Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Monday, May 10, 2004
 

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Ars Technica review: HP Compaq nc6000 laptop. This is a good time to be shopping for an Pentium M laptop. We continue our series of Pentium M reviews with the Compaq nc6000. By Eric Bangeman.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Japanese Cell Phones Offer a Glimpse of the Future
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh
4.  RE: a litle bypass with IE
5.  [Ulf Harnhammar]: LHA Advisory + Patch
6.  DEEP SEA PHISHING: Internet Explorer / Outlook Express
7.  Microsoft virus bounty leads to Sasser arrest
8.  Sasser, Phatbot arrests coordinated, but not linked
9.  Experts: Timing of new Sasser worm raises questions
10.  FreeBSD Union File System Local DoS
11.  FreeBSD gdc Local Overflow
12.  FreeBSD asmon Configuration File Privilege Elevation
13.  FreeBSD ascpu Configuration File Privilege Elevation
14.  FreeBSD man Privilege Escalation
15.  FreeBSD gdc Symlink Modify Arbitrary File
16.  FreeBSD seyon PATH Privilege Escalation

11:24:55 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Gateway Files Patent Suit Against H-P (AP). AP - Gateway Inc. said Monday that it filed a patent infringement lawsuit against Hewlett-Packard Co., alleging that the computer hardware and software company violated five of its patents.
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
2.  Sony VAIO Type X. I don't know why, but I need one.
3.  In a rare bit of good luck, Intel's new 90nm "Dothan" Pentium M is faster and cooler than its "Banias" predecessor. The model numbers are bound to be confusing, though. (Quick, what's the difference between an Opteron 848 and a Pentium M 755?)
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  New Sasser Worm FTP exploit and Java DOS

10:24:36 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Networking industry hopes worst is behind. After a three-year downturn, organizers of the industry tradeshow Networld + Interop are pinning recovery hopes on the maturity of new technologies like VoIP and wireless LANs.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  IBM Unveils Workplace Client Technology (PC World). PC World - Company hopes server-based software platform will compete with Microsoft Office.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Microsoft Backs Out Of Wi-Fi Equipment Market
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
4.  Now that more and more books are on the Web, it would be interesting for a site like isbn.nu to link to them.
5.  Dominic Giampaolo put his book Practical File System Design with the Be File System on the Web since it's out of print. This is one of those books that if you need it, you need it bad.
6.  In other news, the QEmu x86/PowerPC/ARM emulator has been making good progress lately and Valgrind now supports PowerPC.
7.  PearPC is an open source PowerPC emulator that looks like it can even boot OS X.
8.  Byte and Swtich: Broadcom Broadens Storage Play. TCP, iSCSI, and RDMA offload for $35? I wonder what the performance will be like.
9.  Man, the Internet Archive is doing all kinds of cool stuff lately: The Petabox is a machine designed to safely store and process one petabyte of information. (If you have a hard time imagining what to do with 1PB of storage, consider the Google Operating System.)
10.  FreeCache is a system of cooperating caches to move large files of free content closer to users (but you can just call it the poor man's Akamai). Like Coral but unlike BitTorrent or OCN it requires no client software.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  W32.Cycle
12.  WORM_SDBOT.L
13.  New Sasser Worm FTP exploit and Java DOS
14.  Sun, SAP Spice Up Alliance With Grid Tech
15.  Author leaves warning in latest Sasser worm
16.  Can Microsoft's virus bounty fight organised crime?
17.  Can Microsoft bounty end viruses?
18.  Phishing spreads in Europe
19.  Security threats raise concerns about Bluetooth
20.  HP debuts RFID services
21.  Experts: timing of new Sasser worm raises questions
22.  DMCA challenge to be considered this week

