Saturday, April 17, 2004

The New York Times > National > 9/11 Panel Calls Policies on Immigration Ineffective:
"The commission investigating the 9/11 attacks has concluded that immigration policies promoted as essential to keeping the country safe from future attacks have been largely ineffective, producing little, if any, information leading to the identification or apprehension of terrorists."

http://www.nytimes.com/2004/04/17/national/17IMMI.html?pagewanted=all&position=
EMediaLive.com Review: Editor's Choice-Ulead DVD Workshop 2.0:
"Compared to its peers, we found DVD Workshop much more accessible than Adobe Encore, while offering a greater range of design options. Workshop stands up well even if you throw Photoshop and After Effects into the creative mix, especially if you consider development efficiency."

http://www.emedialive.com/Newsletters/EMediaXtra.aspx?NewsletterID=152#9
Understanding and Choosing File Formats in Photoshop CS and Illustrator CS:
"Peter Bauer discusses file formats and their various capabilities, including information on which format to select for which purpose. "

regitration required

http://www.informit.com/articles/printerfriendly.asp?p=169496

Thursday, April 15, 2004

Data Recovery Software. NTFS Reader for DOS NTFS DOS. Freeware & Shareware.:
"NTFS Reader DOS Boot Disk provides read access to NTFS drives from the MS DOS environment. It supports long filenames as well as compressed and fragmented files. NTFS Reader for DOS allows you to preview the files on NTFS and copy them from NTFS to FAT volumes or network drives. In order to use the software you need to copy the readntfs.exe file to a bootable floppy disk and boot from it."

http://www.ntfs.com/products.htm
12 Short Steps Go a Long Way Toward Safeguarding Your Business:
"SMALL BUSINESS SECURITY CHECKLIST

Before you begin, make sure these recommendations concur with your security policy. If you don't have a security policy, learn why you should consider adopting one. "

http://www.microsoft.com/smallbusiness/gtm/securityguidance/hub.mspx
Manipulate the User Agent for Accurate Site Stats:
"If you implement any sort of hit monitoring or tracking on your Website, you probably don't want to include any of your own hits."

Ordinarily, you could set a "self-specific" cookie. Then, when the tracking script was called, you could simply check to see if that cookie existed, and, if it did, exit the tracking script.

However, if, like me, you're frankly scared of cookies on the grounds that they:

are difficult to test with,

are called something silly and

aren't 100% reliable

Furthermore, many Webmasters exclude from tracking certain browsers that are known not to work on their Websites. For example, many sites block any non-Internet Explorer or Netscape browsers, such as Mozilla's excellent new Firebird and a whole heap of others. Being able to manipulate the user agent to fool the Website into thinking we're using Internet Explorer 6.0 when we're really running Firebird 0.7 could be quite handy! …

http://www.sitepoint.com/print/site-stats-user-agent

Wednesday, April 14, 2004

ZDNet: Printer Friendly - Attackers infiltrating supercomputer networks:
"Unknown attackers have compromised a large number of Linux and Solaris machines in high-speed computing networks at Stanford University and other academic research facilities, according to an advisory.

The attacks, which apparently compromised servers as recently as April 3, are currently being investigated, according to an advisory posted April 6 by the Information Technology Systems and Services (ITSS) group at Stanford. "

The attacks start with the compromise of an unprivileged local user account. Usually this is because the attacker's captured the password from somewhere else: it's been sniffed off the network (through the use of insecure protocols like telnet), it's been collected when the user signs on to or from another compromised machine, it's been harvested from the password file on a compromised system.

If the target machine is behind on its patches, the attacker then uses one of a number of public exploits to elevate the unprivileged account to root status. Exploits target the Linux mremap() vulnerabilities, the Solaris kernel module loading vulnerability (for which an attack was made public on 8 Apr), and a Solaris priocntl() issue.

http://zdnet.com.com/2102-1105_2-5191024.html?tag=printthis
New Bugbear Virus finds New IE Hole:
"This has been a busy week for virus writers and antivirus vendors. We've seen some more Netsky and Bagle variants, as well as a number of new Trojans. However, the most prevalent has been last week's top threat Netsky.P, followed by Netsky.C and Netsky.D. While we haven't seen a wide distribution yet, a new Bugbear variety is starting to make the rounds?4Bugbear.C or Bugbear.E (depending on antivirus company reporting it). Bugbear.C attacks through an HTML attachment, and an unpatched Internet Explorer vulnerability. See our top threat for more information. "

