Saturday, July 03, 2004

Microsoft posts work-around for IE flaw - News - ZDNet

Microsoft posts work-around for IE flaw - News - ZDNet:
"Microsoft released on Friday a work-around for an Internet Explorer vulnerability that has left Windows users open to attacks for almost nine months.

The flaw, in an ActiveX scripting component, gained notoriety last month when it became the mechanism used by a network of compromised Web sites to install a malicious program on victims' computers. Microsoft has decided to plug the hole by turning off the ability for the ActiveX component to write to the operating system. The software giant published the work-around on its Web site and directed customers to use its Windows update service to download the patch. "

Though Microsoft intends the change to become a standard configuration for Windows, the software giant is working on a more comprehensive solution, said Stephen Toulouse, security program manager for Microsoft's security response center.

The change fixes a problem that allowed several compromised Web sites to infect visitors' PCs with a Trojan horse program, known as Download.Ject or JS.Scob.Trojan. The program would record the keystrokes and send them to an overseas e-mail address. That Internet Explorer security issue and several others lead some security experts to suggest that users should consider alternative browsers.

Microsoft's configuration change blocks the ability of the ADODB.screen ActiveX component to write to the PC's hard drive. ActiveX, which adds interactivity to Web sites viewed with Internet Explorer, has long been thought to have security issues.

This particular vulnerability has been known about for more than 9 months

http://www.microsoft.com/security/incident/download_ject.mspx

http://zdnet.com.com/2100-1105_2-5256297.html

Thursday, July 01, 2004

Web Searching Tips

Web Searching Tips:
"This section of Search Engine Watch provides tips on using search engines better, along with some fun facts such as what people search for on search engines. "

http://www.searchenginewatch.com/facts/index.php

Pop-up program reads keystrokes, steals passwords - News - ZDNet

Pop-up program reads keystrokes, steals passwords - News - ZDNet:
"A malicious program that installs itself through a pop-up can read keystrokes and steal passwords when victims visit any of nearly 50 targeted banking sites, security researchers warned on Tuesday.

The targeted sites include major financial institutions, such as Citibank, Barclays Bank and Deutsche Bank, researcher Marcus Sachs said Tuesday.

'If (the program) recognizes that you are on one of those sites, it does keystroke logging,' said Sachs, director of the Internet Storm Center, a site that monitors network threats. Even though all financial sites use encryption built into the browser to protect log-in data, the Trojan horse program can capture the information before it gets encrypted by the browser software. 'The browser does not encrypt data between your keyboard and computer. It's encrypting it (when it goes) out onto the Web.' "

Sachs said the Trojan horse was first discovered on the computer of "an employee at a major dot-com." The victim apparently picked up the program from a malicious pop-up ad that used a flaw in Internet Explorer's helper server to install itself on the user's PC. In this case, because of the computer's security settings, the installation failed. Microsoft said IE users should raise the security settings to high until the company issues a patch.

Two other IE flaws, which Microsoft has yet to fix, were used recently in two other hacking schemes, one last week that turned some Web sites into points of digital infection, and another, earlier in the month, that installed a toolbar on victims' computers that triggered pop-ups. This most recent Trojan horse differs from the attack software used in last week's Web site compromises but could be paired with that technique to spread spyware.

Researchers at the Internet Storm Center studied the Trojan horse file, called "img1big.gif," which was provided by the dot-com. Working through the weekend, the security experts reverse-engineered the program and discovered that it targeted a long list of banks and attempted to steal the account information of those institutions' customers.

The program points to a recent trend in computer viruses and remote-access Trojan horse, or RAT, programs: Attackers are increasingly after money.

http://zdnet.com.com/2100-1105_2-5251981.html

Java Technology Fundamentals Newsletter

Java Technology Fundamentals Newsletter:
"Java Developer Connection Java Technology Fundamentals Newsletter.

