Friday, December 10, 2004

Most Browsers Buggy

Most Browsers Buggy:
A European security vendor warned Wednesday that most browsers sport a bug that hackers can exploit to spoof a Web site and trick users into trusting bogus pop-up windows.

The vulnerability, which Danish security firm Secunia rated as "moderately critical" is similar to previous bugs in browsers that was disclosed in July and September of 2004. Attackers could use it to add content into a trusted Web site's window by, for instance, inserting a fake form in a pop-up window seemingly opened by that site.

Affected browsers, said Secunia, include the popular Internet Explorer and the up-and-coming Firefox, as well as third-tier alternatives like Mozilla, Opera, Apple's Safari, and the open-source Konqueror.

IE 5.01, 5.5, and 6.x are vulnerable, claimed Secunia, and the "vulnerability has been confirmed on a fully patched system with Microsoft Windows XP SP1/SP2."

Secunia has posted a test that users can run to determine if their browser's got the bug”

http://www.crn.com/sections/breakingnews/dailyarchives.jhtml?articleId=55300447

Laptop Use Can Damage Male Fertility

Laptop Use Can Damage Male Fertility

http://www.eweek.com/article2/0,1759,1738419,00.asp?kc=ewnws121004dtx1k0000599

Microsoft Security Bulletin Advance Notification

Microsoft Security Bulletin Advance Notification:

“On December 14, 2004 the Microsoft Security Response Center is planning to release:

5 Microsoft Security Bulletins affecting Microsoft Windows

The greatest maximum severity rating for these security updates is Important

Some of these security updates may require a restart

No additional details about bulletin severities or vulnerabilities will be made available until December 14 , 2004.”


http://www.microsoft.com/technet/security/bulletin/advance.mspx

Thursday, December 09, 2004

Using the Windows Firewall INF File in Microsoft Windows XP Service Pack 2

Using the Windows Firewall INF File in Microsoft Windows XP Service Pack 2:
“Microsoft Windows XP Service Pack 2 (SP2) includes the Windows Firewall, a replacement for the Internet Connection Firewall component in previous versions of Windows XP. Windows Firewall is a stateful host firewall that discards unsolicited incoming traffic, providing a level of protection for computers against malicious users or programs. To provide better protection for computers connected to any kind of network (such as the Internet, a home network, or an organization network), Windows XP SP2 enables Windows Firewall on all network connections by default. Network administrators can use the Windows Firewall INF file (Netfw.inf) to modify default settings either before installation or after installation. This article describes the usage of the Windows Firewall INF file.”

System Requirements

  • Supported Operating Systems: Windows XP

Microsoft Word

File Name:

WFINF_Guide.doc

Download Size:

109 KB

Date Published:

11/16/2004

Version:

1.4


http://www.microsoft.com/downloads/details.aspx?familyid=cb307a1d-2f97-4e63-a581-bf25685b4c43&displaylang=en

Wednesday, December 08, 2004

The Hidden Risks of Demo Discs

The Hidden Risks of Demo Discs :
“In mid-November, members of Sony's PlayStation Underground received the Holiday Demo Disc and discovered that after executing one of the game demos on the disc, their PS2 memory cards were completely erased. While that doesn't mean much to nongamers, for anyone who has spent 40-plus hours building a character in a role-playing game or playing through a season of football—well, it's a huge boot in the trousers.

The sampler disc was sent via mail to members of the PlayStation Underground, an opt-in promotional group that Sony calls a ‘personal link to all the insider info from the PlayStation world.’”

There's more to the story than a handful of gamers losing their saved game files. The implications of such a glitch can be huge, especially as consumers start to set up networked computing systems in their homes, complete with routers, networks and servers. Minus cubicles and a water cooler, it's the equivalent of a small enterprise network.

Rick Fleming, chief technology officer at Digital Defense Inc., said that although most consumers don't realize it, game consoles are computers that run off their own proprietary operating systems. As a result, a bug in a demo CD, CD-ROM or DVD-ROM could affect the rest of a home network and spread to an enterprise network through a VPN connection or portable storage devices.

"PlayStation and Xbox are being networked with home computers … so I can easily see how something like that would spread across a network," Fleming said. "Every time you connect to something else, there's another opportunity for something to go wrong."


http://www.eweek.com/article2/0,1759,1735609,00.asp?rsDis=The_Hidden_Risks_of_Demo_Discs-Page001-140370

Java stir puts Sun in a spot

Java stir puts Sun in a spot:

“A flaw in Sun Microsystems' Java software has highlighted the difficulty the company faces as flocks of tech novices start to turn to it for support.

