Sunday, February 29, 2004

----------------------------------------------------------------------
CNET News.com - Front Door
----------------------------------------------------------------------
1.  Microsoft enlists developers in security push. To encourage use of the security features in Windows XP SP2, the company is planning service packs for its core developer products--Visual Studio.Net and the .Net Framework--for release around the middle of the year.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Thief 3 Website Goes Live
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  1 Mar W32/Bagle-F

9:32:14 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Sprint to Combine Tracking Shares (Reuters). Reuters - Sprint Corp., said on Sunday it would combine its wireless and wireline tracking shares and return to a single stock in April, making it easier for the No. 4 U.S. long-distance telephone company to buy a rival while protecting its wireless unit from unwanted takeover bids.
2.  Eclectic Crowd Ponders Bliss at California Meeting (Reuters). Reuters - When it comes to the pursuit of happiness, everyone, it turns out, has an opinion.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  TV Set Doubles as a Mirror
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
4.  Vulnerabilities: Symantec Gateway Security Error Page Cross-Site Scripting Vulnerability. A vulnerability has been reported to exist in the Symantec Gateway Security Management Service object that may allow a remote user to launch cross-site scripting attacks....
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Ban on DVD-cracking tool overturned

8:31:54 PM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Sprint to Combine Tracking Shares (Reuters). Reuters - Sprint Corp., said on Sunday it would combine its wireless and wireline tracking stocks and return to a single stock in April, making it easier for the No. 4 U.S. long-distance telephone company to buy a rival while protecting its wireless unit from unwanted takeover bids.
2.  Norwegian lilliput software company takes on Microsoft giant (AFP). AFP - Perhaps hoping for a modern remake of David's victory over Goliath, Opera Software of Norway has taken on none other than mighty Microsoft as it attempts to get a hold on the emerging mobile phone Internet browser market.
3.  Study: Blogging Still Infrequent (AP). AP - Despite the potential of turning every Internet user into a publisher, relatively few have created Web journals called blogs and even fewer do so with regularly, a new study finds.
4.  Google Founders Keep 'Top 100' List of New Ideas (Reuters). Reuters - Google Inc., which provides lists of Web search results for users around the world, relies on its own brainstorming list to keep innovation at the top of the firm's agenda, Google's co-founders said.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  XFree86 4.4 Released
6.  Evoting in India, Maryland
7.  World's Smallest Homebrew RC Unit
8.  DIY HVAC
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
9.  Vulnerabilities: Linux Kernel NCPFS ncp_lookup() Unspecified Local Privilege Escalation Vulnerability. NCPFS is a suite of programs that allow users to access a Novell server. NetWare servers can be mounted under Linux by NCPFS and functionality to print with NetWare prin...
10.  Vulnerabilities: Apache mod_python Module Malformed Query Denial of Service Vulnerability. Apache's mod_python is a module which allows the web server to interpret Python scripts. mod_python supports Apache 1.3.x and 2.x, and is available for Windows, Linux and...
11.  Vulnerabilities: Libxml2 Remote URI Parsing Buffer Overrun Vulnerability. Libxml2 is an XML parser and toolkit that is implemented in C.

A remotely exploitable buffer overrun vulnerability has been reported in Libxml2. This issue is due to in...

12.  Vulnerabilities: Hylafax HFaxD Unspecified Format String Vulnerability. Hylafax is a software package designed to handle the transmission of Faxes.

Hylafax hfaxd (daemon) has been reported prone to an unspecified format string vulnerability ...

13.  Vulnerabilities: eXtremail Authentication Bypass Vulnerability. eXtremail is a mail server developed for Unix platforms.

eXtremail has been reported prone to an authentication bypass vulnerability. The issue will only present itself ...

14.  Vulnerabilities: PerfectNav Malformed URI Denial Of Service Vulnerability. PerfectNav is an adware plug-in for Internet Explorer; it is designed to redirect unresolved URI's to the PerfectNav web page.

PerfectNav has been reported prone to a de...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
15.  South Korea mulls spam curfew. Cunning plan
16.  IT contracting: don't get carried away. UK upswing anomaly?
17.  VeriSign calls ICANN bluff in world's biggest game of poker. Registrar slams strong hand on table, leans back
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  WORM_NETSKY.GEN
19.  WORM_BAGLE.F
20.  ISS ürünlerinde kritik güvenlik açýðý

7:20:02 PM    

----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
1.  Vulnerabilities: CVS Daemon RCS Off By One Local Buffer Overflow Vulnerability. CVS is the concurrent versioning system. CVS is a freely available, open source software development package for the Unix, Linux, and Microsoft Windows platforms.

A pro...

2.  Vulnerabilities: CVS Malformed Request System Root File Creation Vulnerability. CVS is the Concurrent Versions System, which is a freely available open-source version management package. It is available for the Unix and Linux operating systems.

A v...

3.  Vulnerabilities: Ethereal Q.931 Protocol Dissector Denial of Service Vulnerability. Ethereal Q.931 protocol dissector is prone to remotely exploitable denial of service vulnerability. This issue has been addressed with the release of Ethereal 0.10.0. ..
4.  Vulnerabilities: TCPDump ISAKMP Decoding Routines Multiple Remote Buffer Overflow Vulnerabilities. tcpdump is a freely available open source network monitoring tool. It is available for the Unix, Linux, and Microsoft Windows operating systems.

Multiple buffer overflo...