This monthly newsletter provides a way for you to learn the basics of the Java programming language, discover new resources, and keep up-to-date on the latest additions to Sun Developer Network's New to Java Programming Center."

http://java.sun.com/developer/onlineTraining/new2java/supplements/2004/june04.html

The Java 2 Platform, Standard Edition version 1.5: new language features

J2SE 1.5 (Tiger):
"The Java 2 Platform, Standard Edition version 1.5 (J2SE 1.5) has introduced several enhancements as well as new language features that ease the development of Java applications. This major release is focused along certain key themes, such as quality, monitoring and manageability, performance and scalability, and ease of development. The codename for the J2SE 1.5 release is 'Tiger', and all the new features have been developed under the Java Community Process (JCP)."

http://java.sun.com/developer/technicalArticles/releases/j2se15langfeat/

Wednesday, June 30, 2004

Download details: Windows Application Compatibility Toolkit 3.0

Download details: Windows Application Compatibility Toolkit 3.0:
"The Windows Application Compatibility Toolkit (ACT) version 3.0 for Windows 2000 Service Pack 3 or later, Windows XP and Windows Server 2003 contains the tools and documentation you need to design, deploy, and support applications on these platforms. Tools include the latest versions of the Microsoft Windows Application Compatibility Analyzer that simplifies application inventory and compatibility testing, the Windows Application Verifier that assists developers and testers in locating common compatibility issues during the development cycle, and the Compatibility Administrator that provides access to the necessary compatibility fixes to support legacy applications in Windows."

http://www.microsoft.com/downloads/details.aspx?FamilyID=7fc46855-b8a4-46cd-a236-3159970fde94&displaylang=en

Microsoft Christens Cut-Rate Windows as 'XP Starter Edition'

Microsoft Christens Cut-Rate Windows as 'XP Starter Edition':
"Last summer, in response to the success that Linux was having in the Thai marketplace, Microsoft began offering Thai citizens a Thai-localized bundle of Microsoft Windows XP Home and Office XP Standard. As part of the deal, Microsoft also stripped out some unspecified features from both products and slashed the price for the pair to 1,500 Thai Baht, or about $38 U.S. Microsoft Windows XP Home sells at retail for $225; Office XP Standard retails for $499.

This past spring, Microsoft officials said they would decide whether to continue offering the combination based on customer feedback.

It's not clear if Microsoft also will use the "Windows XP Starter Edition" name in other countries. In March, Microsoft began offering a similar cut-rate Windows XP and Microsoft Works bundle customized for the Malaysian market as part of the Malaysian government's PC Gemilang Project."

http://www.microsoft-watch.com/article2/0,1995,1616618,00.asp

Monday, June 28, 2004

Wi-Fi security standard sealed and delivered - News - ZDNet

Wi-Fi security standard sealed and delivered - News - ZDNet:
"The 802.11i standard should give wireless networking a boost in the eyes of businesses. Previous security measures, such as Wired Equivalent Privacy, were easily broken by hackers, leaving many security-conscious IT managers wary about wireless networking. The 802.11i standard encrypts data sent along wireless networks to protect it from anyone who may intercept it.

The most significant feature of the 802.11i standard is Advanced Encryption Standard (AES), a strong encryption standard supporting 128-bit, 192-bit and 256-bit keys, said Robin Ritch, Intel's director of security industry marketing.

Ritch added that Intel's Centrino bundle of chips will begin to incorporate the 802.11i standard following interoperability certification by the Wi-Fi Alliance, expected in September. All Centrino products will be 802.11i-compliant by the end of the year, and the upgrades will be in software. "

http://zdnet.com.com/2100-1103_2-5248275.html

ZDNet AnchorDesk: Why AOL users are saying, "I've got spam!"

ZDNet AnchorDesk: Why AOL users are saying, "I've got spam!":
"The good news is that AOL apparently segregates its data across different servers. The data that Smathers allegedly stole did not include individual passwords or credit card numbers, for instance. According to the Wall Street Journal (registration required), Smathers may have obtained the lists by searching letter by letter across nearly 30 different servers.

