Thursday, February 10, 2005

Microsoft releases critical security patches for Windows

Latest Security Bulletins - Released on February 8, 2005

Microsoft has released 12 Security Bulletins to mark the usual monthly release in February. A number of these bulletins address vulnerabilities which are classified as critical—three for Office, and seven for Windows.
http://techrepublic.com.com/5100-10595_11-5569345.html

MS05-015: Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
MS05-014: Cumulative Security Update for Internet Explorer (867282)
MS05-013: Vulnerability in the DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (891781)
MS05-012: Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-011: Vulnerability in Server Message Block Could Allow Remote Code Execution (885250)
MS05-010: Vulnerability in the License Logging Service Could Allow Code Execution (885834)
MS05-009: Vulnerability in PNG Processing Could Allow Remote Code Execution (890261)
MS05-008: Vulnerability in Windows Shell Could Allow Remote Code Execution (890047)
MS05-007: Vulnerability in Windows Could Allow Information Disclosure (888302)
MS05-006: Vulnerability in Windows SharePoint Services and SharePoint Team Services Could Allow Cross-Site Scripting and Spoofing Attacks (887981)
MS05-005: Vulnerability in Microsoft Office XP could allow Remote Code Execution (873352)
MS05-004: ASP.NET Path Validation Vulnerability (887219)


http://www.microsoft.com/technet/Security/default.mspx

Tuesday, February 08, 2005

Phishing flaw a danger to alternative browsers

By Robert Lemos
“A security weakness in a standard for handling special character sets in domain names could let an attacker spoof Web sites on non-Microsoft browsers, a researcher has warned.

The problem arises because certain browsers support a standardized way of representing domain names in the letters or characters of any language, security expert Eric Johanson said at the ShmooCon hacker convention this weekend. Called Internationalized Domain Names, the standard allows companies to register domain names that appear to be the same in different languages.

That encoding scheme could enable an attacker to create a fake Web site for a phishing scam. A spoofed link would seem to be a legitimate URL in the address bar of affected browsers--Opera, Apple Computer's Safari, and the Mozilla and Firefox browsers from the Mozilla Foundation. But instead of taking the victim to the trusted site, the link would lead to a phony Web site with a domain rendered as the same address under the IDN process.

The Mozilla Foundation is looking for a long-term solution to the issue, Chris Hofmann, director of engineering at the company, said in a statement.

"With the increase in phishing attacks, there is a growing concern that exploits could take advantage of this feature to trick users into visiting rogue sites," Hofmann stated. "Mozilla is looking at options for fixing or disabling this feature and should have more information available very soon."

Phishing attacks, which try to fool consumers into handing over sensitive information by creating legitimate-looking Web sites and e-mail messages, have become a central security concern recently. While vulnerabilities in Microsoft's Internet Explorer have been the focus of much of the concern, other browsers also have had their fair share of flaws.

The security weakness in the IDN scheme comes as registrars push for support for expressing domain names in different languages and scripts.

"There are now many ways to display any domain name on a browser, as there are a huge number of (character sets) which look very similar to Latin (characters)," Johanson said in an advisory.

The advisory demonstrates the attack using the domain for PayPal, but using an alternate Unicode character for the first "a." That gives an address that looks like "http://www.pàypal.com," but with a smaller "a."

Details of the flaw were shown at ShmooCon, a hacking and computer security convention, in Washington D.C., last weekend.

http://www.shmoo.com/idn/homograph.txt

Browser Bugs Spare Internet Explorer for a Change
By Larry Seltzer

The advisory announcing the vulnerability, which could facilitate phishing and other spoofing attacks, is related to IDN (International Domain Name) support in these browsers.

IDN allows for non-English lettering in domain names. It also allows for English lettering using non-English (unicode) character sets. Thus, in the proof-of-concept provided, when linked to "http://www.pаypal.com/" the browsers display "http://www.paypal.com/". But the browsers' handle it as "http://www.xn—pypal-4ve.com."

