The Sensible Internet Design Journal
Issue 40 of The Sensible Internet Design Letter
http://smallinitiatives.com/journal75_0_1_0_C4.html
http://smallinitiatives.com/
Saturday, August 16, 2003
Text style sampler
Instructions by Jay Small of Small Initiatives
Use this page to try different combinations of typefaces, text line height, paragraph indents and widths, and see the results (and the Cascading Style Sheet properties that made them) in the blocks of text below. Try this in different browsers and observe the subtle differences.
Here are the variables:
Font: Choose from four commonly installed, screen-friendly fonts: Times New Roman, default on many browsers; Verdana, a popular sans-serif choice; Arial, another popular sans-serif face; and Georgia, a serif face that is screen- and printer-friendly.
Line height: The default setting is 1 em. In printing, this setting would be known as "set solid." The line height is identical to the height of the letters themselves. But Web browsers fudge this a bit when they render text -- in fact, if your font size and line height are both left to defaults, there will be at least a pixel of space between lines of text. You may wish to add more space, especially on text set very wide.
Paragraph indents: By default, stacks of paragraphs in Web browsers do not have first-line indents; instead, the first line of each paragraph is flush-left but you see a full line of space between paragraphs. Most printed text is set with paragraph indents, however, and if you want them they are easy to create. The samples with indents have a half line (0.5 em) of space between paragraphs.
Set base font size
Then, select a base font size. The default size (1 em, or what would be applied if you used no style sheets at all) is typically rendered at 16 pixels.…
http://smallinitiatives.com/whatwevedone/presentations/textsampler/
Instructions by Jay Small of Small Initiatives
Use this page to try different combinations of typefaces, text line height, paragraph indents and widths, and see the results (and the Cascading Style Sheet properties that made them) in the blocks of text below. Try this in different browsers and observe the subtle differences.
Here are the variables:
Font: Choose from four commonly installed, screen-friendly fonts: Times New Roman, default on many browsers; Verdana, a popular sans-serif choice; Arial, another popular sans-serif face; and Georgia, a serif face that is screen- and printer-friendly.
Line height: The default setting is 1 em. In printing, this setting would be known as "set solid." The line height is identical to the height of the letters themselves. But Web browsers fudge this a bit when they render text -- in fact, if your font size and line height are both left to defaults, there will be at least a pixel of space between lines of text. You may wish to add more space, especially on text set very wide.
Paragraph indents: By default, stacks of paragraphs in Web browsers do not have first-line indents; instead, the first line of each paragraph is flush-left but you see a full line of space between paragraphs. Most printed text is set with paragraph indents, however, and if you want them they are easy to create. The samples with indents have a half line (0.5 em) of space between paragraphs.
Set base font size
Then, select a base font size. The default size (1 em, or what would be applied if you used no style sheets at all) is typically rendered at 16 pixels.…
http://smallinitiatives.com/whatwevedone/presentations/textsampler/
Blaster Variant on the Loose
Security experts are now tracking a new variant of the Blaster worm that was first spotted Wednesday morning.
The new version is nearly identical to the original, except for a new name on the executable file and a different registry key. The variant's file name is "teekids.exe," and the key it adds to the registry is: "Microsoft Inet Xp.." The key is located in the same place as Blaster's key is, according to Neel Mehta, research engineer at Internet Security Systems Inc. in Atlanta.
"Some of our customers say that they're seeing more copies of the new one than the old one, but I think that's just bad luck," Mehta says. "It scans exactly the same way and acts exactly the same as Blaster."
Mehta said that some copies of the new variant are coming packed with various known Windows Trojan programs, as well.
http://www.eweek.com/article2/0,3959,1219197,00.asp
Security experts are now tracking a new variant of the Blaster worm that was first spotted Wednesday morning.
The new version is nearly identical to the original, except for a new name on the executable file and a different registry key. The variant's file name is "teekids.exe," and the key it adds to the registry is: "Microsoft Inet Xp.." The key is located in the same place as Blaster's key is, according to Neel Mehta, research engineer at Internet Security Systems Inc. in Atlanta.
"Some of our customers say that they're seeing more copies of the new one than the old one, but I think that's just bad luck," Mehta says. "It scans exactly the same way and acts exactly the same as Blaster."
Mehta said that some copies of the new variant are coming packed with various known Windows Trojan programs, as well.
http://www.eweek.com/article2/0,3959,1219197,00.asp
Friday, August 15, 2003
The Bright Side of Blaster
The Blaster worm has infected hundreds of thousands of Windows machines, shut down the Maryland state DMV, put network administrators on overtime, crashed countless consumer's home computers, and on Saturday it will attempt a denial-of-service attack on Microsoft's Windows Update site. But that doesn't make it all bad.
Blaster, also known as MSBlast and LovSan, hit the Internet on Monday, spreading through the RCP DCOM vulnerability discovered by the Polish security research group Last Stage of Delirium earlier this year. The worm is built on dcom.c, one of the public exploit programs that emerged to demonstrate and exercise the flaw in the days and weeks following Microsoft's July 16th advisory. According to data gathered by (SecurityFocus publisher) Symantec's DeepSight network of intrusion detection systems, by Thursday afternoon the worm had infected over 330,000 Windows XP and Windows 2000 machines.
