Friday, November 21, 2003

Apple Plugs Vulnerabilities in Panther, Jaguar:
"The software updates a number of libraries, services and programs, including Personal File Sharing and QuickTime for Java. While described as the Security Update 2003-11-19 for Jaguar 10.2.8, the update is also recommended for Mac OS X 10.3, called Panther through Apple's automatic Software Update program. "

The update comes after Apple in October had been criticized for fixing some security problems in Mac OS X within its latest Panther release but not providing patches for earlier versions of the operating system. Later, the company indicated that it planned to offer patches for Jaguar.

http://www.eweek.com/article2/0,4149,1393307,00.asp?kc=EWNWS112103DTX1K0000599
AeANET : 11/19/2003 - U.S. High-Tech Industry Sheds More than One-Half Million Jobs in 2002, AeA Report Says:
"However, Decline in 2003 Has Slowed Dramatically"

A study released today by AeA shows that in 2002 the U.S. high-tech industry lost 540,000 jobs, dropping from 6.5 million to 6.0 million. A preliminary look at data for 2003 shows that the decline in high-tech employment slowed considerably in 2003. The report, AeA’s annual Cyberstates 2003: A State-by-State Overview of the High-Technology Industry, details national and state trends in high-tech employment, wages, exports, and other economic indicators.

The sector with the largest decrease in jobs was electronics manufacturing, accounting for more than half of all tech jobs lost between 2001 and 2002. For the first time in the seven years of publishing Cyberstates, the software sector recorded a loss of nearly 150,000 jobs last year. Indeed, the once-thriving software sector posted large increases in employment in all previous editions of Cyberstates. The communications services sector posted a similar loss of jobs. The engineering and tech services sector lost 15,000 jobs in 2002. The one bright spot was in R&D and testing labs, where employment increased by 7,000 in 2002.

"While high-tech employment fell by eight percent last year, preliminary 2003 data show a significant slowdown in high-tech job losses, with a decline of four percent," said AeA’s President and CEO William T. Archey. "We project that the 2003 high-tech job losses will total 234,000--down 57 percent from the 540,000 decline in 2002."

Archey further stated, "However, these declines have caused us to pause about two important issues. We are aware of current budget constraints, but now is not the time to cut back on education, particularly in math and science. We need a world class workforce to deal with world class challenges. Our second concern is the decline in basic research, particularly in technology, by the federal government. We worry that we have eaten the seed corn of federal research of 20 and 30 years ago that is not being replenished."

For the first time, Cyberstates 2003 is based on the newly implemented North American Industry Classification System (NAICS). AeA selected 49 NAICS codes to define the high-tech industry. They fall into four broad categories: electronics manufacturing, communications services, software, and engineering and tech services. This more current and comprehensive system allows us to capture several sectors which we could not with the previous system. These include fiber optic cable manufacturers, semiconductor machinery manufacturers, and web search portals.

This new industry classification system is fundamentally different from the old Standard Industrial Classification (SIC) system. Every sector of the economy has been restructured and redefined by the NAICS. Consequently, the data presented in this report are not comparable in any way to previous editions of Cyberstates. In this edition, however, 2001, 2002, and 2003 data use the NAICS system and are therefore comparable.

Cyberstates 2003 found that all but three states lost high-tech jobs in 2002. California lost the greatest number of tech jobs, shedding some 123,000 jobs. Texas was second with tech jobs down by 61,000 jobs. Interestingly, the District of Columbia, Wyoming, and Montana were the only three cyberstates to add technology jobs between 2001 and 2002.

http://www.aeanet.org/PressRoom/idmk_cs2003_US.asp
Customers rage at Google tweak | CNET News.com:
"In a rare sign of trouble for the booming search marketing business, Google is fending off complaints from angry customers who say recent changes to the company's advertising program are costing them sales.
The search engine giant tweaked its AdWords service in late October, saying it was making the move to better identify successful ads--those that get clicks--and to increase their visibility. It also took steps to reduce the number of unsuccessful ads that show up on its search results pages. A company representative said overall ad response rates have improved since the changes took effect. "


As keyword marketing grows in popularity, providers will likely face a tough balancing act to satisfy advertisers intent on bidding up prices and fighting for visibility on increasingly crowded lists.

But the new system hasn't improved results for everyone, leading to an outcry from those on the losing end. Disgruntled customers say the new system pits smaller companies against bigger ones, ultimately favoring deep-pocketed advertisers that can afford to outbid rivals for coveted keywords. In addition, some customers say the changes may be responsible for decreased conversion rates--the crucial sales that come after someone clicks on a Web advertisement.