The advisory lists as vulnerable the following browsers:

  • Most Mozilla-based browsers (Firefox 1.0, Camino .8.5, Mozilla 1.6, etc.)
  • Safari 1.2.5
  • Opera 7.54
  • OmniWeb 5
http://www.eweek.com/article2/0,1759,1761502,00.asp?kc=ewnws020805dtx1k0000599


http://news.zdnet.com/2100-1009_22-5566517.html?tag=nl.e539

Google Maps

Google Maps offers maps, driving directions and the ability to search for local businesses. The search giant appears to be working with TeleAtlas for the mapping products. Neither Google nor TeleAtlas could be reached for comment.

The service offers a few tweaks to standard mapping products. Someone using the service can click and drag the maps, instead of having to click and reload, for example, and magnified views of specific spots pop up in bubbles. The new map service supports Internet Explorer and Mozilla browsers. It covers the United States, Puerto Rico and parts of Canada.

You can search for business and thel'll be marked on your map. You can print email or link to a results page.”

http://maps.google.com/

10 Immutable Laws of Security

“The Microsoft Security Response Center investigates thousands of security reports every year. In some cases, they find that a report describes a bona fide security vulnerability resulting from a flaw in one of our products; when this happens, they develop a patch as quickly as possible to correct the error. (See "A Tour of the Microsoft Security Response Center"). In other cases, the reported problems simply result from a mistake someone made in using the product. But many fall in between. They discuss real security problems, but the problems don't result from product flaws. Over the years, they've developed a list of issues like these, called the 10 Immutable Laws of Security.

Don't hold your breath waiting for a patch that will protect you from the issues we'll discuss below. It isn't possible for Microsoft—or any software vendor—to "fix" them, because they result from the way computers work. But don't abandon all hope yet—sound judgment is the key to protecting yourself against these issues, and if you keep them in mind, you can significantly improve the security of your systems.

On This Page
Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymoreLaw #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore
Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymoreLaw #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore
Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymoreLaw #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore
Law #4: If you allow a bad guy to upload programs to your website, it's not your website any moreLaw #4: If you allow a bad guy to upload programs to your website, it's not your website any more
Law #5: Weak passwords trump strong securityLaw #5: Weak passwords trump strong security
Law #6: A computer is only as secure as the administrator is trustworthyLaw #6: A computer is only as secure as the administrator is trustworthy
Law #7: Encrypted data is only as secure as the decryption keyLaw #7: Encrypted data is only as secure as the decryption key
Law #8: An out of date virus scanner is only marginally better than no virus scanner at allLaw #8: An out of date virus scanner is only marginally better than no virus scanner at all
Law #9: Absolute anonymity isn't practical, in real life or on the WebLaw #9: Absolute anonymity isn't practical, in real life or on the Web
Law #10: Technology is not a panaceaLaw #10: Technology is not a panacea”
http://www.microsoft.com/technet/archive/
community/columns/security/essays/10imlaws.mspx

Saturday, February 05, 2005

The Chargeback Challenge

By John Conde

“Nobody goes into business to lose money. You work hard for every penny, and every penny counts. To have that taken away from you months after a sale was completed is not only bad for business but extremely frustrating. Too many chargebacks usually spells doom for an online merchant.

The best tools for avoiding a chargeback are not available for online merchants. Retail-style businesses can perform certain actions that render them virtually bulletproof to chargebacks (they're still vulnerable, so don't be too envious just yet). They can either swipe the customer's credit card through a processing terminal or get a manual imprint of the card. Plus they can get a signature on that receipt at the time of sale. All of these methods verify that the customer, merchant, merchandise, and credit card were present and satisfactory at the time of sale. It's pretty hard to dispute that.

So what is an online merchant to do? Since giving up is not an option, education and prevention are an online merchant's best weapons. Having some basic policies and procedures in place can significantly reduce the number of chargebacks your business will receive. In this article, we will discuss the realities of chargebacks and identify some strategies that will lower your potential for needing to deal with them.

http://www.sitepoint.com/article/chargeback-challenge

Introduction to Browser-Specific CSS Hacks

By Trenton Moss

“More and more Web developers are ditching tables and coming round to the idea of using CSS to control the layouts of sites. And, given the many benefits of using CSS, such as quicker download time, improved accessibility and easier site management, why not?

