Friday, February 06, 2004

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Nebula Award Nominees Online
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
2.  German band Eisbrecher "has decided to make a statement for its fans and for music consumers in general and is releasing the album including ... 2 blank CD-Rs which have the same label as the CD itself." That is indeed a statement, because it sure isn't practical; it would have probably been cheaper to include three CDs.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  SCO abandons trade secret attack on IBM. But keeps fighting
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  RE: getting rid of outbreaks and spam (junk)
5.  Re: Hysterical first technical alert from US-CERT
6.  Linux 2.4.24 with vserver 1.24 exploit
7.  RE: Hacking USB Thumbdrives, Thumprint authentication
8.  Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47)
9.  Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47)
10.  Re: getting rid of outbreaks and spam

11:22:57 PM    

----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
1.  BugTraq: Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47). Sender: Tyler Larson [noreply at tlarson dot com]
2.  BugTraq: Re: getting rid of outbreaks and spam. Sender: Dave Warren [dave dot warren at devilsplayground dot net]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  UK government launches new intranet
4.  Checking for signs of weakness - Infoworld Staff
5.  Preventive measures - Infoworld Staff
6.  Are your Web apps secure? - Infoworld Staff
7.  The case for outsourcing the disposal process - Infoworld Staff
8.  Disposing of IT assets - Infoworld Staff

10:22:37 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  Qwesting in NYC.

Earlier this week, I participated in an internal symposium in NYC for telecom company Qwest, along with Doug Rushkoff (far left in snapshot here), Sueann Ambron, Omar Wasow, Clay Shirky, Janet Abrams, Justin Hall, Dennis Crowley, and Jane Buckingham. Justin blogs and shares snapshots from the event at links.net. Snip from Justin:

"We wrapped up the extended session by listing all of our telecommunications loyalties - astonishingly long lists (...) That jumble of communications begs simplification. What one company might offer me all those services? A frighteningly large company, I suspect. Or maybe a nimble one. We left them with a number of bold propositions and excited suggestions; I will be interested to see how the company develops itself over the coming years. Between wireless, landlines and high speed internet, with a firm local footing in the middle-West United States, I think Qwest has potential to create new forms of community using telecommunications."

Link

UPDATE: Numerous BoingBoing readers who are current or former Qwest customers wrote in to express, shall we say, less-than-warm-and-fuzzy feelings about past service experiences with this provider. Qwest is currently undergoing aggressive restructuring under a new CEO, after a disastrous recent past. Among the more polite comments received, Robert Rose writes "People here HATE Qwest in Oregon (...) [They need] to get the few services they offer currently right before they start looking at others." To their credit, the handful of Qwest executives I met in NYC this week seemed to be an intelligent and forward-minded lot who are well aware of this fact, and of the inherent challenges involved in planning for the future while contending with the company's past.

2.  American dispatches from London. Yankee Fog is a weekly blog account of life in London written by a former Dennis-Miller-comedy-writer, living as an American in the UK. The weekly essays are engaging and funny and evocative.

Link

(Thanks, Jacob!)

3.  Win a leather-bound "insanely detailed" Necronomicon.

The HP Lovecraft society is holding a contest to write the best "spell, drawing, chapter, or passage of mad Mythos rambling." The grand prize is a "handmade, leather-bound, super authentic copy of the finished work, done up in full 17th-century style at the insane level of detail the HPLHS is known for!"

Link

(Thanks, Alan!)


----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Linux Court Battle Broadens (PC World). PC World - SCO may seek additional damages in trademark complaint against IBM.
5.  Michigan Democrats Vote Online (PC World). PC World - Presidential caucus polls promise secure Internet ballots as an absentee option.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  The Best Colleges for Network Engineering?
7.  The Law of Disassembly
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
8.  BugTraq: Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47). Sender: Todd C dot Campbell [todd dot campbell at core dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
9.  Enterprise Storage Snapshots
10.  Microsoft Issues XML Fix to IE Patch
11.  Volte face du Pentagone, annulation du programme de vote par Internet
12.  Open Journal Blog Authenticaion Bypassing Vulnerability

9:22:16 PM    

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Political Correctness: problem, progress, or myth?. The question is, is political correctness a problem, a symptom of progress, or simply a myth-a pointer to a pretend "problem" used for its own political means? By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
2.  My New Fighting Technique: a tale of xerography on the high seas. David Rees, author of the Get Your War On strips and the book My New Fighting Technique is Unstoppable describes how MNFTIU became a book -- a tale involving countless under-the-table deals with people who have access to high-speed photocopiers. This kind of story illustrates the power of xerography and the importance of having a job wiht access to a high-speed photocopies.

So the book was being distributed via fax without my permission. This is called "file sharing." I asked the guy if he thought his photocopy friend would make me some copies of the book at a reduced rate ? seeing as how he was already engaged in unauthorized fax piracy on the high seas of clip-art comics. He thought this was reasonable. I called the guy at the photocopy shop and we worked out an arrangement whereby I would stop by the shop on Friday afternoons with a 12-pack of beer. I would leave the beer on top of the counter and he would kick a box of books under the counter. I would lug the books (actually, collated pages) home on the subway and staple them in my living room. That is how I learned the ancient art of bookbinding.

Link

(Thanks, Zed!)

3.  Dumbass "Copyright Registration" "service".

GoDaddy has created an idiotic "Copyright Registration" service that provides "expert assistance" in registering your copyright -- something that you have virtually no good earthly reason to do, and something you absolutely don't need any pricey "expert assistance" with. They offer a goony little badge you can put on your work to show that it's really, really, s00per-copyrighted, too ("Display this on your site and show thieves and others that you have federally assured rights to damages and attorneys' fees"). This is about half a step above the Green Card lotto scam and pay-for-book-doctoring "services" that prey on would-be artists' anxieties.

Link

(Thanks, Devon!)


4.  Age-maps: cool photoshoppery to span the years.

Less sez, "Two photographs of the same person, from different periods of time (child and adult) are spliced together. In this fusion a jump-of-time is established at the tear."

Link

(Thanks, Lee!)


5.  Mean Valentine's Day cards.

Love this gallery of print-and-assemble Valentine's Day cards that are full of bitterness, exquisitely expressed.

Link

(Thanks, Eyes Spies and Lies!)


6.  American dispatches from London. Yankee Fog is a weekly blog acocunt of life in London written by a former Dennis-Miller-comedy-writer, living as an American in the UK. The weekly essays are engaging and funny and evocative.

Link

(Thanks, Jacob!)

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
7.  Commentary: VoIP marches on
8.  Nextel to test '4G' broadband service. Cell phone service provider Nextel Communications is set to begin testing a new, "fourth generation" wireless broadband offering later this month with several companies in the Raleigh-Durham, N.C., area.
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
9.  BugTraq: Open Journal Blog Authenticaion Bypassing Vulnerability. Sender: Tri Huynh [trihuynh at zeeup dot com]
10.  Vulnerabilities: Linux Kernel R128 Device Driver Unspecified Privilege Escalation Vulnerability. The Linux Kernel supports numerous driver modules; one such is the R128 ATI Rage 128 bit video card driver module.

It has been reported that the Linux Kernel is prone to...

11.  Vulnerabilities: FreeBSD NetINet TCP Maximum Segment Size Remote Denial Of Service Vulnerability. The FreeBSD netinet implementation has been reported prone to a vulnerability that may allow remote attackers to deny service to affected servers.

The issue presents its...

12.  Vulnerabilities: Apache mod_digest Client-Supplied Nonce Verification Vulnerability. mod_digest is a digest authentication module that is included in Apache HTTPD.