"We would love to spend more with Google, but we're not going to overpay on (search) terms, when the surfer will click on terms and be frustrated and go elsewhere," said Daniel Mardorf, the Webmaster at Cellphonecarriers.com, who said he's seen response rates and sales from his Google ads drop since last month's changes took effect

http://news.com.com/2102-1024_3-5107406.html?tag=st_util_print

Thursday, November 20, 2003

ZDNet AnchorDesk: It wasn't me, it was the Trojan horse:
"Remember the Twinkie defense? Well, now there's the Trojan horse defense. That's right: In three recent court cases in the United Kingdom, defendants pleaded not guilty on the basis that someone else put code on their computer (via a Trojan horse) that caused their machines to break the law. "

While these cases have no direct bearing on U.S. court cases, they could lead to creative defenses for computer-related crimes in this country as well.

THE FIRST TWO cases involved the downloading of child pornography, while the third concerned a denial-of-service attack that caused real-world economic damage. All three defendants were acquitted.

In one of the child pornography cases, Karl Schofield of Whitley, England was cleared of processing 14 images of child pornography on his home PC. In the other, Julian Green of Devon, England, who was acquitted of storing 172 images of child pornography on his system.

In both cases, computer forensics experts found evidence of Trojan horses on the suspects' hard drives. The rogue code was allegedly deposited there via pop-up advertisements, banner ads, or Internet worms.

The third case involved a U.K. teenager named Aaron Caffrey. U.S. police discovered that his computer was responsible for the denial-of-service attack that crashed servers at the Port of Houston in October. However, Caffrey claimed that someone else put a Trojan horse on his PC that allowed his system to be controlled remotely. When investigators were unable to find evidence of such a remote-control Trojan, Caffrey claimed the Trojan had automatically erased itself.

THIS SEEMS suspicious to me, if only because Microsoft Windows (the operating system on Caffrey's computer) is notorious for creating duplicates or logs of all data. So either Caffrey was lying, or the authorities who investigated him were inept, as evidence of a Trojan horse should be relatively easy to find. Computer forensics tools, such as Guidance Software's EnCase, can quickly reveal hidden, partial, or even deleted files.…

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5107486.html?tag=adss

Saturday, November 15, 2003

15 Seconds : Implementing Paging and XSLT Extensions Using XSLT in .NET - Part 1:
"When you have to display a large number of records, the common practice is to use data paging so the information can be presented in a more user-friendly manner. There are many solutions one can use to implement such a system, and each of them has its own advantages and disadvantages. One of the excellent ways of implementing this solution is using XML and XSL.…
One of the main benefits of XML is that it separates data from the presentation. By combining XML data with an XSL Transformation (XSLT) stylesheet, you can dynamically transform the XML data and present the information in any format you want. "


http://www.15seconds.com/issue/031105.htm
Digital Web Magazine - Features: User Interface Design for Web Applications
It’s a Different World from Web Site Design

This article could be also be titled “Things I Wish I'd Known Before Designing My Latest Web-Based Application.”

http://www.digital-web.com/features/feature_2003-11.shtml

Friday, November 14, 2003

New Windows Worm on the Way?:
"The cycle began Tuesday when Microsoft Corp. released its monthly passel of patches, including one for a flaw in the Workstation service in Windows 2000 and XP. A successful exploitation would give the attacker complete control of the compromised PC, Microsoft said.."

Less than 24 hours after Microsoft issued the fix, two members of the BugTraq security mailing list posted exploit code for the vulnerability. The author of one of the exploits said the code had been tested only on a Windows 2000 machine with Service Pack 4 installed and the FAT32 file system running. The other exploit is designed for machines running Windows XP. However, experts said it would take little effort to adapt the code for other Windows machines.

And, more importantly, the Workstation vulnerability appears to be a prime candidate for a worm."


http://www.eweek.com/article2/0,4149,1382096,00.asp?kc=EWNWS111403DTX1K0000599
News: Wireless dilemma: Security isn't cool:
"Wireless communication has dramatically changed the way people work and interact. Unfortunately, the wireless era also continues to be plagued by insufficient security, and both corporations and users are being put at risk."