The Problem with CSS

Historically, the main problem with using CSS has been a lack of browser support. This is no longer the case, as version 5 browsers, which all provide good support for CSS, now account for over 99% of the browsers in use.

The problem that remains is that browsers can sometimes interpret CSS commands in different ways, which fact alone causes many developers to throw their arms up in the air and switch back to pixel-perfect table layouts. Fear not, though! As you learn more about CSS, you'll gradually start to understand the different browser interpretations and realise that there aren't really that many -- and that, where necessary, their idiosyncrasies can be catered to using various workarounds or hacks.

How CSS Hacks Work

The way CSS hacks works is to send one CSS rule to the browser(s) you're trying to trick, and a second CSS rule that overrides the first command to the other browsers. If you have two CSS rules with identical selectors, the second CSS rule will almost always take precedence.

http://www.sitepoint.com/article/browser-specific-css-hacks

Kazaa's a drag at its own company

By Kristyn Maslog-Levis CNET News.com February 4, 2005, 7:14 AM PT

Employees at peer-to-peer provider Sharman Networks "hate" installing the company's own Kazaa software because it has ill effects on their computers, according to an internal document written by Sharman's chief technology officer.

The document, entitled "Kazaa Technology 2004" and written by Phil Morle, says that Sharman needs to be careful about installing too much adware on a computer upon the installation of Kazaa. The document is part of a bundle for which a request for confidentiality was rejected this week by Justice Murray Wilcox, the judge overseeing a copyright trial against Sharman in Australia.

The adware "slows down users' machines and can affect other activity such as browsing the Internet," Morle wrote. "We are also adding increasing p2p networks to the users' machines. These are good value to users but they use more resources and create confusion for users as to what resources they are sharing and where this can be controlled."

These two issues could be reasons why Kazaa manages to "lose users by over-stepping the mark," the document said, adding that the company should take into account how many employees at Sharman refuse to install the peer-to-peer software.

"Consider how many people that work for Sharman Networks and its partners that hate installing Kazaa on their machine," Morle wrote.”

http://news.zdnet.com/2100-3513_22-5563407.html


Triple worm attack

“Three nasty new worms are on the loose--all are designed to lower the victim's guard, then pounce.

MSN Messenger hit by double-whammy worm
The new Bropia offshoot, which uses MSN Messenger to spread, is packaged with a second, more damaging worm.
February 3, 2005

Saddam Hussein 'death' photos used as worm bait
Mass-mailing worm claims to offer photos that show Saddam Hussein killed after trying to escape from custody.
February 3, 2005

Worm uses funny face to distract from danger
Will a picture of an old man making a silly face keep you from noticing a Trojan being installed on your PC? Someone is hoping it will.
February 3, 2005”

http://news.zdnet.com/2100-1009_22-5562313.html?tag=nl.e589

Wednesday, February 02, 2005

Debunking the myth of style defaults

by Michael Meadhra

This article originally appeared in the Design & Usability Tactics newsletter. Click here to subscribe automatically. Free subscription required.

“There is no such thing as a totally unstyled Web document. Even if you don't link to an external CSS style sheet or add any embedded styles to the document, the page gets formatting information from the browser's built-in default style sheet. It's this built-in style sheet that establishes default formatting, such as the size and bolding of text marked up with the heading tags (h1 - h6) and the space above and below paragraphs.

Most Web builders take default styles for granted. They think of the formatting defaults as things that were standardized in the early days of the Web that will always remain the same. That's not entirely true. Although the default styles are generally quite similar in all the major browsers, there are some small (and not so small) differences in the default style sheets of the various browser brands and versions. These style sheet differences are responsible for a significant portion of the page-rendering inconsistencies between browsers.

