Sunday, February 15, 2004

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Sharing Savings and Risk (washingtonpost.com). washingtonpost.com - When the Education Department two years ago decided to abandon an obsolete network and begin trading student loan information with universities over the Internet, it lacked something essential: money. But the agency managed to persuade Accenture Ltd., the global consulting firm, to tackle the project anyway.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  More on MS04-007
3.  Gigabyte arrested, charged with "computer data sabotage"
4.  Zero-Day Exploit of CHM Vulnerability in IE

11:08:28 PM    

----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
1.  Customize this feed. Add more items, descriptions, time stamps, select your version of RSS, aggregate several feeds... Check out NewsIsFree's premium syndication services! (08)
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  hatchet-0.6.1.tar.gz
3.  tcpick-0.1.20.tar.gz
4.  ADMsmb_0.3.tar.gz
5.  motion-3.0.7-1.tar.g..>
6.  uniqueid-0.5.0.tar.g..>
7.  smbmountDoS.txt
8.  waraxe-2004-SA#001.t..>
9.  TA04-033A.txt
----------------------------------------------------------------------
About Internet/Network Security
----------------------------------------------------------------------
10.  Zero-Day Exploit of CHM Vulnerability in IE. An exploit has been discovered for a previously unknown flaw in Internet Explorer which can allow an attacker to execute malicious code on the vulnerable system. As you surf the web be very careful about the sites you visit. Also...

10:08:07 PM    


9:07:48 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  IBM offers PowerPC 970FX chip manufacturing details (MacCentral). MacCentral - Semiconductor manufacturer IBM on Friday provided details about its manufacturing of PowerPC 970FX microprocessors. This is the same processor used in Apple's Xserve G5, announced last month at Macworld Expo San Francisco.
2.  Report: Vodafone Bids for AT&T Wireless (AP). AP - Vodafone Group PLC has bid about $35 billion for AT&T Wireless Services Inc., leaving the contest for the nation's third-largest mobile phone carrier a bidding war with Cingular Wireless, The Wall Street Journal reported Sunday on its Web site.
3.  Apple's iPod Mini Is a Big Deal in the MP3 World (washingtonpost.com). washingtonpost.com - Finally, somebody has outdone the iPod. After years of unsuccessful attempts by Creative, Dell, Rio, Samsung and others to knock Apple's MP3 player off its pedestal, we've got a player that makes the iPod seem like the oversize, clunky relic it (now) is.
4.  Sony Aims for 40-50 Percent Rise in Digicam Sales (Reuters). Reuters - Electronics conglomerate Sony Corp said on Monday that it planned to boost digital camera sales by 40 to 50 percent next year in unit terms, adding to an expected glut of supply in the market.
5.  Texas Instruments Sees Phone-On-Chip by Year's End (Reuters). Reuters - Texas Instruments Inc. (TXN.N), the world's largest maker of cell phone chips, on Monday said it will unveil digital radio technology it says will allow it to combine multiple cellular phone functions into one digital chip by the end of this year.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  Still More on the DARPA Grand Challenge
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Big Tech Guns Collaborate on Security
8.  Big Tech Guns Collaborate on Security
9.  Linux v2.6 Scales the Enterprise
10.  The Big Leak: Windows Source Code on Net
11.  Big Tech Guns Collaborate on Security
12.  MyDoom Takes Last Gasp, Offspring Live On
13.  Linux Security on the Ropes?
14.  Product Review: Linux v2.6
15.  The Big Leak: Windows Code
16.  Big I.T. Guns Join on Security

8:07:32 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  MeFi, Megnut and Whole Lotta Nothing status. MeFi, Megnut and A Whole Lotta Nothing have been offline for a couple days. Here's why:

People have been asking (not really), so I thought I'd let you know that MetaFilter, Megnut, and A Whole Lotta Nothing are down because of a bad computer fan. No ETA as of yet on when the box will be back up. Matt Haughey was unavailable for comment due to laziness on my part, but if he were available, he'd probably say something like, "you tell those ungrateful bastards that I'll order that new fan when I'm damn good and ready."

Link

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Cyberchondria
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  Europe to revoke Rambus memory patent. Memory maker awaits FTC fraudruling

7:37:17 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  Freud/Jung slash. Short (but high-larious) Sigmund Freud/Carl Jung slash fiction:

'I had a dream last night, Siggy.'

'Ja?'

'It was you and me together skipping in a field. Und then this great serpent appeared and slithered into a cave.'

'Du lieber gott! Do you know what you are saying to me? Do you know what zis serpent means?'

'Ja, it is some manifestation of the World-Spirit.'

NSFW Link

(Thanks, Quinn!)