Patches have been released for the Apache mod_digest module to include digest replay prote...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Michigan Dems Proceed With Online Voting
14.  Will E-Voting Make An Impact in 2004?
15.  W97M_CPCK
16.  The Cleaner Database v3477
17.  The Cleaner 4.0 Professional BUILD 4215
18.  Ad-aware referencefile 01R255 06.02.2004
19.  Tiny Personal Firewall 5.5.1296
20.  Sygate Personal Firewall Pro 5.5.2525
21.  Sygate Personal Firewall Free 5.5.2525
22.  Red Hat Plans Security Enhanced Linux Version

8:21:56 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  William Gibson's U.S. book tour. Author William Gibson is on a book tour this month, promoting Pattern Recognition. 02.03.04 to 02.21.04. Check out dates and venues here.
2.  Playboy syndicates Suicide Girl nudie pics. All of the links in this post are not worksafe, but you knew that. So: Playboy online just launched a new feature, "Suicide Girl of the week." I heard about plans for the syndication launch last week from SG founder Sean in LA, and I understand this is the first time Playboy has ever syndicated another site's content directly on playboy.com. An interesting development, given SG's humble, indie dot-com beginnings. BoingBoing reader matt rhodes says, "You can see the thread on the SG board here and the Playboy boards are here. From what I gather, there is some degree of bitching on the Playboy boards. They don't seem to want their nudes with tattoos and piercings."

In other news... SG is launching a bunch of new website content in a beta section called SG Newswire (think hybrid collaborative blog/news format, on music, politics, technology, etc.), plus an RSS feed for SG Newswire, and they've also got another big announcement in the works about a new offline project. If I tell you what it is, hordes of hot chicks clad solely in SG-logo underoos will swarm my office and spank me. And that would be, you know, a bad thing.

3.  Wolfram's giant book free online. Stephen Wolfram has made the complete text of his New Kind of Science (a 1000+-page treatise on the way that virtually everything in the universe can be explained with cellular automata), which he self-published a couple years back with some of the squillions of dollars he's earned on his seminal Mathematica software program, available for free on the Internet.

Link

(via /.)

4.  Two "official" blank CDRs when you buy the new Eisbrecher CD. Eisbrecher, a band, is bundling two blank CDRs, silkscreened to match the official CD, with sales of its new disc:

We are of the opinion that the music buyers are criminalized enough and have been made responsible for the wretched state in the music industry. We are giving them the chance to make 2 legal copies for private use with 'official blanks'. It can't always be that the end users have to take the blame for something that international corporations have arranged with their artist-burning methods.

Link

(via /.)

5.  USB-powered vacuum.

This USB-powered, keyboard-sized vacuum cleaner looks geniunely useful.

192K PDF Link

(via Gizmodo)


----------------------------------------------------------------------
Penny Arcade!
----------------------------------------------------------------------
6.  A Good Plan, In Theory.
----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
7.  Indian IT companies deny visa abuse
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
8.  A Deep Space Primer
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
9.  UK government launches new intranet. LONDON - The U.K. government launched a new secure intranet system this week, promising to more easily connect all central and local government departments, as well as public sector organizations.
10.  EU debate to take up P-to-P filesharing. BRUSSELS - Sharing music over the Internet could become a criminal offense if some members of the European Parliament get their way in a debate next week. The Parliament is set to debate a draft law designed to stamp out mass pirating and counterfeiting of digital products such as music and movies.
11.  Vonage CEO: VOIP will grow, if no regulation. WASHINGTON - Voice over Internet Protocol (VOIP) services are poised to take off in the U.S., if regulators can keep their hands off this alternative to traditional telephone service, the chief executive of a major VOIP provider said Friday.
12.  Oracle cuts price on 10g database - Infoworld Staff. Aiming at the SMB (small to midsize business) market, Oracle is shipping a major upgrade to its database software and is cutting prices on lower-end versions of the product.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
13.  UK government launches new intranet. LONDON - The U.K. government launched a new secure intranet system this week, promising to more easily connect all central and local government departments, as well as public sector organizations.
14.  Checking for signs of weakness - Infoworld Staff. The two web application firewalls from KaVaDo and Sanctum come with companion application vulnerability scan products to enhance the total security provided for the application. While no scan software can provide the depth of vulnerability discovery and analysis that would come from a professional penetration test, we found that each of the scanners we reviewed brought useful information into the security planning process.
15.  Preventive measures - Infoworld Staff. Unless you’ve been tinkering with the rovers on Mars and are just now returning to this planet, you’ve likely had your fill of the stories of the latest worm. And unless you’re running SCO’s Web site, you probably have had little more than inconvenience as a result of that fast spreading worm.
16.  Are your Web apps secure? - Infoworld Staff. Web-based applications have become vital pieces of business infrastructure. Along the way, they’ve also become major security risks for the organizations that rely on them.
17.  The case for outsourcing the disposal process - Infoworld Staff. When Pat Ray, asset management supervisor at Montgomery College in Rockville, Md., sat down to look at her equipment disposal costs two years ago, she was amazed by what she found. Her staff of five had been handling asset disposal and charitable donations themselves for almost a decade. But when she really looked at the numbers for ongoing disposal of the college’s 18,000 assets, she found it was exacting a huge hidden cost.
18.  Disposing of IT assets - Infoworld Staff. How confident are you that your discarded end-of-life IT assets aren’t going to come back to haunt you? Consider this:
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
19.  Vulnerabilities: Summit Computer Networks Lil' HTTP Server URLCount.CGI HTML Injection Vulnerability. Lil' HTTP server is a web server application for Windows environments and is maintained by Summit Computer Networks.

Reportedly, Lil' HTTP Server is vulnerable to HTML i...

20.  Vulnerabilities: PHPX Multiple Vulnerabilities. PHPX is a PHP-based content management system.

Multiple vulnerabilities were reported in PHPX. The specific issues include cross-site scripting, HTML injection and acco...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
21.  Conectiva: libtool Conectiva: 'libtool' temporary file handling vulnerability
22.  Red Hat: mailman Red Hat: 'mailman' XSS vulnerabilities
23.  Mandrake: glibc Mandrake: 'glibc' resolver overflow
24.  FreeBSD: n/a FreeBSD: 'shmat' reference counting bug
25.  Red Hat: netpbm Red Hat: 'netpbm' temporary file vulnerabilities
26.  Debian: mpg123 Debian: 'mpg123' heap overflow
27.  Debian: gaim Debian: 'gaim' vulnerabilities
28.  Discuz! Input Validation Flaw May Permit Cross-Site Scripting Attacks

7:21:36 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  Amazing Iraq photo website from Stephanie Sinclair.