That's the bad news. The good news is that you can do something about it.

http://techrepublic.com.com/5100-22_11-5435275.html?tag=em.e099.020105


Declare independence from tech support!

We recently ran a story on how to survive common technical-support nightmares, such as support reps who speak only eight words of English and 30-minute hold times. Our advice is all good, if I do say so, but I'm here today with an extreme, alternative perspective: Just say no to tech support. Go rogue. Secede from the union and run your own tech country, as it were.

I didn't realize it until recently, but I've been moving in this direction myself for years, dodging tech support whenever I can. After spending a few too many hours listening to synthesizer variations of "Song Sung Blue" during interminable holds, something in my limbic system must have finally switched from tech-support fight into tech-support flight. It's been working out great for me. I can't recommend that a tech novice (Hi, Mom!) follow this route, but I've found that building a support-free computing setup is actually rewarding, if you have the patience and the knack for it. So here's the plan:

Don't ask for trouble
Some products will need tech support, and some are much less likely to. Your task is to actively avoid the former and try to acquire the latter. For example, I'm in the market for a printer, in particular a networked, color all-in-one. I had my eyes on the HP OfficeJet 7410, to which we gave a good review to and that has all the features I want. But the user feedback on this printer is running two to one against, mostly because of an unwieldy software suite that many of CNET's users have said doesn't install correctly, necessitating calls to tech support. Others complain about finicky duplexers, leading to more of the same. I really want this printer, but I don't want the trouble. I'd rather give up some features than use a product that's going to force me onto the tech-support lines.


Monday's monster: Hold times from hell Tuesday's terror: The case of the techie who spoke no English
Wednesday's witch: Warranty woes Thursday's thriller: Attack of the data-eating support zombies
Friday's fiend: The user who fixed his own computer (and lived to tell the tale)

http://reviews-zdnet.com.com/AnchorDesk/
4520-7297_16-5636612.html?tag=adss&tag=nl.e501-2

MySQL worm hits Windows systems

“A worm that takes advantage of administrators' poor password choices has started spreading among database systems.

The malicious program, known as the "MySQL bot" or by the name of its executable code, SpoolCLL, infects computers running the Microsoft Windows operating system and open-source database known as MySQL, the Internet Storm Center said in an advisory published Thursday. Early indications suggest that more than 8,000 computers may be infected so far, said the group, which monitors network threats.

The worm gets initial access to a database machine by guessing the password of the system administrator, using a long list of common passwords. It then uses a flaw in MySQL to run another type of program, known as bot software, which then takes full control of the system.

Because it infects Windows systems running database software, the program resembles the Slammer worm, which spread widely nearly two years ago. However, unlike Slammer, a well-chosen password is protection against SpoolCLL, according to current analyses. The MySQL database is uncommon in Windows operating systems. That means only a small fraction of computers connected to the Internet could be compromised by the MySQL bot.

The flaw used by the worm to gain control of a vulnerable system was discovered in mid-2004, and code to take advantage of the flaw was published in late December. Known as the MySQL UDF Dynamic Libray flaw, the vulnerability occurs because the database software does not do adequate security checks on user-defined functions (UDFs). It's not clear whether the bug has been fixed. ”

http://news.zdnet.com/2100-1009-5553570.html?tag=nl.e550


Monday, January 31, 2005

Defeating Microsoft Windows XP SP2 Heap protection and DEP bypass

“In October 2004 it was discovered by MaxPatrol team that it is possible to defeat Microsoft® Windows® XP SP2 Heap protection and Data Execution Prevention mechanism. As a result it is possible to implement:
  1. Arbitrary memory region write access (smaller or equal to 1016 bytes)
  2. Arbitrary code execution
  3. DEP bypass.
Details are described in the article by our expert: PDF format, HTML format.


http://www.maxpatrol.com/ptmshorp.asp

Thinking Differently About Site Mapping and Navigation

“Visitors don’t necessarily care where something lives as long as they have no problem finding it. Via traditional navigation, that reflects (usually) a site map and it’s hierarchy, is only one way people can go through a site and frankly I feel that in most cases it’s pretty straightforward and, if anything, designers and stakeholders only complicate things by trying to make sure everything is ‘living comfortably.’

