Welcome to TechBuilder.org:
"Secure wireless networking can be a reality, but only if you employ some very straightforward techniques."
http://www.techbuilder.org./article.htm?ArticleID=46364
Tuesday, December 09, 2003
Monday, December 08, 2003
Op-Ed Contributor: A Million Miles From the Green Zone to the Front Lines:
"The other day I told General Petraeus about a young specialist fourth class I had met while waiting for a military flight out of Baghdad. The specialist was a college student from Iowa whose National Guard unit had been called up for the war. He had told me about a prolonged firefight that took place the week before, outside Camp Anaconda on the outskirts of the city of Balad, 40 miles from Baghdad.
'We began taking small arms fire about 8 a.m., from Abu Shakur, the village just north of the base camp's gate,' the specialist told me. 'Our guys responded with small arms and then mortars. Someone on patrol outside the wire got wounded, and they sent Bradley Fighting Vehicles out, and they hit the Bradleys pretty hard, and by 10 a.m., they were firing 155-millimeter howitzers, and attack helicopters were firing missiles into the village, and you could see tracers and smoke everywhere.
'I had just gotten off a night shift, and I was sitting outside my tent about 100 meters from the gate in my pajamas reading a book. Right near me, guys were doing laundry and standing in line for chow. I was sitting there thinking: `Have we had wars like this before? Shouldn't we drop everything and help? I mean, we were spectators! What kind of war is this, sir?' '"
General Petraeus, who graduated from West Point in 1974, just in time to witness the ignominious end to the war in Vietnam, didn't say anything. But slowly, and it seemed, unconsciously, his head began to nod, and his mind seemed far, far away. It seemed clear he knew the answer: yes, specialist, we have had wars like this before.
Commanding generals have had lavishly appointed offices before, as well. My grandfather, Gen. Lucian K. Truscott Jr., occupied the Borghese Palace when his VI Corps swept into Rome in 1943. His aide kept a record of the meals prepared for him by his three Chinese cooks, while every day dozens — and on some days, hundreds — of his soldiers perished on the front lines at Anzio, only a few miles away from his villa on the beach.
So there may be nothing new about this war and the way we are fighting it — with troops on day and night patrols from base camps being hit by a nameless, faceless enemy they cannot see and whose language they do not speak. However, the disconnect between the marbled hallways of the Coalition Provisional Authority palaces in Baghdad and the grubby camp in central Mosul where I spent last week as a guest of Bravo Company, First Battalion, 502nd Infantry Regiment, is profound, and perhaps unprecedented.
An colonel in Baghdad (who will go nameless here for obvious reasons) told me just after I arrived that senior Army officers feel every order they receive is delivered with next November's election in mind, so there is little doubt at and near the top about who is really being used for what over here. The resentment in the ranks toward the civilian leadership in Baghdad and back in Washington is palpable. Another officer described the two camps, military and civilian, inhabiting the heavily fortified, gold-leafed presidential palace inside the so-called Green Zone in Baghdad, as "a divorced couple who won't leave the house."
Meanwhile in Mosul, the troops of Bravo Company bunker down amid smells of diesel fuel and burning trash and rotting vegetables and dishwater and human waste from open sewers running though the maze of stone and mud alleyways in the Old City across the street. Bravo Company's area of operations would be an assault on the senses even without the nightly rattle of AK-47 fire in the nearby streets, and the two rocket-propelled grenade rounds fired at the soldiers a couple of weeks ago.
It is difficult enough for the 120 or so men of Bravo Company to patrol their overcrowded sector of this city of maybe two million people and keep its streets safe and free of crime. But from the first day they arrived in Mosul, Bravo Company and the rest of the 101st Airborne Division were saddled with dozens of other missions, all of them distinctly nonmilitary, and most of them made necessary by the failure of civilian leaders in Washington and Baghdad to prepare for the occupation of Iraq.
The 101st entered Mosul on April 22 to find the city's businesses, civil ministries and utilities looted and its people rioting in the streets. By May 5, the soldiers had supervised elections for mayor and city council. On May 11, they oversaw the signing of harvest accords and the division of wheat profits among the region's frequently warring factions of Arabs, Kurds, Turkmen and Assyrians. On May 14, a company commander of Alpha Company, Third Battalion, 187th Infantry Regiment of the 101st re-opened the Syrian border for trade, and by May 18, soldiers had largely restored the flow of automobile gas and cooking propane, shortages of which had been causing riots.
Since that time, soldiers from the 101st have overseen tens of millions of dollars worth of reconstruction projects: drilling wells for villages that had never had their own water supply; rebuilding playgrounds and schools; repairing outdated and broken electrical systems; installing satellite equipment needed to get the regional phone system up and running; restoring the city's water works; repairing sewers and in some cases installing sewage systems in neighborhoods that had never had them; policing, cleaning and reorganizing the ancient marketplace in the Old City; setting up a de facto social security system to provide "retirement" pay to the 110,000 former Iraqi soldiers in the area; screening and, in most cases, putting back to work most of the former Baath Party members who fled their jobs at the beginning of the war.
So many civil projects were reported on at a recent battle update briefing I attended that staff officers sometimes sounded more like board members of a multinational corporation than the combat-hardened infantry soldiers they are.…The Coalition Provisional Authority nominally has the job of "rebuilding" Iraq — using $20 billion or so of the $78 billion that recently flew out of America's deficit-plagued coffers. But during the time the 101st has been in Mosul, three regional coalition authority directors have come and gone. Only recently, long after the people of Mosul elected their mayor and city council, was a civilian American governance official sent to the area. And, according to the division leadership, not a nickel of the $20 billion controlled by the provisional authority has reached them.
"First they want a planning contractor to come in here, and even that step takes weeks to get approved," one officer in Mosul complained of the civilian leadership. "The planners were up here for months doing assessments, and then more weeks go by because everything has to be approved by Baghdad. If we sat around waiting for the C.P.A. and its civilian contractors to do it, we still wouldn't have electricity and running water in Mosul, so we just took our own funds and our engineers and infantry muscle and did it ourselves. We didn't have the option of waiting on the guys in the Green Zone."
But the guys in the Green Zone seem to have plenty of time on their hands. The place is something to behold, surrounded on one side by the heavily patrolled Tigris River, and on the three others by a 15-foot-high concrete wall backed by several rows of concertina razor wire and a maze of lesser concrete barriers. There's only one way in and out, through a heavily fortified checkpoint near the Jumhiriya Bridge guarded by tanks and Bradley Fighting Vehicles from the First Armored Division and an invisible array of British commando teams. More tanks guard key intersections inside the walls, machine gun towers line the wide boulevards, snipers man firing positions atop palaces great and small.
In all, hundreds of uniformed soldiers and heavily armed civilian security guards stand watch all day, every day over a display of grim garishness that would have given Liberace nightmares. If you're curious about how your tax dollars are being spent in Baghdad, you should get one of the many colonels strolling about the Green Zone to take you on a tour of the rebuilt duck pond across the road from the marble and gold-leafed palace serving as headquarters of an Army brigade. As I went to sleep one night a couple of weeks ago in the Green Zone, listening to the gurgle of the duck pond fountain and the comforting roar of Black Hawk helicopters patrolling overhead, it occurred to me that it was the safest night I've spent in about 25 years.
Which was a blessing for me, but a curse on the war effort. The super-defended Green Zone is the biggest, most secure American base camp in Iraq, but there is little connection between the troops in the field and the bottomless pit of planners and deciders who live inside the palace. Soldiers from the 101st tell me that they waited months for the Bechtel Corporation to unleash its corporate might in northern Iraq. "Then one of the Bechtel truck convoys got ambushed on the way up here three weeks ago, and one of the security guys got wounded," an infantryman told me. "They abandoned their trucks on the spot and pulled out, and we haven't seen them since."
"It's really not helpful when people down in Baghdad and politicians back in Washington refer to the `disorganized and ineffective' enemy we supposedly face," said one young officer, as we walked out of a battalion battle briefing that had been concerned largely with the tactics of an enemy force that is clearly well organized and very, very effective. After spending more than a week with the soldiers of Bravo Company, I know that they resent not only the inaccuracy of such statements, but the implication that soldiers facing a disorganized and ineffective enemy have an easy job.
No matter what you call this stage of the conflict in Iraq — the soldiers call it a guerrilla war while politicians back home often refer to it misleadingly and inaccurately as part of the amorphous "war on terror" — it is without a doubt a nasty, deadly war. And the people doing the fighting are soldiers, not the civilian employees of Kellogg, Brown & Root, or the officials of the Coalition Provisional Authority, or the visiting bigwigs from the Defense Department.
