View, Calif.-based company--which announced its plans for an initial public offering last month--accounts for 41 percent of U.S. search referrals, according to statistics compiled by research company WebSideStory.
In one case in Ohio, a judge who ordered a mother not to smoke near her 8-year-old daughter cited medical journals and a Google search that lists 60,000-plus links for "secondhand smoke" and 30,000-plus links for "secondhand smoke children." In addition, the California Supreme Court has Googled for evidence showing that stun belts, which jolt prisoners with 50,000-volt electric shocks, can be harmful and should not have been used in a criminal trial. And an enterprising federal judge in New York did his own Google search to demonstrate that a watch, jeans and handbag retailer named Alfredo Versace was infringing the trademarks of the famous Gianni Versace design house.
Some legal experts warn that Google searches are no substitute for the painstaking process of evidence and testimony. "If a judge is taking as proof facts that are reported in any public medium that pertain to individual actions by persons involved in a case, that is troubling," said George Fisher, a Stanford University law professor. "Those are the sorts of facts that are supposed to be proved in the courtroom under the rules of evidence.…"
http://zdnet.com.com/2102-1104_2-5211658.html?tag=printthis
DVD Rot, or Not?:
"The recent Associated Press story about insidious, disc-devouring 'rot' wasn't the first to hit the mainstream press. Major news outlets Worldwide have for years been publishing sensational reports that up to 20 percent of all mass-produced CDs and DVD-Video discs were slowly destroying themselves. But when an alarmed DVD industry investigated whether the problem was indeed as catastrophic as it appeared, it turned out that most reported incidents had actually been caused by improper disc handling and storage. Despite the latest round of headlines, true 'DVD Rot' today appears to be exceedingly rare. Users themselves are the greatest threat to the longevity of their DVD collections.
Most people think of DVDs as little more than high-capacity CDs, but though the two are very similar, DVDs have vulnerabilities that require particular care in their handling, storage, and cleaning. But with a bit of knowledge and effort, nearly all damage to DVDs can be prevented.…"
http://www.pcmag.com/print_article/0,1761,a=126783,00.asp
"The recent Associated Press story about insidious, disc-devouring 'rot' wasn't the first to hit the mainstream press. Major news outlets Worldwide have for years been publishing sensational reports that up to 20 percent of all mass-produced CDs and DVD-Video discs were slowly destroying themselves. But when an alarmed DVD industry investigated whether the problem was indeed as catastrophic as it appeared, it turned out that most reported incidents had actually been caused by improper disc handling and storage. Despite the latest round of headlines, true 'DVD Rot' today appears to be exceedingly rare. Users themselves are the greatest threat to the longevity of their DVD collections.
Most people think of DVDs as little more than high-capacity CDs, but though the two are very similar, DVDs have vulnerabilities that require particular care in their handling, storage, and cleaning. But with a bit of knowledge and effort, nearly all damage to DVDs can be prevented.…"
http://www.pcmag.com/print_article/0,1761,a=126783,00.asp
Wallon Worm Skirts Around Windows Patch Release:
"Wallon's infection process is complicated. Unlike the ordinary e-mail worm that arrives in an attachment to a message, Wallon appears as a link in a message to a Yahoo page. But with redirection, the Yahoo connection leads to another page that delivers an encrypted link to yet another page that delivers a special downloader application.
Microsoft provided a security patch for this vulnerability in April and suggested its application for all currently supported Windows versions. The company describes the update as 'critical' and recommends it for all Windows variants, starting with Windows 98, even for systems where Outlook Express is not the default e-mail reader.… "
http://www.eweek.com/article2/0,1759,1591569,00.asp
"Wallon's infection process is complicated. Unlike the ordinary e-mail worm that arrives in an attachment to a message, Wallon appears as a link in a message to a Yahoo page. But with redirection, the Yahoo connection leads to another page that delivers an encrypted link to yet another page that delivers a special downloader application.
Microsoft provided a security patch for this vulnerability in April and suggested its application for all currently supported Windows versions. The company describes the update as 'critical' and recommends it for all Windows variants, starting with Windows 98, even for systems where Outlook Express is not the default e-mail reader.… "
http://www.eweek.com/article2/0,1759,1591569,00.asp
Friday, May 14, 2004
Mac Trojan Set Loose—More to Come?:
"The first malicious Trojan for Mac OS X has been found in the wild, leading some to claim the platform may be on the verge of increased attention from virus writers."
The Trojan—dubbed AS.MW2004.Trojan by anti-virus company Intego—was first discovered by a reader of British Mac magazine MacWorld. It takes the form of a file purporting to be a version of the newly released Office 2004 for Mac and is available on download services such as LimeWire.
However, despite appearing with a legitimate-looking icon, the Trojan is in fact a simple AppleScript application that, when run, erases the contents of the user's Home folder. And, unlike the real release of Office 2004, the application is only 108KB in size.…
http://www.eweek.com/article2/0,1759,1591850,00.asp?kc=ewnws051304dtx1k0000599
"The first malicious Trojan for Mac OS X has been found in the wild, leading some to claim the platform may be on the verge of increased attention from virus writers."
The Trojan—dubbed AS.MW2004.Trojan by anti-virus company Intego—was first discovered by a reader of British Mac magazine MacWorld. It takes the form of a file purporting to be a version of the newly released Office 2004 for Mac and is available on download services such as LimeWire.
However, despite appearing with a legitimate-looking icon, the Trojan is in fact a simple AppleScript application that, when run, erases the contents of the user's Home folder. And, unlike the real release of Office 2004, the application is only 108KB in size.…
http://www.eweek.com/article2/0,1759,1591850,00.asp?kc=ewnws051304dtx1k0000599
New Sasser variant indicates copycat - News - ZDNet:
"A teenager suspected of writing the Sasser code has been arrested by police in Germany. Since his arrest, two variants of the worm have been detected in the wild. The suspected author had confessed to German police that he had released the fifth version of the worm, Sasser.E, four days before he was taken into custody. Antivirus firms didn't detect the variant until the day after the arrest. The most recent, Sasser.F, was first detected Tuesday.
Luis Corrons, head of antivirus company Panda's research labs, said the Sasser.F worm's source code looks like it was written by an inexperienced programmer who has slightly modified the original code but had not added any new functions or behaviors.
'Studying the evolution of Sasser, the fact that variant F does not include any new features confirms that it is the work of a different person,' Corrons said. "
http://zdnet.com.com/2100-1105_2-5211114.html?tag=header.newsfeed
"A teenager suspected of writing the Sasser code has been arrested by police in Germany. Since his arrest, two variants of the worm have been detected in the wild. The suspected author had confessed to German police that he had released the fifth version of the worm, Sasser.E, four days before he was taken into custody. Antivirus firms didn't detect the variant until the day after the arrest. The most recent, Sasser.F, was first detected Tuesday.
Luis Corrons, head of antivirus company Panda's research labs, said the Sasser.F worm's source code looks like it was written by an inexperienced programmer who has slightly modified the original code but had not added any new functions or behaviors.
'Studying the evolution of Sasser, the fact that variant F does not include any new features confirms that it is the work of a different person,' Corrons said. "
http://zdnet.com.com/2100-1105_2-5211114.html?tag=header.newsfeed
Microsoft Issues Single New Security Alert for May:
"Microsoft's security alerts for May were posted this afternoon. And the list was refreshingly short. The single new vulnerability revealed does allow for remote code execution by an attacker, but with many limitations on the attack, leading Microsoft to classify the problem as 'important.'
The problem is in the Windows Help and Support Center in Windows XP and Windows Server 2003. Windows 2000 and other earlier versions are not affected. The Help and Support Center is based on Internet Explorer components and uses a special protocol called HCP, also used by the Control Panel."
Such pages use an "hcp://" prefix, while normal Web pages use an "http://" prefix. The vulnerability is in the process that the Help and Support Center uses to validate the data from an HCP Web site.
