Tuesday, August 19, 2003

Microsoft Virtual PC
Microsoft Virtual PC is a powerful software virtualization solution that allows you to run multiple PC-based operating systems simultaneously on one workstation, providing a safety net to maintain compatibility with legacy applications while you migrate to a new operating system. It also saves reconfiguration time, so your support, development, and training staff can work more efficiently.

Microsoft will release Microsoft Virtual PC 2004 late in calendar year 2003. In the meantime, a 45-day free trial of the Connectix Virtual PC for Windows version 5, now from Microsoft, can be downloaded for evaluation purposes.

http://www.microsoft.com/windowsxp/virtualpc/downloads/trial.asp

http://www.microsoft.com/windowsxp/virtualpc/

Monday, August 18, 2003

Verifying Blaster E-mail Communications from Microsoft
http://go.microsoft.com/?linkid=221444
The above link resolves to https://register.microsoft.com/security/incident/verify.asp

If you applied security patch MS03-026 prior to the discovery of the Blaster worm, your system is secure from the vulnerability that W32.Blaster is using. For the most current information on determining if your systems are infected and how to recover from the infection, please go to the following web site and perform the prescribed steps: http://www.microsoft.com/security/incident/blast.asp. This site will be updated as more information regarding the W32.blaster worm becomes available.

In order to help protect your computing environment from security vulnerabilities, use the Windows Update service by going to http://windowsupdate.microsoft.com and also subscribe to Microsoft's security notification service at http://register.microsoft.com/subscription/subscribeme.asp?ID=135. By using these two services you will automatically receive information on the latest software updates and the latest security notifications, thereby improving the likelihood that your computing environment will be safe from the worms and viruses that occur.

https://register.microsoft.com/security/incident/verify.asp
How To Avoid Blaster Infection
What's more important than figuring out how to get uninfected? Avoiding infection in the first place. Here are some simple steps you can take to safeguard your systems.

http://www.pcmag.com/article2/0,4149,1220051,00.asp
typoGRAPHIC
typoGRAPHIC, an interactive experience informed by type and typography. It aims to illustrate the depth and import of type, and to raise relevant questions about how typography is treated in the digital media, specifically online.

http://www.rsub.com/typographic/

Sunday, August 17, 2003

Actions for the Blaster Worm
For Windows XP
1. If your computer reboots repeatedly, please unplug your network cable from
the wall.

2. First, enable Internet Connection Firewall (ICF) in Windows XP:
http://support.microsoft.com/?id=283673
--In Control Panel, double-click "Networking and Internet Connections", and
then click "Network Connections".
--Right-click the connection on which you would like to enable ICF, and then
click "Properties".
--On the Advanced tab, click the box to select the option to "Protect my
computer or network".

3. Plug the network cable back into the wall to reconnect your computer to the
Internet

4. Download the MS03-026 security patch from Microsoft and install it on your
computer:

5.Install or update your antivirus signature software and scan your computer

6.Download and run the worm removal tool from your antivirus vendor.

Windows XP (32 bit)
http://www.microsoft.com/downloads/details.aspx?FamilyID=2354406c-c5b6-44ac-9532-3de40f69c074&displaylang=en

Related Knowledge Base Articles:
http://support.microsoft.com/?kbid=826955

Related Microsoft Security Bulletins:
http://www.microsoft.com/technet/security/bulletin/MS03-026.asp

http://www.microsoft.com/security/incident/blast.asp

Free Software servers breached
A key server housing software used in Linux and other projects was open to an attacker for four months, creating fears that source code was compromised

The GNU Project, which develops many of the components in the Linux operating system, said this week that the system housing its primary download servers has been compromised by an attacker. The project urged those who have downloaded software from the server since March to check that the source code has not been tampered with.

Linux, an open-source operating system that dominates the Web server market, uses the compiler, libraries and other software that was originally developed by the GNU project. The project warned that the attacker may have inserted malicious code into its software, although it said all the code checked so far appeared to be intact.