The troops in Bravo Company don't pay much attention to the rear-guard political wars being waged back in Washington, but they loved President Bush's quick visit to Baghdad on Thanksgiving. While it was clearly a political stunt, they were quick to credit the risks he took. I can confirm that flying in and out of Baghdad — even at night, when it's safest — is not for the faint of heart. A C-130 on approach takes a nervous, dodgy route, banking this way and that, gaining and losing altitude. Hanging onto one of those web-seats by only a seat belt (no shoulder harnesses), you're nearly upside down half the time — it would feel like the ultimate roller-coaster ride, except it's very much for real.
When Bravo Company troops roll out of the rack at 2 a.m. for street patrols, they walk the broad boulevards and narrow alleyways spread out as if they're walking a jungle trail — wheeling to the rear, sideways, back to the front; their eyes searching doorways, alleys, windows, rooftops, passing cars, even donkey carts — trying to keep one another alive for another day, another week, another month, whatever it takes to get home.
Meanwhile, two soldiers armed with M-4 carbines and fearsome M-249 Saws machine guns stand guard inside concrete and sandbag bunkers atop the Bravo Company camp's roof, while squads of soldiers patrol alleys with no names in Mosul's Old City, and everyone prays.
http://www.nytimes.com/2003/12/07/opinion/07TRUS.html?pagewanted=all&position=
"The other day I told General Petraeus about a young specialist fourth class I had met while waiting for a military flight out of Baghdad. The specialist was a college student from Iowa whose National Guard unit had been called up for the war. He had told me about a prolonged firefight that took place the week before, outside Camp Anaconda on the outskirts of the city of Balad, 40 miles from Baghdad.
'We began taking small arms fire about 8 a.m., from Abu Shakur, the village just north of the base camp's gate,' the specialist told me. 'Our guys responded with small arms and then mortars. Someone on patrol outside the wire got wounded, and they sent Bradley Fighting Vehicles out, and they hit the Bradleys pretty hard, and by 10 a.m., they were firing 155-millimeter howitzers, and attack helicopters were firing missiles into the village, and you could see tracers and smoke everywhere.
'I had just gotten off a night shift, and I was sitting outside my tent about 100 meters from the gate in my pajamas reading a book. Right near me, guys were doing laundry and standing in line for chow. I was sitting there thinking: `Have we had wars like this before? Shouldn't we drop everything and help? I mean, we were spectators! What kind of war is this, sir?' '"
General Petraeus, who graduated from West Point in 1974, just in time to witness the ignominious end to the war in Vietnam, didn't say anything. But slowly, and it seemed, unconsciously, his head began to nod, and his mind seemed far, far away. It seemed clear he knew the answer: yes, specialist, we have had wars like this before.
Commanding generals have had lavishly appointed offices before, as well. My grandfather, Gen. Lucian K. Truscott Jr., occupied the Borghese Palace when his VI Corps swept into Rome in 1943. His aide kept a record of the meals prepared for him by his three Chinese cooks, while every day dozens — and on some days, hundreds — of his soldiers perished on the front lines at Anzio, only a few miles away from his villa on the beach.
So there may be nothing new about this war and the way we are fighting it — with troops on day and night patrols from base camps being hit by a nameless, faceless enemy they cannot see and whose language they do not speak. However, the disconnect between the marbled hallways of the Coalition Provisional Authority palaces in Baghdad and the grubby camp in central Mosul where I spent last week as a guest of Bravo Company, First Battalion, 502nd Infantry Regiment, is profound, and perhaps unprecedented.
An colonel in Baghdad (who will go nameless here for obvious reasons) told me just after I arrived that senior Army officers feel every order they receive is delivered with next November's election in mind, so there is little doubt at and near the top about who is really being used for what over here. The resentment in the ranks toward the civilian leadership in Baghdad and back in Washington is palpable. Another officer described the two camps, military and civilian, inhabiting the heavily fortified, gold-leafed presidential palace inside the so-called Green Zone in Baghdad, as "a divorced couple who won't leave the house."
Meanwhile in Mosul, the troops of Bravo Company bunker down amid smells of diesel fuel and burning trash and rotting vegetables and dishwater and human waste from open sewers running though the maze of stone and mud alleyways in the Old City across the street. Bravo Company's area of operations would be an assault on the senses even without the nightly rattle of AK-47 fire in the nearby streets, and the two rocket-propelled grenade rounds fired at the soldiers a couple of weeks ago.
It is difficult enough for the 120 or so men of Bravo Company to patrol their overcrowded sector of this city of maybe two million people and keep its streets safe and free of crime. But from the first day they arrived in Mosul, Bravo Company and the rest of the 101st Airborne Division were saddled with dozens of other missions, all of them distinctly nonmilitary, and most of them made necessary by the failure of civilian leaders in Washington and Baghdad to prepare for the occupation of Iraq.
The 101st entered Mosul on April 22 to find the city's businesses, civil ministries and utilities looted and its people rioting in the streets. By May 5, the soldiers had supervised elections for mayor and city council. On May 11, they oversaw the signing of harvest accords and the division of wheat profits among the region's frequently warring factions of Arabs, Kurds, Turkmen and Assyrians. On May 14, a company commander of Alpha Company, Third Battalion, 187th Infantry Regiment of the 101st re-opened the Syrian border for trade, and by May 18, soldiers had largely restored the flow of automobile gas and cooking propane, shortages of which had been causing riots.
Since that time, soldiers from the 101st have overseen tens of millions of dollars worth of reconstruction projects: drilling wells for villages that had never had their own water supply; rebuilding playgrounds and schools; repairing outdated and broken electrical systems; installing satellite equipment needed to get the regional phone system up and running; restoring the city's water works; repairing sewers and in some cases installing sewage systems in neighborhoods that had never had them; policing, cleaning and reorganizing the ancient marketplace in the Old City; setting up a de facto social security system to provide "retirement" pay to the 110,000 former Iraqi soldiers in the area; screening and, in most cases, putting back to work most of the former Baath Party members who fled their jobs at the beginning of the war.
So many civil projects were reported on at a recent battle update briefing I attended that staff officers sometimes sounded more like board members of a multinational corporation than the combat-hardened infantry soldiers they are.…The Coalition Provisional Authority nominally has the job of "rebuilding" Iraq — using $20 billion or so of the $78 billion that recently flew out of America's deficit-plagued coffers. But during the time the 101st has been in Mosul, three regional coalition authority directors have come and gone. Only recently, long after the people of Mosul elected their mayor and city council, was a civilian American governance official sent to the area. And, according to the division leadership, not a nickel of the $20 billion controlled by the provisional authority has reached them.
"First they want a planning contractor to come in here, and even that step takes weeks to get approved," one officer in Mosul complained of the civilian leadership. "The planners were up here for months doing assessments, and then more weeks go by because everything has to be approved by Baghdad. If we sat around waiting for the C.P.A. and its civilian contractors to do it, we still wouldn't have electricity and running water in Mosul, so we just took our own funds and our engineers and infantry muscle and did it ourselves. We didn't have the option of waiting on the guys in the Green Zone."
But the guys in the Green Zone seem to have plenty of time on their hands. The place is something to behold, surrounded on one side by the heavily patrolled Tigris River, and on the three others by a 15-foot-high concrete wall backed by several rows of concertina razor wire and a maze of lesser concrete barriers. There's only one way in and out, through a heavily fortified checkpoint near the Jumhiriya Bridge guarded by tanks and Bradley Fighting Vehicles from the First Armored Division and an invisible array of British commando teams. More tanks guard key intersections inside the walls, machine gun towers line the wide boulevards, snipers man firing positions atop palaces great and small.
In all, hundreds of uniformed soldiers and heavily armed civilian security guards stand watch all day, every day over a display of grim garishness that would have given Liberace nightmares. If you're curious about how your tax dollars are being spent in Baghdad, you should get one of the many colonels strolling about the Green Zone to take you on a tour of the rebuilt duck pond across the road from the marble and gold-leafed palace serving as headquarters of an Army brigade. As I went to sleep one night a couple of weeks ago in the Green Zone, listening to the gurgle of the duck pond fountain and the comforting roar of Black Hawk helicopters patrolling overhead, it occurred to me that it was the safest night I've spent in about 25 years.
Which was a blessing for me, but a curse on the war effort. The super-defended Green Zone is the biggest, most secure American base camp in Iraq, but there is little connection between the troops in the field and the bottomless pit of planners and deciders who live inside the palace. Soldiers from the 101st tell me that they waited months for the Bechtel Corporation to unleash its corporate might in northern Iraq. "Then one of the Bechtel truck convoys got ambushed on the way up here three weeks ago, and one of the security guys got wounded," an infantryman told me. "They abandoned their trucks on the spot and pulled out, and we haven't seen them since."