Sun disclosed a serious security flaw in its Java virtual machine (JVM) software last month. The rare problem, which affects Sun's plug-in for running Java on a variety of Web browsers and operating systems, could allow a virus to spread through PCs running both Microsoft Windows and Linux.

A flaw-free version of the JVM software is available on Sun's Web site, and the company is encouraging people to swap it out. But some users of the Firefox Web browser who attempted to download the new software received a version that contained the vulnerability, Sun representatives told CNET News.com.

On Tuesday, Sun was in the process of updating the download pages on Java.com and its download site to fix that problem, having previously said it would make the change on Dec. 13.

Sun said the mix-up in support arose because it had not had a chance to update the download features for Firefox. It also said that it first concentrated on developing a patch for the more pervasive browsers--Microsoft's Internet Explorer, Netscape and Mozilla.…”


http://news.zdnet.com/2100-9593_22-5482023.html

Monday, December 06, 2004

Colly's CSS rollover generator

Colly's CSS rollover generator:
“By removing the advanced fields, you can simply create a standard "sliding doors" rollover, or use the extra fields to create an advanced rollover with background and text elements. The CSS produced is lean and clean”

http://www.collylogic.com/index.php?/weblog/comments/
collys_advanced_css_rollover_generator/

The Ten Commandments of Keyword Selection

The Ten Commandments of Keyword Selection :
“Is your website getting a lot of traffic, but not a lot of sales? Maybe you need to take a look at the keywords you're using. Praveen Viswanath walks you through keyword selection process, and sums it up with ten keyword selection commandments to help keep you on track.

A term or a phrase used by a searcher to find information on a particular topic is called a "keyword." "Keyword selection" is the process of scrutinizing different prospective keywords to select the right ones for your campaign. It is the stepping stone to your success in the Web world. Find the right keyword, and you strike gold. Make a mistake, and you've just punched yourself in the face.

There are two categories of people interested in keyword selection: those trying to get more website traffic in general, and those trying to get more ‘qualified’ traffic. This article is for the latter type. What is the use, if you have some 10,000 hits a day but the business conversion is just 0.1%? Wouldn't it be better to have only 1000 visitors with a 30% conversion rate? After all, 300 is better than 10. From here on, whatever we do, our final aim shall be to get more "qualified" traffic.”



The Ten Commandments
http://www.seochat.com/c/a/Choosing-Keywords-Help/The-Ten-Commandments-of-Keyword-Selection/3/

http://www.seochat.com/c/a/Choosing-Keywords-Help/The-Ten-Commandments-of-Keyword-Selection/

Thursday, December 02, 2004

Semantic (X)HTML Markup: Using Tables Appropriately

Semantic (X)HTML Markup: Using Tables Appropriately

This is the seventh article in the Semantic (X)HTML Markup series. Before we begin, you'll want to read the previous articles:

  1. Semantic (X)HTML Markup: An Introduction
  2. Semantic (X)HTML Markup: Headings and Paragraphs
  3. Semantic (X)HTML Markup: Creating Emphasis
  4. Semantic (X)HTML Markup: Blockquote, Q, and Cite
  5. Semantic (X)HTML Markup: Structuring Lists
  6. Semantic (X)HTML Markup: Styling Lists

In this article we'll learn how to use perhaps the most misused semantic element: the table element. Like all the other (X)HTML elements we've learned about, there's a right and wrong way to use tables. The W3C created the HTML table model to "arrange data — text, preformatted text, images, links, forms, form fields, other tables, etc. — into rows and columns of cells." They specifically state that tables are not to be used for layout:

Tables should not be used purely as a means to layout document content as this may present problems when rendering to non-visual media. Additionally, when used with graphics, these tables may force users to scroll horizontally to view a table designed on a system with a larger display. To minimize these problems, authors should use style sheets to control layout rather than tables.

The accessibility problems of layout tables are why avoiding tables for layout is checkpoint 5.3 of the Web Content Accessibility Guidelines (WCAG). Using tables for layout can also rob you of one of the greatest benefits of CSS: its flexibility. Using CSS, the entire look of a site can be changed with a few edits to one style sheet. If complicated, nested tables were used instead, creating even minor layout changes can become a huge undertaking.

In recent years, many web developers have begun listening to the guideline to avoid layout tables and now use CSS to lay out their web pages. Instead of fitting sections of the page into rigid table grids, this new layout method involves placing content (marked up with semantic headings, paragraphs, and lists, of course) into div elements for each section of the page and then using CSS to position and style these divs.

Unfortunately, many forgot that tables still have a valid and valuable place in web design and tried to get rid of tables in their designs altogether. This is not the correct approach either. The table is still a valid (X)HTML element, and when you are trying to mark up tabular data, it is incorrect to use anything else!