http://zdnet.com.com/2100-1107_2-5105460.html
Evaluating the wireless networking options - TechUpdate - ZDNet:
"Now that wireless networking has been around for several years and is starting to mature, companies have a variety of wireless networking standards and products to choose from. There are long-distance products used to send data between buildings miles away and then there are the shorter range products that typically provide wireless networking services within an office building or a warehouse. Both of these areas have a lot of different products and standards available, and there is no way that I could discuss them all within one article. However, since Wi-Fi is the dominant wireless networking technology at the moment, I want to discuss the various Wi-Fi options available and how to choose between them. "

http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2914510,00.html
Wireless Toolkit - NOW - TechUpdate - ZDNet:
"Wireless Networks Toolkit - Now
Keep up on the latest wireless trends and products
Extend your network range
Support your wireless network "


http://techupdate.zdnet.com/networking_upgrades/wireless_now.html?tag=tu.nu.toplink5
News: Spam spike signals more junk e-mail:
"An e-mail security firm has warned that spammers may be increasing their assault on Web users, after detecting a rise in the amount of unsolicited junk messages sent across the Internet.

FrontBridge, which provides outsourced e-mail filtering services for companies, said this week that it detected a 15 percent increase in spam between the 14th and 18th October--which it believes is a sign that organized spammers are ratcheting up their activities.

'Users who until this point had remained spam-free are now reporting multiple messages per day,' said Craig Whitney, FrontBridge's European director. 'This latest jump in the volume of spam being generated just adds to the load that enterprises have to manage every day,' Whitney added. "


http://zdnet.com.com/2100-1105_2-5105526.html?tag=adnews
Under Attack!:
"The largest virus outbreak in history hit millions of computers around the world this past August. Even before Microsoft Corp. and millions of victims could find a way to cope with the Blaster worm and a spate of imitators and mutations, Sobig began to live up to its name—with a vengeance.

Headline-making malware—viruses, worms, and Trojan horses—have managed to find a surprising number of unprotected PCs, despite the computer industry and media repeatedly urging people to use antivirus and firewall software. Some of the computers Sobig attacked had outdated antivirus software installed or none at all. A May 2003 study for the National Cyber Security Alliance conducted by America Online concluded that 62 percent of broadband consumers were not running up-to-date antivirus (AV) software.

But AV software alone isn't enough these days: You need a firewall, too, and privacy controls and spam filtering can further protect you. The AOL study also showed that 67 percent of broadband consumers did not have properly configured firewalls.

All manner of malware has been spreading via friendly e-mails and—more irritating—through mail no one wants in the first place—spam. Using the latest method of infection, worms send themselves out to the Internet from infected systems. Where do the worms end up? They end up in machines without firewalls or AV software. Worms either include a tiny e-mail server to send themselves out—usually with a spoofed sender address obtained from address lists—or search for unprotected shared network drives where they can unload themselves.

Once malware hits your PC, the damage can take many forms. A true virus attaches itself to a file and replicates itself when you launch the file. A Trojan horse hides on your system to do its damage, which may involve sending private data to its creator. One particularly obnoxious type of Trojan horse is a dialer, which uses your modem to call a pay number, sticking you with the bill.

A worm will often send mail to everyone on your e-mail address lists or propagate itself on shared network drives. Even viruses that don't destroy your data can wreak havoc by slowing Internet service to a crawl or hogging system resources.

Some people couldn't care less about malware and Internet security, claiming they have nothing personal or valuable stored on their hard drives. But such attitudes actually contribute to the larger problem, as these people let their machines become overrun by malware. Although you may notice only a slowdown in performance of your unprotected PC, you could actually be helping to cause massive damage on the Internet: Many viruses take part in launching denial-of-service attacks on prominent Web sites. Silently, unprotected systems in homes and offices are doing the bidding of malware that works alone or is controlled remotely by its miscreant authors, attacking other sites and systems in the process.…"

http://www.pcmag.com/article2/0,4149,1373605,00.asp

Thursday, November 13, 2003

O'Reilly Network Weblogs: PTO Director Orders Re-Exam for '906 Patent:
"In what could be good news for the Web, the Director of the US Patent and Trademark Office has ordered a re-examination of the '906 patent, which was the subject of a patent infringement lawsuit this summer brought by Eolas against Microsoft.

Issued in 1998 to Michael Doyle of Eolas Technologies, the patent (#5,838,906) covers the ability to embed and control applications (or objects) in a web browser. Doyle succeeded in obtaining a $500M judgement against Microsoft. In the aftermath, Microsoft said that changes to the browser were necessary to work around paying royalties on the patent, and that these changes would impact developers who create and maintain web pages. Many believe that the patent would also affect other technologies such as Flash and Java as well, which are launched from a browser. "



http://www.oreillynet.com/lpt/wlg/3969
Holes Found in Online Job Search Privacy:
"Some career Web sites, recruitment services and automated job-application kiosks offer flimsy privacy protections and might even violate employment and credit laws, a report released Tuesday asserts."