"It's really not helpful when people down in Baghdad and politicians back in Washington refer to the `disorganized and ineffective' enemy we supposedly face," said one young officer, as we walked out of a battalion battle briefing that had been concerned largely with the tactics of an enemy force that is clearly well organized and very, very effective. After spending more than a week with the soldiers of Bravo Company, I know that they resent not only the inaccuracy of such statements, but the implication that soldiers facing a disorganized and ineffective enemy have an easy job.
No matter what you call this stage of the conflict in Iraq — the soldiers call it a guerrilla war while politicians back home often refer to it misleadingly and inaccurately as part of the amorphous "war on terror" — it is without a doubt a nasty, deadly war. And the people doing the fighting are soldiers, not the civilian employees of Kellogg, Brown & Root, or the officials of the Coalition Provisional Authority, or the visiting bigwigs from the Defense Department.
The troops in Bravo Company don't pay much attention to the rear-guard political wars being waged back in Washington, but they loved President Bush's quick visit to Baghdad on Thanksgiving. While it was clearly a political stunt, they were quick to credit the risks he took. I can confirm that flying in and out of Baghdad — even at night, when it's safest — is not for the faint of heart. A C-130 on approach takes a nervous, dodgy route, banking this way and that, gaining and losing altitude. Hanging onto one of those web-seats by only a seat belt (no shoulder harnesses), you're nearly upside down half the time — it would feel like the ultimate roller-coaster ride, except it's very much for real.
When Bravo Company troops roll out of the rack at 2 a.m. for street patrols, they walk the broad boulevards and narrow alleyways spread out as if they're walking a jungle trail — wheeling to the rear, sideways, back to the front; their eyes searching doorways, alleys, windows, rooftops, passing cars, even donkey carts — trying to keep one another alive for another day, another week, another month, whatever it takes to get home.
Meanwhile, two soldiers armed with M-4 carbines and fearsome M-249 Saws machine guns stand guard inside concrete and sandbag bunkers atop the Bravo Company camp's roof, while squads of soldiers patrol alleys with no names in Mosul's Old City, and everyone prays.
http://www.nytimes.com/2003/12/07/opinion/07TRUS.html?pagewanted=all&position=
IE 6.0 - QuirksMode - for all your browser quirks:
"QuirksMode.org is the personal and professional site of Peter-Paul Koch, freelance web developer in Amsterdam, the Netherlands. It contains more than 150 pages with CSS and JavaScript tips and tricks, and is one of the best sources on the WWW for studying and defeating browser incompatibilities.
It is free of charge and ads, and largely free of copyrights."
This site is quite large. The table of contents mostly leads to other tables of contents.
http://www.quirksmode.org/
"QuirksMode.org is the personal and professional site of Peter-Paul Koch, freelance web developer in Amsterdam, the Netherlands. It contains more than 150 pages with CSS and JavaScript tips and tricks, and is one of the best sources on the WWW for studying and defeating browser incompatibilities.
It is free of charge and ads, and largely free of copyrights."
This site is quite large. The table of contents mostly leads to other tables of contents.
http://www.quirksmode.org/
Friday, December 05, 2003
Warning: Look Out for the eBay Scam:
"The trick message arrived with a very official looking header featuring eBay's logo. It was signed 'Thank you, Accounts Management.' The text read: 'Dear eBay Member, We at eBay are sorry to inform you that we are having problems with the billing information of your account. We would appreciate it if you would visit our website, eBay Billing Center, and fill out the proper information that we are needing to keep you as an eBay member.' The 'eBay Billing Center' referenced was a link to a Web page asking for a credit card number, a social security number, and more. The message also contained an 'ebay.com' suffix, just as a real message from an eBay employee might."
As is often true in spoof messages and phishing efforts, the trick e-mail contained telltale signs that it did not come from eBay. The subject line of the message read "eBay Member Billing Information Uptade" with the word "update" misspelled. The text string "fill out the proper information that we are needing" also had suspicious syntax.…
http://www.pcmag.com/article2/0,4149,1402431,00.asp
"The trick message arrived with a very official looking header featuring eBay's logo. It was signed 'Thank you, Accounts Management.' The text read: 'Dear eBay Member, We at eBay are sorry to inform you that we are having problems with the billing information of your account. We would appreciate it if you would visit our website, eBay Billing Center, and fill out the proper information that we are needing to keep you as an eBay member.' The 'eBay Billing Center' referenced was a link to a Web page asking for a credit card number, a social security number, and more. The message also contained an 'ebay.com' suffix, just as a real message from an eBay employee might."
As is often true in spoof messages and phishing efforts, the trick e-mail contained telltale signs that it did not come from eBay. The subject line of the message read "eBay Member Billing Information Uptade" with the word "update" misspelled. The text string "fill out the proper information that we are needing" also had suspicious syntax.…
http://www.pcmag.com/article2/0,4149,1402431,00.asp
News: Antispammers again targeted by worm:
"Antispam organizations are the target of a new Internet worm outbreak that tries to knock them offline with a crippling data barrage, computer security experts said Tuesday.
Virus experts believe the worm, W32/Mimail-L, is the work of a vengeful spam e-mail peddler bent on paralyzing organizations that try to deal with spam, the torrents of get-rich-quick schemes and body-enhancement deals that clog in-boxes daily.
'It's the third Mimail variation to come after us, except this one is trying to do more,' said Steve Linford, founder of The Spamhaus Project, a British-based group that singles out spammers. Spamhaus was hit by Mimail late Monday. "
According to anti-virus and spam-filtering company Sophos Plc, the Mimail-L program comes as an attachment to an e-mail purporting to be from a woman named Wendy who details an erotic encounter and then offers naked photographs.
Clicking on the attachment activates the virus. Once triggered, the worm forwards itself to other e-mail users.
The worm can also turn the affected PC into a "zombie," which can then be remotely commanded to bombard one of a select group of targets, such as Spamhaus, with a disabling blizzard of data--a so-called denial-of-service attack.
In a new twist, a follow-up e-mail is sent to the infected user stating that an order for a CD containing images of child pornography will be delivered to their postal address.
To stop the order, the e-mail advises, they should respond to what appears to be an e-mail address for billing complaints, but which is actually an e-mail for one of the eight targets.…
http://zdnet.com.com/2100-1105_2-5112997.html
"Antispam organizations are the target of a new Internet worm outbreak that tries to knock them offline with a crippling data barrage, computer security experts said Tuesday.
Virus experts believe the worm, W32/Mimail-L, is the work of a vengeful spam e-mail peddler bent on paralyzing organizations that try to deal with spam, the torrents of get-rich-quick schemes and body-enhancement deals that clog in-boxes daily.
'It's the third Mimail variation to come after us, except this one is trying to do more,' said Steve Linford, founder of The Spamhaus Project, a British-based group that singles out spammers. Spamhaus was hit by Mimail late Monday. "
According to anti-virus and spam-filtering company Sophos Plc, the Mimail-L program comes as an attachment to an e-mail purporting to be from a woman named Wendy who details an erotic encounter and then offers naked photographs.
Clicking on the attachment activates the virus. Once triggered, the worm forwards itself to other e-mail users.
The worm can also turn the affected PC into a "zombie," which can then be remotely commanded to bombard one of a select group of targets, such as Spamhaus, with a disabling blizzard of data--a so-called denial-of-service attack.
In a new twist, a follow-up e-mail is sent to the infected user stating that an order for a CD containing images of child pornography will be delivered to their postal address.
To stop the order, the e-mail advises, they should respond to what appears to be an e-mail address for billing complaints, but which is actually an e-mail for one of the eight targets.…
http://zdnet.com.com/2100-1105_2-5112997.html
Wednesday, December 03, 2003
'Critical' IE Security Warning Released:
"A Chinese security researcher has warned of five serious vulnerabilities in Microsoft's (Quote, Chart) Internet Explorer browser, warning that a successful exploit could lead to system takeover.
Liu Die Yu released details of the flaws on the Bugtraq mailing list and issued a warning that the vulnerabilities could lead to system access, exposure of sensitive information, cross site scripting and security bypass.
Yu also released proof-of-concept exploits on the popular mailing list, noting that the flaws affect Internet Explorer versions 5.0, 5.5 and 6.0."
Independent security consultant Secunia has rated the flaws 'Extremely Critical' and urged IE users to disable Active Scripting as a workaround until Microsoft issues a fix.