Since the Semantic (X)HTML series is focused on how to use and mark up semantic elements, not about how to not use certain elements, this article will focus on the proper use of tables for data rather than on how to create layouts without tables.

http://www.communitymx.com/content/article.cfm?cid=0BEA6


Tuesday, November 30, 2004

How To Install and Configure Handwriting Recognition in Windows XP

How To Install and Configure Handwriting Recognition in Windows XP:
“This article explains, step-by-step, how to install and configure handwriting recognition in Windows XP. You can use handwriting recognition to enter text by writing instead of by typing. To use this feature, the Microsoft handwriting-recognition engine must be installed.

With the handwriting-recognition feature, you can use your handwriting instead of a keyboard to enter text. You can write by using a handwriting input device, such as a digital pen or stylus, or by moving your mouse pointer. The computer converts your handwritten words to typed characters, and then inserts the text exactly where you want it. ”

The handwriting-recognition engine is language-specific. The engine is currently available for the following languages: Simplified Chinese, Traditional Chinese, English, Japanese, and Korean. Engines for other languages will become available.

To use handwriting recognition, you need the following:
A writing tool. The minimum requirement for a writing tool is a mouse. To write with your mouse, press and hold down the primary mouse button, and then move the mouse pointer to form characters. The recommended tool is a handwriting input device, such as a pen stylus and tablet, connected to your computer through a serial port or USB port. Graphics tablets that are used with three-dimensional (3-D) drawing or computer-aided design (CAD) programs can also be used.
The Microsoft handwriting-recognition engine installed on a Windows XP-based computer.


http://support.microsoft.com/?scid=kb;en-us;306906

5 safety tips for using a public computer

5 safety tips for using a public computer:
Public computers at libraries, Internet cafes, airports, and copy shops are convenient, cheaper than buying your own laptop, and sometimes even free to use. But are they safe? Depends on how you use them.

Here are 5 tips on using public computers without compromising your personal or financial information.”

http://www.microsoft.com/nz/athome/security/
onthego/publiccomputer.mspx

Sunday, November 21, 2004

Two Cities, Two Gatherings for Two Kinds of Content Creators

Two Cities, Two Gatherings for Two Kinds of Content Creators:
"A good mix of different types of bloggers ranging from hobby/personal to professional/commercial. Also a number of journalist bloggers. Enthusiasts who don't blog but wanted to know more about it or wanted to have an influence on the direction software, services and organization. Would-be bloggers. Vendors. All ages from hip to former hippie and beyond. Multiple countries. A larger tech crowd than the last two because of proximity to Silicon Valley. More women than the last two but still a male majority. Some people complained that there weren't enough conservative bloggers but since anyone can register as long as space is available it's not like they were being kept away. Still, BloggerCon could do a better job of reaching out to the wider blogging community. Those who want more diversity in any area should do their share. "

Sometimes brainstorms work. BloggerCon III was Nov. 6 in Palo Alto; the Online News Association was holding its fifth national conference in Los Angeles the following weekend. For someone flying in from St. Louis, that was as good as next door. Why not do both?

The result is the kind of compare-and-contrast assignment English composition teachers love: Attend two disparate conferences with overlapping interests a week and a few hundred miles apart. Meet very different people with widely varying goals. Learn.

Then explain what works and what doesn't, keeping in mind that you know the people who put on each conference and that you hope to be back next year.


Hot TopicPodcasting (session audio)



Takeaway

Free MP3s of every session are being posted by ITConversations.com; a morning-after thread; posts from discussion leaders summing up their sessions; conversations in the blogosphere as people digest the experience.



http://209.200.80.136/ojr/stories/041119kramer/

Wednesday, November 17, 2004

Free MP3s from the Creative Commons

Free MP3s from the Creative Commons:
“…this column includes 16 free MP3s. But before we get to them, I'm hoping you'll read about what the availability of these tracks means to you, your music, and the Internet in general because this is all very important stuff.”

Last year, the Ninth U.S. Circuit Court of Appeals ruled that P2P file-sharing applications are legal because they can be used in substantial, noninfringing ways. The reasoning behind this goes all the way to Sony vs. Universal, back in 1984, when Universal sued Sony for selling the first Betamax machines. Universal said that because VCRs could be used to pirate movies, they should be strictly verboten. Sony replied that because VCRs have legit uses (storing video for later viewing, making a backup copy of a purchased movie), they're perfectly OK. The Supreme Court sided with Sony and consumers, and while Betamax later lost out to the VHS format, peoples' ability to copy media for personal use was preserved.

http://reviews-zdnet.com.com/AnchorDesk/4520-7298_16-5575644.html?tag=adss&tag=nl.e501-2