The attacker would have to construct a malicious Web page and entice the user to visit it and click on a specific link. According to Microsoft's advisory on the issue, "After they click the link, they would be prompted to perform several actions. An attack could only occur after they performed these actions."
Certain very old versions of Outlook, lacking certain past security patches, also might allow the attack to be sent through an HTML e-mail. All versions of Outlook and Outlook Express for the past several years run HTML e-mails in the "restricted zone," which would make it much harder to exploit this vulnerability.
Microsoft released a patch for the vulnerability, which can be downloaded from the same page that contains the advisory describing the vulnerability. There are also workarounds available, including unregistering the HCP protocol. These are described in the advisory.
http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx
http://www.eweek.com/article2/0,1759,1590651,00.asp?kc=ewnws051104dtx1k0000599
"Microsoft's security alerts for May were posted this afternoon. And the list was refreshingly short. The single new vulnerability revealed does allow for remote code execution by an attacker, but with many limitations on the attack, leading Microsoft to classify the problem as 'important.'
The problem is in the Windows Help and Support Center in Windows XP and Windows Server 2003. Windows 2000 and other earlier versions are not affected. The Help and Support Center is based on Internet Explorer components and uses a special protocol called HCP, also used by the Control Panel."
Such pages use an "hcp://" prefix, while normal Web pages use an "http://" prefix. The vulnerability is in the process that the Help and Support Center uses to validate the data from an HCP Web site.
The attacker would have to construct a malicious Web page and entice the user to visit it and click on a specific link. According to Microsoft's advisory on the issue, "After they click the link, they would be prompted to perform several actions. An attack could only occur after they performed these actions."
Certain very old versions of Outlook, lacking certain past security patches, also might allow the attack to be sent through an HTML e-mail. All versions of Outlook and Outlook Express for the past several years run HTML e-mails in the "restricted zone," which would make it much harder to exploit this vulnerability.
Microsoft released a patch for the vulnerability, which can be downloaded from the same page that contains the advisory describing the vulnerability. There are also workarounds available, including unregistering the HCP protocol. These are described in the advisory.
http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx
http://www.eweek.com/article2/0,1759,1590651,00.asp?kc=ewnws051104dtx1k0000599
Thursday, May 13, 2004
Microsoft Security Bulletin MS04-015: Vulnerability in Help and Support Center Could Allow Remote Code Execution (840374):
"This update resolves a newly-discovered vulnerability. A remote code execution vulnerability exists in the Help and Support Center because of the way that it handles HCP URL validation. The vulnerability is documented in the Vulnerability Details section of this bulletin.
If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.
Microsoft recommends that customers install the update at the earliest opportunity."
http://www.microsoft.com/technet/security/bulletin/ms04-015.mspx
"This update resolves a newly-discovered vulnerability. A remote code execution vulnerability exists in the Help and Support Center because of the way that it handles HCP URL validation. The vulnerability is documented in the Vulnerability Details section of this bulletin.
If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.
Microsoft recommends that customers install the update at the earliest opportunity."
http://www.microsoft.com/technet/security/bulletin/ms04-015.mspx
Wednesday, May 12, 2004
Motherboards.org - The Elusive Zen of Motherboard Identification:
"It certainly may appear to the inexperienced that there is some 'black magic' involved in the art of motherboard identification but really it only involves patience, determination and a little common sense in most cases. There is no doubt that those of us that have some experience do have an advantage in the ability to recognise some common model numbers or bios strings and in knowing the location of certain resources but all this really does is make the search quicker.
80% of the requests for motherboard identification in this forum can be answered in a few seconds by doing a search using the information supplied by the poster and a good search engine such as www.google.com
This can be done by anyone, 'guru' or not."
http://www.motherboards.org/articlesd/how-to-guides/910_1.html
"It certainly may appear to the inexperienced that there is some 'black magic' involved in the art of motherboard identification but really it only involves patience, determination and a little common sense in most cases. There is no doubt that those of us that have some experience do have an advantage in the ability to recognise some common model numbers or bios strings and in knowing the location of certain resources but all this really does is make the search quicker.
80% of the requests for motherboard identification in this forum can be answered in a few seconds by doing a search using the information supplied by the poster and a good search engine such as www.google.com
This can be done by anyone, 'guru' or not."
http://www.motherboards.org/articlesd/how-to-guides/910_1.html
Saturday, May 08, 2004
Why your personal firewall could be obsolete - TechUpdate - ZDNet:
"If your business has turned the use of personal firewalls into a required countermeasure, now's a good time to start thinking more strategically before buying any more personal firewall technology from a third party.
Although it still has a serious flaw that Microsoft will have no choice but to fix, the morphing of Windows XP's built-in personal firewall from a toy into a more serious security technology means that now's also a good time for the remaining independent personal firewall vendors like Zone Labs to be thinking about long term survival strategies. For the cottage industry of personal firewalls that includes giants like Symantec and McAfee (a division of Network Associates) and smaller players like Zone Labs, Sygate, Internet Security Systems (makers of BlackICE), and Panda Software, this was an inevitable turn of events.… "
http://64.95.71.98/techupdate/stories/main/Preview4987.html
"If your business has turned the use of personal firewalls into a required countermeasure, now's a good time to start thinking more strategically before buying any more personal firewall technology from a third party.
Although it still has a serious flaw that Microsoft will have no choice but to fix, the morphing of Windows XP's built-in personal firewall from a toy into a more serious security technology means that now's also a good time for the remaining independent personal firewall vendors like Zone Labs to be thinking about long term survival strategies. For the cottage industry of personal firewalls that includes giants like Symantec and McAfee (a division of Network Associates) and smaller players like Zone Labs, Sygate, Internet Security Systems (makers of BlackICE), and Panda Software, this was an inevitable turn of events.… "
http://64.95.71.98/techupdate/stories/main/Preview4987.html
Friday, May 07, 2004
Patches Could Have Lessened Sasser Worm Spread:
"Sasser's spread began to stabilize Tuesday, but not after infecting hundreds of thousands of computers since Friday by exploiting a known Windows flaw for which Microsoft Corp. issued a software patch three weeks ago. "
Twenty British Airways flights were each delayed about 10 minutes Tuesday due to Sasser troubles at check-in desks, while British coastguard stations used pen and paper for charts normally generated by computer.
On Monday, the worm hit public hospitals in Hong Kong and one-third of Taiwan's post office branches. Major corporations around the world also were infected.
Home users were particularly hit hard, computer security experts say, because they generally lack the know-how to install patches and tend not to have the firewalls needed to keep Sasser from spreading to other computers via the Internet.
Late this summer, Microsoft plans to introduce a Windows XP update that would turn on a built-in firewall and automatically obtain and install security patches regularly. Microsoft is currently testing the update.
For now, computer users must manually turn such settings on—through "System" or "Automatic Updates" in Windows' Control Panel—or they must periodically check the company's Web site for new patches.…
http://www.eweek.com/article2/0,1759,1585008,00.asp?kc=ewnws050504dtx1k0000599
"Sasser's spread began to stabilize Tuesday, but not after infecting hundreds of thousands of computers since Friday by exploiting a known Windows flaw for which Microsoft Corp. issued a software patch three weeks ago. "
Twenty British Airways flights were each delayed about 10 minutes Tuesday due to Sasser troubles at check-in desks, while British coastguard stations used pen and paper for charts normally generated by computer.
On Monday, the worm hit public hospitals in Hong Kong and one-third of Taiwan's post office branches. Major corporations around the world also were infected.
Home users were particularly hit hard, computer security experts say, because they generally lack the know-how to install patches and tend not to have the firewalls needed to keep Sasser from spreading to other computers via the Internet.
Late this summer, Microsoft plans to introduce a Windows XP update that would turn on a built-in firewall and automatically obtain and install security patches regularly. Microsoft is currently testing the update.