The flaws related to a redirection feature in the browser using the "mhtml:" URI handler. The researcher warned that it could be exploited to bypass a security check in Internet Explorer which normally blocks web pages in the "Internet" zone from parsing local files.
Yu said the redirection feature could also be exploited to download and execute a malicious file on a user's system. Successful exploitation requires that script code can be executed in the "MyComputer" zone, he explained.
The security alert also included a cross-site scripting vulnerability that could allow a malicious attacker to execute script code in the security zone associated with another Web page if it contains a subframe.
A variant of a previously fixed flaw can still be exploited to hijack a user's clicks and perform certain actions without the user's knowledge, the researcher explained.
Microsoft late Wednesday confirmed it was investigating Lu's warnings. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," said Stephen Toulouse, Security Program Manager, Microsoft Security Response Center.
Toulouse told internetnews.com Microsoft would take the "appropriate action to protect our customers" and hinted that a fix could come via an out-of-cycle patch, depending on the seriousness of its findings.
He said Microsoft was concerned that Lu's warnings were not disclosed responsibly, potentially putting computer users at risk. "We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality patches for security vulnerabilities with no exposure to malicious attackers while the patch is being developed," Toulouse declared.
In the interim, Toulouse is recommending that IE users install the cumulative patch issued earlier this month (MS03-048).…
http://www.internetnews.com/dev-news/print.php/3114171
"A Chinese security researcher has warned of five serious vulnerabilities in Microsoft's (Quote, Chart) Internet Explorer browser, warning that a successful exploit could lead to system takeover.
Liu Die Yu released details of the flaws on the Bugtraq mailing list and issued a warning that the vulnerabilities could lead to system access, exposure of sensitive information, cross site scripting and security bypass.
Yu also released proof-of-concept exploits on the popular mailing list, noting that the flaws affect Internet Explorer versions 5.0, 5.5 and 6.0."
Independent security consultant Secunia has rated the flaws 'Extremely Critical' and urged IE users to disable Active Scripting as a workaround until Microsoft issues a fix.
The flaws related to a redirection feature in the browser using the "mhtml:" URI handler. The researcher warned that it could be exploited to bypass a security check in Internet Explorer which normally blocks web pages in the "Internet" zone from parsing local files.
Yu said the redirection feature could also be exploited to download and execute a malicious file on a user's system. Successful exploitation requires that script code can be executed in the "MyComputer" zone, he explained.
The security alert also included a cross-site scripting vulnerability that could allow a malicious attacker to execute script code in the security zone associated with another Web page if it contains a subframe.
A variant of a previously fixed flaw can still be exploited to hijack a user's clicks and perform certain actions without the user's knowledge, the researcher explained.
Microsoft late Wednesday confirmed it was investigating Lu's warnings. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," said Stephen Toulouse, Security Program Manager, Microsoft Security Response Center.
Toulouse told internetnews.com Microsoft would take the "appropriate action to protect our customers" and hinted that a fix could come via an out-of-cycle patch, depending on the seriousness of its findings.
He said Microsoft was concerned that Lu's warnings were not disclosed responsibly, potentially putting computer users at risk. "We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality patches for security vulnerabilities with no exposure to malicious attackers while the patch is being developed," Toulouse declared.
In the interim, Toulouse is recommending that IE users install the cumulative patch issued earlier this month (MS03-048).…
http://www.internetnews.com/dev-news/print.php/3114171
Tuesday, December 02, 2003
Webmasters Wary of Latest Google Tweaks:
"Some sites have fallen from high rankings to the nether reaches, while others have gained better slots. While such shifts are nothing new, this time around some observers say it appears that Google is trying to penalize sites using the most aggressive search-engine-optimization techniques with keywords and links to rank well on Google results. "
The problem is that along with these abusers of search engine optimization, many more innocent sites have fallen as well, said Barry Lloyd, CEO of Clogher, Ireland-based search-engine marketing company Microchannel Technologies Ltd.
"It's gone from a Google love fest to some of the most vitriolic attacks I've ever heard," he said of the reaction to the latest tweaks. "My genuine belief is that there's been too much collateral damage. A lot of people not deliberately gaming the system have been affected."
Google, as a matter of policy, does not discuss changes to its search engine algorithm. A spokesman said that the Mountain View, Calif., regularly tweaks its algorithms to improve the relevancy of search results.
"This is why it is common to see movement in the ranking of sites on Google search results pages," he said.
It remains to be seen to what extent the common user of Google has noticed the shifting positions of sites in search results. Search-engine marketers and optimizers readily admit that they watch the results with hawk eyes, noticing the slightest shifts in rank.
To Danny Sullivan, editor of SearchEngineWatch.com, the current spat of debate filling Webmaster and search-engine message boards is part of the regular cycle of complaints that follows a Google change. Quantifying whether the latest shifting is producing better or worse results is difficult since the results vary depending on the search query.
"If your job is to optimize a site for a particular term, then you know intimately what site comes up for that term," Sullivan said. "For a typical Google user, they probably won't notice anything."
Along with link tricks, some sites and search-engine optimizers have created doorway pages. The pages are designed specifically for search engine spiders indexing Web pages and are optimized to match coveted keywords. They are often invisible to actual users or appear as a quick introductory page that leads into the main site.
"(Google) had to come up with a way of overcoming the gaming of their algorithm because it was becoming so corrupted," Lloyd said.
In the course of combating techniques what Google and others consider search-engine spam, Google's algorithm changes also appear to have caught other sites in the crosshairs, Lloyd said. The changes appear to be affecting the rank of commercial-oriented search terms the most, ones where over-optimization is often common, and to be hurting sites that use a given keyword term frequently in the site or in the domain, Lloyd said.
At the same time, Lloyd and others have noticed that the results for some search terms seem more focused on directory listings or non-commercial sites rather than commercial sites. On one example, Lloyd tried searching for "Web design Calgary," expecting to find Web design companies in Calgary, Canada. Instead the first result was the site for the Calgary Flames hockey team.
More than anything, the most recent brouhaha over Google algorithm changes points to the danger of relying too heavily on search-result positioning for one's business, experts say.…
http://www.eweek.com/print_article/0,3048,a=113607,00.asp
"Some sites have fallen from high rankings to the nether reaches, while others have gained better slots. While such shifts are nothing new, this time around some observers say it appears that Google is trying to penalize sites using the most aggressive search-engine-optimization techniques with keywords and links to rank well on Google results. "
The problem is that along with these abusers of search engine optimization, many more innocent sites have fallen as well, said Barry Lloyd, CEO of Clogher, Ireland-based search-engine marketing company Microchannel Technologies Ltd.
"It's gone from a Google love fest to some of the most vitriolic attacks I've ever heard," he said of the reaction to the latest tweaks. "My genuine belief is that there's been too much collateral damage. A lot of people not deliberately gaming the system have been affected."
Google, as a matter of policy, does not discuss changes to its search engine algorithm. A spokesman said that the Mountain View, Calif., regularly tweaks its algorithms to improve the relevancy of search results.
"This is why it is common to see movement in the ranking of sites on Google search results pages," he said.
It remains to be seen to what extent the common user of Google has noticed the shifting positions of sites in search results. Search-engine marketers and optimizers readily admit that they watch the results with hawk eyes, noticing the slightest shifts in rank.
To Danny Sullivan, editor of SearchEngineWatch.com, the current spat of debate filling Webmaster and search-engine message boards is part of the regular cycle of complaints that follows a Google change. Quantifying whether the latest shifting is producing better or worse results is difficult since the results vary depending on the search query.
"If your job is to optimize a site for a particular term, then you know intimately what site comes up for that term," Sullivan said. "For a typical Google user, they probably won't notice anything."
Along with link tricks, some sites and search-engine optimizers have created doorway pages. The pages are designed specifically for search engine spiders indexing Web pages and are optimized to match coveted keywords. They are often invisible to actual users or appear as a quick introductory page that leads into the main site.
"(Google) had to come up with a way of overcoming the gaming of their algorithm because it was becoming so corrupted," Lloyd said.
In the course of combating techniques what Google and others consider search-engine spam, Google's algorithm changes also appear to have caught other sites in the crosshairs, Lloyd said. The changes appear to be affecting the rank of commercial-oriented search terms the most, ones where over-optimization is often common, and to be hurting sites that use a given keyword term frequently in the site or in the domain, Lloyd said.
At the same time, Lloyd and others have noticed that the results for some search terms seem more focused on directory listings or non-commercial sites rather than commercial sites. On one example, Lloyd tried searching for "Web design Calgary," expecting to find Web design companies in Calgary, Canada. Instead the first result was the site for the Calgary Flames hockey team.