The site map is important, but not as important as addressing the paths that people follow through your site in their search for information. Another thing stakeholders tend to want to do is make sure content is prioritized. This is fine when talking about internal goals, and has some relevance when it comes to a site’s visitors, but…and this is a big but…when someone is looking for content that piece of content they’re currently looking for is the most important bit. I guess what I’m getting at is that as business goals shift, and audience and user needs change the value placed on different sections and groupings of content will change as well.

It’s pretty hard to create a hierarchical site map that adjusts in real time to shifting priorities, goals and needs—regardless of where the originate.

Shouldn’t more time be spent on addressing the user’s real needs? We should be helping them to find the information they’re looking for and giving them options to keep them on track when traditional navigation fails.

http://www.7nights.com/asterisk/archive/2005/01/
thinking-differently-about-site-mapping-and-navigation


Friday, January 28, 2005

$100 Home Recording Studio

E-MU 0404 Digital Audio System

The PC has turned media into an active creation activity, instead of just a passive, TV-watching, radio-listening "let-it-wash-over-you" experience. We can make and edit movies. We can doctor digital photos. We can record and remix music.

While you can do basic recording using your motherboard's integrated audio, in most cases the results won't sound especially good. An Audigy 2 sound card has clean enough inputs and outputs to do some home recording, and even supports ASIO, the driver standard for most professional and prosumer audio applications. But it lacks the 1/4-inch jacks you'll want for connecting instruments. If you're ready to get more serious, it's time to leave the world of sound cards behind, and delve into the realm of audio interface cards.

A semantic difference, you say? Not really. Audio interface cards are specifically designed for audio and music production. They usually won't accelerate game audio, and their mixer applications are much more intricate and granular. They also offer up a lot more I/O—both analog and digital. Cards offering 8-in/8-out are typical, and are usually priced at around $400–$500. Also, the software bundles usually come with audio sequencers and wave editors rather than media player applications and games.

Another important difference is the price: Most decent audio interfaces start at $150 and head north from there. Cards like M-Audio's Delta 44, Echo Audio's Mia MIDI and E-MU's 1212M are in this price band, and all represent good entry-level solutions. But E-MU has gone one better. The company has taken its 1212M interface, and trimmed some features from it to produce the 0404, a $99 2-in/2-out (analog) audio interface card that delivers very impressive performance at that price point.

Are you ready to get your groove on and gear up to record all those musical ideas dancing around in your head? Read on to see if the 0404 is the right place to start for you. Continued...

TABLE OF CONTENTS
Introduction
Guided Tour
How We Tested
RightMark Audio Analyzer Results
SoundForge Noise Floor Results
Hands-On Time
The Proteus X Synth Software
Final Thoughts/What to Buy

http://www.extremetech.com/article2/0,1558,1753502,00.asp

Return of the Browser Wars

By Jerry Pournelle
July 26, 2004
(Return of the Browser Wars : Page 1 of 1 )
Column 288 (Continued from the Previous Month)

“The Big Question: Internet Explorer

The VX2 spyware scare was one problem. Another was Download.Ject, aka Scob, and called by some The Russian Hack. This exploited vulnerabilities in the Microsoft IIS servers (one reason why Apache has a significant web server market share) to broadcast malware that exploited in turn Internet Explorer vulnerabilities. That was significant because it caused some journalists to advise users to abandon Internet Explorer entirely. Others didn't go that far, but did say that one ought not use Microsoft Internet Explorer as one's default Internet browser. Perhaps the most extreme statement was "The U.S. government's Computer Emergency Readiness Team (US-CERT) is warning Web surfers to stop using Microsoft's Internet Explorer (IE) browser."