For now, computer users must manually turn such settings on—through "System" or "Automatic Updates" in Windows' Control Panel—or they must periodically check the company's Web site for new patches.…
http://www.eweek.com/article2/0,1759,1585008,00.asp?kc=ewnws050504dtx1k0000599
Thursday, May 06, 2004
Sasser.D Worm Arrives, Ready to Do Damage:
"A fourth version of Sasser has the potential to cause serious slowdowns and outages; a hoax e-mail claiming to contain a fix for the worm in fact contains a version of the NetSky worm.…"
Sasser.D appeared Monday afternoon and is similar to the previous three versions in most respects. The main difference in the new variant is that it uses ICMP echo requests, also known as pings, to look for other machines to infect. The Nachi worm of last summer had the same capability and, on networks with a number of vulnerable machines, the worm caused severe congestion.
The new Sasser variant could cause the same problems, experts warn. And, Sasser.D can scan multicast addresses, which has led to it causing some destabilization of routers that handle multicast traffic, analysts at The SANS Institute in Bethseda, Md., said.
Sasser.D also uses a different name for the file it leaves on infected PCs: Skynetave.exe. And it creates a remote shell on TCP port 9995, instead of 9996, which is used by the other three variants.
In addition to the new variant, there also is a hoax e-mail circulating that claims to contain a fix for Sasser. The message actually contains a new version of the NetSky worm.…
http://www.eweek.com/article2/0,1759,1584121,00.asp?kc=ewnws050404dtx1k0000599
"A fourth version of Sasser has the potential to cause serious slowdowns and outages; a hoax e-mail claiming to contain a fix for the worm in fact contains a version of the NetSky worm.…"
Sasser.D appeared Monday afternoon and is similar to the previous three versions in most respects. The main difference in the new variant is that it uses ICMP echo requests, also known as pings, to look for other machines to infect. The Nachi worm of last summer had the same capability and, on networks with a number of vulnerable machines, the worm caused severe congestion.
The new Sasser variant could cause the same problems, experts warn. And, Sasser.D can scan multicast addresses, which has led to it causing some destabilization of routers that handle multicast traffic, analysts at The SANS Institute in Bethseda, Md., said.
Sasser.D also uses a different name for the file it leaves on infected PCs: Skynetave.exe. And it creates a remote shell on TCP port 9995, instead of 9996, which is used by the other three variants.
In addition to the new variant, there also is a hoax e-mail circulating that claims to contain a fix for Sasser. The message actually contains a new version of the NetSky worm.…
http://www.eweek.com/article2/0,1759,1584121,00.asp?kc=ewnws050404dtx1k0000599
Tuesday, May 04, 2004
Symantec Security Response - W32.Sasser.B.Worm:
"W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011. This worm spreads by scanning randomly selected IP addresses of vulnerable systems.… "
Notes:
The MD5 hash value of this worm is 0x1A2C0E6130850F8FD9B9B5309413CD00.
Symantec Security Response has developed a removal tool to clean the infections of W32.Sasser.B.Worm.
Block TCP ports 5554, 9996, and 445 at the perimeter firewall and install the appropriate Microsoft patch (MS04-011) to prevent the remote exploitation of the vulnerability.
--------------------------------------------------------------------------------
W32.Sasser.B.Worm can run on, but not infect, Windows 95/98/Me computers. Although these operating systems cannot be infected, they can still be used to infect the vulnerable systems to which they are able to connect. In this case, the worm will waste a lot of resources so that programs cannot properly run, including our removal tool. (On Windows 95/98/Me computers, the tool should be run in Safe mode.)
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html
"W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011. This worm spreads by scanning randomly selected IP addresses of vulnerable systems.… "
Notes:
The MD5 hash value of this worm is 0x1A2C0E6130850F8FD9B9B5309413CD00.
Symantec Security Response has developed a removal tool to clean the infections of W32.Sasser.B.Worm.
Block TCP ports 5554, 9996, and 445 at the perimeter firewall and install the appropriate Microsoft patch (MS04-011) to prevent the remote exploitation of the vulnerability.
--------------------------------------------------------------------------------
W32.Sasser.B.Worm can run on, but not infect, Windows 95/98/Me computers. Although these operating systems cannot be infected, they can still be used to infect the vulnerable systems to which they are able to connect. In this case, the worm will waste a lot of resources so that programs cannot properly run, including our removal tool. (On Windows 95/98/Me computers, the tool should be run in Safe mode.)
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html
Keyboard Shortcuts with Windows XP Home Edition:
"When speed counts, the keyboard is still king. Almost all the actions and commands you can perform with a mouse you can perform faster using combinations of keys on your keyboard. These simple keyboard shortcuts can get you where you want to go faster than several clicks of a mouse. You'll work faster on spreadsheets and similar documents, too, because you won't lose your place switching back and forth between mouse and keys.
Here are some of the most useful keyboard shortcuts:"
http://www.microsoft.com/windowsxp/home/using/tips/personalize/keyboardsc.asp
"When speed counts, the keyboard is still king. Almost all the actions and commands you can perform with a mouse you can perform faster using combinations of keys on your keyboard. These simple keyboard shortcuts can get you where you want to go faster than several clicks of a mouse. You'll work faster on spreadsheets and similar documents, too, because you won't lose your place switching back and forth between mouse and keys.
Here are some of the most useful keyboard shortcuts:"
http://www.microsoft.com/windowsxp/home/using/tips/personalize/keyboardsc.asp
Monday, May 03, 2004
ZDNet: Printer Friendly - Alarm growing over bot software:
"Known as bot software, the remote attack tools can seek out and place themselves on vulnerable computers, then run silently in the background, letting an attacker send commands to the system while its owner works away, oblivious. The latest versions of the software created by the security underground let attackers control compromised computers through chat servers and peer-to-peer networks, command the software to attack other computers and steal information from infected systems.
News.context
What's new:
Internet security watchers warn that the most common kind of bot software has been upgraded. A new variant incorporates publicly available code for breaching security through a vulnerability on almost every Windows system sold in the past five years.
Bottom line:
Bot software has spread widely--just how quickly is difficult even for security experts to evaluate. Symantec puts the number of computers compromised in the hundreds of thousands. Other security experts have put the number in the millions. Moreover, with source code commonly available, bot software gets quickly updated to take advantage of the latest flaws.…"
http://zdnet.com.com/2100-1105_2-5202236.html?tag=adnews
"Known as bot software, the remote attack tools can seek out and place themselves on vulnerable computers, then run silently in the background, letting an attacker send commands to the system while its owner works away, oblivious. The latest versions of the software created by the security underground let attackers control compromised computers through chat servers and peer-to-peer networks, command the software to attack other computers and steal information from infected systems.
News.context
What's new:
Internet security watchers warn that the most common kind of bot software has been upgraded. A new variant incorporates publicly available code for breaching security through a vulnerability on almost every Windows system sold in the past five years.
Bottom line:
Bot software has spread widely--just how quickly is difficult even for security experts to evaluate. Symantec puts the number of computers compromised in the hundreds of thousands. Other security experts have put the number in the millions. Moreover, with source code commonly available, bot software gets quickly updated to take advantage of the latest flaws.…"
http://zdnet.com.com/2100-1105_2-5202236.html?tag=adnews
URLScan Security Tool:
"UrlScan version 2.5 is a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan security tool helps prevent potentially harmful requests from reaching the server. UrlScan 2.5 will now install as a clean installation on servers running IIS 4.0 and later.…"
http://www.microsoft.com/technet/security/tools/urlscan.mspx
"UrlScan version 2.5 is a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan security tool helps prevent potentially harmful requests from reaching the server. UrlScan 2.5 will now install as a clean installation on servers running IIS 4.0 and later.…"
http://www.microsoft.com/technet/security/tools/urlscan.mspx
Saturday, May 01, 2004
Spam Report Card 2004 - TechUpdate - ZDNet:
"More than 50 percent of e-mail is spam. Billions of spam attacks are launched each month. Spam costs U.S. companies at least $1 billion per year in security and human resources expenditures, as well as lost productivity. Increasingly, virus-infected machines are used to distribute spam and perpetuate additional fraud, such as phishing. Is combating spam a losing battle?"
http://techupdate.zdnet.com/special_report/Spam_Report_Card_2004.html
"More than 50 percent of e-mail is spam. Billions of spam attacks are launched each month. Spam costs U.S. companies at least $1 billion per year in security and human resources expenditures, as well as lost productivity. Increasingly, virus-infected machines are used to distribute spam and perpetuate additional fraud, such as phishing. Is combating spam a losing battle?"
http://techupdate.zdnet.com/special_report/Spam_Report_Card_2004.html
Friday, April 30, 2004
Signs Point to Worm Attack on SSL Vulnerability:
"Security experts on Tuesday said they are seeing evidence of what appears to be a worm exploiting the recently announced vulnerability in the Windows implementation of the Secure Sockets Layer (SSL) protocol.