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Report: Vodafone Bids for AT&T Wireless (AP). AP - Vodafone Group PLC has bid about $35 billion for AT&T Wireless Services Inc., leaving the contest for the nation's third-largest mobile phone carrier a bidding war with Cingular Wireless, The Wall Street Journal reported Sunday on its Web site.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  Sun starts Solaris 10 salutations. Able to leap Linux
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  crobFTP351.txt
5.  SCSA027.txt
6.  overkill.txt
7.  ZH2004-03SA.txt

6:36:58 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Vodafone Makes Bid for AT&T Wireless (Dow Jones). Dow Jones - Vodafone Group PLC (NYSE:VOD - News) , the world's largest wireless carrier by revenue, has made a bid of about $35 billion for AT&T Wireless Services Inc. (NYSE:AWE - News) , people close to the situation said, roughly matching the bid made Friday by Cingular Wireless. As the bids submitted are similar, AT&T Wireless's advisers asked the companies to hand in a second round of offers on Sunday, turning the contest to buy the third-largest U.S. wireless carrier into a global bidding war.
2.  AMD Turning the Heat Up on Rivalry with Intel (Reuters). Reuters - Advanced Micro Devices Inc. (AMD.N) is preparing to shake off its reputation as a seller of less-expensive clones of Intel computer chips with a re-energized marketing campaign and a new pricing structure that takes the emphasis off rock-bottom price tags.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Linux in Munich Followup
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
4.  Vulnerabilities: Crob FTP Server Remote Denial Of Service Vulnerability. Crob FTP server is a commercially available file transfer utility developed for the Windows platform.

It has been reported that the Crob FTP server is prone to a remote ...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  The case of the malicious critic (June 21, 1999)
6.  The State of Electronic Voting in Georgia
7.  Critics punch at touch-screen voting security

5:36:37 PM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Migrating Device Drivers to the 2.6 Kernel
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
2.  I just discovered the Camino community center.
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
3.  Vulnerabilities: AIM Sniff Temporary File Symlink Attack Vulnerability. AIM Sniff is a network reconnaissance tool that is used to specifically target AIM traffic.

AIM Sniff has been reported prone to a Symbolic link vulnerability. The issue...

4.  Vulnerabilities: Mailmgr Insecure Temporary File Creation Vulnerabilities. Mailmgr is an application for analyzing Sendmail logs and generating reports in HTML. It is available for Unix/Linux variants.

Mailmgr is reportedly to be prone to a vu...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Big I.T. Guns Collaborate on Security
6.  The Big Leak: Windows Code on Net
7.  Big I.T. Guns Collaborate on Security
8.  The Big Leak: Windows Code on Net
9.  Big I.T. Guns Collaborate on Security

4:36:18 PM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  The State of Electronic Voting in Georgia

3:35:59 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  Freud/Nietzsche slash. Short (but high-larious) Sigmund Freud/Friedrich Nietzsche slash fiction:

'I had a dream last night, Siggy.'

'Ja?'

'It was you and me together skipping in a field. Und then this great serpent appeared and slithered into a cave.'

'Du lieber gott! Do you know what you are saying to me? Do you know what zis serpent means?'

'Ja, it is some manifestation of the World-Spirit.'

NSFW Link

(Thanks, Quinn!)

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  A Power Users Look at Linux on the Mac
3.  GameSpot Recaps 25-Year History of SNK
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
4.  Vulnerabilities: SandSurfer Unspecified User Authentication Vulnerability. SandSurfer is a web-based time keeping application. It is available for Unix/Linux variants.

An unspecified vulnerability related to user authentication was reported in...

5.  Vulnerabilities: Sophos Anti-Virus MIME Header Handling Denial Of Service Vulnerability. Sophos Anti-Virus is multi platform computer virus detection software.

Sophos Anti-Virus has been reported prone to a remote denial of service vulnerability. The issue p...

6.  Vulnerabilities: Sophos Anti-Virus Delivery Status Notification Handling Scanner Bypass Vulnerability. Sophos Anti-Virus is multi platform computer virus detection software.

Sophos Anti-Virus has been reported prone to a scanner bypass vulnerability. The issue presents it...

7.  Vulnerabilities: PHPNuke Category Parameter SQL Injection Vulnerability. PHPNuke is a freely available, open source web content management system. It is maintained by Francisco Burzi, and available for the Unix, Linux, and Microsoft Operating ...
8.  Vulnerabilities: Netpbm Temporary File Vulnerabilities. Netpbm is a collection of utilities for the manipulation of graphic images.

Debian has announced that Netpbm is affected by numerous vulnerabilities related to its use o...