As nasty as that is, security experts say it could have been much worse: the worm is hampered by clumsy construction, and it does not contain a malicious payload to damage victim's files. Moreover, in its reckless tear through cyberspace Blaster is accomplishing what a month of warnings from the security community, an unprecedented mass-e-mail campaign by Microsoft, and two advisories from the Department of Homeland Security all failed to do: it's forcing companies and consumers to install the patch for the serious RPC DCOM vulnerability, shutting down computer intruders who've had their pick of these systems for weeks.
http://www.securityfocus.com/news/6728
The Blaster worm has infected hundreds of thousands of Windows machines, shut down the Maryland state DMV, put network administrators on overtime, crashed countless consumer's home computers, and on Saturday it will attempt a denial-of-service attack on Microsoft's Windows Update site. But that doesn't make it all bad.
Blaster, also known as MSBlast and LovSan, hit the Internet on Monday, spreading through the RCP DCOM vulnerability discovered by the Polish security research group Last Stage of Delirium earlier this year. The worm is built on dcom.c, one of the public exploit programs that emerged to demonstrate and exercise the flaw in the days and weeks following Microsoft's July 16th advisory. According to data gathered by (SecurityFocus publisher) Symantec's DeepSight network of intrusion detection systems, by Thursday afternoon the worm had infected over 330,000 Windows XP and Windows 2000 machines.
As nasty as that is, security experts say it could have been much worse: the worm is hampered by clumsy construction, and it does not contain a malicious payload to damage victim's files. Moreover, in its reckless tear through cyberspace Blaster is accomplishing what a month of warnings from the security community, an unprecedented mass-e-mail campaign by Microsoft, and two advisories from the Department of Homeland Security all failed to do: it's forcing companies and consumers to install the patch for the serious RPC DCOM vulnerability, shutting down computer intruders who've had their pick of these systems for weeks.
http://www.securityfocus.com/news/6728
Thursday, August 14, 2003
Photos.com, unlimited downloads of the 60,000 photos, for only $299.95
You know that high-quality stock photos are not inexpensive, and yet bargain-priced images often don't have the quality you need for your Web or print design projects. Variety and image freshness are also important – when you're on a deadline, looking for just the right image, time is money.
This is why the subscription-based Photos.com site has proven so popular. Now you can take advantage of this special offer to obtain unlimited downloads of the 60,000 photos, for only $299.95 (a 40% savings) for an entire year. Photos are available in three convenient sizes, in such popular categories as business, health, technology, lifestyles and more. Why not try out a few of the free photos first, to make sure the image quality meets your needs?
Sign up by August 30, 2003 at www.photos.com/promo/andromeda to take advantage of this limited-time offer.
www.photos.com/promo/andromeda
You know that high-quality stock photos are not inexpensive, and yet bargain-priced images often don't have the quality you need for your Web or print design projects. Variety and image freshness are also important – when you're on a deadline, looking for just the right image, time is money.
This is why the subscription-based Photos.com site has proven so popular. Now you can take advantage of this special offer to obtain unlimited downloads of the 60,000 photos, for only $299.95 (a 40% savings) for an entire year. Photos are available in three convenient sizes, in such popular categories as business, health, technology, lifestyles and more. Why not try out a few of the free photos first, to make sure the image quality meets your needs?
Sign up by August 30, 2003 at www.photos.com/promo/andromeda to take advantage of this limited-time offer.
www.photos.com/promo/andromeda
Wednesday, August 13, 2003
Blasting Blaster
In mid-July, Microsoft supplied patches for a vulnerability in the DCOM Remote Procedure Call module that could allow a worm to download and run any program. Microsoft Windows NT4, 2000, XP, and Windows Server 2003 were affected. This Monday, machines without the patch became fair game for the fast-spreading Blaster worm. Blaster is set to launch a Distributed Denial of Service (DDoS) attack on windowsupdate.microsoft.com this Saturday, August 16th. You don't want to be a part of that, so be sure you have the patch installed.
But what if your system is one of tens of thousands already compromised by Blaster? You may not be able to install the patch, or to do much of anything. On most machines Blaster triggers a Windows shut down sequence with a 60-second warning, leaving no time for downloading. Your first step is to abort the shutdown by entering the command "shutdown /a" (no quotes) in the Start menu's Run dialog. With the countdown halted, you can try the free removal tool from Symantec or do the job by hand.
http://www.microsoft.com/security/security_bulletins/ms03-026.asp
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
http://www.pcmag.com/article2/0,4149,1217751,00.asp
In mid-July, Microsoft supplied patches for a vulnerability in the DCOM Remote Procedure Call module that could allow a worm to download and run any program. Microsoft Windows NT4, 2000, XP, and Windows Server 2003 were affected. This Monday, machines without the patch became fair game for the fast-spreading Blaster worm. Blaster is set to launch a Distributed Denial of Service (DDoS) attack on windowsupdate.microsoft.com this Saturday, August 16th. You don't want to be a part of that, so be sure you have the patch installed.
But what if your system is one of tens of thousands already compromised by Blaster? You may not be able to install the patch, or to do much of anything. On most machines Blaster triggers a Windows shut down sequence with a 60-second warning, leaving no time for downloading. Your first step is to abort the shutdown by entering the command "shutdown /a" (no quotes) in the Start menu's Run dialog. With the countdown halted, you can try the free removal tool from Symantec or do the job by hand.
http://www.microsoft.com/security/security_bulletins/ms03-026.asp
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
http://www.pcmag.com/article2/0,4149,1217751,00.asp
Blaster Worm on the Move
The Blaster worm continued to tear through the Internet Tuesday morning as security experts struggled to find and fix infected systems. The worm is presenting a unique problem for security specialists because it is infecting a large number of PCs owned by home users, many of whom may be unaware that their machines are compromised.