During the morning and early afternoon Tuesday, specialists at VeriSign Inc.'s security operations center observed a large-scale exploitation of the vulnerability. While there are a number of software tools available on the Internet to attack the vulnerability, experts said the volume of activity is too great for the attacks to be manual.…"
http://www.eweek.com/article2/0,1759,1573827,00.asp
"Security experts on Tuesday said they are seeing evidence of what appears to be a worm exploiting the recently announced vulnerability in the Windows implementation of the Secure Sockets Layer (SSL) protocol.
During the morning and early afternoon Tuesday, specialists at VeriSign Inc.'s security operations center observed a large-scale exploitation of the vulnerability. While there are a number of software tools available on the Internet to attack the vulnerability, experts said the volume of activity is too great for the attacks to be manual.…"
http://www.eweek.com/article2/0,1759,1573827,00.asp
Microsoft Confirms Bug In SSL Patch:
"The knowledge base article goes by the unusually long name: 'Your computer stops responding, you cannot log on to Windows, or your CPU usage for the System process approaches 100 percent after you install the security update that is described in Microsoft Security Bulletin MS04-011.'
The problem occurs, according to the article, because Windows tries repeatedly to load drivers that fail to load. Microsoft acknowledges that the problem is a bug in the patch and that the company is investigating solutions.…"
http://www.eweek.com/article2/0,1759,1578752,00.asp
"The knowledge base article goes by the unusually long name: 'Your computer stops responding, you cannot log on to Windows, or your CPU usage for the System process approaches 100 percent after you install the security update that is described in Microsoft Security Bulletin MS04-011.'
The problem occurs, according to the article, because Windows tries repeatedly to load drivers that fail to load. Microsoft acknowledges that the problem is a bug in the patch and that the company is investigating solutions.…"
http://www.eweek.com/article2/0,1759,1578752,00.asp
Scams, Lies, Deceit, and Offshoring:
"Someone has to take the jobs that, as President Bush and others say, 'Americans don't want.' There appear to be a large number of these jobs. In fact, it seems that our fastest-growing business segment is the creation of more and more jobs that Americans don't want. Often, American companies will lay people off, only to train newcomers to replace them."
Here is how the real scam works. You are a programmer at one of the big IT or computer companies. You're 55 and nearing a retirement plateau; in fact, you're a liability. You're making, say, $80,000 as a program designer. You have various responsibilities. The company eliminates your position in the process of downsizing.
To be fair to you, it creates a new position, Associate Program Designer, that pays $35,000 a year. Its responsibilities coincidentally match those of your old job. You can take this job, doing what you did before but at a huge cut in pay, or look elsewhere. If the latter, it's apparent that this new job is one that "Americans don't want." The company can then hire a "body shop" to drop in a foreign H-1B or L1 visa holder, who will not be quite as good but will work for a lot less.
This is a bait-and-switch scheme that is designed to screw older and more experienced workers out of their retirement benefits, plain and simple. This sort of thing, unfortunately, is nothing new to corporate America:…
http://www.pcmag.com/article2/0,1759,1573102,00.asp
"Someone has to take the jobs that, as President Bush and others say, 'Americans don't want.' There appear to be a large number of these jobs. In fact, it seems that our fastest-growing business segment is the creation of more and more jobs that Americans don't want. Often, American companies will lay people off, only to train newcomers to replace them."
Here is how the real scam works. You are a programmer at one of the big IT or computer companies. You're 55 and nearing a retirement plateau; in fact, you're a liability. You're making, say, $80,000 as a program designer. You have various responsibilities. The company eliminates your position in the process of downsizing.
To be fair to you, it creates a new position, Associate Program Designer, that pays $35,000 a year. Its responsibilities coincidentally match those of your old job. You can take this job, doing what you did before but at a huge cut in pay, or look elsewhere. If the latter, it's apparent that this new job is one that "Americans don't want." The company can then hire a "body shop" to drop in a foreign H-1B or L1 visa holder, who will not be quite as good but will work for a lot less.
This is a bait-and-switch scheme that is designed to screw older and more experienced workers out of their retirement benefits, plain and simple. This sort of thing, unfortunately, is nothing new to corporate America:…
http://www.pcmag.com/article2/0,1759,1573102,00.asp
Wednesday, April 28, 2004
Phishing Scams Increase 1,200% in 6 Months:
"Beware your email.
In the last six months, the number of phishing email scams has increased 1,200 percent, putting end users and major companies at an even greater risk, according to a report from MessageLabs Inc., a managed email security firm based in New York.
MessageLabs reports that last September its analysts had only seen 279 phishing emails. But that number had risen nearly 800-fold to 215,643. Phishing emails peaked in January with 337,050.… "
Phishing is the latest online scam financial scam. It's a con game based on posing.
Spammers send out millions of emails claiming to be from legitimate organizations, such as major U.S. banks or credit card companies. The spammers even fake the senders address so it appears to be from the company they're posing to be. The message in the email often says there is a problem with the recipient's account and it has been shut down. To reinstate the account, or deal with whatever fictional problem the email refers to, the user is instructed to click on a link that then takes them to a phony Web site.
The users are then led to what is often a perfect replica of the Web site that the spammer is pretending to be. At this point, the victim is asked to 'update' his personal security information, passwords, Social Security numbers, addresses and bank account information. The information is then used to siphon money out of the victim's bank account or to make financial transactions with their money.…
http://www.esecurityplanet.com/trends/article.php/3344141
"Beware your email.
In the last six months, the number of phishing email scams has increased 1,200 percent, putting end users and major companies at an even greater risk, according to a report from MessageLabs Inc., a managed email security firm based in New York.
MessageLabs reports that last September its analysts had only seen 279 phishing emails. But that number had risen nearly 800-fold to 215,643. Phishing emails peaked in January with 337,050.… "
Phishing is the latest online scam financial scam. It's a con game based on posing.
Spammers send out millions of emails claiming to be from legitimate organizations, such as major U.S. banks or credit card companies. The spammers even fake the senders address so it appears to be from the company they're posing to be. The message in the email often says there is a problem with the recipient's account and it has been shut down. To reinstate the account, or deal with whatever fictional problem the email refers to, the user is instructed to click on a link that then takes them to a phony Web site.