Compared with PC users, Apple users have been fairly immune to viruses. However, a new "concept" Trojan is making waves in the Mac community. Intego, a security company announced the appearance of a new Trojan, MP3Concept. While Indego's press release describes potentially malicious payload the Trojan can have such as file deletion, sending e-mail, or infecting other MP3, Jpeg, GIF or QuickTime files, the MP3 Concept only shows a text message, and plays an MP3 of a man laughing. According to Symantec, the Trojan is not in the wild yet. Codemonkey takes a bit more of a swipe at Intego saying they are spreading FUD. The famous Nigerian 419 scam (also known as the advance payment scam) was in the news this week, with the conviction of one of the scammers. According to UK newspaper AllAfrica.com , Peter Okoeguale, a Nigerian living in Wales, was arrested for committing fraud. He was sentenced to 20 months, and faces deportation to Nigeria once freed. Unfortunately, this perpetrator is only one of probably hundreds or thousands of scammers preying on victims looking to make a fast buck. The Nigerian 419 scam, named after the Nigerian penal code covering fraud, comes in a number of varieties. Some offer a victim an investment in a Nigerian company, or a share of a large sum of money being spirited out of the country by an exiled high official. They often send the victim a forged or stolen check that the victim is to hold while they put up their own money. There are many web sites that explain and fight the scam. A quick search on Google for Nigerian Scam will bring up hundreds results. Peter Ferrie and Frederic Perriot, researchers at Symantec have just published an analysis of the Welchia.B (Nachi.B) worm in Virus Bulletin called "The Wormpire Strikes Back". Welchia.B attempts to be a good worm by removing other worm infections. The analysis is a terrific look under the hood of the virus, with a little Star Wars humor tossed in. If you're interested in a deeper understanding of worms in general, and Welchia in particular, take a look at Peter's whitepaper.

http://www.pcmag.com/print_article/0,1761,a=124102,00.asp
Cheaper Shared Hosting Imperils Security:
"How secure is that $16.95-a-month hosted Web account? Hosted servers, especially shared accounts, can pose real security problems. Some hosts are better than others, but with shared hosting, you basically have to keep your fingers crossed. "

http://www.eweek.com/article2/0,1759,1565792,00.asp

Tuesday, April 13, 2004

833786 - Steps that you can take to help identify and to help protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks:
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.

However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL."

http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
Magical Jelly Bean Software - Magical Jelly Bean Keyfinder v1.41:
"The Magical Jelly Bean Keyfinder is a freeware utility that retrieves your Product Key (cd key) used to install windows from your registry. It has the options to copy the key to clipboard, save it to a text file, or print it for safekeeping. It works on Windows 95, 98, ME, NT4, 2000, XP, Server 2003, Office 97, and Office XP. This version is a quick update to make it work with Windows Server 2003."

http://www.magicaljellybean.com/keyfinder.shtml

Monday, April 12, 2004

Internet Explorer 6 Security and Privacy Essentials:
"Protect your privacy and the security of your computer on the Web. The following topics are packed with information and easy-to-follow, practical instructions that explain how features in Internet Explorer 6 help make your Web browsing experience better. "

http://www.microsoft.com/windows/ie/using/howto/privacy/secprivessntl.asp

Friday, April 09, 2004

RealPlayer 10 Release Supports More Formats:
"RealNetworks Inc. on Wednesday released the latest version of its digital media player with support for all of the major Internet media formats, including those from competitors Microsoft Corp. and Apple Computer Inc.

RealNetworks of Seattle first announced RealPlayer 10 for Windows in January and said it would include support for playing music purchased through Apple's iTunes, working around Apple's digital rights management technology. "

http://www.eweek.com/article2/0,1759,1563416,00.asp
Researcher Claims Online Anti-virus Scanners Buggy:
"Online scanners from Symantec, McAfee and Panda all contain buffer overflows. One researcher claims an attacker could execute arbitrary code, another just that they could crash the browser. Panda reports their software has been fixed and Symantec denies there is a problem at all. "

http://www.eweek.com/article2/0,1759,1563092,00.asp
Authorama - Public Domain Books:
"Authorama.com, featuring completely free books from a variety of different authors, collected here for you to read online or offline. The books may have been published before, but not in this form, which I hope you find enjoyable to read and print."