In an alert issued on Wednesday, computer security response organisation CERT warned that the breach could prove to be a serious problem. "Because this system serves as a centralised archive of popular software, the insertion of malicious code into the distributed software is a serious threat," the warning stated.…

http://news.zdnet.co.uk/0,39020330,39115701,00.htm
Worm a Sign of Horrors to Come?
The attack forced Maryland's motor vehicle agency to close for the day and kicked Swedish Internet users offline as it spread.

Security experts said the world was lucky this time because LovSan is comparatively mild and doesn't destroy files. They worry that a subsequent attack exploiting the same flaw -- one of the most severe to afflict Windows -- could be much more damaging.

"We think we're going to be dealing with it for quite some time," said Dan Ingevaldson, engineering manager at Internet Security Systems in Atlanta.

Although LovSan does not appear to do any permanent damage, Ingevaldson said instructions to do that could easily be written into a worm that propagates in the same way.

Microsoft itself still faces the wrath of the worm's coder.…

The attack was preventable for many machines running Windows. On July 16, Microsoft posted on its website a free patch that prevents LovSan and similar infections. The patch fixes an underlying flaw that affects nearly all versions of the software giant's flagship Windows operating system.

Notwithstanding high-profile alerts issued by Microsoft and the Department of Homeland Security, many businesses did not install the patches and scrambled Tuesday to shore up their computers.

Security experts say patches often stay on "to do" lists until outbreaks occur.

"You're looking at 70 new vulnerabilities every week," said Sharon Ruckman, senior director at the research lab for antivirus vendor Symantec. "It's more than a full-time job trying to make sure you are up-to-date."

Microsoft spokesman Sean Sundwall acknowledged that the blame does not really lie with customers.

"Ultimately, it's a flaw in our software," he said.

Non-Microsoft systems were not vulnerable, though some may have had trouble connecting with websites, e-mail and other servers that run on Windows.

Symantec's probes detected more than 125,000 infected computers worldwide.

The worm exploits a flaw in a Windows feature for sharing data files across computer networks. It was reported Monday in the United States first and spread across the globe as businesses opened Tuesday and workers logged on.

Additional U.S. computers were hit Tuesday, and Maryland's Motor Vehicle Administration shut all its offices at noon.

"There's no telephone service right now. There's no online service right now. There's no kiosk or express office service," spokeswoman Cheron Wicker said. "We are currently working on a fix and expect to be operational again in the morning."

In Sweden, Internet provider TeliaSonera said about 20,000 of its customers were affected after the infection clogged 40 servers that handle Internet traffic.

Among companies affected in Germany was automaker BMW, said spokesman Eckhard Vannieck. He said the problems did not affect production.

The worm also affected networks in China, but the damage apparently was not serious.…

http://www.wired.com/news/infostructure/0,1377,59994,00.html
http://www.wired.com/news/technology/0,1282,60019,00.html
Breadcrumb Navigation: Further Investigation of Usage
The term “breadcrumb” derives its name from the Grimm’s fairy tale, Hansel and Gretel. Hansel left a trail of breadcrumbs through the woods as a strategy to find his way back home. Since today’s internet user often has a need to navigate back through a website path, the cyber-version “breadcrumb trail” was named1.

There are three different types of breadcrumbs represented in websites – path, attribute, and location…

In general, the breadcrumb trail serves two purposes: 1) it provides information to users as to where they are located within the site, and 2) it offers shortcut links for users to “jump” to previously viewed pages without using the Back button, other navigation bars, or typing in a keyword search. Breadcrumb trails give location information and links in a backward linear manner; whereas, navigation methods, such as search fields or horizontal/vertical navigation bars, serve to retrieve information for the user in a forward-seeking approach. As suggested by Marchionini (1995), systems that support navigation by both browsing and analytical strategies are most beneficial to users since tactics associated with both types of strategies are normally used. According to Steven Krug (2000), breadcrumb trails are most valuable as an accessory to a site’s navigational scheme and are optimally located at the top of a web page in a smaller font.