And because Blaster's scanning algorithm tends to start by looking for IP addresses that are close to the infected machine's, the worm can rattle around inside a local network for quite a while, consuming bandwidth.
Officials at the CERT Coordination Center estimated that the number of infected machines is in the hundreds of thousands and will continue to grow. "A large number of the compromised machines are those of home users. In this case it isn't as easy as downloading a patch because they can't get enough bandwidth to get online and get the patch," said Marty Lindner, team leader for incident handling at CERT, based at Carnegie Mellon University in Pittsburgh.
"The compromise has a harder time getting out of the local network, so it's harder to measure how many machines are infected."
Blaster began spreading early Monday afternoon Eastern time and quickly gained momentum. The worm exploits the RPC DCOM (Distributed Component Object Model) vulnerability in all of the current versions of Windows, except ME. The worm scans the Internet and attempts to connect to TCP port 135. After establishing a connection, Blaster spawns a remote shell on port 4444 and then uses TFTP (Trivial File Transfer Protocol) to download the actual binary containing the worm. The worm is self-extracting and immediately begins scanning for other machines to infect.
For users who cannot free up enough bandwidth to download the patch from Microsoft Corp., CERT recommends an alternative remedy. Users should physically disconnect the infected machine from the Internet or network. Then, kill the running copy of "msblast.exe" in the Task Manager utility. Users should then disable DCOM and reconnect to the Internet and download the patch.
Instructions for disabling DCOM are available at Microsoft's Knowledge Base Web site.
http://support.microsoft.com/default.aspx?scid=kb;[LN];825750
http://www.eweek.com/article2/0,3959,1217020,00.asp
The Blaster worm continued to tear through the Internet Tuesday morning as security experts struggled to find and fix infected systems. The worm is presenting a unique problem for security specialists because it is infecting a large number of PCs owned by home users, many of whom may be unaware that their machines are compromised.
And because Blaster's scanning algorithm tends to start by looking for IP addresses that are close to the infected machine's, the worm can rattle around inside a local network for quite a while, consuming bandwidth.
Officials at the CERT Coordination Center estimated that the number of infected machines is in the hundreds of thousands and will continue to grow. "A large number of the compromised machines are those of home users. In this case it isn't as easy as downloading a patch because they can't get enough bandwidth to get online and get the patch," said Marty Lindner, team leader for incident handling at CERT, based at Carnegie Mellon University in Pittsburgh.
"The compromise has a harder time getting out of the local network, so it's harder to measure how many machines are infected."
Blaster began spreading early Monday afternoon Eastern time and quickly gained momentum. The worm exploits the RPC DCOM (Distributed Component Object Model) vulnerability in all of the current versions of Windows, except ME. The worm scans the Internet and attempts to connect to TCP port 135. After establishing a connection, Blaster spawns a remote shell on port 4444 and then uses TFTP (Trivial File Transfer Protocol) to download the actual binary containing the worm. The worm is self-extracting and immediately begins scanning for other machines to infect.
For users who cannot free up enough bandwidth to download the patch from Microsoft Corp., CERT recommends an alternative remedy. Users should physically disconnect the infected machine from the Internet or network. Then, kill the running copy of "msblast.exe" in the Task Manager utility. Users should then disable DCOM and reconnect to the Internet and download the patch.
Instructions for disabling DCOM are available at Microsoft's Knowledge Base Web site.
http://support.microsoft.com/default.aspx?scid=kb;[LN];825750
http://www.eweek.com/article2/0,3959,1217020,00.asp
MediaSavvy
The online ad boom could delay content charges
Right now, there is more money to be made selling ads online than selling news.
With online advertising continuing to climb (Emarketer says online ad spending will be up 4.8% in 2003), and with online newspapers getting an outsized share of that growth, who is going to be willing to jeopardize their seat on the gravy train by charging for content?…
http://mediasavvy.com/archives/000412.shtml#000412
The online ad boom could delay content charges
Right now, there is more money to be made selling ads online than selling news.
With online advertising continuing to climb (Emarketer says online ad spending will be up 4.8% in 2003), and with online newspapers getting an outsized share of that growth, who is going to be willing to jeopardize their seat on the gravy train by charging for content?…
http://mediasavvy.com/archives/000412.shtml#000412
checkinstall
…it's not always easy to get ready-made binary packages. Checkinstall handles that problem by building a binary package out of a compiled source tree. Where you normally do the ./configure && make && make install routine to build a package, checkinstall intercepts the make install part and builds a package ready for installation in Red Hat, Debian, Slackware, or RPM-based distributions. That way, when your vendor finally does catch up, you can remove the package with a single command (instead of hunting its components down by hand) and install the new binary package without a hassle. Good stuff.
After you ./configure; make your program, CheckInstall will run make install (or whatever you tell it to run) and keep track of every file modified by this installation, using the excelent installwatch utility written by Pancrazio 'Ezio' de Mauro (p@demauro.net).
When make install is done, CheckInstall will create a Slackware, RPM or Debian compatible package and install it with Slackware's installpkg, "rpm -i" or Debian's "dpkg -i" as appropriate, so you can view it's contents with pkgtool ("rpm -ql" for RPM users or "dpkg -l" for Debian) or remove it with removepkg ("rpm -e"|"dpkg -r"). Aditionally, this script will leave you a copy of the installed package in the source directory so you can install it wherever you want, which is my second motivation: I don't have to compile the same software again and again every time I need to install it on another box :-).
http://asic-linux.com.mx/~izto/checkinstall/
…it's not always easy to get ready-made binary packages. Checkinstall handles that problem by building a binary package out of a compiled source tree. Where you normally do the ./configure && make && make install routine to build a package, checkinstall intercepts the make install part and builds a package ready for installation in Red Hat, Debian, Slackware, or RPM-based distributions. That way, when your vendor finally does catch up, you can remove the package with a single command (instead of hunting its components down by hand) and install the new binary package without a hassle. Good stuff.