However, as of this writing, AOL has not offered a site where AOL members can see if their e-mail address, telephone number, and zip code was sold, nor has the ISP offered any further assistance to those affected beyond a simple apology. That's unfortunate, since the stolen lists contain enough information for direct marketers to add customers to e-mail and telemarketing lists. Affected AOL members can expect to hear their phones ringing more and see their in-boxes a little fuller in the near future. "

In addition to rogue employees, companies are also under attack from virus-infected laptops connecting inside their networks and Trojan horses installed on individual workstations that give outsiders inside access. Using that yardstick, last summer's MSBlast worm also qualifies as an inside attack. By installing personal firewalls and antivirus software on each workstation and laptop (even home computers that connect to the corporate network via VPN), companies can eliminate these dangers. Still, even these measures won't stop a determined cracker who gains employment in a company as a janitor or a temp to snoop around for vulnerable points of access.

http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5141384.html?tag=adss

Saturday, June 26, 2004

Web site virus attack blunted - News - ZDNet

Web site virus attack blunted - News - ZDNet:
"Web surfers are no longer playing Russian roulette each time they visit a Web site, security researchers say, now that a far-reaching Internet attack has been disarmed.

The attack, which had turned some Web sites into points of digital infection, was nipped in the bud Friday, when Internet engineers managed to shut down a Russian server that had been the source of malicious code. Compromised Web sites are still attempting to infect Web surfers' PCs by referring them to the server in Russia, but that computer can no longer be reached."

Still, Web surfers should take precautions, as the Internet underground is increasingly using this type of attack as a way to get by network defenses and infect officer workers' and home users' computers.

http://zdnet.com.com/2100-1105_2-5248279.html

Infected Web site attack prevention

Infected Web site attack prevention:
"Criminal hackers (a.k.a. crackers) have launched a different kind of attack on the Internet this week. By simply visiting certain, infected popular Web sites, home and business Internet surfers using Internet Explorer on a PC may indirectly download a remote-access Trojan horse (RAT) onto their desktop computers, which in turn, may record keystrokes necessary to log into secure sites and relay that information to remote sources. This attack does not, however, slow or otherwise interfere with Internet traffic, and it affects only Internet Explorer browsers. Other browsers, including Opera and Mozilla, are not affected. Systems running Linux, Mac OS, Unix, and other operating systems are also unaffected. Microsoft is urging Web sites running on Windows 2000 servers with IIS Version 5.0 to update with the MS04-011 security patch. However, home and business Internet surfers using Internet Explorer are left with few options. Given the widespread but not yet epidemic nature of this attack, we're assigning this threat a Medium designation. "

How it works
There are two parts to this attack. Part one has already happened and affected Web site hosts. Earlier this week, crackers identified Windows 2000 servers with IIS Version 5.0 that have not applied the latest security patch from Microsoft, MS04-011. Some of these Web sites include popular search engines, shopping, and auction sites. The configurations of these servers were altered to include a small file that is in turn added to each file called upon by users.

The second part of the attack affects home and business users of the Internet and occurs whenever an Internet surfer stumbles upon a Web page served by an infected server. Unfortunately, you cannot immediately discern whether a page is infected, and some known pages include those hosted on major Web sites. The second part of the attack uses two vulnerabilities: one that can be patched with Microsoft security patch MS04-013, and another that can't be patched at this time. The flaws affected Internet Explorer only and allow malicious JavaScript from the infected Web server to execute on the desktop system. The JavaScript, in turn, downloads a remote-access Trojan horse from a remote site. This Trojan can record keystrokes used when logging into bank accounts and auction sites and using a credit card to make a purchase online.

For updates from Microsoft see http://www.microsoft.com/security/incident/download_ject.mspx

End users should install MS04-013, if they have not already done so, plus they should increase their security settings within Internet Explorer and update their antivirus settings to protect against known Trojan horses that may be installed because of this attack.
http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx

http://techrepublic.com.com/5100-6265_11-5247988.html

MSN Hotmail Joins Storage Race

MSN Hotmail Joins Storage Race:
"Free MSN Hotmail users will be gaining 250 megabytes of storage, up from 2MB today, while premium users, for $19.95 a year, will be receiving 2 gigabytes of storage, MSN will announce."

http://zdnet.com.com/2100-1104_2-5245523.html?tag=adnews

Over the past few years, Yahoo and Hotmail have both taken steps to decrease memory in hopes of convincing free users to become paying subscribers.

http://www.eweek.com/article2/0,1759,1616649,00.asp

Researchers warn of infectious Web sites - News - ZDNet

Researchers warn of infectious Web sites - News - ZDNet:
"The researchers believe that online organized crime groups are breaking into Web servers and surreptitiously inserting code that takes advantage of two flaws in Internet Explorer that Microsoft has not yet fixed. Those flaws allow the Web server to install a program that takes control of the user's computer.