For those unfamiliar with it, US-CERT "is a partnership between the Department of Homeland Security and the public and private sectors. Established to protect the nation's Internet infrastructure, US-CERT coordinates defense against and responses to cyber attacks across the nation," so a warning from US-CERT is pretty serious, and if they're advising you to "stop using Microsoft's Internet Explorer (IE) browser," it may be time to do just that.

All of which prompted a call to Microsoft's public relations people, who arranged a telephone interview with two senior program managers on Microsoft's Security team.

Microsoft's Side of the Story

My interview was with Gary Schare, Director of Security Project Management for Windows, and some of his team.

First, regarding CERT advice to drop IE, they said "We haven't seen any such CERT headline. We've seen journalists who report it, but we can't find any such thing." Which prompted me to go do my own search, and they're right: While I see a number of signed editorials and columns stating that this is CERT's advice, I found no URL linking that statement to CERT itself, and my search of CERT didn't turn it up either.

CERT does have a warning entitled "Microsoft Internet Explorer does not properly validate source of redirected frame," and if you scroll down past a number of other suggestions, the last one is

Use a different web browser

There are a number of significant vulnerabilities in technologies relating to the IE domain/zone security model, the DHTML object model, MIME type determination, and ActiveX. It is possible to reduce exposure to these vulnerabilities by using a different web browser, especially when browsing untrusted sites. Such a decision may, however, reduce the functionality of sites that require IE-specific features such as DHTML, VBScript, and ActiveX. Note that using a different web browser will not remove IE from a Windows system, and other programs may invoke IE, the WebBrowser ActiveX control, or the HTML rendering engine (MSHTML).

but that is not quite the same as saying ‘Don't use Internet Explorer,’ and a very long way from ‘CERT says use anything but IE.’ ”


http://www.byte.com/documents/s=9011/byt1090781086558/0726_pournelle.html?temp=1h6pvBLxoD

Dear IE, I'm leaving you for good

By Robert Vamosi
Senior editor, CNET Reviews
“Dear Internet Explorer:

It's over. Our relationship just hasn't been working for a while, and now, this is it. I'm leaving you for another browser.


I know this isn't a good time--you're down with yet another virus. I do hope you feel better soon--really, I do--but I, too, have to move on with my life. Fact is, in the entire time I've known you, you seem to always have a virus or an occasional worm. You should really see a doctor.

That said, I just can't continue with this relationship any longer. I know you say you'll fix things, that next time it'll go better--but that's what you said the last time--and the time before that. Each time I believed you.

Well, not any longer.

http://builder.com.com/5100-6371_14-5455092.html?tag=nl.e601

Google Video: Beta

“Search recent TV programs online.”

Preferences

Google Video Help

http://video.google.com/

Wednesday, January 26, 2005

Microsoft Cites IP Defense in Blogger Crackdown

By Mary Jo Foley

“On the heels of Apple Computer's attempt to crack down on journalists for allegedly misappropriating trade secrets, some free-speech advocates are worried that Microsoft has launched a similar campaign.

In a Jan. 18 letter it said was issued on behalf of Microsoft, the law firm of Covington & Burling asked the publisher of tech-enthusiast site Engadget.com to remove screenshots of a forthcoming Microsoft operating-system release known as "Windows Mobile 2005." According to the request, Microsoft considers the images to contain "proprietary trade secret information belonging to Microsoft."

Microsoft also requested that two other Windows-focused sites, Neowin.net and Bink.nu, remove related information from their Web sites. Neowin was the first site to publish in early January the alleged screen shots and development schedule for Windows Mobile 2005.

Neowin and Bink removed the Windows Mobile 2005 information at Microsoft's request. (Neowin received a phone request from a Microsoft representative and Bink, an e-mail one from a "Microsoft Internet Investigator," site principal Steven Bink said.)

As of the time this article was published, Engadget publisher Weblogs Inc. still had not removed the Windows Mobile 2005 screen shots and information from its site.

Microsoft did not respond to questions from Microsoft Watch about whether it is stepping up its campaign to limit the publication of information it considers trade secrets.

http://www.microsoft-watch.com/article2/0,1995,1753658,00.asp