More than anything, the most recent brouhaha over Google algorithm changes points to the danger of relying too heavily on search-result positioning for one's business, experts say.…
http://www.eweek.com/print_article/0,3048,a=113607,00.asp
News: Flaw in Linux kernel allows attack:
"The Debian Project warned on Monday that a flaw in the Linux kernel helped attackers compromise four of the open-source software project's development servers.
During several intrusions Nov. 19, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.
Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released Friday, eight days after the Debian breach."
The unknown attacker compromised at least four servers. The systems--known as Master, Murphy, Gluck and Klecker--had maintained the open-source project's bug tracking system, source code database, mailing lists, Web site and security patches.
The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published Friday. When the programmer logged into the klecker system, the attacker recorded his password.
Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw--in a part of the kernel that manages memory--allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.
The attacks have been the latest leveled at open-source software. In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open-source projects.
http://zdnet.com.com/2100-1104_2-5112427.html
"The Debian Project warned on Monday that a flaw in the Linux kernel helped attackers compromise four of the open-source software project's development servers.
During several intrusions Nov. 19, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.
Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released Friday, eight days after the Debian breach."
The unknown attacker compromised at least four servers. The systems--known as Master, Murphy, Gluck and Klecker--had maintained the open-source project's bug tracking system, source code database, mailing lists, Web site and security patches.
The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published Friday. When the programmer logged into the klecker system, the attacker recorded his password.
Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw--in a part of the kernel that manages memory--allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.
The attacks have been the latest leveled at open-source software. In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open-source projects.
http://zdnet.com.com/2100-1104_2-5112427.html
Economy & Business: I.R.S. Set to Resolve Disputes Online:
"The I.R.S. is testing a system called Electronic Account Resolution with a handful of tax professionals. Lawyers, accountants and enrolled agents - a kind of preparer who is authorized to represent taxpayers before the I.R.S. - will be able to use the system; they can go online now to register. But individuals and other paid preparers will not have access.
James Leimbach, an enrolled agent in Panama City, Fla., who is one of the testers, is enthusiastic. 'Through a simple three-step process,' Mr. Leimbach said, 'I will be able to electronically access my client's tax records and then resolve problems.'
Under the present nonelectronic system, tax professionals must show the agency a power of attorney from the taxpayer before the I.R.S. will talk to them. While I.R.S. clerks will sometimes accept a faxed form, getting approval to represent a client can take days."
With the new system, a taxpayer fills out the power of attorney form and gives it to the tax adviser. Then the adviser logs on to an I.R.S. computer, using a secure Internet connection, punching in the client's adjusted gross income from any of the three previous years, the year of the return and the taxpayer's birth date. The taxpayer also gives a self-selected personal identification number.
"You get disclosure authorization almost instantly," Mr. Leimbach said. Immediately, a request can be made for the taxpayer's records, known as a transcript.
"Typically, getting a transcript took 5 to 10 days when ordered through the mail," he said. "With the new system, I will be able to pull transcripts up electronically."
Such speedy gathering of information and problem resolution - in contrast to hours or days of work - should hold down the fees taxpayers pay their advisers.
At first, the system can be used to resolve simple problems, like tracing payments, tracking refunds and entering into installment agreements to pay taxes.
The agency has not begun to work on more complex problems, like proposals to settle a tax debt for less than the full amount…
http://www.nytimes.com/2003/12/01/business/01taxx.html
"The I.R.S. is testing a system called Electronic Account Resolution with a handful of tax professionals. Lawyers, accountants and enrolled agents - a kind of preparer who is authorized to represent taxpayers before the I.R.S. - will be able to use the system; they can go online now to register. But individuals and other paid preparers will not have access.
James Leimbach, an enrolled agent in Panama City, Fla., who is one of the testers, is enthusiastic. 'Through a simple three-step process,' Mr. Leimbach said, 'I will be able to electronically access my client's tax records and then resolve problems.'
Under the present nonelectronic system, tax professionals must show the agency a power of attorney from the taxpayer before the I.R.S. will talk to them. While I.R.S. clerks will sometimes accept a faxed form, getting approval to represent a client can take days."
With the new system, a taxpayer fills out the power of attorney form and gives it to the tax adviser. Then the adviser logs on to an I.R.S. computer, using a secure Internet connection, punching in the client's adjusted gross income from any of the three previous years, the year of the return and the taxpayer's birth date. The taxpayer also gives a self-selected personal identification number.
"You get disclosure authorization almost instantly," Mr. Leimbach said. Immediately, a request can be made for the taxpayer's records, known as a transcript.
"Typically, getting a transcript took 5 to 10 days when ordered through the mail," he said. "With the new system, I will be able to pull transcripts up electronically."
Such speedy gathering of information and problem resolution - in contrast to hours or days of work - should hold down the fees taxpayers pay their advisers.
At first, the system can be used to resolve simple problems, like tracing payments, tracking refunds and entering into installment agreements to pay taxes.
The agency has not begun to work on more complex problems, like proposals to settle a tax debt for less than the full amount…
http://www.nytimes.com/2003/12/01/business/01taxx.html
News: Sobig lingers despite shutdown date:
"Sobig is still rampaging around the Internet, two months after the virus was supposed to have terminated itself. "
E-mail security firm MessageLabs said Friday that Sobig was the third most active virus in November, with some 264,000 copies being detected by its e-mail virus-scanning servers.
Although this activity is well below the virus's peak, it is still surprising as Sobig--like several other members of the Sobig family--contained a built-in shutdown date that was supposed to prevent it propagating after Sept. 10. Sobig.F's continued proliferation is due to a combination of factors, including the successful efforts that prevented it wreaking even more havoc and the fact that many PCs are set to the wrong date, according to MessageLabs.
http://zdnet.com.com/2100-1104_2-5112207.html
"Sobig is still rampaging around the Internet, two months after the virus was supposed to have terminated itself. "
E-mail security firm MessageLabs said Friday that Sobig was the third most active virus in November, with some 264,000 copies being detected by its e-mail virus-scanning servers.
Although this activity is well below the virus's peak, it is still surprising as Sobig--like several other members of the Sobig family--contained a built-in shutdown date that was supposed to prevent it propagating after Sept. 10. Sobig.F's continued proliferation is due to a combination of factors, including the successful efforts that prevented it wreaking even more havoc and the fact that many PCs are set to the wrong date, according to MessageLabs.
http://zdnet.com.com/2100-1104_2-5112207.html
Score one for the spammers: CAN SPAM bill to become law - TechUpdate - ZDNet:
"For the umpteenth time: Anti-spam laws are a bad idea as long as they're written by those out of touch with the underpinnings of Internet e-mail. For example, writing into law anything that ventures down the path of 'opting out' (short-hand for 'optioning out,' deselecting, or unsubscribing yourself from membership in a mailing list) --- which CAN SPAM does --- creates a virtually unenforceable law since there are a million and one reasons (most of which would not be due to negligence on behalf of mailing list operators) that an opt-out mechanism may not work at some given point in time. Before opt-out language can be included in a law, there needs to exist an opt-out standard under the guise of what I call a relationship termination protocol over which dissimilar email clients and servers can interoperate. "
Perhaps you think I'm on the lunatic fringe, an ultraconservative who refuses to see the good in legislation that clearly has the welfare of the spam-afflicted in mind? OK ignore me. But don't ignore the following warning, reported in a recent CNET News.com story about the CAN SPAM bill, that was sent from the National Association of Attorneys General to Congress: "The bill creates so many loopholes, exceptions, and high standards of proof, that it provides minimal consumer protections and creates too many burdens for effective enforcement...We respectfully request that you not move forward."
Lack of enforceability has been my main point all along and it's refreshing to see the very folks chartered with upholding the CAN SPAM bill saying to Congress "Hey, you're all off your rockers if you move forward with this law." Still not convinced? Assuming that the law's effectiveness is dependent on the fact that all evil spammers fall within its jurisdiction (a very bad assumption considering the mounting tide of spam from China and South Korea), then you, as a concerned Netizen, should consider its definition of spam. To the relief of e-mail marketers everywhere, spam will not be the first unsolicited commercial email you get from someone you consider to be a spammer. It's one of the subsequent ones. That's right. It's the second, third, fourth, or later one and it is only such if, after receiving the first one, you issued an objection according to a method the sender, not you, says you are permitted to do so (the vaulted "opt-out" for which no standard method exists and no auditable test for proven functionality has been created).
Are you getting ill yet?