After you ./configure; make your program, CheckInstall will run make install (or whatever you tell it to run) and keep track of every file modified by this installation, using the excelent installwatch utility written by Pancrazio 'Ezio' de Mauro (p@demauro.net).
When make install is done, CheckInstall will create a Slackware, RPM or Debian compatible package and install it with Slackware's installpkg, "rpm -i" or Debian's "dpkg -i" as appropriate, so you can view it's contents with pkgtool ("rpm -ql" for RPM users or "dpkg -l" for Debian) or remove it with removepkg ("rpm -e"|"dpkg -r"). Aditionally, this script will leave you a copy of the installed package in the source directory so you can install it wherever you want, which is my second motivation: I don't have to compile the same software again and again every time I need to install it on another box :-).
http://asic-linux.com.mx/~izto/checkinstall/
Monday, August 11, 2003
Download and Build Quake II for .NET
Vertigo Software Inc. has released Quake II .NET, a version of id Software's popular Quake II game ported to the Microsoft .NET common language runtime (CLR) using Microsoft Visual C++ .NET 2003.
Download Quake II .NET from Vertigo Software, Inc., including full source code and project files for Visual C++ .NET 2003, as well as a white paper describing the effort.
This application demonstrates the powerful capability of Visual C++ to retarget existing C++ code at the .NET CLR with little effort. It shows how a highly performance-critical application like Quake II can retain these characteristics in the CLR environment, while simultaneously offering new features implemented using the .NET Framework.
Download Quake II .NET from Vertigo Software, Inc.
http://www.vertigosoftware.com/Quake2.htm
http://msdn.microsoft.com/visualc/quake/
Vertigo Software Inc. has released Quake II .NET, a version of id Software's popular Quake II game ported to the Microsoft .NET common language runtime (CLR) using Microsoft Visual C++ .NET 2003.
Download Quake II .NET from Vertigo Software, Inc., including full source code and project files for Visual C++ .NET 2003, as well as a white paper describing the effort.
This application demonstrates the powerful capability of Visual C++ to retarget existing C++ code at the .NET CLR with little effort. It shows how a highly performance-critical application like Quake II can retain these characteristics in the CLR environment, while simultaneously offering new features implemented using the .NET Framework.
Download Quake II .NET from Vertigo Software, Inc.
http://www.vertigosoftware.com/Quake2.htm
http://msdn.microsoft.com/visualc/quake/
Sunday, August 10, 2003
Photo Album Script Generator
This program automatically generates HTML codes for a customized photo gallery. HTML developers, who do not have much time to write codes or want to use a simple personal photo gallery, can use it. For Microsoft Internet Explorer 5+, Netscape Navigator 6+, Opera 6+ and Mozilla 1.2+.
http://javascript.internet.com/miscellaneous/photo-album-script-generator.html
This program automatically generates HTML codes for a customized photo gallery. HTML developers, who do not have much time to write codes or want to use a simple personal photo gallery, can use it. For Microsoft Internet Explorer 5+, Netscape Navigator 6+, Opera 6+ and Mozilla 1.2+.
http://javascript.internet.com/miscellaneous/photo-album-script-generator.html
Friday, August 08, 2003
New Tool Roots Out SCO Code
With legal terms such as liability, indemnification and lawsuit as prominent themes of the LinuxWorld show here, a small software company has addressed the issue with a solution to find offensive code.
Aduva Inc., Sunnyvale, Calif., has developed a system known as OnStage that contains a feature known as SCO Check that will "conduct a complete inventory of your system and if SCO [The SCO Group] identifies some illegal code, we can do a check to find the code, identify it and then automate the replacement of that code" with Red Hat Linux or an appropriate fix, said Chris Van Tuin, director of customer service for Aduva.
In addition, Aduva also announced SoundCheck, a snippet of the OnStage technology the company is delivering for free. SoundCheck scans Linux servers and identifies potential problems, such as missing dependencies, security issues and unaccepted bug fixes that could cause application failures or security leaks. It is available for download free of charge at www.aduva.com/soundcheck.
http://www.eweek.com/article2/0,3959,1212134,00.asp
With legal terms such as liability, indemnification and lawsuit as prominent themes of the LinuxWorld show here, a small software company has addressed the issue with a solution to find offensive code.
Aduva Inc., Sunnyvale, Calif., has developed a system known as OnStage that contains a feature known as SCO Check that will "conduct a complete inventory of your system and if SCO [The SCO Group] identifies some illegal code, we can do a check to find the code, identify it and then automate the replacement of that code" with Red Hat Linux or an appropriate fix, said Chris Van Tuin, director of customer service for Aduva.
In addition, Aduva also announced SoundCheck, a snippet of the OnStage technology the company is delivering for free. SoundCheck scans Linux servers and identifies potential problems, such as missing dependencies, security issues and unaccepted bug fixes that could cause application failures or security leaks. It is available for download free of charge at www.aduva.com/soundcheck.
http://www.eweek.com/article2/0,3959,1212134,00.asp
Prevent data loss on XP workstations with large hard drives
When hard drives first became standard on PCs, they were commonly only around 10 MB in size. Today, depending on your organization, you might have users with ATA hard drives sizes well in excess of 100 GB, with individual data file sizes that dwarf the hard drives of old. Unfortunately, Windows XP can encounter problems with large hard drives. To avoid losing data on large hard drives on XP workstations, you should obtain and install the latest patch from Microsoft.