Late Thursday, Microsoft advised customers to increase their browser security to the highest settings, although that could cause some Web site functions to stop working.

The extent of the attacks is unknown, but the security community has seen numerous cases of personal computers infected when the user merely visits a Web site.

'It is not epidemic, but it is being seen,' said Alfred Huger, senior director of engineering for security company Symantec. 'Do we think it is serious? Yeah. It's a concern and it's insidious.' "

http://zdnet.com.com/2100-1105_2-5247187.html

Using Accesskeys is Easy

Using Accesskeys is Easy:
"Quite a few Web developers still get a glint of terror in their eyes when someone suggests they add accesskeys to their sites. Well, don't be scared. This article is very short for a very good reason. If you want to use them, accesskeys are so easy to add, you'll wonder why you never did before."

So, what are accesskeys? For the uninitiated, they are a means for people to jump immediately to a specific part of an HTML page by pressing ALT (PC) or CTRL (Mac), followed by the appropriate key on the keyboard, as defined by you via an accesskey parameter.

They're particularly useful for people with mobility issues who don't use a mouse and have a keyboard for their every movement on a computer. Accesskeys allow them quickly and easily to hop around the content of your Web pages. Able-bodied users can find them equally useful as shortcuts, too.

http://www.sitepoint.com/print/accesskeys

Exhibitor Shortage Puts Brakes on Comdex

Exhibitor Shortage Puts Brakes on Comdex:
"Last year's Comdex, the first run by MediaLive, attracted more than 40,000 qualified technology buyers and 550 exhibiting companies, according to MediaLive officials.

But the show's total attendance was just 51,000, compared to nearly 125,000 in 2002, according to the Las Vegas Convention and Visitors Authority. That lowered Comdex's nongaming economic impact on Vegas to just $69 million from $170 million the year before, according to the LVCA.

The LVCA projected numbers virtually identical to those of 2003 for this year's Comdex. "

http://www.eweek.com/article2/0,1759,1616762,00.asp

Experts Study Developing Internet Attack, Infection Tries to Implant Software

Chicago Tribune | Experts Study Developing Internet Attack:
"Government and industry experts warned late Thursday of a mysterious, large-scale Internet attack against thousands of popular Web sites. The virus-like infection tries to implant hacker software onto the computers of all Web site visitors.

Industry experts and the Homeland Security Department were studying the infection to determine how it spreads across Web sites and find adequate defenses against it.

'Users should be aware that any Web site, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code,' the government warned in one Internet alert. "

http://www.chicagotribune.com/technology/sns-ap-internet-attack,1,905229.story

Wednesday, June 23, 2004

Online Journalism Review article: States' Shield Laws Might Not Cover Online Journalists

States' Shield Laws Might Not Cover Online Journalists:
"The Internet has lowered the barriers to entry for publishers. This complicates the question of who qualifies as a journalist when it comes to laws designed to protect the confidentiality of sources. How inclusive should shield laws be? A test case for this murky issue has yet to emerge. First in a two-part series."

http://ojr.org/ojr/law/1086825172.php

Online Journalism Review article: The Best (and Worst) Video Feeds Online

The Best (and Worst) Video Feeds Online:
"Video quality has improved, but it's still a struggle to find feeds on many news sites."

http://ojr.org/ojr/technology/1087947933.php

Web Page Analyzer - free test speed, optimization, performance analysis, load test tool

Web Page Analyzer - free website speed test website optimization performance analysis faster web page download time load test webpage speed tool:
"Test your web site speed and improve website performance with our free web-based analyzer. Enter a URL below to calculate page size, composition, and page download time. The script calculates the size of individual elements and finds the total for each type of web page component. Based on these page characteristics the script then offers advice on how to improve page display time and website speed. The script incorporates best practices from HCI research into its recommendations."

http://www.websiteoptimization.com/services/analyze/

The real reason you should care about web standards

Design by Fire: The real reason you should care about web standards:
"The real reason you should care about web standards.

A well-written entry for a new, original reason why Web sites should be designed to follow Web standards. More and more corporate sites are making the move to standards "

http://www.designbyfire.com/000099.html