Many job sites still let too much information from resumes posted online get into the hands of third parties through online "cookies" that monitor Web surfing, according to the report, led by Pam Dixon, formerly of the University of Denver's Privacy Foundation and now head of her own group, the World Privacy Forum.

The report also faults self-service job application computers commonly used by chain stores. It says they almost always demand social security numbers and perform background checks on applicants without clearly stating who will see the information.

Dixon is urging job seekers to demand more stringent privacy protections. She also wants the Federal Trade Commission and the Equal Employment Opportunity Commission to look more closely at how job sites and recruitment services handle information.

"Technology is in such a place right now where it really is at odds with Title 7," the employment-discrimination section of the Civil Rights Act, Dixon said. "I don't want to see that eroded at all."

Other prominent Internet watchdogs also participated in the investigation, including members of the Electronic Privacy Information Center and the Privacy Rights Clearinghouse.

The report says that even people who don't hunt for jobs online should be aware that many resumes, no matter how they are submitted, are processed through vast databases.

For example, Eliyon Technologies Corp., a private company in Cambridge, Mass., has a file of 16 million executives that it sells to headhunters, employers and companies seeking leads for sales pitches. Eliyon's Web site says its customers include IBM Corp., Microsoft Corp. and Time Warner Inc.

Eliyon's advanced software mines information about people from Web sites, press releases, Securities and Exchange Commission filings and other public sources. Dixon said she was surprised at the level of detail in an Eliyon search about her sister. Though the sister is not a public figure, the names of her children and husband were listed.

Dixon alleged that Eliyon has no clear method for people to correct or remove erroneous data. That makes it "an end-run around the Fair Credit Reporting Act," which requires that consumers be able to examine adverse information maintained about them in commercial files, she said.…

http://www.eweek.com/article2/0,4149,1379992,00.asp?kc=EWNWS111203DTX1K0000599
Microsoft Issues Security Patches:
"Hardest hit in this month's batch of patches is IE, which contains five newly discovered vulnerabilities. Three of the flaws are related to the cross-domain security model in the browser. This mechanism is meant to prevent windows in different domains from sharing information. However, these weaknesses allow an attacker to run script in the browser's My Computer zone, which typically does not carry the same level of security as the Internet zone might."

In order to exploit this flaw, the attacker would either need to entice the user into visiting a malicious Web site or opening an HTML mail message containing the attack code. This would let the attacker access data from other Web sites that the user has visited and read files on the user's machine, Microsoft said in its bulletin.

Another flaw in IE concerns the manner in which the browser passes zone data to XML objects. Like the other three vulnerabilities, this one also can be exploited via Web sites and HTML mail messages. However, the attack also requires that users agree to download an HTML file, which would let the attacker read local files on the user's machine, if he knows the exact location of the files.

The final weakness in IE affects drag-and-drop operations during dynamic HTML events. If a user clicked on a link supplied by an attacker, the attacker could save a file on a user's machine in an arbitrary location. All of these flaws affect IE 5.01, 5.5 and 6, including IE 6, Service Pack 1.

The batch of patches also addresses a buffer overrun flaw in Windows 2000 and XP that could allow an attacker to run arbitrary code on remote machines. The vulnerability is in the Workstation service in Windows and a successful exploitation would give the attacker complete control of the compromised PC, Microsoft said.

Windows XP users who have installed the patch for MS03-043 are already protected against this vulnerability, but all Windows 2000 users would still need to apply this latest patch.…

The patches are at Microsoft's Security and Privacy Page.
http://www.microsoft.com/security/

http://www.eweek.com/article2/0,4149,1379656,00.asp?kc=EWNWS111203DTX1K0000599

Wednesday, November 12, 2003

Mimail Can Capture Keystrokes:
"Top 10 E-Mail Viruses as Reported by MessageLabs
These are the latest threats as of Monday Nov 10, 2003 as listed by MessageLabs:
  • W32/Swen.A-mm

  • W32/Dumaru.A-mm

  • W32/Sobig.F-mm

  • W32/Klez.H-mm

  • W32/Mimail.A-mm

  • W32/Mimail.C-mm

  • W32/Mimail.E-mm

  • W32/Holar.L-mm

  • W32/Yaha.P-mm

  • W32/Yaha.E-mm

For MessageLabs's complete list of email viruses, click here."


http://www.messagelabs.com/viruseye/threats/

http://www.pcmag.com/print_article/0,3048,a=111807,00.asp
Messaging and Collaboration News, Product Reviews, Trends and Analysis:
"More IM technology is enterprise-ready, but security and other issues still loom large."

http://www.eweek.com/category2/0,4148,1237933,00.asp
154036 - How to Disable Active Content in Internet Explorer:
"This article lists troubleshooting steps to help you troubleshoot problems with active content such as ActiveX scripts, ActiveX controls, and Java programs in Internet Explorer. "

Configure Internet Explorer so that it does not run Active scripts automatically:

Configure Internet Explorer so that it does not automatically use items that show active content, such as vertical marquees or animations.