2:35:38 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Experts Warn of Microsoft 'Monoculture' (AP). AP - Dan Geer lost his job, but gained his audience. The very idea that got the computer security expert fired has sparked serious debate in information technology. The idea, borrowed from biology, is that Microsoft Corp. has nurtured a software "monoculture" that threatens global computer security.
2.  Commercial Software Aided Reboot on Mars (AP). AP - It's a PC user's nightmare: You're almost done with a lengthy e-mail, or about to finish a report at the office, and the computer crashes for no apparent reason. It tries to restart but never quite finishes booting. Then it crashes again. And again.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Cell-Phone Wars
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
4.  Vulnerabilities: slocate Local Buffer Overrun Vulnerability. Secure Locate (slocate) provides a secure way to index and quickly search for files on your system. It is available for the Linux and Unix operating systems. Typically sl...
5.  Vulnerabilities: OpenSSL ASN.1 Parsing Vulnerabilities. Multiple vulnerabilities were reported in the ASN.1 parsing code in OpenSSL. OpenSSL does not directly implement ASN.1 but does use ASN.1 objects in X.509 certificates a...
6.  Vulnerabilities: JelSoft VBulletin Cross-Site Scripting Vulnerability. VBulletin is a commercially available web based bulletin board application. It is implemented in PHP and may be run on Unix and Unix like operating systems as well as Wi...

1:35:19 PM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  James Joyce's descendants are copyright jerks. James Joyce's terrible descendants have decided to use the newly extended Euro copyright to bully anyone who publicly reads his work, in Ireland, on Bloomsday, into silence.

Christ, this makes me angry enough to spit. Note to my literary executor: if you ever dream of doing anything like this after I die, I'll come back from the dead and reach out of the toilet and unspool your guts while dragging you down to hell. Sheesh.

..[T]he Joyce estate has informed the Irish government that it intends to sue for copyright infringement if there are any public readings of Joyce's works during the festival commemorating the 100th anniversary of Bloomsday this June.

James Joyce died in 1941 and the copyright in his work expired in 1991. Then the EU extended terms to life+70 years, and the work went back into copyright in July 1995. The estate has been very active in enforcing their copyright, suing regularly.

Link

(via Lessig)

2.  Earn $25 for each junk fax you send in.. The Demirali Law Firm says it will pay you $25 for each junk fax you send it (if a collection is made). You need to send in at least ten faxes at a time.Consumer rights advocate Tom Martino is behind this. Link i>(Thanks, Travis!)
----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
3.  Many New Causes for Old Problem of Jobs Lost Abroad. Globalization and technology are amplifying the impact of outsourcing, ranging from call center operators to computer programmers. By Steve Lohr.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Portable Phone Numbers = Market for Cool Numbers
5.  IBM Wants to Port Office to Linux
6.  WB Cancels Angel
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
7.  Vulnerabilities: Macallan Mail Solution Web Interface Authentication Bypass Vulnerability. Macallan Mail Solution is a mail server for Microsoft Windows operating systems.

A vulnerability has been reported in Macallan Mail Solution that may permit remote attac...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  New Computer Security Incident Handling Guide from NIST.gov

12:34:58 PM    

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  IBM to bring MS Office to... Linux?. IBM has plans to bring Microsoft Office to the Linux desktop. current indicators are that this may possibly be done via work from Codeweavers, Wine, and efforts from IBM to utilize "code provided by Microsoft to make it happen." By Matt Woodward.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Sony aims to boost digital camera sales by 50 percent (AFP). AFP - Japanese technology giant Sony is aiming to boost its digital camera sales by 50 percent year-on-year to 15 million units worldwide in the next financial year starting in April 2004, a report said.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  AT&T Wireless considering offers. Third-largest US phone operator, AT&T Wireless, could reveal as early as Tuesday who is the successful bidder for the firm.
4.  Concerns over US computer voting. Two leading US experts on computer voting warn that the forthcoming presidential election could be more chaotic than the last.
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
5.  Vulnerabilities: SLocate User-Supplied Database Heap Overflow Vulnerability. slocate is the Secure Locate program. It is available for various UNIX and Linux operating systems, and is maintained by public domain.

It has been reported that a vulne...


11:34:39 AM    

----------------------------------------------------------------------
Boing Boing Blog
----------------------------------------------------------------------
1.  IRC log from Trippi's talk at ETCON. Kevin Burton kept a running transcript of Joe Trippi's talk at the ETCON Emergent Democracy event, pasting it into IRC as he went. He's posted the IRC log, which includes Kevin's transcription and the peanut gallery's responses (Burtonator tells us not to mind the typos: "The Internet is not a system for testing spell-checkers")

amazed that the press frankly can't figure out what the dean campaign WAS
WHY DIDN'T YOU LET US HAVE THE CONTACT INFO FOR LOCAL DEAN SUPPORTERS EARLIER?
not it's defining if it's a SUCCESS but still doesn't konw what it was
the sound of typing everywhere....
it's a mistake to buy the spin from broadcast media
broadcast politics has failed us miserably
no debate about the war

Link

(Thanks, Kevin!)