There has been speculation that a breadcrumb trail also aids the user’s “mental model” of the site’s layout to reduce disorientation within the site (Bernard, 2003); however, we have not found research to validate this assumption. It would seem logical, however, that a constant visualization of the path to the user’s current location would increase their awareness and knowledge of the site structure. Toms (2000) suggests that users need both a stable orienting device, such as a menu, to facilitate pathways through the site, as well as a system that supports scanning to smooth the progress of the search. Research has reported that breadcrumb navigation improves measures of site efficiency (Maldonado & Resnick, 2002; Bowler, Ng & Schwartz, 2001). Our earlier study, however, found limited use of breadcrumb trails as a navigational tool and no differences in site efficiency for two online sites, OfficeMax and Google Directory (Lida, et al. 2003).…

http://psychology.wichita.edu/surl/usabilitynews/52/breadcrumb.htm

Saturday, August 16, 2003

The Sensible Internet Design Journal

Issue 40 of The Sensible Internet Design Letter
http://smallinitiatives.com/journal75_0_1_0_C4.html

http://smallinitiatives.com/
Text style sampler
Instructions by Jay Small of Small Initiatives

Use this page to try different combinations of typefaces, text line height, paragraph indents and widths, and see the results (and the Cascading Style Sheet properties that made them) in the blocks of text below. Try this in different browsers and observe the subtle differences.

Here are the variables:

Font: Choose from four commonly installed, screen-friendly fonts: Times New Roman, default on many browsers; Verdana, a popular sans-serif choice; Arial, another popular sans-serif face; and Georgia, a serif face that is screen- and printer-friendly.

Line height: The default setting is 1 em. In printing, this setting would be known as "set solid." The line height is identical to the height of the letters themselves. But Web browsers fudge this a bit when they render text -- in fact, if your font size and line height are both left to defaults, there will be at least a pixel of space between lines of text. You may wish to add more space, especially on text set very wide.

Paragraph indents: By default, stacks of paragraphs in Web browsers do not have first-line indents; instead, the first line of each paragraph is flush-left but you see a full line of space between paragraphs. Most printed text is set with paragraph indents, however, and if you want them they are easy to create. The samples with indents have a half line (0.5 em) of space between paragraphs.

Set base font size

Then, select a base font size. The default size (1 em, or what would be applied if you used no style sheets at all) is typically rendered at 16 pixels.…
http://smallinitiatives.com/whatwevedone/presentations/textsampler/
Blaster Variant on the Loose
Security experts are now tracking a new variant of the Blaster worm that was first spotted Wednesday morning.

The new version is nearly identical to the original, except for a new name on the executable file and a different registry key. The variant's file name is "teekids.exe," and the key it adds to the registry is: "Microsoft Inet Xp.." The key is located in the same place as Blaster's key is, according to Neel Mehta, research engineer at Internet Security Systems Inc. in Atlanta.

"Some of our customers say that they're seeing more copies of the new one than the old one, but I think that's just bad luck," Mehta says. "It scans exactly the same way and acts exactly the same as Blaster."

Mehta said that some copies of the new variant are coming packed with various known Windows Trojan programs, as well.

http://www.eweek.com/article2/0,3959,1219197,00.asp

Friday, August 15, 2003

The Bright Side of Blaster
The Blaster worm has infected hundreds of thousands of Windows machines, shut down the Maryland state DMV, put network administrators on overtime, crashed countless consumer's home computers, and on Saturday it will attempt a denial-of-service attack on Microsoft's Windows Update site. But that doesn't make it all bad.

Blaster, also known as MSBlast and LovSan, hit the Internet on Monday, spreading through the RCP DCOM vulnerability discovered by the Polish security research group Last Stage of Delirium earlier this year. The worm is built on dcom.c, one of the public exploit programs that emerged to demonstrate and exercise the flaw in the days and weeks following Microsoft's July 16th advisory. According to data gathered by (SecurityFocus publisher) Symantec's DeepSight network of intrusion detection systems, by Thursday afternoon the worm had infected over 330,000 Windows XP and Windows 2000 machines.