The users are then led to what is often a perfect replica of the Web site that the spammer is pretending to be. At this point, the victim is asked to 'update' his personal security information, passwords, Social Security numbers, addresses and bank account information. The information is then used to siphon money out of the victim's bank account or to make financial transactions with their money.…
http://www.esecurityplanet.com/trends/article.php/3344141
Tuesday, April 27, 2004
AntiOnline - Windows XP Security Guide (phase one):
"This guide will take you from a FRESH install of XP, to the high level of security … Note that this is more intended for singular computer use (and possibly work office) and not for mission critical server usage. While yes, … use XP for server usages, because it can handle it with the proper settings, a mission critical server requires a primary focus on the 'Server' portion, rather than being evently distrubuted between server, desktop, and game machine. … when it comes down to mission critical servers, it isn't about bending tools to work, it's about how well they work. Windows XP as a *mission* critical server is not recommended because of latency issues, forced RAM on the GUI, and process handling meant for low latency on the GUI responcivness, instead of packet and server process stability handling."
http://www.antionline.com/showthread.php?s=&threadid=255353
"This guide will take you from a FRESH install of XP, to the high level of security … Note that this is more intended for singular computer use (and possibly work office) and not for mission critical server usage. While yes, … use XP for server usages, because it can handle it with the proper settings, a mission critical server requires a primary focus on the 'Server' portion, rather than being evently distrubuted between server, desktop, and game machine. … when it comes down to mission critical servers, it isn't about bending tools to work, it's about how well they work. Windows XP as a *mission* critical server is not recommended because of latency issues, forced RAM on the GUI, and process handling meant for low latency on the GUI responcivness, instead of packet and server process stability handling."
http://www.antionline.com/showthread.php?s=&threadid=255353
Saturday, April 24, 2004
Fonts in Cyberspace:
"A guide to finding language fonts on the Internet. Containing more than 400 sources for 123 languages"
http://www.sil.org/computing/fonts/
"A guide to finding language fonts on the Internet. Containing more than 400 sources for 123 languages"
http://www.sil.org/computing/fonts/
Tuesday, April 20, 2004
Getting a Job in CG: Real Advice from Reel People, Chapter 3: What to Learn. By Sybex - WebReference.com-:
"This book excerpt is from 'Getting a Job in CG: Real Advice from Reel People' ISBN 0-7821-4257-5. All rights reserved. Chapter 3: What to Learn., is posted with permission from Sybex.
Knowing the job descriptions in 3D and effects described in the first two chapters can help you find the kind of job that fits your skills and interests. Perusing the descriptions and sample listings, you might have realized that there are skills you lack.
This chapter explains the skills involved in 3D and effects and gives you direction on how to acquire them.…"
http://www.webreference.com/3d/cg/
"This book excerpt is from 'Getting a Job in CG: Real Advice from Reel People' ISBN 0-7821-4257-5. All rights reserved. Chapter 3: What to Learn., is posted with permission from Sybex.
Knowing the job descriptions in 3D and effects described in the first two chapters can help you find the kind of job that fits your skills and interests. Perusing the descriptions and sample listings, you might have realized that there are skills you lack.
This chapter explains the skills involved in 3D and effects and gives you direction on how to acquire them.…"
http://www.webreference.com/3d/cg/
Security issues move Linksys routers off the short list:
"As more companies adopt a telecommuting-friendly culture, more employees are taking the plunge for cable or DSL-based Internet access. In many cases, their households have more than one Internet user and are installing turnkey connection-sharing appliances. The two companies that most often come to mind for me as providers of these appliances are the recently Cisco-acquired Linksys and the as-of-yet-to-be acquired NetGear. Linksys is apparently having some engineering difficulties that are leaving its customers exposed to potential security problems.… "
http://techupdate.zdnet.com/techupdate/stories/main/Linksys_routers_and_DDoS.html
"As more companies adopt a telecommuting-friendly culture, more employees are taking the plunge for cable or DSL-based Internet access. In many cases, their households have more than one Internet user and are installing turnkey connection-sharing appliances. The two companies that most often come to mind for me as providers of these appliances are the recently Cisco-acquired Linksys and the as-of-yet-to-be acquired NetGear. Linksys is apparently having some engineering difficulties that are leaving its customers exposed to potential security problems.… "
http://techupdate.zdnet.com/techupdate/stories/main/Linksys_routers_and_DDoS.html
ZDNet AnchorDesk: What's wrong with Internet phones:
"The best thing about the traditional phone system is what people take for granted: Any phone on the planet can connect to any other. Some Internet telephone systems, such as Vonage, can also connect to any other phone. But except in extremely rare cases, two people on different VoIP systems can't connect to each other directly over the Internet--they have to use the public phone system as a go-between.… "
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5130570.html?tag=adss
"The best thing about the traditional phone system is what people take for granted: Any phone on the planet can connect to any other. Some Internet telephone systems, such as Vonage, can also connect to any other phone. But except in extremely rare cases, two people on different VoIP systems can't connect to each other directly over the Internet--they have to use the public phone system as a go-between.… "
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5130570.html?tag=adss
Monday, April 19, 2004
Training:
"This set of labs will help you learn how to design and deploy Extensible Markup Language (XML)-based forms in Microsoft® Office InfoPath® 2003 SP-1."
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/odc_2003_ta/html/odc_landinfo03_tr.asp
"This set of labs will help you learn how to design and deploy Extensible Markup Language (XML)-based forms in Microsoft® Office InfoPath® 2003 SP-1."
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/odc_2003_ta/html/odc_landinfo03_tr.asp
Saturday, April 17, 2004
The New York Times > National > 9/11 Panel Calls Policies on Immigration Ineffective:
"The commission investigating the 9/11 attacks has concluded that immigration policies promoted as essential to keeping the country safe from future attacks have been largely ineffective, producing little, if any, information leading to the identification or apprehension of terrorists."
http://www.nytimes.com/2004/04/17/national/17IMMI.html?pagewanted=all&position=
"The commission investigating the 9/11 attacks has concluded that immigration policies promoted as essential to keeping the country safe from future attacks have been largely ineffective, producing little, if any, information leading to the identification or apprehension of terrorists."
http://www.nytimes.com/2004/04/17/national/17IMMI.html?pagewanted=all&position=
EMediaLive.com Review: Editor's Choice-Ulead DVD Workshop 2.0:
"Compared to its peers, we found DVD Workshop much more accessible than Adobe Encore, while offering a greater range of design options. Workshop stands up well even if you throw Photoshop and After Effects into the creative mix, especially if you consider development efficiency."
http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=152#9
"Compared to its peers, we found DVD Workshop much more accessible than Adobe Encore, while offering a greater range of design options. Workshop stands up well even if you throw Photoshop and After Effects into the creative mix, especially if you consider development efficiency."
http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=152#9
Understanding and Choosing File Formats in Photoshop CS and Illustrator CS:
"Peter Bauer discusses file formats and their various capabilities, including information on which format to select for which purpose. "
regitration required
http://www.informit.com/articles/printerfriendly.asp?p=169496
"Peter Bauer discusses file formats and their various capabilities, including information on which format to select for which purpose. "
regitration required
http://www.informit.com/articles/printerfriendly.asp?p=169496
Thursday, April 15, 2004
Data Recovery Software. NTFS Reader for DOS NTFS DOS. Freeware & Shareware.:
"NTFS Reader DOS Boot Disk provides read access to NTFS drives from the MS DOS environment. It supports long filenames as well as compressed and fragmented files. NTFS Reader for DOS allows you to preview the files on NTFS and copy them from NTFS to FAT volumes or network drives. In order to use the software you need to copy the readntfs.exe file to a bootable floppy disk and boot from it."
http://www.ntfs.com/products.htm
"NTFS Reader DOS Boot Disk provides read access to NTFS drives from the MS DOS environment. It supports long filenames as well as compressed and fragmented files. NTFS Reader for DOS allows you to preview the files on NTFS and copy them from NTFS to FAT volumes or network drives. In order to use the software you need to copy the readntfs.exe file to a bootable floppy disk and boot from it."
http://www.ntfs.com/products.htm
12 Short Steps Go a Long Way Toward Safeguarding Your Business:
"SMALL BUSINESS SECURITY CHECKLIST
Before you begin, make sure these recommendations concur with your security policy. If you don't have a security policy, learn why you should consider adopting one. "
http://www.microsoft.com/smallbusiness/gtm/securityguidance/hub.mspx
"SMALL BUSINESS SECURITY CHECKLIST
Before you begin, make sure these recommendations concur with your security policy. If you don't have a security policy, learn why you should consider adopting one. "
http://www.microsoft.com/smallbusiness/gtm/securityguidance/hub.mspx
Manipulate the User Agent for Accurate Site Stats:
"If you implement any sort of hit monitoring or tracking on your Website, you probably don't want to include any of your own hits."
Ordinarily, you could set a "self-specific" cookie. Then, when the tracking script was called, you could simply check to see if that cookie existed, and, if it did, exit the tracking script.