Verify that Internet Explorer's internal Java Just-In-Time (JIT) compiler is disabled:

Configure Internet Explorer so that it does not run Java programs automatically.

While most active content contained in Web pages is safe, some Web pages contain active content that can potentially cause security problems on your computer. For example, an ActiveX control that runs automatically when you load a particular Web page might damage your data or cause your computer to become infected with a virus. Internet Explorer uses safety levels for active content to help prevent this situation from occurring.…

http://support.microsoft.com/default.aspx?scid=kb;en-us;154036

Tuesday, November 11, 2003

AntiSpam: Up Close and Personal:
"A feature of Norton AntiSpam is its log of statistics. Here are my spam statistics since I began using the software on September 25, 2003, through Sunday November 9, 2003. Let's call that 44 days."

  • E-mail scanned: 14,737 messages

  • Average (over the 44 days): 335 per day

  • Sent e-mail: 781 messages

  • Valid e-mail: 6,023 messages(40.87%)

  • Mail correctly identified: 5,996 messages (99.55%)

  • >Spam: 8,714 messages (59.13%)

  • Spam correctly identified: 8,103 messages (92.99%)



The most stunning number in this list is the sheer quantity of mail I receive. Something is clearly wrong with me—I must make a note to get myself an actual life (actually, a lot of it is security mailing lists that I don't read thoroughly). Maybe this weekend.

Still, it looks like I had 27 false positives (0.45% of valid mail), and that sounds like what I remember from my use of the product. NAS counts false positives when I manually scan the Spam folder in Outlook and mark non-spam messages with the "This is not Spam" button. Conversely, when I mark a message in the Inbox with the "This is Spam" button, it gets tracked as a false negative. The difference between the "Spam" and "Spam correctly identified" results totaled 611 messages or a hair over 7 percent of spam.

Now, I'm pretty happy with the ability of the product to find spam and reaching 93 percent is pretty good. At the same time, my instincts are that the 0.45 percent figure for false positives seems like a small number.

But those 27 false positives over 43 days may be non-trivial. This figure tells me I still should check the Spam folder periodically, and even relatively often, because if I don't I'll be intimidated by the amount of mail in it.

I was also struck by the fact that the statistics page reported that the last Antispam update was released on 8/29/2003. If they can go a month and a half without an update (and yes, I do run LiveUpdate frequently), Symantec can't be following the spam business the way they follow the virus business.…

One more bit of perspective on the amount of spam I receive. It's actually a lot more than that 59 percent figure presented by Norton. Some of my e-mail accounts are already filtered at the servers. Note the difference in the handling of three addresses of mine that are filtered through FrontBridge's server-based spam filtering. In the last month, that product found 523 spam messages and only one of them was a false positive.

Perhaps the answer is to switch to Outlook 2003. The numbers showed that it had not a single false positive, although it found far less spam. Oh well, the products get better, but the decisions we have to make continue to get harder.

http://www.eweek.com/article2/0,4149,1378794,00.asp?kc=EWNWS111103DTX1K0000599
Internet Tax Ban Stops Dead in Senate:
"A push to permanently ban taxes on Internet access came to an abrupt halt in the Senate on Friday amid concern that state and local governments could lose millions in taxes from phones, music and movies that are migrating to the Internet."

State and local governments collect more than $20 billion every year on telecommunications and fear the permanent ban will wipe out a large part of that revenue. A core group of senators pressing for a permanent end to taxes on Internet access said those fears are unfounded.

"All the bill says is you cannot discriminate against electronic commerce, and not one state has come forward and given an example of how they have been hurt by their inability to discriminate against electronic commerce," said Sen. Ron Wyden, D-Ore.

An analysis by the Congressional Budget Office said the bill could hit state and local governments in three ways. About 10 states that imposed a tax on Internet access charges before the original ban, and who were permitted to keep collecting those taxes, would lose $80 million to $120 million each year.

http://www.eweek.com/article2/0,4149,1376712,00.asp