Despite the fact that the Attorneys General will be reluctant to expend the resources necessary to prosecute given the loopholes it envisions, Senators Burns and Wyden cited the financial implications in their declarations of victory. Sen. Ron Wyden, D-Ore., said that "when this bill takes effect, the big-time spammers who up until now have faced virtually no penalties will suddenly be at risk of criminal prosecution, (Federal Trade Commission) prosecution and million-dollar lawsuits." Sen. Conrad Burns, R-Mont., said: "In cases where e-mail marketers don't comply with the CAN-SPAM bill, the penalties are very severe...Spammers are actually on the hook for (per e-mail) damages, with a cap of $2 million."
Newsflash. The big time spammers --- at least the ones who are intentionally sidestepping all sense of Internet decorum in order to invade the sanctity of your inbox --- have about a hundred dollars in their checking accounts--collectively. It was only about six months ago, at the now infamous Federal Trade Commission three-day workshop on spam, that we heard from several Attorneys General and Internet Service Providers about how their investments in certain investigations, indictments, prosecutions, and lawsuits were disproportionate to the final outcome: one or two bad apples (out of an ocean-sized apple orchard) with little or no money to their names shut down. My inbox didn't notice. Did yours? Despite efforts to publicly draw, quarter, flog, and hang the offenders, the rest of the orchard didn't appear to flinch. It may have yawned, though. We'll never know. They're a secretive bunch. It's not like they have offices on Madison Avenue.
http://techupdate.zdnet.com/techupdate/stories/main/Score_one_for_the_spammers.html
"For the umpteenth time: Anti-spam laws are a bad idea as long as they're written by those out of touch with the underpinnings of Internet e-mail. For example, writing into law anything that ventures down the path of 'opting out' (short-hand for 'optioning out,' deselecting, or unsubscribing yourself from membership in a mailing list) --- which CAN SPAM does --- creates a virtually unenforceable law since there are a million and one reasons (most of which would not be due to negligence on behalf of mailing list operators) that an opt-out mechanism may not work at some given point in time. Before opt-out language can be included in a law, there needs to exist an opt-out standard under the guise of what I call a relationship termination protocol over which dissimilar email clients and servers can interoperate. "
Perhaps you think I'm on the lunatic fringe, an ultraconservative who refuses to see the good in legislation that clearly has the welfare of the spam-afflicted in mind? OK ignore me. But don't ignore the following warning, reported in a recent CNET News.com story about the CAN SPAM bill, that was sent from the National Association of Attorneys General to Congress: "The bill creates so many loopholes, exceptions, and high standards of proof, that it provides minimal consumer protections and creates too many burdens for effective enforcement...We respectfully request that you not move forward."
Lack of enforceability has been my main point all along and it's refreshing to see the very folks chartered with upholding the CAN SPAM bill saying to Congress "Hey, you're all off your rockers if you move forward with this law." Still not convinced? Assuming that the law's effectiveness is dependent on the fact that all evil spammers fall within its jurisdiction (a very bad assumption considering the mounting tide of spam from China and South Korea), then you, as a concerned Netizen, should consider its definition of spam. To the relief of e-mail marketers everywhere, spam will not be the first unsolicited commercial email you get from someone you consider to be a spammer. It's one of the subsequent ones. That's right. It's the second, third, fourth, or later one and it is only such if, after receiving the first one, you issued an objection according to a method the sender, not you, says you are permitted to do so (the vaulted "opt-out" for which no standard method exists and no auditable test for proven functionality has been created).
Are you getting ill yet?
Despite the fact that the Attorneys General will be reluctant to expend the resources necessary to prosecute given the loopholes it envisions, Senators Burns and Wyden cited the financial implications in their declarations of victory. Sen. Ron Wyden, D-Ore., said that "when this bill takes effect, the big-time spammers who up until now have faced virtually no penalties will suddenly be at risk of criminal prosecution, (Federal Trade Commission) prosecution and million-dollar lawsuits." Sen. Conrad Burns, R-Mont., said: "In cases where e-mail marketers don't comply with the CAN-SPAM bill, the penalties are very severe...Spammers are actually on the hook for (per e-mail) damages, with a cap of $2 million."
Newsflash. The big time spammers --- at least the ones who are intentionally sidestepping all sense of Internet decorum in order to invade the sanctity of your inbox --- have about a hundred dollars in their checking accounts--collectively. It was only about six months ago, at the now infamous Federal Trade Commission three-day workshop on spam, that we heard from several Attorneys General and Internet Service Providers about how their investments in certain investigations, indictments, prosecutions, and lawsuits were disproportionate to the final outcome: one or two bad apples (out of an ocean-sized apple orchard) with little or no money to their names shut down. My inbox didn't notice. Did yours? Despite efforts to publicly draw, quarter, flog, and hang the offenders, the rest of the orchard didn't appear to flinch. It may have yawned, though. We'll never know. They're a secretive bunch. It's not like they have offices on Madison Avenue.
http://techupdate.zdnet.com/techupdate/stories/main/Score_one_for_the_spammers.html
Friday, November 28, 2003
Beware the Worm in Your Handset:
"As more consumers begin surfing the Web and sending e-mail messages on cellphone and hand-held devices, along comes a new worry: worms and viruses spread via Internet-enabled handsets."
The problem is still small, with only a few cases reported globally. But as operating systems in cellphones become standardized, hackers will probably begin focusing on vulnerabilities in those systems as they have with personal computers. And as cellphones and personal digital assistants connect to the Internet at ever faster speeds, more users will be able to download files with attachments - some of which may be infected.
Asia, where high-speed networks and text messaging on mobile phones are common, is the most vulnerable to these threats. As carriers in Europe and North America adopt similar technology, they will confront the same kinds of hazards.
Telecommunications companies currently spend as much as $8 billion a year fixing handsets with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business.
"The danger to mobile phone networks is probably five times bigger than with personal computers because very few people are focused on this problem now," said Andrew Cole, senior vice president at Adventis, a Boston-based consultant specializing in telecommunications issues. "The dominant form of messaging is going to be cell-to-cell, so this could escalate very rapidly and overload phone networks. What if viruses phone 911 randomly?"
That, in fact, is what happened in Japan in 2000 and 2001. NTT DoCoMo, the country's largest cellular phone provider, received complaints from customers who were being sent messages that froze their screens and automatically dialed 110, the emergency line to the police in Japan.…
That event was a shock because the company is spending billions of dollars introducing its high-speed third-generation, or 3G, network that allows users to download data up to 40 times faster than conventional mobile phone networks. A rash of viruses might turn off users to the new network before it was released. Eventually, DoCoMo dealt with the problem by installing special security software on its servers and new handsets, which were also being bombarded with unwanted commercial e-mail and text messages from advertisers, dating clubs and other marketers. DoCoMo blocks about 55 percent of the one billion text messages that reach its servers each day because of suspicious return addresses or attachments. Another 26 percent of those messages are blocked by DoCoMo users who have programmed their handsets to turn back unwanted mail or spam.
http://www.nytimes.com/2003/11/28/technology/28cell.html
"As more consumers begin surfing the Web and sending e-mail messages on cellphone and hand-held devices, along comes a new worry: worms and viruses spread via Internet-enabled handsets."
The problem is still small, with only a few cases reported globally. But as operating systems in cellphones become standardized, hackers will probably begin focusing on vulnerabilities in those systems as they have with personal computers. And as cellphones and personal digital assistants connect to the Internet at ever faster speeds, more users will be able to download files with attachments - some of which may be infected.
Asia, where high-speed networks and text messaging on mobile phones are common, is the most vulnerable to these threats. As carriers in Europe and North America adopt similar technology, they will confront the same kinds of hazards.
Telecommunications companies currently spend as much as $8 billion a year fixing handsets with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business.
"The danger to mobile phone networks is probably five times bigger than with personal computers because very few people are focused on this problem now," said Andrew Cole, senior vice president at Adventis, a Boston-based consultant specializing in telecommunications issues. "The dominant form of messaging is going to be cell-to-cell, so this could escalate very rapidly and overload phone networks. What if viruses phone 911 randomly?"
That, in fact, is what happened in Japan in 2000 and 2001. NTT DoCoMo, the country's largest cellular phone provider, received complaints from customers who were being sent messages that froze their screens and automatically dialed 110, the emergency line to the police in Japan.…
That event was a shock because the company is spending billions of dollars introducing its high-speed third-generation, or 3G, network that allows users to download data up to 40 times faster than conventional mobile phone networks. A rash of viruses might turn off users to the new network before it was released. Eventually, DoCoMo dealt with the problem by installing special security software on its servers and new handsets, which were also being bombarded with unwanted commercial e-mail and text messages from advertisers, dating clubs and other marketers. DoCoMo blocks about 55 percent of the one billion text messages that reach its servers each day because of suspicious return addresses or attachments. Another 26 percent of those messages are blocked by DoCoMo users who have programmed their handsets to turn back unwanted mail or spam.
http://www.nytimes.com/2003/11/28/technology/28cell.html
Wednesday, November 26, 2003
News: The computer virus--no cures to be found:
"Of all the accomplishments in the annals of technology, Fred Cohen's contribution is undeniably unique: He introduced the term 'virus' to the lexicon of computers."