However, if, like me, you're frankly scared of cookies on the grounds that they:
are difficult to test with,
are called something silly and
aren't 100% reliable
Furthermore, many Webmasters exclude from tracking certain browsers that are known not to work on their Websites. For example, many sites block any non-Internet Explorer or Netscape browsers, such as Mozilla's excellent new Firebird and a whole heap of others. Being able to manipulate the user agent to fool the Website into thinking we're using Internet Explorer 6.0 when we're really running Firebird 0.7 could be quite handy! …
http://www.sitepoint.com/print/site-stats-user-agent
"If you implement any sort of hit monitoring or tracking on your Website, you probably don't want to include any of your own hits."
Ordinarily, you could set a "self-specific" cookie. Then, when the tracking script was called, you could simply check to see if that cookie existed, and, if it did, exit the tracking script.
However, if, like me, you're frankly scared of cookies on the grounds that they:
are difficult to test with,
are called something silly and
aren't 100% reliable
Furthermore, many Webmasters exclude from tracking certain browsers that are known not to work on their Websites. For example, many sites block any non-Internet Explorer or Netscape browsers, such as Mozilla's excellent new Firebird and a whole heap of others. Being able to manipulate the user agent to fool the Website into thinking we're using Internet Explorer 6.0 when we're really running Firebird 0.7 could be quite handy! …
http://www.sitepoint.com/print/site-stats-user-agent
Wednesday, April 14, 2004
ZDNet: Printer Friendly - Attackers infiltrating supercomputer networks:
"Unknown attackers have compromised a large number of Linux and Solaris machines in high-speed computing networks at Stanford University and other academic research facilities, according to an advisory.
The attacks, which apparently compromised servers as recently as April 3, are currently being investigated, according to an advisory posted April 6 by the Information Technology Systems and Services (ITSS) group at Stanford. "
The attacks start with the compromise of an unprivileged local user account. Usually this is because the attacker's captured the password from somewhere else: it's been sniffed off the network (through the use of insecure protocols like telnet), it's been collected when the user signs on to or from another compromised machine, it's been harvested from the password file on a compromised system.
If the target machine is behind on its patches, the attacker then uses one of a number of public exploits to elevate the unprivileged account to root status. Exploits target the Linux mremap() vulnerabilities, the Solaris kernel module loading vulnerability (for which an attack was made public on 8 Apr), and a Solaris priocntl() issue.
http://zdnet.com.com/2102-1105_2-5191024.html?tag=printthis
"Unknown attackers have compromised a large number of Linux and Solaris machines in high-speed computing networks at Stanford University and other academic research facilities, according to an advisory.
The attacks, which apparently compromised servers as recently as April 3, are currently being investigated, according to an advisory posted April 6 by the Information Technology Systems and Services (ITSS) group at Stanford. "
The attacks start with the compromise of an unprivileged local user account. Usually this is because the attacker's captured the password from somewhere else: it's been sniffed off the network (through the use of insecure protocols like telnet), it's been collected when the user signs on to or from another compromised machine, it's been harvested from the password file on a compromised system.
If the target machine is behind on its patches, the attacker then uses one of a number of public exploits to elevate the unprivileged account to root status. Exploits target the Linux mremap() vulnerabilities, the Solaris kernel module loading vulnerability (for which an attack was made public on 8 Apr), and a Solaris priocntl() issue.
http://zdnet.com.com/2102-1105_2-5191024.html?tag=printthis
New Bugbear Virus finds New IE Hole:
"This has been a busy week for virus writers and antivirus vendors. We've seen some more Netsky and Bagle variants, as well as a number of new Trojans. However, the most prevalent has been last week's top threat Netsky.P, followed by Netsky.C and Netsky.D. While we haven't seen a wide distribution yet, a new Bugbear variety is starting to make the rounds?4Bugbear.C or Bugbear.E (depending on antivirus company reporting it). Bugbear.C attacks through an HTML attachment, and an unpatched Internet Explorer vulnerability. See our top threat for more information. "
Compared with PC users, Apple users have been fairly immune to viruses. However, a new "concept" Trojan is making waves in the Mac community. Intego, a security company announced the appearance of a new Trojan, MP3Concept. While Indego's press release describes potentially malicious payload the Trojan can have such as file deletion, sending e-mail, or infecting other MP3, Jpeg, GIF or QuickTime files, the MP3 Concept only shows a text message, and plays an MP3 of a man laughing. According to Symantec, the Trojan is not in the wild yet. Codemonkey takes a bit more of a swipe at Intego saying they are spreading FUD. The famous Nigerian 419 scam (also known as the advance payment scam) was in the news this week, with the conviction of one of the scammers. According to UK newspaper AllAfrica.com , Peter Okoeguale, a Nigerian living in Wales, was arrested for committing fraud. He was sentenced to 20 months, and faces deportation to Nigeria once freed. Unfortunately, this perpetrator is only one of probably hundreds or thousands of scammers preying on victims looking to make a fast buck. The Nigerian 419 scam, named after the Nigerian penal code covering fraud, comes in a number of varieties. Some offer a victim an investment in a Nigerian company, or a share of a large sum of money being spirited out of the country by an exiled high official. They often send the victim a forged or stolen check that the victim is to hold while they put up their own money. There are many web sites that explain and fight the scam. A quick search on Google for Nigerian Scam will bring up hundreds results. Peter Ferrie and Frederic Perriot, researchers at Symantec have just published an analysis of the Welchia.B (Nachi.B) worm in Virus Bulletin called "The Wormpire Strikes Back". Welchia.B attempts to be a good worm by removing other worm infections. The analysis is a terrific look under the hood of the virus, with a little Star Wars humor tossed in. If you're interested in a deeper understanding of worms in general, and Welchia in particular, take a look at Peter's whitepaper.
http://www.pcmag.com/print_article/0,1761,a=124102,00.asp
"This has been a busy week for virus writers and antivirus vendors. We've seen some more Netsky and Bagle variants, as well as a number of new Trojans. However, the most prevalent has been last week's top threat Netsky.P, followed by Netsky.C and Netsky.D. While we haven't seen a wide distribution yet, a new Bugbear variety is starting to make the rounds?4Bugbear.C or Bugbear.E (depending on antivirus company reporting it). Bugbear.C attacks through an HTML attachment, and an unpatched Internet Explorer vulnerability. See our top threat for more information. "
Compared with PC users, Apple users have been fairly immune to viruses. However, a new "concept" Trojan is making waves in the Mac community. Intego, a security company announced the appearance of a new Trojan, MP3Concept. While Indego's press release describes potentially malicious payload the Trojan can have such as file deletion, sending e-mail, or infecting other MP3, Jpeg, GIF or QuickTime files, the MP3 Concept only shows a text message, and plays an MP3 of a man laughing. According to Symantec, the Trojan is not in the wild yet. Codemonkey takes a bit more of a swipe at Intego saying they are spreading FUD. The famous Nigerian 419 scam (also known as the advance payment scam) was in the news this week, with the conviction of one of the scammers. According to UK newspaper AllAfrica.com , Peter Okoeguale, a Nigerian living in Wales, was arrested for committing fraud. He was sentenced to 20 months, and faces deportation to Nigeria once freed. Unfortunately, this perpetrator is only one of probably hundreds or thousands of scammers preying on victims looking to make a fast buck. The Nigerian 419 scam, named after the Nigerian penal code covering fraud, comes in a number of varieties. Some offer a victim an investment in a Nigerian company, or a share of a large sum of money being spirited out of the country by an exiled high official. They often send the victim a forged or stolen check that the victim is to hold while they put up their own money. There are many web sites that explain and fight the scam. A quick search on Google for Nigerian Scam will bring up hundreds results. Peter Ferrie and Frederic Perriot, researchers at Symantec have just published an analysis of the Welchia.B (Nachi.B) worm in Virus Bulletin called "The Wormpire Strikes Back". Welchia.B attempts to be a good worm by removing other worm infections. The analysis is a terrific look under the hood of the virus, with a little Star Wars humor tossed in. If you're interested in a deeper understanding of worms in general, and Welchia in particular, take a look at Peter's whitepaper.
http://www.pcmag.com/print_article/0,1761,a=124102,00.asp
Cheaper Shared Hosting Imperils Security:
"How secure is that $16.95-a-month hosted Web account? Hosted servers, especially shared accounts, can pose real security problems. Some hosts are better than others, but with shared hosting, you basically have to keep your fingers crossed. "
http://www.eweek.com/article2/0,1759,1565792,00.asp
"How secure is that $16.95-a-month hosted Web account? Hosted servers, especially shared accounts, can pose real security problems. Some hosts are better than others, but with shared hosting, you basically have to keep your fingers crossed. "
http://www.eweek.com/article2/0,1759,1565792,00.asp
Tuesday, April 13, 2004
833786 - Steps that you can take to help identify and to help protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks:
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.