Friday, November 12, 2004

Thursday, November 11, 2004

MSN Search (beta)

It isn't google, but it's surprisingly good

http://beta.search.msn.com/
http://beta.search.msn.com/images/results.aspx?FORM=IRHP&q
http://beta.search.msn.com/news/results.aspx?FORM=NRIR&q

The trouble with using ems and percents for font sizing

The trouble with using ems and percents for font sizing:
"When good intentions fail

Relative font sizing is a great idea that fails to live up to its promises of user accessibility or design flexibility for the Web builder. In order to use relative font sizing successfully, you need to plan your page design and CSS styles very carefully to avoid the potential problems of nesting elements. You can do it, but it's not easy and it imposes significant restrictions on your design options. Otherwise, you need to rely on keywords or absolute measurements for font sizing. "

Free registration

http://builder.com.com/5100-6371_14-5210803.html?tag=nl.e601

Monday, November 08, 2004

US-CERT Vulnerability Note VU#842160 IE contains a buffer overflow vulnerability

US-CERT Vulnerability Note VU#842160:
"Microsoft Internet Explorer (IE) contains a buffer overflow vulnerability that can be exploited to execute arbitrary code with the privileges of the user running IE. "

A heap buffer overflow vulnerability exists in the way IE handles the SRC and NAME attributes of FRAME and IFRAME elements. Publicly available exploit code uses JavaScript to prepare heap memory with blocks that consist of NOP slides and shell code. After mishandling overly long SRC and NAME attributes, IE dereferences a memory address that may fall within one of the prepared heap blocks, running through the NOP slide and executing the attacker's shell code. Without the ability to prepare the heap blocks, this attack become significantly more difficult.

Other programs (e.g., Outlook, Outlook Express, AOL, Lotus Notes) that use the WebBrowser ActiveX control could be affected by this vulnerability

Install Windows XP Service Pack 2 (SP2)

Microsoft Windows XP SP2 does not appear to be affected by this vulnerability.

Disable Active scripting

Disabling Active scripting makes it more difficult for an attacker to prepare the heap to easily execute arbitrary code. At a minimum, disable Active scripting in the Internet zone and the zone used by Outlook, Outlook Express, or any other software that uses the WebBrowser ActiveX control. Instructions for disabling Active scripting can be found in the Malicious Web Scripts FAQ.

Do not follow unsolicited links

http://www.kb.cert.org/vuls/id/842160

Thursday, November 04, 2004

Apple disables iTunes plug-in | Tech News on ZDNet

Apple disables iTunes plug-in Tech News on ZDNet:
"With the latest version of iTunes, Apple Computer has disabled an add-on program that let people transfer songs off of their iPod. "

Apple introduced iTunes 4.7 last week, announcing new features such as support for the iPod Photo and the ability to find and delete duplicate tracks in a music library. But this week, Apple confirmed that version 4.7 does break compatibility with iPodDownload. The iTunes plug-in is designed to enable iPod owners to copy songs from the music player to an iTunes library, a feature that Apple has not supported.

Apple has in the past used new versions of iTunes to disable support for third-party software that adds unintended file-sharing abilities to the popular jukebox software. The company has also been pushing users to continue moving to more current versions of iTunes.

An Apple representative did not say why the company had disabled support for iPodDownload. The program's creator had already stopped distributing the software after Apple's lawyers contacted the company that housed its Web hosting.

"After Apple threatened my Web-hosting company, and my site was shut down for more than one hour, I had to withdraw the plug-in," Sylvain Demongeot said on the iPodDownload Web site. Demongeot did not return an e-mail.

http://news.zdnet.com/2100-1040_22-5436447.html


IE exploit is top of the hacks | Tech News on ZDNet

IE exploit is top of the hacks Tech News on ZDNet:
"A Microsoft Internet Explorer exploit represented the highest number of hacking attacks in the second quarter, according to figures from ScanSafe. "

The London-based security company said that the No. 1 hack was Exploit.HTML.Mht, which attempts to download and install a malicious program on a computer by using a security breach in Microsoft's IE browser software. The exploit was used to target almost twice as many organizations as other exploits, ScanSafe said.

"One of the things we've been surprised at is the growth rate of threats," said Roy Tuvey, director of ScanSafe. "There's been a 15 percent rise every quarter, and the threat is really rising. The first thing exploited are browser vulnerabilities."

Twenty-one percent of virus attacks occurred on Wednesdays and 6 percent at the weekend, ScanSafe found. The managed Web security company said the reason was that most viruses were launched at weekends and spread during the week.

http://news.zdnet.com/2100-1009_22-5436186.html