2.  Firsthand account of the gay marriage rush at San Fran city hall. My colleague Seth Schoen took a walk yesterday down to the San Francisco city hall and watched the hundreds of lesbian and gay couple in various states of marriage. His first-person account is touching and sent a shiver up my spine.

We walked around the side of the line and saw hundreds of same-sex couples in all states of dress (punk to tuxedo to family heirloom dress to just-off-the-street-in-work-attire). One couple wore yarmulkes and carried a siddur; another couple looked like ordained ministers, but I didn't know for sure of which Christian denomination. (It must be one willing to ordain gay women.) At the back of City Hall, the line was making its way through the door past a group of about half a dozen well-wishers with big pink signs. They looked like high school students. One of them was carrying an American flag with gay rights symbols in place of the stars. (Oddly enough, San Francisco regular Frank Chu was demonstrating too, with his usual sign that had nothing to do with same-sex marriage -- instead about galaxies, a rocket society, and impeaching former U.S. presidents. I was pretty sure he was just trying to get on TV with his message. You see him frequently in the Financial District.)...

Zack and I applauded for the couples as they were married, and shook hands with them. The couples were as diverse in age as they were in dress: I saw a pair of women get married and was sure they were younger than I am. And I saw and was most touched by several weddings of people who had likely been waiting even longer than 18 years. Two women of my mother's age, or a little older, were married right in front of me, and they started to cry. I almost started to cry, too.

Link

3.  Disney takeover photoshopping contest.

Nice: a Fark photoshopping contest whose theme is "Would-be takeover attempts of the Walt Disney Company."

Link

(Thanks, Mark!)


----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Apple's iPod Mini Is a Big Deal in the MP3 World (washingtonpost.com). washingtonpost.com - Finally, somebody has outdone the iPod. After years of unsuccessful attempts by Creative, Dell, Rio, Samsung and others to knock Apple's MP3 player off its pedestal, we've got a player that makes the iPod seem like the oversize, clunky relic it (now) is.
5.  Programs: Nancy Drew Finds Danger in Whale Tale (Reuters). Reuters - "Nancy Drew: Danger on Deception Island," the $20 Windows game from Her Interactive, begins with an act of vandalism, but evolves into something much more interesting.
6.  Bluetooth Wireless Resurrected with New Gadgets (Reuters). Reuters - Bluetooth wireless, considered tech roadkill just a few years ago, has been resurrected by the release of a slew of gadgets and widespread industry support.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  FBI on the Windows Source Code Theft

10:34:18 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  India Woos Medical Tourists

9:33:58 AM    


8:33:37 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Live Windows Bootable CDs for Sysadmins
2.  DVDCCA Claims Patent on CSS

7:33:18 AM    


6:32:58 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  FTC Warns of No-Spam Registry (washingtonpost.com). washingtonpost.com - The Federal Trade Commission is warning people not to fall for a Web site claiming to offer an e-mail version of the federal do-not-call registry. The "Do Not Email Registry" invites folks to submit their e-mail addresses to stop getting junk e-mail. Trouble is, the site has no affiliation with the government, despite what its Web address (www.unsub.us) might suggest.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  W32.Welchia.C.Worm

5:32:38 AM    

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 15 Feb 2004.

4:32:17 AM    

----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
1.  It looks like Helix Community dumped CollabNet. I wonder why. I also see that they figured out how to do CVS+SSH the right way instead of with port-forwarding kludges.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
2.  Workplace data theft runs rampant. Many staff are happy to steal key information from the firms they work for, a study has found.

3:31:58 AM    

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
1.  Amazon.com Pierces Reviewer Anonymity
2.  Amazon Glitch Unmasks War of Reviewers
3.  Paper: Glitch identifies Amazon reviewers

2:31:39 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  An Interview with Jeff Waugh
----------------------------------------------------------------------
SecurityNewsPortal.com HomelandSecurity.com
----------------------------------------------------------------------
2.  Belgium police arrest famous female virus writer Gigabyte. Faces 3 years in prison and $127,000 fine

1:31:17 AM    

----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
1.  Vulnerabilities: MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability. MIT cgiemail is designed to take the input of web forms and convert it to an e-mail format defined by the author of the form. It was written for use on UNIX and Linux var...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  News: Belgium police arrest female virus-writer

12:26:47 AM