However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL."
http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.
However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL."
http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
Magical Jelly Bean Software - Magical Jelly Bean Keyfinder v1.41:
"The Magical Jelly Bean Keyfinder is a freeware utility that retrieves your Product Key (cd key) used to install windows from your registry. It has the options to copy the key to clipboard, save it to a text file, or print it for safekeeping. It works on Windows 95, 98, ME, NT4, 2000, XP, Server 2003, Office 97, and Office XP. This version is a quick update to make it work with Windows Server 2003."
http://www.magicaljellybean.com/keyfinder.shtml
"The Magical Jelly Bean Keyfinder is a freeware utility that retrieves your Product Key (cd key) used to install windows from your registry. It has the options to copy the key to clipboard, save it to a text file, or print it for safekeeping. It works on Windows 95, 98, ME, NT4, 2000, XP, Server 2003, Office 97, and Office XP. This version is a quick update to make it work with Windows Server 2003."
http://www.magicaljellybean.com/keyfinder.shtml
Monday, April 12, 2004
Internet Explorer 6 Security and Privacy Essentials:
"Protect your privacy and the security of your computer on the Web. The following topics are packed with information and easy-to-follow, practical instructions that explain how features in Internet Explorer 6 help make your Web browsing experience better. "
http://www.microsoft.com/windows/ie/using/howto/privacy/secprivessntl.asp
"Protect your privacy and the security of your computer on the Web. The following topics are packed with information and easy-to-follow, practical instructions that explain how features in Internet Explorer 6 help make your Web browsing experience better. "
http://www.microsoft.com/windows/ie/using/howto/privacy/secprivessntl.asp
Friday, April 09, 2004
RealPlayer 10 Release Supports More Formats:
"RealNetworks Inc. on Wednesday released the latest version of its digital media player with support for all of the major Internet media formats, including those from competitors Microsoft Corp. and Apple Computer Inc.
RealNetworks of Seattle first announced RealPlayer 10 for Windows in January and said it would include support for playing music purchased through Apple's iTunes, working around Apple's digital rights management technology. "
http://www.eweek.com/article2/0,1759,1563416,00.asp
"RealNetworks Inc. on Wednesday released the latest version of its digital media player with support for all of the major Internet media formats, including those from competitors Microsoft Corp. and Apple Computer Inc.
RealNetworks of Seattle first announced RealPlayer 10 for Windows in January and said it would include support for playing music purchased through Apple's iTunes, working around Apple's digital rights management technology. "
http://www.eweek.com/article2/0,1759,1563416,00.asp
Researcher Claims Online Anti-virus Scanners Buggy:
"Online scanners from Symantec, McAfee and Panda all contain buffer overflows. One researcher claims an attacker could execute arbitrary code, another just that they could crash the browser. Panda reports their software has been fixed and Symantec denies there is a problem at all. "
http://www.eweek.com/article2/0,1759,1563092,00.asp
"Online scanners from Symantec, McAfee and Panda all contain buffer overflows. One researcher claims an attacker could execute arbitrary code, another just that they could crash the browser. Panda reports their software has been fixed and Symantec denies there is a problem at all. "
http://www.eweek.com/article2/0,1759,1563092,00.asp
Authorama - Public Domain Books:
"Authorama.com, featuring completely free books from a variety of different authors, collected here for you to read online or offline. The books may have been published before, but not in this form, which I hope you find enjoyable to read and print."
http://www.authorama.com/
"Authorama.com, featuring completely free books from a variety of different authors, collected here for you to read online or offline. The books may have been published before, but not in this form, which I hope you find enjoyable to read and print."
http://www.authorama.com/
Thursday, April 08, 2004
Tax Center:
"American Express has created a Web site to help small-business owners learn about new tax developments and interact with other entrepreneurs on tax issues."
http://home3.americanexpress.com/smallbusiness/Landing/tax_center_main.asp?openvan=taxcenter
"American Express has created a Web site to help small-business owners learn about new tax developments and interact with other entrepreneurs on tax issues."
http://home3.americanexpress.com/smallbusiness/Landing/tax_center_main.asp?openvan=taxcenter
Wednesday, April 07, 2004
Attrition Security Rant: Anti-Virus Companies: Tenacious Spammers:
"For roughly three years, the Internet has seen worms that spread via e-mail, often taking addresses out of the infected machine's web cache, user addressbook or other sources. Some of these worms will also forge/spoof the 'From:' line so the mail appears to be from someone else, in an attempt to make the mail more 'trusted'. To be clear, here is a sample timeline of how these work:
EvilGuy01 writes and releases a new worm.
Fred is a moron and clicks on an attachment from a stranger, infecting his machine.
The worm mails a copy of itself to everyone in Fred's addressbook.
The mail sent out spoofs the headers of the mail so it may be 'From: George' or 'From: Sally'.
Tom gets a copy of the mail 'From: Sally' and clicks on the attachment, infecting himself.
Tom sends mail to Sally complaining about her evil shenanigans.
Sally replies to Tom with 'd00d WTF?! lol' since she never sent the mail. "
How enterprise AV systems add to the Internet traffic
But wait, it gets worse. Even if friends and family understand that I likely did not send them a virus, some enterprise antivirus program with built-in return messages will state emphatically that I have a virus. Here's how that works: As the forged e-mail enters their enterprise system, that system bounces it back to the apparent sender with a message that authoritatively states, "You are infected with XXX virus." I have hundreds of these bounced e-mail messages claiming that I am infected with MyDoom.f, Netsky.d, or Bagle.c. I'm not.
In the middle of an e-mail virus outbreak, messages such as these--originally intended to provide a useful service--only add to the Internet traffic jam. Brian Martin, a.k.a. Jericho at Attrition.org, wrote a thorough critique of the current methods being used, complete with examples. His conclusion? System administrators need to turn off this "helpful" feature if they haven't already.
Unfortunately, the spoofing problem itself lies deep under the hood of the Internet, within SMTP, Simple Mail Transfer Protocol, the Internet protocol used for sending e-mail. SMTP was created many years ago and lacks a modern method for verifying the authenticity of the sender. With a little finesse, almost anyone can manipulate the header information on an e-mail message to disguise its true origin and make it appear as though someone else sent you a message.
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5128975.html?tag=adss
http://www.attrition.org/security/rant/av-spammers.html
"For roughly three years, the Internet has seen worms that spread via e-mail, often taking addresses out of the infected machine's web cache, user addressbook or other sources. Some of these worms will also forge/spoof the 'From:' line so the mail appears to be from someone else, in an attempt to make the mail more 'trusted'. To be clear, here is a sample timeline of how these work:
EvilGuy01 writes and releases a new worm.
Fred is a moron and clicks on an attachment from a stranger, infecting his machine.
The worm mails a copy of itself to everyone in Fred's addressbook.
The mail sent out spoofs the headers of the mail so it may be 'From: George' or 'From: Sally'.
Tom gets a copy of the mail 'From: Sally' and clicks on the attachment, infecting himself.
Tom sends mail to Sally complaining about her evil shenanigans.