http://www.authorama.com/

Thursday, April 08, 2004

Tax Center:
"American Express has created a Web site to help small-business owners learn about new tax developments and interact with other entrepreneurs on tax issues."

http://home3.americanexpress.com/smallbusiness/Landing/tax_center_main.asp?openvan=taxcenter

Wednesday, April 07, 2004

Attrition Security Rant: Anti-Virus Companies: Tenacious Spammers:
"For roughly three years, the Internet has seen worms that spread via e-mail, often taking addresses out of the infected machine's web cache, user addressbook or other sources. Some of these worms will also forge/spoof the 'From:' line so the mail appears to be from someone else, in an attempt to make the mail more 'trusted'. To be clear, here is a sample timeline of how these work:

EvilGuy01 writes and releases a new worm.

Fred is a moron and clicks on an attachment from a stranger, infecting his machine.

The worm mails a copy of itself to everyone in Fred's addressbook.

The mail sent out spoofs the headers of the mail so it may be 'From: George' or 'From: Sally'.

Tom gets a copy of the mail 'From: Sally' and clicks on the attachment, infecting himself.

Tom sends mail to Sally complaining about her evil shenanigans.

Sally replies to Tom with 'd00d WTF?! lol' since she never sent the mail. "

How enterprise AV systems add to the Internet traffic

But wait, it gets worse. Even if friends and family understand that I likely did not send them a virus, some enterprise antivirus program with built-in return messages will state emphatically that I have a virus. Here's how that works: As the forged e-mail enters their enterprise system, that system bounces it back to the apparent sender with a message that authoritatively states, "You are infected with XXX virus." I have hundreds of these bounced e-mail messages claiming that I am infected with MyDoom.f, Netsky.d, or Bagle.c. I'm not.

In the middle of an e-mail virus outbreak, messages such as these--originally intended to provide a useful service--only add to the Internet traffic jam. Brian Martin, a.k.a. Jericho at Attrition.org, wrote a thorough critique of the current methods being used, complete with examples. His conclusion? System administrators need to turn off this "helpful" feature if they haven't already.

Unfortunately, the spoofing problem itself lies deep under the hood of the Internet, within SMTP, Simple Mail Transfer Protocol, the Internet protocol used for sending e-mail. SMTP was created many years ago and lacks a modern method for verifying the authenticity of the sender. With a little finesse, almost anyone can manipulate the header information on an e-mail message to disguise its true origin and make it appear as though someone else sent you a message.

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5128975.html?tag=adss

http://www.attrition.org/security/rant/av-spammers.html
Microsoft Releases Source Code on SourceForge:
"On Monday, Microsoft released some of its code under an open-source license, and posted it on SourceForge, the open-source code repository.

To date, Microsoft has made its source code available under a variety of licensing mechanisms, all under its 'shared source' umbrella. But until today, the company had not released code under what is commonly considered a true open-source license."

Microsoft made available an internally-developed product called the "Windows Installer XML" (WiX) to SourceForge. The code is downloadable here.

WiX is a toolset for building Windows installation packages from XML source code. It runs on Windows NT and Windows 2000.…

http://sourceforge.net/projects/wix/

http://www.microsoft-watch.com/article2/0,1995,1561953,00.asp

Tuesday, April 06, 2004

Microsoft Security Newsletter For Home Users- Current Edition

http://www.microsoft.com/security/home/secnews/current.asp
Executive E-Mail: Current Edition:
"Microsoft Progress Report: Security

Malicious software code has been around for decades. But only in the last few years have the Internet, high-speed connections and millions of new computing devices converged to create a truly global computing network in which a virus or worm can circle the world in a matter of minutes.

Meanwhile, criminal hackers have become more sophisticated, creating and distributing digital epidemics like Slammer, Blaster, Sobig and Mydoom that spread almost instantaneously, threatening the potential of technology to advance business productivity, commerce and communication.

The kinds of threats are evolving too. Blaster, for example, hijacked individual computers, turning innocent users into unknowing and innocent worm propagators. These kinds of attacks – "swarming" attacks that are coordinated to cause multiplied, cascading effects – change the landscape of security threats. They put new demands on IT professionals and consumers to take preventative measures, and on the technology industry to continue to innovate and develop new solutions.…

Given human nature, evolving threat models and the increasing interconnectedness of computers, the number of security exploits will never reach zero. But we can dramatically blunt the impact of cybercriminals, and are dedicating a major portion of our R&D investments to security advances.…"

http://www.microsoft.com/mscorp/execmail/