Click thumbnail for full-size image. A weblog and an incredible collection of images from Iraq (also Cuba), shot and written by photographer Stephanie Sinclair.

link

(note: Her blog and photo gallery launch by way of a nasty javascript pop-up window, but the UI is well worth enduring for the truly stunning images inside)

(Thanks, Sean)

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
2.  Linux battles rage on. roundup SCO fires another broadside in its legal wranglings with IBM over the open-source operating system. Microsoft, meanwhile, sharpens its competitive attack on Big Blue and Linux.
3.  SAP replaces head of key initiative. The Germany company swaps the leader of a program to migrate thousands of customers from aging versions of its business-management software to newer releases.
4.  SCO claim reaches $5 billion. The SCO Group tacks on another $2 billion to its claim against IBM and adds new copyright allegations in an amendment to the Unix and Linux suit.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  IBM Introduces Lightest ThinkPad Yet (NewsFactor). NewsFactor - IBM (NYSE: IBM) is pushing the envelope in mobile computing by scaling down even more its popular ThinkPad X product line while at the same time adding new functionality. Its primary goal: to capture the executive road-warrior market.
6.  Microsoft MSN Posts Loss Again After Brief Profit (Reuters). Reuters - Microsoft Corp.'s (MSFT.O) MSN Internet division slipped back into the red on an operating basis with a $79 million loss, despite posting its first-ever profit in the previous quarter, the world's largest software maker said in a regulatory filing on Friday.
7.  Is There Room for Mandrake in the Enterprise? (NewsFactor). NewsFactor - The list of Linux software companies with significant market share is short: Red Hat (Nasdaq: RHAT) and SuSE, in that order, own the lion's share of the corporate market. All the others grouped together get the scraps, collectively falling in the low single digits.
8.  Tech Shares Advance With Data, Earnings (Dow Jones). Dow Jones - NEW YORK -- Wireless stocks advanced Friday following an encouraging report from Telefon AB L.M. Ericsson, helping to lift the broader tech sector. Semiconductor stocks were also strong, but shares of Electronic Data Systems dropped following its report.
9.  Michigan Dems Proceed With Online Voting (AP). AP - Thousands of Michigan Democrats have cast ballots for Saturday's caucuses using an Internet system that security experts say shares some of the risks found in a just-scrapped Pentagon effort.
10.  Marvel, EA Tie Up Seen Tricky But with Big Potential (Reuters). Reuters - Spider-Man, the X-Men and Marvel Enterprises's other superheroes will soon be faced with deadly new enemies being dreamed up by video game publisher Electronic Arts Inc.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
11.  SCO Adds Copyright Claim to IBM Suit
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
12.  Debian: mpg123 Debian: 'mpg123' heap overflow
13.  Debian: gaim Debian: 'gaim' vulnerabilities
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
14.  Vulnerabilities: RhinoSoft Serv-U FTP Server MDTM Command Stack Overflow Vulnerability. RhinoSoft Serv-U FTP Server is designed for use with Microsoft Windows operating systems.

Serv-U FTP Server is reportedly prone to a stack-based buffer overflow.

When a...

15.  Vulnerabilities: Microsoft Internet Explorer NavigateAndFind() Cross-Zone Policy Vulnerability. A vulnerability has been reported in Microsoft Internet Explorer. Because of this, an attacker may be able to violate cross-zone policy.

It has been reported that the is...

16.  Vulnerabilities: Cauldron Chaser Remote Denial Of Service Vulnerability. Chaser is a client-server, first person shooter computer game. It is available for the Windows operating system.

Chaser has been reported to be prone to a denial of ser...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
17.  AT&T Wireless awaits prom call from Vodafone. Please bid for us
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  Best Practices for Wireless Network Security
19.  Äûðêè â ïðîäóêòàõ RealNetworks
20.  Code Access Security in SQL Server 2000 Reporting Services
21.  Global Cost Of Political Risk On The Rise

6:21:16 PM    

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
1.  Corel sells XML division
2.  Commentary: Web services ripe for consolidation
3.  Microsoft server unit flips to quarterly loss. Stung by the cost of a stock option transfer program and larger work force, the unit posts a hefty operating loss in the December quarter, reversing the profit posted a year earlier.
4.  HP to unveil new Itanium, Unix servers. Hewlett-Packard is expected to announce its new PA-8800 processor and an accompanying Unix server line Monday, as well as a new system built with Intel's Itanium 2 for technical computing, according to sources.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  Michigan Plans Internet Vote Despite Hacking Risks (Reuters). Reuters - The Michigan Democratic Party is sticking with its Internet voting system even though security concerns have prompted the Pentagon to abandon its own online voting efforts, a state party spokesman said on Friday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  The World of Virus Writers
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Best Practices for Wireless Network Security
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
8.  BugTraq: Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47). Sender: Seth Arnold [sarnold at wirex dot com]
9.  BugTraq: formmail (PHP) Upload file using CSS. Sender: Himeur Nourredine [lostnoobs at security-challenge dot com]
10.  BugTraq: Re: Two checkpoint fw-1/vpn-1 vulns. Sender: Markus Wernig [listener at wernig dot net]
11.  BugTraq: Re: Two checkpoint fw-1/vpn-1 vulns. Sender: Mariusz Woloszyn [emsi at ipartners dot pl]
12.  Vulnerabilities: Tunez Multiple Remote SQL Injection Vulnerabilities. Tunez is a freely available, open source web MP3 jukebox. It is available for the Unix and Linux platforms.

Several problems in the handling of user-supplied input have...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
13.  US markets warm to Linux makers over SCO. Cash Register It was good while it lasted

5:20:56 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Brazil Regulator Approves Mobile, Fixed-Line Tariff Hikes (Dow Jones). Dow Jones - RIO DE JANEIRO -(Dow Jones)- Brazil's telecommunications regulator, Anatel, announced Friday a 6.99% tariff hike for calls from fixed-line to wireless phones.
2.  Fujifilm Expands Digicam Line (PC World). PC World - Two entry-level FinePix models debut; high-end professional cameras promised.
3.  Michigan Dems Proceed With Online Voting (AP). AP - Thousands of Michigan Democrats have cast ballots for Saturday's caucuses using an Internet system that security experts say shares some of the risks found in a just-scrapped Pentagon effort.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Radar For Safer Driving
5.  Dream Jobs of 2004
6.  Inside Microsoft's New Digital Photo Project
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  419ers get a taste of Texas Justice. Urgent proposal for jail time
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  Re: Major hack attack on the U.S. Senate
9.  Open Source: Swimming with the Tide
10.  UPDATE: DoD Confirms It's Ditching Serve For Time Being
11.  Digital Rights Go Mobile
12.  Pentagon Cancels Internet Voting System
13.  RealNetworks Sounds Security Alarm
14.  RealNetworks Sounds Security Alarm

4:20:36 PM    

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Trade group: pay, don't sue, the song swappers. From the um-what-department comes a novel, interesting, and totally clued-out suggestion from the Distributed Computing Industry Association: pay the song swappers for their services as distributors. By Ken "Caesar" Fisher.
2.  New HyperTransport spec ready. HyperTransport 2.0 will be officially launched on Monday (2/9). It will feature the ability to map to PCI Express and clock speeds of up to 1.4GHz By Eric Bangeman.
----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
3.  Qwesting in NYC. Earlier this week, I participated in an internal symposium in NYC for telecom company Qwest, along with Doug Rushkoff, Sueann Ambron, Omar Wasow, Clay Shirky, Janet Abrams, Justin Hall, and others. Justin blogs and shares snapshots from the event at links.net. Snip:
We wrapped up the extended session by listing all of our telecommunications loyalties - astonishingly long lists (...) That jumble of communications begs simplification. What one company might offer me all those services? A frighteningly large company, I suspect. Or maybe a nimble one. We left them with a number of bold propositions and excited suggestions; I will be interested to see how the company develops itself over the coming years. Between wireless, landlines and high speed internet, with a firm local footing in the middle-West United States, I think Qwest has potential to create new forms of community using telecommunications.
Link
----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
4.  T-Mobile, AT&T Wireless form roaming pact
5.  Briefly: T-Mobile, AT&T Wireless form roaming pact. The companies will let each other's customers use their hot-spot networks in certain airports...Group proposes new P2P music model...Equant offers hosted Exchange 2003.
6.  China gears up for RFID. A Chinese working group is developing a national standard for inventory-tracking radio tags, a process likely to be closely watched given China's recent demand that foreign Wi-Fi makers take on local partners.
7.  Week in review: Super shocking Sunday. The tech week got off to a not-so-super start on Super Bowl Sunday, as an e-mail virus and a risque halftime performance became the biggest things on the Internet.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
8.  European Stocks Advance on Robust Technology Shares (Dow Jones). Dow Jones - LONDON -- European stocks rose Friday as the technology sector gained after Ericsson, the world's largest maker of wireless telecom equipment, beat consensus forecasts with its fourth-quarter update.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
9.  Open Source: Swimming with the Tide
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
10.  Vulnerabilities: Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability. Multiple vendor antivirus software applications have been reported to be prone to a denial of service vulnerability. This issue presents itself when an affected applicat...
11.  Vulnerabilities: phpMyAdmin Export.PHP File Disclosure Vulnerability. phpMyAdmin is a freely available tool that provides a web interface for handling MySQL administrative tasks.

phpMyAdmin is prone to a vulnerability that may permit remo...