What's the problem?
If you have or support systems with ATA hard drive sizes exceeding 137 GB running any version of Windows XP or XP with Service Pack 1—Home, Professional, Media Center Edition, Tablet PC Edition, or 64-bit Edition—you may be at risk from a flaw in the operating system. This flaw may become apparent when the system enters Hibernation/Standby mode or after a memory dump is written out to the disk.
It's important to note that you aren't likely to run into this problem in XP without SP1, because only SP1 has native support for drives exceeding the 137-GB limit. While support can be enabled in pre-SP1 XP installations, this isn't recommended outside a test lab.
Only ATA drives are affected by this flaw. If you're running systems exclusively with SCSI drives, you aren't at risk.
To make use of the space beyond the old 137-GB limit, Windows XP SP1 uses 48-bit logical block addressing (LBA). Unfortunately, the processes that write the memory dump and Hibernation/Standby files do not write their data to the disk using 48-bit LBA. Moreover, when a Windows XP SP1 system with 48-bit LBA enabled enters Hibernation, Windows fails to issue a flush cache command to the IDE system's cache. As a result, any information still in the cache won't be written to the disk.
There are a number of symptoms that you can watch for to determine whether you're suffering from this flaw. If your system restarts rather than waking up from Hibernation, or if you experience data corruption upon entering Hibernation/Standby mode or after a memory dump or stop error, you may be afflicted. Data corruption can manifest itself in a variety of ways including problems starting the system, shutting down the system, running programs, or opening and/or saving files.…
Windows XP Patch: Hard Disk May Become Corrupted When Entering Standby or Hibernation
http://www.microsoft.com/downloads/details.aspx?FamilyID=b997cc5f-4483-4edc-a17e-6f659a033b0d&DisplayLang=en
http://techrepublic.com.com/5102-6255-5055171.html
When hard drives first became standard on PCs, they were commonly only around 10 MB in size. Today, depending on your organization, you might have users with ATA hard drives sizes well in excess of 100 GB, with individual data file sizes that dwarf the hard drives of old. Unfortunately, Windows XP can encounter problems with large hard drives. To avoid losing data on large hard drives on XP workstations, you should obtain and install the latest patch from Microsoft.
What's the problem?
If you have or support systems with ATA hard drive sizes exceeding 137 GB running any version of Windows XP or XP with Service Pack 1—Home, Professional, Media Center Edition, Tablet PC Edition, or 64-bit Edition—you may be at risk from a flaw in the operating system. This flaw may become apparent when the system enters Hibernation/Standby mode or after a memory dump is written out to the disk.
It's important to note that you aren't likely to run into this problem in XP without SP1, because only SP1 has native support for drives exceeding the 137-GB limit. While support can be enabled in pre-SP1 XP installations, this isn't recommended outside a test lab.
Only ATA drives are affected by this flaw. If you're running systems exclusively with SCSI drives, you aren't at risk.
To make use of the space beyond the old 137-GB limit, Windows XP SP1 uses 48-bit logical block addressing (LBA). Unfortunately, the processes that write the memory dump and Hibernation/Standby files do not write their data to the disk using 48-bit LBA. Moreover, when a Windows XP SP1 system with 48-bit LBA enabled enters Hibernation, Windows fails to issue a flush cache command to the IDE system's cache. As a result, any information still in the cache won't be written to the disk.
There are a number of symptoms that you can watch for to determine whether you're suffering from this flaw. If your system restarts rather than waking up from Hibernation, or if you experience data corruption upon entering Hibernation/Standby mode or after a memory dump or stop error, you may be afflicted. Data corruption can manifest itself in a variety of ways including problems starting the system, shutting down the system, running programs, or opening and/or saving files.…
Windows XP Patch: Hard Disk May Become Corrupted When Entering Standby or Hibernation
http://www.microsoft.com/downloads/details.aspx?FamilyID=b997cc5f-4483-4edc-a17e-6f659a033b0d&DisplayLang=en
http://techrepublic.com.com/5102-6255-5055171.html
Thursday, August 07, 2003
Microsoft Windows XP Peer-to-Peer Downloads
The new Windows XP Peer-to-Peer SDK and the related Advanced Networking Pack for Windows XP will help developers create advanced networking applications. The SDK provides documentation and sample code while the Pack adds advanced networking support to the XP client, including enhanced IPv6 support, APIs for Peer-to-Peer name resolution, network graphing, grouping, and identity management. This SDK will help developers to create decentralized applications that harness the collective power of edge of the network PCs.
Microsoft Windows XP Peer-to-Peer Software Development Kit (SDK)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5116A614-A487-4DFF-B384-829CD8CE977D&displaylang=en
The Windows XP Peer-to-Peer SDK provides documentation, sample code and other tools that allow developers to build peer-to-peer applications or services that capitalize on the new Advanced Networking Pack for Windows XP available for users.
Note: In order to run applications built with the Windows XP Peer-to-Peer SDK, the Advanced Networking Pack for Windows XP must be installed.