As nasty as that is, security experts say it could have been much worse: the worm is hampered by clumsy construction, and it does not contain a malicious payload to damage victim's files. Moreover, in its reckless tear through cyberspace Blaster is accomplishing what a month of warnings from the security community, an unprecedented mass-e-mail campaign by Microsoft, and two advisories from the Department of Homeland Security all failed to do: it's forcing companies and consumers to install the patch for the serious RPC DCOM vulnerability, shutting down computer intruders who've had their pick of these systems for weeks.

http://www.securityfocus.com/news/6728

Thursday, August 14, 2003

Photos.com, unlimited downloads of the 60,000 photos, for only $299.95
You know that high-quality stock photos are not inexpensive, and yet bargain-priced images often don't have the quality you need for your Web or print design projects. Variety and image freshness are also important – when you're on a deadline, looking for just the right image, time is money.

This is why the subscription-based Photos.com site has proven so popular. Now you can take advantage of this special offer to obtain unlimited downloads of the 60,000 photos, for only $299.95 (a 40% savings) for an entire year. Photos are available in three convenient sizes, in such popular categories as business, health, technology, lifestyles and more. Why not try out a few of the free photos first, to make sure the image quality meets your needs?

Sign up by August 30, 2003 at www.photos.com/promo/andromeda to take advantage of this limited-time offer.

www.photos.com/promo/andromeda

Wednesday, August 13, 2003

Blasting Blaster
In mid-July, Microsoft supplied patches for a vulnerability in the DCOM Remote Procedure Call module that could allow a worm to download and run any program. Microsoft Windows NT4, 2000, XP, and Windows Server 2003 were affected. This Monday, machines without the patch became fair game for the fast-spreading Blaster worm. Blaster is set to launch a Distributed Denial of Service (DDoS) attack on windowsupdate.microsoft.com this Saturday, August 16th. You don't want to be a part of that, so be sure you have the patch installed.

But what if your system is one of tens of thousands already compromised by Blaster? You may not be able to install the patch, or to do much of anything. On most machines Blaster triggers a Windows shut down sequence with a 60-second warning, leaving no time for downloading. Your first step is to abort the shutdown by entering the command "shutdown /a" (no quotes) in the Start menu's Run dialog. With the countdown halted, you can try the free removal tool from Symantec or do the job by hand.

http://www.microsoft.com/security/security_bulletins/ms03-026.asp

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

http://www.pcmag.com/article2/0,4149,1217751,00.asp
Blaster Worm on the Move
The Blaster worm continued to tear through the Internet Tuesday morning as security experts struggled to find and fix infected systems. The worm is presenting a unique problem for security specialists because it is infecting a large number of PCs owned by home users, many of whom may be unaware that their machines are compromised.

And because Blaster's scanning algorithm tends to start by looking for IP addresses that are close to the infected machine's, the worm can rattle around inside a local network for quite a while, consuming bandwidth.

Officials at the CERT Coordination Center estimated that the number of infected machines is in the hundreds of thousands and will continue to grow. "A large number of the compromised machines are those of home users. In this case it isn't as easy as downloading a patch because they can't get enough bandwidth to get online and get the patch," said Marty Lindner, team leader for incident handling at CERT, based at Carnegie Mellon University in Pittsburgh.


"The compromise has a harder time getting out of the local network, so it's harder to measure how many machines are infected."

Blaster began spreading early Monday afternoon Eastern time and quickly gained momentum. The worm exploits the RPC DCOM (Distributed Component Object Model) vulnerability in all of the current versions of Windows, except ME. The worm scans the Internet and attempts to connect to TCP port 135. After establishing a connection, Blaster spawns a remote shell on port 4444 and then uses TFTP (Trivial File Transfer Protocol) to download the actual binary containing the worm. The worm is self-extracting and immediately begins scanning for other machines to infect.

For users who cannot free up enough bandwidth to download the patch from Microsoft Corp., CERT recommends an alternative remedy. Users should physically disconnect the infected machine from the Internet or network. Then, kill the running copy of "msblast.exe" in the Task Manager utility. Users should then disable DCOM and reconnect to the Internet and download the patch.