12.  Vulnerabilities: Linley Henzell Dungeon Crawl Unspecified Local Buffer Overflow Vulnerability. Linley Henzell Dungeon Crawl is a console based game.

Dungeon Crawl has been reported to be prone to an unspecified local buffer overflow vulnerability. The condition is...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Re: Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior
14.  RE: Decompression Bombs
15.  Diebold May Face Consequences for Misuse of Copyright Law
16.  Sharman Offices, Homes, ISPs Raided In Australia
17.  Xlight FTP Server Can Be Crashed When the Admin Views the Log
18.  Phishers to target ISP customers next
19.  SGI Adds "Fuel" to 3D Workstation Upgrades
20.  TROJ_STOMCC.A

3:20:16 PM    

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
1.  FCC to limit VoIP regulations. The Federal Communications Commission reaches an agreement with the FBI permitting it to approve a VoIP company's request for limited regulation of its operations.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Tech Stocks Advance at Early Afternoon on Ericsson Report (Dow Jones). Dow Jones - NEW YORK -- Wireless stocks advanced Friday following an encouraging report from Telefon AB L.M. Ericsson, helping to lift the broader tech sector. Semiconductor stocks were also strong, but shares of Electronic Data Systems dropped following its report.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  HP Discusses Anti-Counterfeiting Measures
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  Sony offers limited edition 'Aqua' PS2. Crystal Xbox? Never heard of it...
5.  Small.biz faces Treasury tax terror. So you thought IR35 was bad...
6.  Sun buys $200 million worth of an N1 vision. Coding pays
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Novell iChain May Grant Remote Users Access Via Mandatory Telnet Service if No Password is Set
8.  RealPlayer Vulnerabilities Disclosed
9.  RealNetworks Patches Player Vulnerabilities
10.  Janet Jackson Leads Web Searches, Spawns Spam
11.  Public Sector More Likely To Use Disaster Recovery Systems Than Private Companies

2:19:57 PM    

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Pentagon dumps current Internet voting plan. On account of security concerns, the Pentagon has scraped its SERVE program to develop an Internet voting system for American troops and other foreign service people abroad. By Ken "Caesar" Fisher.
2.  Sharman Networks (Kazaa) served search warrant. The owners of Kazaa, were served a search warrant by the Federal Court of Australia this morning. Is this the beginning of the end for Kazaa? By Matt Woodward.
----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
3.  Sexually explicit snowpersons. Snapshots of pornographic snow figure tableaus. Link (Thanks, Siege)
4.  eBay as distribution channel for haute couture. NYT article on a new eBay hack of sorts -- up-and-coming fashion designers are using the online auction site as a means of reaching would-be customers who don't live in spitting distance of Park Avenue or Rodeo Drive.
The 10-day auction, planned for Feb. 26 to March 7, will not be the first on eBay by a fashion designer. Narciso Rodriquez crossed that threshold last September. But in that case only two items, a nude-tone sequin dress and a similar colored suit, were direct from the runway.

The coming Proenza Schouler auction, by contrast, will be "virtually an online trunk show - the first of its kind,'' said Constance White, the style director at eBay. The Web site is intent on expanding its clothing offerings and special promotions. "The potential is vast," Ms. White said.

Link (Thanks, Susannah!)
5.  Dell's Linux Blog. Genuine, honest-to-blog corporate weblogging from a Fortune 500? Dell Linux engineers speak freely in this collaborative online journal, which consists mostly of software update news, patch pointers, and other deeply geeky stuff: Link. Also available in tasty, low-carb RSS.
----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
6.  Study: IT spending to improve in 2004. After meager spending in 2003, businesses are likely to shell out more than their planned IT budgets for this year, according to market researcher Gartner.
7.  Vonage dials in $40 million in funding. The broadband phone provider's plan to expand into international markets gets a multimillion-dollar boost from venture capital investors 3i and Meritech Capital Partners.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
8.  Pentagon E-Voting Program Drops out of the Race (washingtonpost.com). washingtonpost.com - The Internet's role in campaigns and elections continues to grow, but security snags continue to mar e-voting efforts. Amid a public outcry over security, the Pentagon said it would pull the plug on its plan to let U.S. citizens living abroad cast their votes online in the upcoming presidential election.
9.  Florida Lawmakers Take Aim at Violent Video Games (Reuters). Reuters - Bolstered by outrage from Haitian Americans and parents over a top-selling game, a group of Florida lawmakers is moving to stiffen penalties for retailers that sell or rent violent or sexually explicit computer games to minors.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
10.  Would you Warranty Your Email?
11.  The Golden Ratio
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
12.  Vulnerabilities: Qualiteam X-Cart Remote Command Execution Vulnerability. X-Cart is a web based shopping card application implemented in PHP and integrated with a MySQL database backend.

X-Cart has been reported to be prone to an issue that ma...

13.  Vulnerabilities: Qualiteam X-Cart Multiple Remote Information Disclosure Vulnerabilities. X-Cart is a web based shopping card application implemented in PHP and integrated with a MySQL database backend.

X-Cart has been reported to be prone to an issue that ma...

14.  Vulnerabilities: Sun ONE/iPlanet Web Server HTTP TRACE Credential Theft Vulnerability. Sun ONE Web Server is a web server implementation that is maintained by Sun Microsystems. It has been rebranded from iPlanet.

A vulnerability has been reported to exist...

15.  Vulnerabilities: Cisco IOS MSFC2 Malformed Layer 2 Frame Denial Of Service Vulnerability. IOS is the device operating system available for the Cisco hardware platform. It is maintained and distributed by Cisco.

A problem has been identified in the handling o...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
16.  Europe and US inch towards GPS accord. Jammin' in the name of the competing power blocs
17.  Nanotech researchers see the light. Through fibres smaller than lambda
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  Computer Forensics conference line-up finalised

1:19:36 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  Sexually explicit snowpersons. Snapshots of pornorgaphic snow figure tableaus. Link (Thanks, Siege)
2.  So.... ahem... there was life on Mars?. BoingBoing reader Roland Piquepaille says:

Two researchers from the University of Queensland (UQ) have confirmed that life existed on Mars. They first looked at magnetic crystals found in mud samples from a water trap of an Australian golf course. UQ News Online reports that they found their proof by comparing these crystals with those contained in a meteorite discovered in Antartica in 1984 and named ALH84001. "Our research shows that the structures found in the NASA meteorite were more than likely made by bacteria present on Mars four billion years ago, before life even started on Earth," said Dr Taylor, one of the two scientists. You'll find more details and references in this overview, both on the research work and the meteorite.
Link
3.  Gallery of fabulous 3D-like sidewalk chalk paintings. BoingBoing reader satirista says,
"A half-dozen photos of simply the finest trompe l'oeil works I've ever seen--and they're done on sidewalks with pastels! The pix at Snopes are better than the gallery photos at Kurt Wenner's own site (in my opinion), but here's a link to Wenner's Q&A with the Artist page, which answers questions like 'what happens when it rains on your pictures?'"
Link to Wenner gallery at Snopes.com
4.  Web Zen: Comic Zen. (1) her! (2) the boy fitz hammond (3) a softer world (4) death to the extremist (5) my fighting technique. Link to web zen home, web zen store, (Thanks, Frank).
5.  eBay as distribution channel for haute couture. NYT article on a new eBay hack of sorts -- up-and-coming fashion designers using the online auction site as a means of getting goods to would-be customers who don't live in spitting distance of Park Avenue or Rodeo Drive.
The 10-day auction, planned for Feb. 26 to March 7, will not be the first on eBay by a fashion designer. Narciso Rodriquez crossed that threshold last September. But in that case only two items, a nude-tone sequin dress and a similar colored suit, were direct from the runway.