Date: July 23, 2003
Microsoft Advanced Networking Pack for Windows XP
http://www.microsoft.com/downloads/details.aspx?FamilyId=E88CC382-8CE6-4739-97C0-1A52A6F005E4&displaylang=en
The Advanced Networking Pack for Windows XP is a set of platform technologies designed to run on Windows XP to enable the use and deployment of distributed, peer-to-peer applications based on Internet standards. The update includes a new version of the IPv6 stack, including support for NAT traversal for IPv6 applications. An IPv6 firewall is included to protect the end-user's machine from unsolicited IPv6 traffic, while the peer-to-peer platform makes it simple to write distributed solutions.
Date: July 23, 2003
http://msdn.microsoft.com/library/default.asp?url=/downloads/list/winxppeer.asp
The new Windows XP Peer-to-Peer SDK and the related Advanced Networking Pack for Windows XP will help developers create advanced networking applications. The SDK provides documentation and sample code while the Pack adds advanced networking support to the XP client, including enhanced IPv6 support, APIs for Peer-to-Peer name resolution, network graphing, grouping, and identity management. This SDK will help developers to create decentralized applications that harness the collective power of edge of the network PCs.
Microsoft Windows XP Peer-to-Peer Software Development Kit (SDK)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5116A614-A487-4DFF-B384-829CD8CE977D&displaylang=en
The Windows XP Peer-to-Peer SDK provides documentation, sample code and other tools that allow developers to build peer-to-peer applications or services that capitalize on the new Advanced Networking Pack for Windows XP available for users.
Note: In order to run applications built with the Windows XP Peer-to-Peer SDK, the Advanced Networking Pack for Windows XP must be installed.
Date: July 23, 2003
Microsoft Advanced Networking Pack for Windows XP
http://www.microsoft.com/downloads/details.aspx?FamilyId=E88CC382-8CE6-4739-97C0-1A52A6F005E4&displaylang=en
The Advanced Networking Pack for Windows XP is a set of platform technologies designed to run on Windows XP to enable the use and deployment of distributed, peer-to-peer applications based on Internet standards. The update includes a new version of the IPv6 stack, including support for NAT traversal for IPv6 applications. An IPv6 firewall is included to protect the end-user's machine from unsolicited IPv6 traffic, while the peer-to-peer platform makes it simple to write distributed solutions.
Date: July 23, 2003
http://msdn.microsoft.com/library/default.asp?url=/downloads/list/winxppeer.asp
What's the problem with CGI scripts?
The problem with CGI scripts is that each one presents yet another opportunity for exploitable bugs. CGI scripts should be written with the same care and attention given to Internet servers themselves, because, in fact, they are miniature servers. Unfortunately, for many Web authors, CGI scripts are their first encounter with network programming.
CGI scripts can present security holes in two ways:
They may intentionally or unintentionally leak information about the host system that will help hackers break in.
Scripts that process remote user input, such as the contents of a form or a "searchable index" command, may be vulnerable to attacks in which the remote user tricks them into executing commands.
CGI scripts are potential security holes even though you run your server as "nobody". A subverted CGI script running as "nobody" still has enough privileges to mail out the system password file, examine the network information maps, or launch a log-in session on a high numbered port (it just needs to execute a few commands in Perl to accomplish this). Even if your server runs in a chroot directory, a buggy CGI script can leak sufficient system information to compromise the host.
http://www.w3.org/Security/faq/wwwsf4.html
The problem with CGI scripts is that each one presents yet another opportunity for exploitable bugs. CGI scripts should be written with the same care and attention given to Internet servers themselves, because, in fact, they are miniature servers. Unfortunately, for many Web authors, CGI scripts are their first encounter with network programming.
CGI scripts can present security holes in two ways:
They may intentionally or unintentionally leak information about the host system that will help hackers break in.
Scripts that process remote user input, such as the contents of a form or a "searchable index" command, may be vulnerable to attacks in which the remote user tricks them into executing commands.
CGI scripts are potential security holes even though you run your server as "nobody". A subverted CGI script running as "nobody" still has enough privileges to mail out the system password file, examine the network information maps, or launch a log-in session on a high numbered port (it just needs to execute a few commands in Perl to accomplish this). Even if your server runs in a chroot directory, a buggy CGI script can leak sufficient system information to compromise the host.
http://www.w3.org/Security/faq/wwwsf4.html
Tuesday, August 05, 2003
SCO's Smoking-Gun Tour
Is SCO's smoking gun against IBM a sheet of 8 x 11 paper with pertinent lines of programming highlighted in red and blue?
This code, which was allegedly lifted almost verbatim from Unix to Linux, belongs to a large unnamed hardware vendor that isn't IBM, according to SCO, which was waving it around late in July.
But SCO argues it is evidence that many companies are violating its intellectual property, says Chris Sontag, general manager for SCO's SCOsource unit. SCO acquired not just the source code for Unix System 5 from AT&T years ago—but the contracts that pertain to its use by commercial software and hardware makers.
Sontag is making the rounds with press and analysts, arguing IBM is the "ringleader," something akin to an industrywide porting of Unix to Linux without permission.
His presentation boils down to this: IBM "donated" some of the functionality from its own Unix variant, known as AIX, to Linux version 2.4 and beyond. This helped the open-source software grow to handle nonuniform memory access (NUMA), journal file system and other important features for an operating system asked to be a workhorse of enterprise computers. "How did this happen in that short of time?" asks Sontag. "A third or more of the Linux 2.4 kernel is at issue."
According to Sontag, IBM, along with other vendors, gave Linux a helping hand and violated a "derivatives clause" in the contracts for using Unix System 5. The contracts appear to say the source code can be only used for internal purposes and can't be redistributed elsewhere.
http://www.baselinemag.com/article2/0,3959,1208916,00.asp
Is SCO's smoking gun against IBM a sheet of 8 x 11 paper with pertinent lines of programming highlighted in red and blue?