Instructions for disabling DCOM are available at Microsoft's Knowledge Base Web site.
http://support.microsoft.com/default.aspx?scid=kb;[LN];825750

http://www.eweek.com/article2/0,3959,1217020,00.asp
MediaSavvy
The online ad boom could delay content charges
Right now, there is more money to be made selling ads online than selling news.

With online advertising continuing to climb (Emarketer says online ad spending will be up 4.8% in 2003), and with online newspapers getting an outsized share of that growth, who is going to be willing to jeopardize their seat on the gravy train by charging for content?…

http://mediasavvy.com/archives/000412.shtml#000412
checkinstall
…it's not always easy to get ready-made binary packages. Checkinstall handles that problem by building a binary package out of a compiled source tree. Where you normally do the ./configure && make && make install routine to build a package, checkinstall intercepts the make install part and builds a package ready for installation in Red Hat, Debian, Slackware, or RPM-based distributions. That way, when your vendor finally does catch up, you can remove the package with a single command (instead of hunting its components down by hand) and install the new binary package without a hassle. Good stuff.

After you ./configure; make your program, CheckInstall will run make install (or whatever you tell it to run) and keep track of every file modified by this installation, using the excelent installwatch utility written by Pancrazio 'Ezio' de Mauro (p@demauro.net).

When make install is done, CheckInstall will create a Slackware, RPM or Debian compatible package and install it with Slackware's installpkg, "rpm -i" or Debian's "dpkg -i" as appropriate, so you can view it's contents with pkgtool ("rpm -ql" for RPM users or "dpkg -l" for Debian) or remove it with removepkg ("rpm -e"|"dpkg -r"). Aditionally, this script will leave you a copy of the installed package in the source directory so you can install it wherever you want, which is my second motivation: I don't have to compile the same software again and again every time I need to install it on another box :-).

http://asic-linux.com.mx/~izto/checkinstall/

Monday, August 11, 2003

Download and Build Quake II for .NET
Vertigo Software Inc. has released Quake II .NET, a version of id Software's popular Quake II game ported to the Microsoft .NET common language runtime (CLR) using Microsoft Visual C++ .NET 2003.

Download Quake II .NET from Vertigo Software, Inc., including full source code and project files for Visual C++ .NET 2003, as well as a white paper describing the effort.

This application demonstrates the powerful capability of Visual C++ to retarget existing C++ code at the .NET CLR with little effort. It shows how a highly performance-critical application like Quake II can retain these characteristics in the CLR environment, while simultaneously offering new features implemented using the .NET Framework.

Download Quake II .NET from Vertigo Software, Inc.
http://www.vertigosoftware.com/Quake2.htm

http://msdn.microsoft.com/visualc/quake/

Sunday, August 10, 2003

Photo Album Script Generator
This program automatically generates HTML codes for a customized photo gallery. HTML developers, who do not have much time to write codes or want to use a simple personal photo gallery, can use it. For Microsoft Internet Explorer 5+, Netscape Navigator 6+, Opera 6+ and Mozilla 1.2+.

http://javascript.internet.com/miscellaneous/photo-album-script-generator.html

Friday, August 08, 2003

New Tool Roots Out SCO Code
With legal terms such as liability, indemnification and lawsuit as prominent themes of the LinuxWorld show here, a small software company has addressed the issue with a solution to find offensive code.

Aduva Inc., Sunnyvale, Calif., has developed a system known as OnStage that contains a feature known as SCO Check that will "conduct a complete inventory of your system and if SCO [The SCO Group] identifies some illegal code, we can do a check to find the code, identify it and then automate the replacement of that code" with Red Hat Linux or an appropriate fix, said Chris Van Tuin, director of customer service for Aduva.

In addition, Aduva also announced SoundCheck, a snippet of the OnStage technology the company is delivering for free. SoundCheck scans Linux servers and identifies potential problems, such as missing dependencies, security issues and unaccepted bug fixes that could cause application failures or security leaks. It is available for download free of charge at www.aduva.com/soundcheck.



http://www.eweek.com/article2/0,3959,1212134,00.asp