The coming Proenza Schouler auction, by contrast, will be "virtually an online trunk show - the first of its kind,'' said Constance White, the style director at eBay. The Web site is intent on expanding its clothing offerings and special promotions. "The potential is vast," Ms. White said.

Link (Thanks, Susannah!)
6.  Kazaa, Sharman offices raided in Australia. Australian recording industry investigators raided the Sydney offices of Kazaa, of owner Sharman Networks, and homes of two company execs today seeking evidence to support copyright infringement allegations.
The raid was conducted under a rarely used law, known as Anton Pillar, which allows litigants in civil copyright cases to gather evidence. The Federal Court gave major Australian record labels permission to raid 12 premises in three states to collect evidence against Kazaa, said Michael Speck, general manager of Music Industry Piracy Investigations. The group is owned by Universal, Festival Mushroom Records, EMI Music, Sony Music, Warner Music Australia and BMG Australia. (...) Speck said the recording industry would launch a civil action against Kazaa in the Federal Court on Tuesday.
Link to SF Chronicle article. Link to statement from Sharman Networks about the raid. (via pho)
----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
7.  EU approves German grants to AMD. Advanced Micro Devices secures subsidies by the German and Saxon governments for its second chipmaking facility in Dresden.
8.  European train operator considers Wi-Fi. Cross-channel train operator Eurostar is following in the footsteps of GNER and Virgin Trains with a wireless Internet access plan.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
9.  Music Industry Raids Offices of Kazaa (AP). AP - Investigators from the Australian recording industry raided the Sydney offices of Internet file-swapping network Kazaa on Friday in search of evidence to support allegations of copyright infringements.
10.  Zipped Files Can Zap Antivirus Apps (PC World). PC World - Compressed folders can hide worms, viruses, and more, experts warn.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
11.  Review: KDE 3.2
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
12.  Update: J2SE to get a makeover with 1.5 upgrade. Sun Microsystems Inc. has released a beta version of the next release of Java 2 Standard Edition (J2SE), a set of specifications used for creating desktop applications and which also form the basis of Java development tools from Sun and its partners.
13.  Apple Japan president may trade iMacs for Big Macs. TOKYO -- Apple Japan Inc.'s President may be trading iMacs for Big Macs after he steps down from the computer company later this month.
14.  SCO looks to widen Linux complaint against IBM. The SCO Group Inc. aimed more legal fire at IBM Corp. this week, filing a motion to amend its Linux complaint against the company ahead of a hearing due to take place Friday.
15.  RealNetworks warns of media player security flaws. RealNetworks Inc.'s media player software contains vulnerabilities that could let an attacker take control of a PC on which the software is used to download multimedia files, the company confirmed this week.
16.  OSDL delivers guidelines on Linux for datacenters. In a move to accelerate the development and adoption of Linux in datacenters, a global consortium of IT companies known as Open Source Development Labs Inc. (OSDL) has issued a set of technical guidelines for the use of the open source operating system in running mission-critical enterprise applications on server platforms.
17.  Samsung to put satellite TV into cell phone. Samsung Electronics Co. Ltd. is planning a cellular telephone that can receive multimedia programming broadcasts via satellite, the company said Thursday.
18.  AOL launches AIM 5.5 with streaming video. AOL Instant Messenger (AIM) users can now establish live video streaming conversations with iChat Macintosh users, thanks to an AIM software upgrade released by America Online Inc. Thursday.
19.  Motorola, Opera team on WAP-HTML browser. Motorola Inc. and Norway's Opera Software ASA will jointly offer products for cellular phone browsers that utilize both HTML (Hypertext Markup Language) and WAP (Wireless Application Protocol) technologies, the companies announced Friday.
20.  AMD receives $683M in aid for Dresden fab. Germany and the state of Saxony will give Advanced Micro Devices Inc. (AMD) approximately €545 million ($683 million) in grants and allowances toward the construction of its new manufacturing plant in Dresden after the European Commission approved the aid package, AMD said Friday.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
21.  RealNetworks warns of media player security flaws. RealNetworks Inc.'s media player software contains vulnerabilities that could let an attacker take control of a PC on which the software is used to download multimedia files, the company confirmed this week.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
22.  Unstrung Insider Analyzes Wireless Intrusion Detection and Prevention
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
23.  Elsewhere: MyDoom-ed PCs still prey to hackers. Victims of the MyDoom virus may still be vulnerable. While the focus of much of the attention awarded MyDoom focused on the DOS (denial of service) attacks it launched ag...
24.  News: Clueless office workers help spread computer viruses. The Register By John Leyden [john dot leyden at theregister dot co dot uk]
25.  News: Unholy trio of RealOne Player holes unearthed. The Register By John Leyden [john dot leyden at theregister dot co dot uk]
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
26.  Vulnerabilities: All Enthusiast Photopost PHP Pro SQL Injection Vulnerability. Photopost PHP Pro is a web based gallery application written in PHP.

A vulnerability has been reported to exist in the software that may allow an attacker to influence S...

27.  Vulnerabilities: Util-Linux Login Program Information Leakage Vulnerability. Login is a component of the util-linux package. It is available for the Linux platform.

A problem has been identified in the handling of information by the login compon...

28.  Vulnerabilities: PHP-Nuke GBook Module HTML Injection Vulnerability. PHP-Nuke is web portal software. GBook is a guestbook module for PHP-Nuke.

A vulnerability has been reported to exist in the software that may allow a remote attacker t...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
29.  Computer Forensics conference line-up finalised. Digital Evidence Symposium
30.  Sony offer limited edition 'Aqua' PS2. Crystal Xbox? Never heard of it...
31.  Revealed: the perils of automated replies. Customer services heartened by utter failure
32.  BT hides mobile transmitters in street furniture. Preserving the aesthetics of Cheshire
33.  What do you get if you cross a 419er with 3000 oxen?. Answer: confusion of Herculean proportions
34.  IBM tries to clean up South Korean biz with new exec. Bribe fallout
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
35.  6 Feb Troj/Sdbot-FM
36.  Kinderen negeren chat gevaren
37.  PayPal virusschrijver en oplichter bekent schuld
38.  Elsewhere: Real media players open doors for hackers
39.  Elsewhere: RealNetworks warns of media player security flaws
40.  Mesh Meets Security
41.  Re: BUG IN APACHE HTTPD SERVER 2.0.47/48 (to who replied me)
42.  Re: BUG IN APACHE HTTPD SERVER 2.0.47/48 (to who replied me)
43.  Durch IE-Update unterbunden: So können Sie wieder Benutzer/Passwort-URLs verwenden