The University of New Haven professor used the phrase in a 1984 research paper, in which he described threats self-propagating programs pose and explored potential defenses against them. When he asked for funding from the National Science Foundation three years later to further explore countermeasures, the agency rebuffed him.
"They turned it down," said Cohen, who is also principal analyst for research firm Burton Group. "They said it wasn't of current interest."
Two decades later, countless companies and individuals are still paying for that mistake. The technology industry has yet to find a blanket solution to the ever-growing list of viruses and worms that constitute the greatest risk to computers on the Internet. Every year, companies lose billions of dollars when forced to halt work and deal with infectious digital diseases, such as Sobig and Slammer.
While much attention has been paid to the malicious online attackers who exploit technology's vulnerabilities, little has been documented about the origins of the virus. Its early iterations were not created by malcontent teenagers or antisocial geeks but by campus researchers, system administrators and a handful of old-school hackers who thought that the ability to reproduce their programs automatically was a neat trick.
http://zdnet.com.com/2100-1105_2-5111442.html
"Of all the accomplishments in the annals of technology, Fred Cohen's contribution is undeniably unique: He introduced the term 'virus' to the lexicon of computers."
"The design of the Internet facilitates the distribution of information--all sorts of information; it's a double-edged sword," Gordon said in a recent e-mail interview. "Even if (viruses) are not designed to be intentionally malicious or dangerous, if they get outside of a controlled environment, there can be unexpected results."
The University of New Haven professor used the phrase in a 1984 research paper, in which he described threats self-propagating programs pose and explored potential defenses against them. When he asked for funding from the National Science Foundation three years later to further explore countermeasures, the agency rebuffed him.
"They turned it down," said Cohen, who is also principal analyst for research firm Burton Group. "They said it wasn't of current interest."
Two decades later, countless companies and individuals are still paying for that mistake. The technology industry has yet to find a blanket solution to the ever-growing list of viruses and worms that constitute the greatest risk to computers on the Internet. Every year, companies lose billions of dollars when forced to halt work and deal with infectious digital diseases, such as Sobig and Slammer.
While much attention has been paid to the malicious online attackers who exploit technology's vulnerabilities, little has been documented about the origins of the virus. Its early iterations were not created by malcontent teenagers or antisocial geeks but by campus researchers, system administrators and a handful of old-school hackers who thought that the ability to reproduce their programs automatically was a neat trick.
http://zdnet.com.com/2100-1105_2-5111442.html
Domain Theft is Still a Little Too Easy:
"Do you ever get spam offering to sell you fake IDs? Here's one reason why some people want to buy one: a fake ID, a fax machine, and an absence of morals are all that's needed to hijack any domain name. "
Yes, stealing a domain name from its rightful owners still appears to be child's play. A reader contacted me about his case involving the domain name DVDMovies.com. Several weeks ago Arnold Jones of Visionario Inc., a storage consulting firm and owner of dvdmovies.com, discovered that this domain had been transferred to someone else.
This person had sent in to Network Solutions, the registrar holding the registry of dvdmovies.com, a request by fax to change the e-mail contacts on the registration to a free yahoo.com address. Even though his identification information had been forged, including a copy of a fake Florida drivers license with Jones's work address on it, Network Solutions happily obliged and did not scrutinize the license.
Once the e-mail contact had been changed, the domain pirate simply sent a request to reset the password on the account, and he replied from the new address. Now that he had control over the account, he could transfer the registration to another registrar.
However, according to Jones' account, there were many other glaring red flags that should have alerted Network Solutions to a possible hijacking:
The fax requesting the e-mail change came from area code 530, in California, but all registrant information was for Florida.
The key administrative contact e-mail address was changed to a free, untraceable yahoo.com address.
The fake Florida drivers license lacked all the major characteristics of a legitimate Florida drivers license.
Jones required two weeks of time and effort before he got his domain back. If he was less sophisticated about these matters, it might have taken him much longer to take control of the domain. To compensate him for the two weeks of time and the lack of his domain, Network Solutions extended his registration by a year, a $35 value. Gosh, I hope he declares this on his taxes.…
http://www.eweek.com/article2/0,4149,1384450,00.asp
"Do you ever get spam offering to sell you fake IDs? Here's one reason why some people want to buy one: a fake ID, a fax machine, and an absence of morals are all that's needed to hijack any domain name. "
Yes, stealing a domain name from its rightful owners still appears to be child's play. A reader contacted me about his case involving the domain name DVDMovies.com. Several weeks ago Arnold Jones of Visionario Inc., a storage consulting firm and owner of dvdmovies.com, discovered that this domain had been transferred to someone else.
This person had sent in to Network Solutions, the registrar holding the registry of dvdmovies.com, a request by fax to change the e-mail contacts on the registration to a free yahoo.com address. Even though his identification information had been forged, including a copy of a fake Florida drivers license with Jones's work address on it, Network Solutions happily obliged and did not scrutinize the license.
Once the e-mail contact had been changed, the domain pirate simply sent a request to reset the password on the account, and he replied from the new address. Now that he had control over the account, he could transfer the registration to another registrar.
However, according to Jones' account, there were many other glaring red flags that should have alerted Network Solutions to a possible hijacking:
The fax requesting the e-mail change came from area code 530, in California, but all registrant information was for Florida.
The key administrative contact e-mail address was changed to a free, untraceable yahoo.com address.
The fake Florida drivers license lacked all the major characteristics of a legitimate Florida drivers license.
Jones required two weeks of time and effort before he got his domain back. If he was less sophisticated about these matters, it might have taken him much longer to take control of the domain. To compensate him for the two weeks of time and the lack of his domain, Network Solutions extended his registration by a year, a $35 value. Gosh, I hope he declares this on his taxes.…
http://www.eweek.com/article2/0,4149,1384450,00.asp
Creating Interactive Video With MPEG4:
"MPEG4 is finally starting to gain some traction. The allure of platform and vendor independence and ubiquitous players on all kinds of devices is strong. But in many areas, MPEG4 is still a 'bleeding-edge' technology. You'll quickly feel the pain when you try to do any but the most basic audio/video delivery using it. Today, all the major streaming players support MPEG4, mostly through the EnvivioTV plugin. And Apple's Quicktime lets you convert all kinds of movies to MPEG4 using the best-$30-you-ever-spent-on-software Quicktime Pro. But to really unlock the promise of MPEG4 – universal and reliable authoring and playback of complex interactive multimedia – you still have to go out on the edge."
Profiles and Compatibility
MPEG4 is designed to be useful for video playback across a wide variety of devices, from cell phones to powerful desktop computers; from pocket sized handhelds to TV set top boxes. To support this flexibility, the spec is divided into different profiles and levels, each defining a subset of MPEG4's total feature set. An MPEG player will support a particular profile by implementing all of that profile's features. IBM's SamplesForMPEG4 (also available at alphaWorks) includes dozens of examples of varied XMT and MPEG4 features. Many of these play in the QT and Real players, while others do not. (Of course, they all play in IBM's M4Play, part of the Toolkit.)
http://www.streamingmedia.com/article.asp?id=8544
"MPEG4 is finally starting to gain some traction. The allure of platform and vendor independence and ubiquitous players on all kinds of devices is strong. But in many areas, MPEG4 is still a 'bleeding-edge' technology. You'll quickly feel the pain when you try to do any but the most basic audio/video delivery using it. Today, all the major streaming players support MPEG4, mostly through the EnvivioTV plugin. And Apple's Quicktime lets you convert all kinds of movies to MPEG4 using the best-$30-you-ever-spent-on-software Quicktime Pro. But to really unlock the promise of MPEG4 – universal and reliable authoring and playback of complex interactive multimedia – you still have to go out on the edge."
Profiles and Compatibility
MPEG4 is designed to be useful for video playback across a wide variety of devices, from cell phones to powerful desktop computers; from pocket sized handhelds to TV set top boxes. To support this flexibility, the spec is divided into different profiles and levels, each defining a subset of MPEG4's total feature set. An MPEG player will support a particular profile by implementing all of that profile's features. IBM's SamplesForMPEG4 (also available at alphaWorks) includes dozens of examples of varied XMT and MPEG4 features. Many of these play in the QT and Real players, while others do not. (Of course, they all play in IBM's M4Play, part of the Toolkit.)
http://www.streamingmedia.com/article.asp?id=8544
Tuesday, November 25, 2003
washingtonpost.com: On the Web, Research Work Proves Ephemeral:
"It was in the mundane course of getting a scientific paper published that physician Robert Dellavalle came to the unsettling realization that the world was dissolving before his eyes.