5.  Vulnerabilities: TCPDump ISAKMP Decoding Routines Denial Of Service Vulnerability. tcpdump is a freely available, open source network monitoring tool. It is available for the Unix, Linux, and Microsoft Windows operating systems.

A vulnerability has be...

6.  Vulnerabilities: TCPDump Malformed RADIUS Packet Denial Of Service Vulnerability. tcpdump is a freely available, open source network monitoring tool. It is available for the Unix, Linux, and Microsoft Windows operating systems.

A vulnerability in the ...


6:19:49 PM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Roomba + Tablet PC = ?
2.  RSS Web-Feeds, The Next Big Thing?
3.  MIT Professor Michael Hawley
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
4.  Vulnerabilities: Qualiteam X-Cart Remote Command Execution Vulnerability. X-Cart is a web based shopping card application implemented in PHP and integrated with a MySQL database backend.

X-Cart has been reported to be prone to an issue that ma...


2:36:48 PM    

----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
1.  Vulnerabilities: MTools MFormat Privilege Escalation Vulnerability. Mtools are a collection of tools designed to allow users to access MS-DOS formatted discs from Linux operating systems. MFormat is a utility designed to enable the addit...
2.  Vulnerabilities: CalaCode @mail Webmail System Cross-Site Scripting Vulnerability. @mail Webmail System is a web based e-mail software package. It can be installed with a SQL database or flat files.

A cross-site scripting vulnerability has been identif...

3.  Vulnerabilities: CalaCode @mail Webmail System POP3 Remote Denial of Service Vulnerability. @mail webmail system is a web based e-mail software package. It can be installed with a SQL database or flat files.

@mail webmail system has been reported to be prone t...

4.  Vulnerabilities: Dell OpenManage Web Server POST Request Heap Overflow Vulnerability. Dell OpenManage Web Server is a service used to aid remote system management.

Dell OpenManage Web Server has been reported prone to a remote heap overflow vulnerability....


1:36:27 PM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Saturn Rings But No Spokes

12:36:07 PM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  WebTV 911 Hacker... Cyber Terrorist?
----------------------------------------------------------------------
SecurityFocus Vulnerabilities
----------------------------------------------------------------------
2.  Vulnerabilities: Multiple Oracle Database Parameter/Statement Buffer Overflow Vulnerabilities. Oracle is a commercial database product, which is available for a number of platforms including Microsoft Windows and Unix and Linux variants.

Oracle database has been ...

3.  Vulnerabilities: Linux Kernel Vicam USB Driver Userspace/Kernel Memory Copying Weakness. It has been reported that the Vicam USB driver does not access userspace memory in a safe manner. The source of the problem is that the copy_from_user function is not us...
4.  Vulnerabilities: Linux Kernel R128 Device Driver Unspecified Privilege Escalation Vulnerability. The Linux Kernel supports numerous driver modules; one such is the R128 ATI Rage 128 bit video card driver module.

It has been reported that the Linux Kernel is prone to...

5.  Vulnerabilities: Linux Kernel 32 Bit Ptrace Emulation Full Kernel Rights Vulnerability. Unix and Unix-like kernels offer a debugging facility called ptrace. Ptrace allows for one process to 'attach' to another and inspect/modify it's memory. Updating certain...

11:35:47 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  The Virus Squad
2.  Star Wars Episode III Spoiler Photos
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  Faille critique sur différentes versions de WinZip (8.x & 9.x)

10:35:27 AM    


9:35:08 AM    

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Google Prospects Party Like It's 1999 (Reuters). Reuters - For the starry-eyed computer engineers who attended a flashy Google recruitment party outside Los Angeles on Thursday night, it was as though the Internet bubble never burst.
2.  PluggedIn: Technology Lets Garage Studios Challenge Hollywood (Reuters). Reuters - Home movie makers, take heart. You may be able to take on Hollywood.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  HDTV On Your PC - ATi's HDTV Wonder

8:34:49 AM    


7:34:27 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Build Your Own iPod Battery

6:34:07 AM    

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  Breathe new life into dial-up. While more people are switching to broadband, many still rely on dial-up modems to go online.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Ballmer haalt uit naar dure Linux

5:33:47 AM    

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 29 Feb 2004.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Audit Finds Problems with ISS Management
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  Invision Power Board Input Validation Holes in 'showuser' and Others Lets Remote Users Conduct Cross-Site Scripting Attacks

4:33:29 AM    

----------------------------------------------------------------------
Digital Identity World
----------------------------------------------------------------------
1.  Financial Services Discover Identity
2.  Biometrics and Financial Services -- Show me the money!
3.  When the walls come tumbling down
4.  The Digital ID World Newsletter - January 7, 2004 Issue
5.  The Digital ID World Newsletter - January 22, 2004 Issue
6.  The Digital ID World Newsletter - January 29, 2004 Issue
7.  The Digital ID World Newsletter - February 5, 2004 Issue
8.  Identinet - A Runaway Cluetrain
9.  XDI: Weaving the "Dataweb"
10.  The Great Enabler

3:33:08 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Vint Cerf's Disruption-Tolerant Networking
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Criminal Editing of the Enemy

2:32:47 AM    

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
1.  WORM_AGOBOT.DQ

1:32:28 AM    

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Xbox 2 SDK Released On Mac G5?
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  WFTPD Memory Allocation Flaw Lets Remote Authenticated Users Deny Service

12:21:07 AM