12:19:16 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Pentagon E-Voting Program Drops out of the Race (washingtonpost.com). washingtonpost.com - The Internet's role in campaigns and elections continues to grow, but security snags continue to mar e-voting efforts. Amid a public outcry over security, the Pentagon said it would pull the plug on its plan to let U.S. citizens living abroad cast their votes online in the upcoming presidential election.
2.  Are your old gizmos new enough to be donated? (USATODAY.com). USATODAY.com - Do you still have the 286 desktop PC you bought when Dubya's dad occupied the White House?
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Wolfram's New Kind of Science Now Online
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
4.  Elsewhere: Real media players open doors for hackers. RealNetworks acknowledged on Wednesday that three flaws affecting different versions of its media player could allow attackers to create corrupt music or video files that...
5.  Elsewhere: RealNetworks warns of media player security flaws. RealNetworks Inc.'s media player software contains vulnerabilities that could let an attacker take control of a PC on which the software is used to download multimedia fi...
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
6.  BugTraq: US-CERT Technical Cyber Security Alert TA04-036A -- HTTP Parsing Vulnerabilities in Check Point Firewall-1. Sender: CERT Advisory [cert-advisory at cert dot org]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  accipiter.txt
8.  manpage.txt
9.  ezcontents.txt
10.  DameWeird.c
11.  _SRT2004-01-09-1022...>
12.  phpGedView.txt
13.  hdsoft.c
14.  cisco-sa-20040113-h3..>
15.  antivir.c
16.  susegnome.txt
17.  racoon.txt
18.  nCipher08.txt
19.  advisory-20040114-1...>
20.  fishcart.txt
21.  CA-2004-01.H323.txt
22.  phpdig16x.txt
23.  6 Feb W32/Agobot-CP
24.  eFarm 1.0
25.  IE-Update: So dürfen Sie wieder Benutzer/Passwort-URLs verwenden
26.  IT Regulations May Weaken Security
27.  Should You Shut the Computer Down?
28.  Sharman Networks Raided!
29.  [RHSA-2004:030-01] Updated NetPBM packages fix multiple temporary file vulnerabilities
30.  Re: getting rid of outbreaks and spam (junk) [WAS: Re: RFC: virus handling]
31.  Fast jede Web-Applikation hat Sicherheitslücken

11:18:57 AM    

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
1.  Piracy fighters raid offices of Sharman, others. A judge in Australia authorizes a record industry group to search peer-to-peer companies including Kazaa owner Sharman and several ISPs, along with key executives' homes.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Wireless Phone Co. Ericsson Turns Profit (AP). AP - LM Ericsson, the world's largest supplier of equipment for wireless phone networks, swung to a profit in the fourth quarter, citing escalating sales in Asia and the Americas.
3.  RealNetworks Warns of Media Player Flaws (PC World). PC World - Vulberabilities could allow an attacker to take control of your PC.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  IC Failures Linked to Resin Series?
5.  Two Blanks Against the Trend
6.  Computer Engineering Degree Most Valuable
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
7.  Children ignore net chat dangers. Many children are still ignoring the potential dangers of net chatrooms despite warnings, according to research.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  EU approves €545m grants for AMD Dresden. Volume output for 300mm fab in 2006
9.  Infineon preps €120m R&D fab expansion plan. Costs €1m for every new job created
10.  Upbeat Ericsson beats forecasts. Demand stabilises
11.  Sony of offer limited edition 'Aqua' PS2. Crystal Xbox? Never heard of it...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  Linux Advisory Watch - February 6th 2004
13.  Clueless office workers help spread computer viruses
14.  Zipped Files Can Zap Antivirus Apps
15.  Great Taste, Less Privacy
16.  0900: Information und Schutz der Konsumenten vor PC-Dialern
17.  Internet Explorer: Patch zum Patch
18.  Re: getting rid of outbreaks and spam
19.  Sicherheitslücke im RealPlayer

10:18:37 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Vodafone Weighs U.S. Bid Ambition (Reuters). Reuters - Mobile phone titan Vodafone Group Plc has seven days to decide whether to join a $30 billion auction of U.S. rival AT&T Wireless, but market experts say it may leave a final decision to the eleventh hour.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
2.  Clueless office workers help spread computer viruses. Don't know, don't care
3.  Contact The Register. Who's Who at Vulture Central
4.  EU approves €545m grants for AMD 300mm fab. Volume output in 2006
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Mambo Open Source Input Validation Hole in 'Itemid' Permits Cross-Site Scripting Attacks
6.  Unholy trio of RealOne Player holes unearthed
7.  Privacy and the WHOIS Database
8.  Pentagon Drops Internet Voting
9.  VBS_QOMA.A
10.  Interview: Intel's approach to security
11.  Leniency may encourage more hackers
12.  Possible Cross Site Scripting in Discuz! Board

9:18:17 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Pentagon Calls Off Voting by Internet (washingtonpost.com). washingtonpost.com - The Pentagon has canceled plans to collect votes over the Internet from military personnel and civilians abroad for this fall's presidential election because of security concerns.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
2.  Record labels in 'piracy' raids. Australian record labels raid universities and internet firms to hunt for evidence of online music "piracy".
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
3.  Linux Advisory Watch - February 6th 2004
4.  Linux Advisory Watch - February 6th 2004
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
5.  Unholy trio of RealOne Player holes unearthed. Patching time again
6.  Tiny transforms into e-business. Tiny.com to go live on 20 Feb.
7.  What are Boffins? And other important questions. Letters More from The Reg's bulging postbag
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  Gelaagde security aanpak bewaakt netwerk integriteit
9.  40-jarige wetenschapper gearresteerd wegens hacken
10.  Nieuwe generatie zwendel e-mails kan iedereen treffen
11.  Pentagon Scraps Internet Voting System
12.  Security Firm Warns of Holes In Bluetooth Mobiles
13.  How Spammers Are Targeting Mobile Phones in Asia
14.  CWShredder 1.47.5
15.  Norton AntiVirus Virus Definitions February 4, 2004
16.  VCatch Basic 5.0.20.2
17.  McAfee DAT 4322
18.  McAfee SuperDAT 4322
19.  Trend Micro Pattern File February 5, 2004
20.  Kerio Personal Firewall 4.0.11 RC2
21.  RealPlayer flaws open PCs up to hijackers
22.  Norton AntiVirus Virus Definitions February 5, 2004
23.  MSXML3.0 SP4 Critical Update
24.  MyDoom (A,B) Worm Removal Tool
25.  Mambo "Itemid" Parameter Cross-Site Scripting Vulnerability
26.  Mambo "Itemid" Parameter Cross-Site Scripting Vulnerability
27.  IBM Cloudscape Command Injection Vulnerability
28.  IBM Cloudscape Command Injection Vulnerability
29.  VMware ESX Server Privilege Escalation Vulnerabilities
30.  VMware ESX Server Privilege Escalation Vulnerabilities

8:17:57 AM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  Steve Jobs for Disney CEO?. One of the purged Disney board members working to secure theouster of Michael Eisner thinks that Steve Jobs should run their show.

Gold, who left Disney in December, told The New York Post: "There are five or six guys I believe can run this company. Steve Jobs would absolutely be one of them."

Gold confirmed that he hasn't approached Jobs, nor has Jobs asked him for the job.