Sally replies to Tom with 'd00d WTF?! lol' since she never sent the mail. "
How enterprise AV systems add to the Internet traffic
But wait, it gets worse. Even if friends and family understand that I likely did not send them a virus, some enterprise antivirus program with built-in return messages will state emphatically that I have a virus. Here's how that works: As the forged e-mail enters their enterprise system, that system bounces it back to the apparent sender with a message that authoritatively states, "You are infected with XXX virus." I have hundreds of these bounced e-mail messages claiming that I am infected with MyDoom.f, Netsky.d, or Bagle.c. I'm not.
In the middle of an e-mail virus outbreak, messages such as these--originally intended to provide a useful service--only add to the Internet traffic jam. Brian Martin, a.k.a. Jericho at Attrition.org, wrote a thorough critique of the current methods being used, complete with examples. His conclusion? System administrators need to turn off this "helpful" feature if they haven't already.
Unfortunately, the spoofing problem itself lies deep under the hood of the Internet, within SMTP, Simple Mail Transfer Protocol, the Internet protocol used for sending e-mail. SMTP was created many years ago and lacks a modern method for verifying the authenticity of the sender. With a little finesse, almost anyone can manipulate the header information on an e-mail message to disguise its true origin and make it appear as though someone else sent you a message.
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5128975.html?tag=adss
http://www.attrition.org/security/rant/av-spammers.html
Microsoft Releases Source Code on SourceForge:
"On Monday, Microsoft released some of its code under an open-source license, and posted it on SourceForge, the open-source code repository.
To date, Microsoft has made its source code available under a variety of licensing mechanisms, all under its 'shared source' umbrella. But until today, the company had not released code under what is commonly considered a true open-source license."
Microsoft made available an internally-developed product called the "Windows Installer XML" (WiX) to SourceForge. The code is downloadable here.
WiX is a toolset for building Windows installation packages from XML source code. It runs on Windows NT and Windows 2000.…
http://sourceforge.net/projects/wix/
http://www.microsoft-watch.com/article2/0,1995,1561953,00.asp
"On Monday, Microsoft released some of its code under an open-source license, and posted it on SourceForge, the open-source code repository.
To date, Microsoft has made its source code available under a variety of licensing mechanisms, all under its 'shared source' umbrella. But until today, the company had not released code under what is commonly considered a true open-source license."
Microsoft made available an internally-developed product called the "Windows Installer XML" (WiX) to SourceForge. The code is downloadable here.
WiX is a toolset for building Windows installation packages from XML source code. It runs on Windows NT and Windows 2000.…
http://sourceforge.net/projects/wix/
http://www.microsoft-watch.com/article2/0,1995,1561953,00.asp
Tuesday, April 06, 2004
Executive E-Mail: Current Edition:
"Microsoft Progress Report: Security
Malicious software code has been around for decades. But only in the last few years have the Internet, high-speed connections and millions of new computing devices converged to create a truly global computing network in which a virus or worm can circle the world in a matter of minutes.
Meanwhile, criminal hackers have become more sophisticated, creating and distributing digital epidemics like Slammer, Blaster, Sobig and Mydoom that spread almost instantaneously, threatening the potential of technology to advance business productivity, commerce and communication.
The kinds of threats are evolving too. Blaster, for example, hijacked individual computers, turning innocent users into unknowing and innocent worm propagators. These kinds of attacks – "swarming" attacks that are coordinated to cause multiplied, cascading effects – change the landscape of security threats. They put new demands on IT professionals and consumers to take preventative measures, and on the technology industry to continue to innovate and develop new solutions.…
Given human nature, evolving threat models and the increasing interconnectedness of computers, the number of security exploits will never reach zero. But we can dramatically blunt the impact of cybercriminals, and are dedicating a major portion of our R&D investments to security advances.…"
http://www.microsoft.com/mscorp/execmail/
"Microsoft Progress Report: Security
Malicious software code has been around for decades. But only in the last few years have the Internet, high-speed connections and millions of new computing devices converged to create a truly global computing network in which a virus or worm can circle the world in a matter of minutes.
Meanwhile, criminal hackers have become more sophisticated, creating and distributing digital epidemics like Slammer, Blaster, Sobig and Mydoom that spread almost instantaneously, threatening the potential of technology to advance business productivity, commerce and communication.
The kinds of threats are evolving too. Blaster, for example, hijacked individual computers, turning innocent users into unknowing and innocent worm propagators. These kinds of attacks – "swarming" attacks that are coordinated to cause multiplied, cascading effects – change the landscape of security threats. They put new demands on IT professionals and consumers to take preventative measures, and on the technology industry to continue to innovate and develop new solutions.…
Given human nature, evolving threat models and the increasing interconnectedness of computers, the number of security exploits will never reach zero. But we can dramatically blunt the impact of cybercriminals, and are dedicating a major portion of our R&D investments to security advances.…"
http://www.microsoft.com/mscorp/execmail/
HOAXBUSTERS Home Page:
"Interspersed among the junk mail and spam that fills our Internet e-mail boxes are dire warnings about devastating new viruses, Trojans that eat the heart out of your system, and malicious software that can steal the computer right off your desk. Added to that are messages about free money, children in trouble, and other items designed to grab you and get you to forward the message to everyone you know. Most all of these messages are hoaxes or chain letters. While hoaxes do not automatically infect systems like a virus or Trojan, they are still time consuming and costly to remove from all the systems where they exist. At CIAC, we find that we spend much more time de-bunking hoaxes than handling real virus and Trojan incidents. These pages describe some of the warnings, offers, and pleas for help that are filling our mailboxes, clogging our mailservers, and that generally do not have any basis in fact.…"
http://hoaxbusters.ciac.org/
"Interspersed among the junk mail and spam that fills our Internet e-mail boxes are dire warnings about devastating new viruses, Trojans that eat the heart out of your system, and malicious software that can steal the computer right off your desk. Added to that are messages about free money, children in trouble, and other items designed to grab you and get you to forward the message to everyone you know. Most all of these messages are hoaxes or chain letters. While hoaxes do not automatically infect systems like a virus or Trojan, they are still time consuming and costly to remove from all the systems where they exist. At CIAC, we find that we spend much more time de-bunking hoaxes than handling real virus and Trojan incidents. These pages describe some of the warnings, offers, and pleas for help that are filling our mailboxes, clogging our mailservers, and that generally do not have any basis in fact.…"
http://hoaxbusters.ciac.org/
Monday, April 05, 2004
MSBlast epidemic far larger than believed - News - ZDNet:
"New data from Microsoft suggests that at least 8 million Windows computers have been infected by the MSBlast, or Blaster, worm since last August--many times more than previously thought.… "
http://zdnet.com.com/2100-1105_2-5184439.html
"New data from Microsoft suggests that at least 8 million Windows computers have been infected by the MSBlast, or Blaster, worm since last August--many times more than previously thought.… "
http://zdnet.com.com/2100-1105_2-5184439.html
A Heretical View of File Sharing:
"But what if the industry is wrong, and file sharing is not hurting record sales?
It might seem counterintuitive, but that is the conclusion reached by two economists who released a draft last week of the first study that makes a rigorous economic comparison of directly observed activity on file-sharing networks and music buying.
'Downloads have an effect on sales which is statistically indistinguishable from zero, despite rather precise estimates,' write its authors, Felix Oberholzer-Gee of the Harvard Business School and Koleman S. Strumpf of the University of North Carolina at Chapel Hill.… "
http://www.nytimes.com/2004/04/05/technology/05music.html
"But what if the industry is wrong, and file sharing is not hurting record sales?
It might seem counterintuitive, but that is the conclusion reached by two economists who released a draft last week of the first study that makes a rigorous economic comparison of directly observed activity on file-sharing networks and music buying.
'Downloads have an effect on sales which is statistically indistinguishable from zero, despite rather precise estimates,' write its authors, Felix Oberholzer-Gee of the Harvard Business School and Koleman S. Strumpf of the University of North Carolina at Chapel Hill.… "
http://www.nytimes.com/2004/04/05/technology/05music.html
Sunday, April 04, 2004
Subscribe to:
Posts (Atom)