This code, which was allegedly lifted almost verbatim from Unix to Linux, belongs to a large unnamed hardware vendor that isn't IBM, according to SCO, which was waving it around late in July.
But SCO argues it is evidence that many companies are violating its intellectual property, says Chris Sontag, general manager for SCO's SCOsource unit. SCO acquired not just the source code for Unix System 5 from AT&T years ago—but the contracts that pertain to its use by commercial software and hardware makers.
Sontag is making the rounds with press and analysts, arguing IBM is the "ringleader," something akin to an industrywide porting of Unix to Linux without permission.
His presentation boils down to this: IBM "donated" some of the functionality from its own Unix variant, known as AIX, to Linux version 2.4 and beyond. This helped the open-source software grow to handle nonuniform memory access (NUMA), journal file system and other important features for an operating system asked to be a workhorse of enterprise computers. "How did this happen in that short of time?" asks Sontag. "A third or more of the Linux 2.4 kernel is at issue."
According to Sontag, IBM, along with other vendors, gave Linux a helping hand and violated a "derivatives clause" in the contracts for using Unix System 5. The contracts appear to say the source code can be only used for internal purposes and can't be redistributed elsewhere.
http://www.baselinemag.com/article2/0,3959,1208916,00.asp
Even Antivirus Scanners Make Mistakes
Security fundamentally requires trust. You can't function without trusting some other users and some programs. On the other hand, you can't completely trust everything, and that includes normally trustworthy software, such as Symantec's Norton AntiVirus.
http://security.ziffdavis.com/article2/0,3973,1203522,00.asp
Security fundamentally requires trust. You can't function without trusting some other users and some programs. On the other hand, you can't completely trust everything, and that includes normally trustworthy software, such as Symantec's Norton AntiVirus.
http://security.ziffdavis.com/article2/0,3973,1203522,00.asp
Microsoft Security Bulletin MS03-026 Print
Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
Originally posted: July 16, 2003
Revised: July 21, 2003
Summary
Who should read this bulletin: Users running Microsoft ® Windows ®
Impact of vulnerability: Run code of attacker’s choice
Maximum Severity Rating: Critical
Recommendation: Systems administrators should apply the patch immediately
End User Bulletin: An end user version of this bulletin is available at:
http://www.microsoft.com/security/security_bulletins/ms03-026.asp.
Affected Software:
Microsoft Windows NT® 4.0
Microsoft Windows NT 4.0 Terminal Services Edition
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server™ 2003
Not Affected Software:
Microsoft Windows Millennium Edition
Microsoft originally released this bulletin and patch on July 16, 2003 to correct a security vulnerability in a Windows Distributed Component Object Model (DCOM) Remote Procedure Call (RPC) interface. The patch was and still is effective in eliminating the security vulnerability. However, the “mitigating factors” and “workarounds” discussions in the original security bulletin did not clearly identify all of the ports by which the vulnerability could potentially be exploited. We have updated this bulletin to more clearly enumerate the ports over which RPC services can be invoked, and to ensure that customers who have chosen to implement a workaround before installing the patch have the information that they need to protect their systems. Customers who have already installed the patch are protected from attempts to exploit this vulnerability, and need take no further action.
Remote Procedure Call (RPC) is a protocol used by the Windows operating system. RPC provides an inter-process communication mechanism that allows a program running on one computer to seamlessly execute code on a remote system. The protocol itself is derived from the Open Software Foundation (OSF) RPC protocol, but with the addition of some Microsoft specific extensions.
There is a vulnerability in the part of RPC that deals with message exchange over TCP/IP. The failure results because of incorrect handling of malformed messages. This particular vulnerability affects a Distributed Component Object Model (DCOM) interface with RPC, which listens on RPC enabled ports. This interface handles DCOM object activation requests that are sent by client machines to the server. An attacker who successfully exploited this vulnerability would be able to run code with Local System privileges on an affected system. The attacker would be able to take any action on the system, including installing programs, viewing changing or deleting data, or creating new accounts with full privileges.
http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-026.asp
Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
Originally posted: July 16, 2003
Revised: July 21, 2003
Summary
Who should read this bulletin: Users running Microsoft ® Windows ®
Impact of vulnerability: Run code of attacker’s choice
Maximum Severity Rating: Critical
Recommendation: Systems administrators should apply the patch immediately
End User Bulletin: An end user version of this bulletin is available at:
http://www.microsoft.com/security/security_bulletins/ms03-026.asp.
Affected Software:
Microsoft Windows NT® 4.0
Microsoft Windows NT 4.0 Terminal Services Edition
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server™ 2003
Not Affected Software:
Microsoft Windows Millennium Edition
Microsoft originally released this bulletin and patch on July 16, 2003 to correct a security vulnerability in a Windows Distributed Component Object Model (DCOM) Remote Procedure Call (RPC) interface. The patch was and still is effective in eliminating the security vulnerability. However, the “mitigating factors” and “workarounds” discussions in the original security bulletin did not clearly identify all of the ports by which the vulnerability could potentially be exploited. We have updated this bulletin to more clearly enumerate the ports over which RPC services can be invoked, and to ensure that customers who have chosen to implement a workaround before installing the patch have the information that they need to protect their systems. Customers who have already installed the patch are protected from attempts to exploit this vulnerability, and need take no further action.
Remote Procedure Call (RPC) is a protocol used by the Windows operating system. RPC provides an inter-process communication mechanism that allows a program running on one computer to seamlessly execute code on a remote system. The protocol itself is derived from the Open Software Foundation (OSF) RPC protocol, but with the addition of some Microsoft specific extensions.