The world, that is, of footnotes, references and Web pages."
Dellavalle, a dermatologist with the Veterans Affairs Medical Center in Denver, had co-written a research report featuring dozens of footnotes -- many of which referred not to books or journal articles but, as is increasingly the case these days, to Web sites that he and his colleagues had used to substantiate their findings.
Problem was, it took about two years for the article to wind its way to publication. And by that time, many of the sites they had cited had moved to other locations on the Internet or disappeared altogether, rendering useless all those Web addresses -- also known as uniform resource locators (URLs) -- they had provided in their footnotes.
"Every time we checked, some were gone and others had moved," said Dellavalle, who is on the faculty at the University of Colorado Health Sciences Center. "We thought, 'This is an interesting phenomenon itself. We should look at this.' "
He and his co-workers have done just that, and what they have found is not reassuring to those who value having a permanent record of scientific progress. In research described in the journal Science last month, the team looked at footnotes from scientific articles in three major journals -- the New England Journal of Medicine, Science and Nature -- at three months, 15 months and 27 months after publication. The prevalence of inactive Internet references grew during those intervals from 3.8 percent to 10 percent to 13 percent.
"I think of it like the library burning in Alexandria," Dellavalle said, referring to the 48 B.C. sacking of the ancient world's greatest repository of knowledge. "We've had all these hundreds of years of stuff available by interlibrary loan, but now things just a few years old are disappearing right under our noses really quickly."
http://www.washingtonpost.com/ac2/wp-dyn/A8730-2003Nov23
"It was in the mundane course of getting a scientific paper published that physician Robert Dellavalle came to the unsettling realization that the world was dissolving before his eyes.
The world, that is, of footnotes, references and Web pages."
Dellavalle, a dermatologist with the Veterans Affairs Medical Center in Denver, had co-written a research report featuring dozens of footnotes -- many of which referred not to books or journal articles but, as is increasingly the case these days, to Web sites that he and his colleagues had used to substantiate their findings.
Problem was, it took about two years for the article to wind its way to publication. And by that time, many of the sites they had cited had moved to other locations on the Internet or disappeared altogether, rendering useless all those Web addresses -- also known as uniform resource locators (URLs) -- they had provided in their footnotes.
"Every time we checked, some were gone and others had moved," said Dellavalle, who is on the faculty at the University of Colorado Health Sciences Center. "We thought, 'This is an interesting phenomenon itself. We should look at this.' "
He and his co-workers have done just that, and what they have found is not reassuring to those who value having a permanent record of scientific progress. In research described in the journal Science last month, the team looked at footnotes from scientific articles in three major journals -- the New England Journal of Medicine, Science and Nature -- at three months, 15 months and 27 months after publication. The prevalence of inactive Internet references grew during those intervals from 3.8 percent to 10 percent to 13 percent.
"I think of it like the library burning in Alexandria," Dellavalle said, referring to the 48 B.C. sacking of the ancient world's greatest repository of knowledge. "We've had all these hundreds of years of stuff available by interlibrary loan, but now things just a few years old are disappearing right under our noses really quickly."
http://www.washingtonpost.com/ac2/wp-dyn/A8730-2003Nov23
Debian: Attack Didn't Harm Source Code:
"Despite a cracker incursion into Debian Project servers this week, representatives of the Debian Linux distribution said the open-source code behind it remains untouched."
This is not the first time an open-source site has been attacked by crackers. In March of this year, the Free Software Foundation Inc.'s GNU Project ftp servers were attacked. This assault, which caused no damage to the code, was only discovered months afterwards.
In the Debian case, though, the break-in was discovered within 24 hours. The cracker had gained access to four machines: "master," the bug-tracking system; "murphy," the mailing-list manager; "gluck," the Web server and Concurrent Versions System (CVS) system; and "klecker," which houses security, quality assurance and search-engine code. Martin Schulze, a Debian spokesman, reported that the Debian source code archives themselves were "not affected by this compromise."
"This kind of attack is inevitable in open source," Murdoch said. "We've increased security. At the beginning of Debian, becoming a developer was as easy as sending me an e-mail, but these days there are checks and balances in place to make sure that only real developers get in and that the code stays clean."
http://www.eweek.com/article2/0,4149,1394420,00.asp?kc=EWNWS112403DTX1K0000599
But Open Source is Safer?
"Despite a cracker incursion into Debian Project servers this week, representatives of the Debian Linux distribution said the open-source code behind it remains untouched."
This is not the first time an open-source site has been attacked by crackers. In March of this year, the Free Software Foundation Inc.'s GNU Project ftp servers were attacked. This assault, which caused no damage to the code, was only discovered months afterwards.
In the Debian case, though, the break-in was discovered within 24 hours. The cracker had gained access to four machines: "master," the bug-tracking system; "murphy," the mailing-list manager; "gluck," the Web server and Concurrent Versions System (CVS) system; and "klecker," which houses security, quality assurance and search-engine code. Martin Schulze, a Debian spokesman, reported that the Debian source code archives themselves were "not affected by this compromise."
"This kind of attack is inevitable in open source," Murdoch said. "We've increased security. At the beginning of Debian, becoming a developer was as easy as sending me an e-mail, but these days there are checks and balances in place to make sure that only real developers get in and that the code stays clean."
http://www.eweek.com/article2/0,4149,1394420,00.asp?kc=EWNWS112403DTX1K0000599
Monday, November 24, 2003
Take note of critical Office 2003 update and MiMail worm - TechRepublic:
"Fix
Symantec has posted a free tool for removing MiMail variants A through E, which will:
End the W32.Mimail viral processes.
Remove the W32.Mimail files.
Delete dropped files.
Delete the worm’s registry values."
http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.removal.tool.html
http://techrepublic.com.com/5100-6264_11-5104786.html
"Fix
Symantec has posted a free tool for removing MiMail variants A through E, which will:
End the W32.Mimail viral processes.
Remove the W32.Mimail files.
Delete dropped files.
Delete the worm’s registry values."
http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.removal.tool.html
http://techrepublic.com.com/5100-6264_11-5104786.html
Chicago Tribune | Survey: 31 Percent of U.S. Tech-Savvy:
"Technology geeks, unite. There are more of you than you might have realized. A study released Sunday found that 31 percent of Americans are 'highly tech-savvy' people for whom the Internet, cell phones and handheld organizers are more indispensable than TVs and old-fashioned wired phones. "
John Horrigan, author of the report by the Pew Internet & American Life Project, said the size of this "tech elite" was somewhat surprising. And while this group is predominantly young, the Pew researchers found plenty of baby boomers and seniors who are equally ardent about using technology.
The difference, though, is that techies in their late teens and 20s are more likely to create online content, like Web logs, or "blogs." Generation Xers are more likely to pay for content on the Web, while wired boomers and seniors generally plumb the Internet for news or to do work-related research.
So are you part of the "tech elite"? Consider these other Pew findings about how they live:…
http://www.chicagotribune.com/technology/sns-ap-tech-elite.story
"Technology geeks, unite. There are more of you than you might have realized. A study released Sunday found that 31 percent of Americans are 'highly tech-savvy' people for whom the Internet, cell phones and handheld organizers are more indispensable than TVs and old-fashioned wired phones. "
John Horrigan, author of the report by the Pew Internet & American Life Project, said the size of this "tech elite" was somewhat surprising. And while this group is predominantly young, the Pew researchers found plenty of baby boomers and seniors who are equally ardent about using technology.
The difference, though, is that techies in their late teens and 20s are more likely to create online content, like Web logs, or "blogs." Generation Xers are more likely to pay for content on the Web, while wired boomers and seniors generally plumb the Internet for news or to do work-related research.
So are you part of the "tech elite"? Consider these other Pew findings about how they live:…
http://www.chicagotribune.com/technology/sns-ap-tech-elite.story
Chicago Tribune | Questions, answers on cell phone changes:
"Questions and answers for consumers about changes in telecommunications rules:"
http://www.chicagotribune.com/technology/sns-ap-cell-phone-qa,1,1844433.story
"Questions and answers for consumers about changes in telecommunications rules:"
http://www.chicagotribune.com/technology/sns-ap-cell-phone-qa,1,1844433.story
Subscribe to:
Posts (Atom)