Link

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
2.  Dusty brands make a rerun in TV market. Old-time appliance makers may have an edge in the scramble for the high-end TV market: strong brand-name recognition.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Pressure on PeopleSoft (SiliconValley.com). SiliconValley.com - With Oracle's move Wednesday to raise its hostile takeover offer, PeopleSoft's board faces a moment of truth: Either make a final stand against its rival or wave a white flag and negotiate a merger.
4.  PC software sales take a dive (USATODAY.com). USATODAY.com - Entertainment and educational software isn't exactly flying off store shelves. Declines in those categories contributed to a drop in overall PC software sales at retailers last year, according to figures released Thursday by The NPD Group, a marketing data provider. Retail software sales fell 4% to $3.7 billion in 2003, the sharpest plunge in four years. Units sold dropped nearly 10% to 102 million.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
5.  Nature of the internet makes cybercriminals hard to catch
6.  Common sense security
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  ATI licenses 'dynamic logic' tech for faster, cheaper chips. Intrinsity's Fast 14 yields 'four times the performance per silicon dollar'
8.  Phone makers to make major launches at CeBIT. But Peeping Toms could be fined or jailed
9.  Music industry raids KaZaA's Australia HQ. Telcos, Net firms, universities targeted too
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
10.  ASP authentication using XOR encryption
11.  FBI asks computer shops to help fight cybercrime
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  OMB: Cybersecurity first
13.  Pentagon schrapt stemmen via internet
14.  Linux gemeenschap boos over BBC artikel
15.  FBI wil dat computershops en consultants klikken
16.  ASP authenticatie via XOR encryptie
17.  Ervaren computergebruikers zijn beginners zat
18.  Gelaagde security aanpak voor bewaken netwerk integriteit
19.  ASP authentication using XOR encryption
20.  FBI asks computer shops to help fight cybercrime
21.  Patch für Microsoft Internet Explorer setzt Webseiten ausser Gefecht
22.  Manipulierte Archive können Virenscanner blockieren
23.  Sicherheits-Patches für RealPlayer gegen gefährliche Lücken
24.  BSD "shmat()" Privilege Escalation Vulnerability
25.  BSD "shmat()" Privilege Escalation Vulnerability
26.  Nature of the internet makes cybercriminals hard to catch
27.  Common sense security

7:17:37 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  DOJ studies Oracle-PeopleSoft (TheDeal.com). TheDeal.com - The final decision on whether to sue or let the deal proceed will be made by R. Hewitt Pate, the assistant attorney general for antitrust.
2.  Qualcomm Japan Eyes W-CDMA Chip Market Sweet Spot (Reuters). Reuters - Qualcomm Japan aims to carve out a significant share of Japan's market for W-CDMA chips, used in NTT DoCoMo Inc. and Vodafone Holdings Inc. mobile phones with high-speed Internet access, it said on Friday.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Fighting talk from EA and Marvel. Catch up with the latest news from the world of video gaming.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  Missing teen's Net meeting. Police following lead with caution
5.  Adobe brings grid to the mass market. For the little people
6.  Motorola phone launch makes play for high end and low. Pushes cameras, MP3 ringtone support
----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
7.  Stay Fat and Live Long. Extreme calorie restriction could help you live to be 120. But it also might make you cranky and cold, and diminish your libido. Luckily, researchers are one step closer to the gain without the pain. By Kristen Philipkoski.
8.  NASA Rover Rolls Around Mars. Opportunity takes a 10-foot trip as Spirit gets ready for a reboot. Meanwhile, NASA scientists puzzle over pictures of rounded pebbles and other intriguing data sent back from the red planet.
9.  Pentagon Gives E-Voting the Boot. The military scraps an Internet voting system designed for use by overseas soldiers and other U.S. citizens this fall over concerns about the system's security.
10.  Wi-Fi Enters the Space Race. If people do land on Mars, NASA wants to make sure they can get a decent wireless connection. By Daniel Terdiman.
11.  Getting in Bed With the Customer. After two years, Microsoft's home video game system has failed to make a splash in Japan -- maybe free 'love pillows' will be the answer. By Chris Kohler.
12.  Telling Lies in the Name of Art. In Charlie White's surreal world, photographs are just like the movies -- a creep show full of killer special effects. And nothing is as it seems. By Jenn Shreve from Wired magazine.
13.  Iran's Most Wanted: Filmmakers. With inexpensive digital cameras, underground filmmakers expose Iran's festering social ills. It's dangerous work. One of these haunting films could land its creator in prison for years. By Jason Silverman.
14.  Stop the Cash Flow, Kill the Spam. Although spammers are using ever-more-sophisticated methods to flood your inbox, tracking the miscreants down isn't all that complicated. Just follow the money. By Kari L. Dean.
15.  Great Taste, Less Privacy. More and more bars and restaurants scan patrons' driver's licenses, ostensibly to verify age. But the licenses contain lots of valuable information, and the temptation to use the data for marketing is hard to resist. By Kim Zetter.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
16.  Security lek in FreeBSD, NetBSD en OpenBSD
17.  MyDoom schadeclaim van 38,5 miljard dollar is absurd
18.  Verspreiden van virussen kan werknemers niets schelen
19.  Microsoft komt met MyDoom verwijder tool
20.  Cable modem hackers conquer the co-ax
21.  Protecting home computers - a site with bite
22.  Remote crash Xlight ftp server 1.52
23.  Conectiva update for libtool
24.  Conectiva update for libtool
25.  Debian update for gaim
26.  Debian update for gaim
27.  Oracle9i Database Multiple Buffer Overflow Vulnerabilities
28.  Oracle9i Database Multiple Buffer Overflow Vulnerabilities
29.  BSD shmat() Integer Overflow Lets Local Users Gain Elevated Privileges
30.  IBM Cloudscape Default Configuration Lets Remote Users Inject SQL Commands to Execute Arbitrary Binaries
31.  MS demos Jetsons' kitchen on FoodTV

6:17:16 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Sun Shows Off 3D Desktop (PC World). PC World - Project Looking Glass gives users 360 degrees of space.
2.  Free Agent: The View from LinuxWorld Expo (PC World). PC World - Why you're probably not on the radar of the major Linux vendors--yet.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Kazaa Offices Raided
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
4.  BSkyB finance chief Stewart quits. BSkyB loses its chief financial officer Martin Stewart just three months after James Murdoch took over the helm.
5.  Broadband prices to hold steady. The days of broadband bargains could be over, as a study shows prices are holding steady.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
6.  MS demos Jetsons' kitchen on FoodTV. An RFID paradise
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
7.  Cable modem hackers conquer the co-ax
8.  Protecting home computers - a site with bite
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
9.  XS4ALL: Overheidscampagne moet virusverspreiding tegengaan
10.  Dual curses: Viruses and spam
11.  MDKSA-2004:009 - Updated glibc packages fix resolver vulnerabilities
12.  Pentagon Gives E-Voting the Boot
13.  Popping Pills in Preschool
14.  RFID's Hidden Costs and Opportunities
15.  RealOne Player / RealPlayer Multiple Vulnerabilities