There is a vulnerability in the part of RPC that deals with message exchange over TCP/IP. The failure results because of incorrect handling of malformed messages. This particular vulnerability affects a Distributed Component Object Model (DCOM) interface with RPC, which listens on RPC enabled ports. This interface handles DCOM object activation requests that are sent by client machines to the server. An attacker who successfully exploited this vulnerability would be able to run code with Local System privileges on an affected system. The attacker would be able to take any action on the system, including installing programs, viewing changing or deleting data, or creating new accounts with full privileges.
http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-026.asp
Monday, August 04, 2003
Attack bot strikes Windows flaw
Online vandals are using a program to compromise Windows servers and remotely control them through Internet relay chat (IRC) networks, system administrators said Saturday.
Several programs, including one that exploits a recent vulnerability in computers running Windows, have been cobbled together to create a remote attack tool. The tool takes commands from an attacker through the IRC networks and can scan for and compromise computers vulnerable to the recently discovered flaw in Windows.
Files left behind on a compromised server by the worm were posted to a security mailing list. Computer security company Symantec analyzed the files and determined that what was first thought to be a worm was actually an attack program.
Based on our analysis, the threat does not appear to be a worm," said Oliver Friedrichs, senior manager for Symantec's security response team. "It doesn't go and try to spread." Friedrichs was in Las Vegas attending the Black Hat Briefings and DefCon hacking conferences.
The ability to spread automatically is the hallmark of a computer worm. The collection of programs that Symantec analyzed is a tool that compromises computers and is referred to as an autorooter. It also acts like an IRC bot, listening to specific channels on the chat network and taking commands from attackers via IRC.
The initial post describing what security researchers thought might be a worm appeared at 10 a.m. PDT Saturday on the Full-Disclosure security list.
The tool consists of six files that work together to find vulnerable systems and attack them. Ever since the Windows flaw was announced, security researchers widely expected a worm to be written to exploit it. The IRC bot is one step removed from a worm and less disruptive.
This bot compromises computers using a flaw that Microsoft warned the public about on July 16.
The flaw is in the distributed component object model (DCOM) interface, a part of the OS that allows other computers to request the system to perform an action or service. The object, known as the remote procedure call (RPC) process, facilitates activities such as sharing files and allowing others to use the computer's printer. By sending too much data to the DCOM interface, an attacker can cause the system to grant full access to the computer.
A week ago, hackers from the Chinese X-Focus security group publicly posted a program to several security lists designed to allow an intruder to use the vulnerability to break into Windows computers. The Windows flaw has been characterized by some security experts as the most widespread ever found in Windows. In the past week, security researchers and hackers have been refining the exploit code.
That program is one of the six that make up the tool. The files include rpc.exe, rpctest.exe, tftpd.exe, worm.exe, lolx.exe and dcomx.exe. Although one of the programs sports the name "worm.exe," the resulting set of files is not a worm, because it doesn't spread automatically, Friedrichs said.
http://zdnet.com.com/2100-1105_2-5059263.html
Online vandals are using a program to compromise Windows servers and remotely control them through Internet relay chat (IRC) networks, system administrators said Saturday.
Several programs, including one that exploits a recent vulnerability in computers running Windows, have been cobbled together to create a remote attack tool. The tool takes commands from an attacker through the IRC networks and can scan for and compromise computers vulnerable to the recently discovered flaw in Windows.
Files left behind on a compromised server by the worm were posted to a security mailing list. Computer security company Symantec analyzed the files and determined that what was first thought to be a worm was actually an attack program.
Based on our analysis, the threat does not appear to be a worm," said Oliver Friedrichs, senior manager for Symantec's security response team. "It doesn't go and try to spread." Friedrichs was in Las Vegas attending the Black Hat Briefings and DefCon hacking conferences.
The ability to spread automatically is the hallmark of a computer worm. The collection of programs that Symantec analyzed is a tool that compromises computers and is referred to as an autorooter. It also acts like an IRC bot, listening to specific channels on the chat network and taking commands from attackers via IRC.
The initial post describing what security researchers thought might be a worm appeared at 10 a.m. PDT Saturday on the Full-Disclosure security list.
The tool consists of six files that work together to find vulnerable systems and attack them. Ever since the Windows flaw was announced, security researchers widely expected a worm to be written to exploit it. The IRC bot is one step removed from a worm and less disruptive.
This bot compromises computers using a flaw that Microsoft warned the public about on July 16.
The flaw is in the distributed component object model (DCOM) interface, a part of the OS that allows other computers to request the system to perform an action or service. The object, known as the remote procedure call (RPC) process, facilitates activities such as sharing files and allowing others to use the computer's printer. By sending too much data to the DCOM interface, an attacker can cause the system to grant full access to the computer.
A week ago, hackers from the Chinese X-Focus security group publicly posted a program to several security lists designed to allow an intruder to use the vulnerability to break into Windows computers. The Windows flaw has been characterized by some security experts as the most widespread ever found in Windows. In the past week, security researchers and hackers have been refining the exploit code.
That program is one of the six that make up the tool. The files include rpc.exe, rpctest.exe, tftpd.exe, worm.exe, lolx.exe and dcomx.exe. Although one of the programs sports the name "worm.exe," the resulting set of files is not a worm, because it doesn't spread automatically, Friedrichs said.
http://zdnet.com.com/2100-1105_2-5059263.html
Subscribe to:
Posts (Atom)