5:16:57 AM    

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 06 Feb 2004.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  New Laptop Is Tiny, IBM Boasts (TechWeb). TechWeb - The ThinkPad X40 is 20% smaller and 25% lighter than its predecessor.
3.  NEWS SNAP: Ericsson Reports Strong 4Q Earnings (Dow Jones). Dow Jones - STOCKHOLM -- Telefon AB LM Ericsson , the world's largest maker of wireless telecommunications equipment, Friday reported a swing to net profit in the fourth quarter on the back of escalating sales in Asia and the Americas.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
4.  Ericsson profits beat forecasts. The Swedish telecoms giant says the last three months of 2003 saw profits soar, and predicts a modestly healthy 2004.
5.  Pentagon e-voting plan scrapped. The US decides against an internet voting system for ex-pats after experts say the risk of fraud is too high.
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
6.  EU acts to improve protection of citizens with security research
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Re: getting rid of outbreaks and spam (junk) [WAS: Re: RFC: virus handling]
8.  Cosign: Secure, Intra-Institutional Web Authentication
9.  Campus Architectural Middleware Planning (CAMP) Meeting
10.  Three Vulnerabilities Discovered in Real Player
11.  RealPlayer flaws open PCs up to hijackers
12.  "Port Knocking" For Added Security
13.  PORTKNOCKING - A system for stealthy authentication across closed ports
14.  HowTo: Port Knocking
15.  Spyware Masquerading as Spyware Removal Software
16.  Spyware cures may cause more harm than good
17.  The Trouble with RFID
18.  The Trouble with RFID
19.  Pentagon Cancels Internet Voting System
20.  Pentagon Cancels Internet Voting System
21.  Congress Eyes Whois Crackdown
22.  Congress Eyes Internet Fraud Crackdown

4:16:47 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Janet Sparks Internet Breast-Feeding Frenzy (Reuters). Reuters - Janet Jackson's near-baring of her breast at the Super Bowl might be the most searched event in the history of the Internet.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  BKDR_FEARLESS.A
3.  BAT_DMENU.A
4.  Linux group releases enterprise guidelines
5.  Windows XP's big security fix
6.  Using a layered security approach to achieve network integrity
7.  OMB: cybersecurity first
8.  Pentagon scraps Net voting plan
9.  [CLA-2004:811] Conectiva Security Announcement - libtool
10.  [RHSA-2004:020-01] Updated mailman packages close cross-site scripting vulnerabilities
11.  OpenBSD IPv6 remote kernel crash
12.  Checkpoint 4.1 Vulnerability
13.  Re: X-Cart vulnerability
14.  Two checkpoint fw-1/vpn-1 vulns
15.  Re: Symlink Vulnerability in GNU libtool
16.  Five keys to success with identity management
17.  ISS warns of holes in Check Point firewall, VPN server
18.  .zip files putting the zap on antivirus products
19.  Pentagon drops Internet voting plans for military personnel

3:16:16 AM    

----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
1.  E-Mail at The Washington Post Disrupted by a Missed Payment. The Washington Post inadvertently allowed the registration for one of its Internet domain names to expire, and that lapse had the immediate effect of shutting down the e-mail system. By Jacques Steinberg.
2.  Big Investors Would Gain in a Change at Big Board. The New York Stock Exchange plans to open up electronic trading to institutional investors to a much greater extent than it ever has before. By Floyd Norris.
3.  Online Voting Canceled for Americans Overseas. Citing security concerns, the Department of Defense canceled plans to allow Americans overseas to cast votes over the Internet in this year's elections. By John Schwartz.
4.  A Portrait of a Neighborhood Is Now Just a Click Away. Under a new program, anyone who wants to tap into a wealth of housing (and other) information about any of New York City's neighborhoods can log on to a simple-to-use Web site, for free. By Dennis Hevesi.
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
5.  Linux group releases enterprise guidelines
6.  Windows XP's big security fix
7.  Using a layered security approach to achieve network integrity
8.  OMB: cybersecurity first
9.  Pentagon scraps Net voting plan
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  Checkpoint Firewall-1 HTTP Parsing Format String
11.  RE: Hacking USB Thumbdrives, Thumprint authentication
12.  Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow
13.  GNU Radius Remote Denial of Service
14.  Re: TYPSoft FTP Server 1.10 may be crashed
15.  Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47)

2:15:56 AM    

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  MyDoom reignites the rift between lusers and the tech-savvy. Technophiles are showing more anger towards those they believe are not making efforts to learn more about technology. By Fred "zAmboni" Locklear.
----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
2.  iTunes/Pepsi ad parody. This is a great parody (cum attack on the recording industry) of the iTunes/Pepsi ad that ran during the Superbowl.

Link

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Overseas Voting by Internet Is Canceled (washingtonpost.com). washingtonpost.com - The Pentagon has canceled plans to collect votes over the Internet from military personnel and civilians abroad for this fall's presidential election because of security concerns.
4.  Electronic Arts, Marvel Sign Game Development Deal (Reuters). Reuters - Video game publisher Electronic Arts Inc. on Thursday said it has signed a deal with comic book publisher Marvel Enterprises Inc. to develop a series of fighting games pitting newly developed EA characters against Marvel superheroes like Spider-Man.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Three Vulnerabilities Discovered in Real Player
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
6.  BugTraq: [CLA-2004:811] Conectiva Security Announcement - libtool. Sender: Conectiva Updates [secure at conectiva dot com dot br]
7.  BugTraq: OpenBSD IPv6 remote kernel crash. Sender: Thor Larholm [thor at pivx dot com]
8.  BugTraq: Checkpoint 4.1 Vulnerability. Sender: Macroscape Solutions [lists at macroscape dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
9.  ISS warns of holes in Check Point firewall, VPN server
10.  .zip files putting the zap on antivirus products
11.  Holy Cyber Alert! Severe Vulnerability In Checkpoint Firewalls

1:15:36 AM    

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Game.Ars and the rise of the console. Game.Ars returns with a look at a somewhat surprising story of 2003 — the ascendancy of console gaming By Eric Bangeman.
----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
2.  Worst ToS on the entire Internet. The Central Pacific Railroad Photographic History Museum has 21,000 words of legalese on its homepage, a disclaimer and terms-of-service document that is likely the very worst of its kind on the entire Internet. James Grimmelman shreds this thing, picking out the dumbest moments in a 21 kiloword extravanganza of dumbness:

[It] gives every sign of having been professionally drafted by a competent lawyer with severe OCD. It's not quite that any individual term is clearly insane as that the redundancy makes the whole much less than the sum of its parts. We've been cracking each other up by reading selections aloud. Some highlights inside:

"All other access, use, disclosure, reproduction, delayed use, reduction to human-perceivable form, printing, copying or saving of digital image files or other content, reformatting, file sharing, downloading, uploading, storing, posting, mirroring, archiving, recording, distributing, redistribution, repurposing, modification, rewriting, manipulation, creation of derivative works, translations, or products, licensing, sale, transfer, display, public performance, publicity, broadcast, televising, reporting, publication (in whole or part) or transmission whether by http, ftp, electronic mail or any other file transfer protocol, and whether by electronic means or otherwise, or use by other than individual scholars, or commercial use requires prior written permission of the rights owner(s) and payment of a fee, and severe penalties apply for theft and unauthorized publication, which is also a crime."

Link

(Thanks, James!)

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
3.  SCO adds copyright claim to IBM suit. The company significantly widens its Unix and Linux lawsuit against IBM, adding a copyright infringement claim to the already complicated case, sources say.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Pentagon Dumps Vulnerable Internet Voting System (Reuters). Reuters - The Pentagon said on Thursday it had scrapped its program to allow U.S. troops and other Americans overseas to vote through the Internet because the system was so vulnerable to computer hackers it could cast doubt on the integrity of U.S. election results.
5.  Microsoft Site Weathers MyDoom Attack (Reuters). Reuters - Microsoft Corp.'s (MSFT.O) Web site remained online on Tuesday despite a pre-planned attack by a MyDoom worm variant, which had not spread as widely as the first version that infected hundreds of thousands of computers worldwide.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  Palm Changing OS Strategy
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Re: MS to stop allowing passwords in URLs
8.  Re: Hysterical first technical alert from US-CERT
9.  MyDoom Reward Posted by SCO
10.  RealNetworks Patches Security Holes
11.  TROJ_KREPPER.I

12:15:16 AM