9:24:16 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Microsoft: Separate trail led to second virus writer. The suspected author of the Agobot program was arrested by German police the same day they nabbed the alleged writer of the Sasser worm. Microsoft says "two different paths led to two different cases."
2.  Kerry leads fund-raising race--on Amazon. The Massachusetts senator, down 3-1 in overall fund-raising for the November race against President Bush, is far ahead on Amazon.com's presidential campaign donation page.
3.  Congressional panel to weigh digital copyright. The harsh penalties for circumventing copyright protection technology could eventually be replaced with a fair-use-friendly "Digital Media Consumers' Rights Act."
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Intel Launches Three Laptop Processors (AP). AP - Intel Corp. launched three new microprocessors for laptop computers Monday as the chip-making giant widened its mobile technology marketing blitz to include consumers as well as businesses.
5.  REVIEW: CSI Returns to Computer Screen (AP). AP - CBS has done well turning the crime lab into popular entertainment. "CSI: Crime Scene Investigation" was first, then came "CSI: Miami." On the heels of last year's "CSI" video game comes another franchise spinoff for home computers: "CSI: Dark Motives."
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  More On The BBC's Codec 'Dirac'
7.  G4TechTV Announced
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
8.  Google unveils new version of Blogger. Google on Monday rolled out an updated version of its Blogger online self-publishing service. The new version features an enhanced dashboard, the ability to post blogs via e-mail, a shared comments function, and author profiles.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
9.  Experts: Timing of new Sasser worm raises questions. BOSTON - The release of a new version of the Sasser worm calls into question claims by some German authorities that they have the sole author of the worm in custody, according to antivirus experts.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  Re: a litle bypass with IE
11.  Emule 0.42e Remote Denial Of Service Exploit
12.  Microsoft virus bounty leads to Sasser arrest
13.  News: 'Sasser' creator launched damage-limiting version before arrest
14.  Sasser, Phatbot arrests coordinated, but not linked
15.  Phatbot Author Arrested In Germany
16.  Evoting in the News
17.  FBI Investigates Open Records Request
18.  FBI investigates underground tunnel requests
19.  The Face Detector
20.  Facing facts in computer recognition
21.  Welcome to the RI Face Detection Algorithm Demo
22.  Second German Teen Arrested After Sasser Author
23.  Sasser Lives On Despite Author's Arrest
24.  Sasser Lives On Despite Author's Arrest
25.  Sasser Lives On Despite Author's Arrest
26.  Sasser Lives On Despite Author's Arrest
27.  Evaluate Security Risks Involved In Outsourcing Before Signing Agreements
28.  eMule 0.42e Remote Denial Of Service Exploit
29.  10 May Troj/Adtoda-A
30.  Birthday Arrest May Save Sasser Virus Youth from Jail

8:23:55 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  MTV's new mashup bootleg TV show "MTV Mash". French DJ/producer duo Loo & Placido tell BoingBoing: X-NAS-Bayes: #0: 5.01973E-168; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 613 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

We've been doing bootlegs / mash-ups for a few years now. For the last several months, we've been working with MTV on exclusive bootlegs for a new show called ""MTV MASH" which is broadcast all around Europe 3 times a week. We already made12 tracks for the show so far. If you want to listen to our bootlegs, check out our website, it's still under construction, but there's already a lot of tracks to listen to.

Link to the L&P site. The MTV out-takes you can listen to here are terrific, and if this is what ended up on the cutting room floor -- the show should be amazing. I'm particularly fond of the Missy Elliot meets Green day track "get your green on," as well as the Goldbug meets ODB number "Golden Bastard."
----------------------------------------------------------------------
Penny Arcade!
----------------------------------------------------------------------
2.  How To Make Friends And Influence Bats.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  Gateway countersues HP over patents. As the giants prepare to slug it out in court, Gateway reports that its estimated first-quarter loss was shy by $6 million, for a revised total of $172 million.
4.  Microsoft says bye-bye to Wi-Fi. Despite quickly becoming one of the leading sellers of wireless networking products, Microsoft has decided to discontinue its entire line of Wi-Fi gear, CNET News.com has learned.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  Date Set for PeopleSoft Suit Vs. Oracle (Reuters). Reuters - A California judge has set a Nov. 1 trial date for PeopleSoft Inc.'s (PSFT.O) lawsuit against Oracle Corp. (ORCL.O) for unfair business practices related to its $9.4 billion hostile takeover bid.
6.  HP Plays Up PC for Gamers (PC World). PC World - Basic system offers customizable components, easy access for upgrades.
7.  MSN Teams Up With Fox Sports (AdWeek.com). AdWeek.com - MSN's multiyear, multi-million-dollar content partnership with Fox Sports--due to start July 1 --opens up ad-sales opportunities for the portal in the hugely popular sports vertical, previously unavailable under its expiring contract with ESPN.
8.  IBM Launches Software for Networked Computing (Reuters). Reuters - IBM said on Monday it will launch software for running applications over far-flung networks and devices, challenging Microsoft Corp.'s (MSFT.O) hold on the desktop business software market.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  Stopping Overseas Fax Spam?
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
10.  Security threats raise concerns about Bluetooth. Below are the fields to populate the Article Content Type.  These fields are automatically tied to their corresponding styles available in the Style Dropdown.  
11.  Intel readies four additional mobile processors. SAN FRANCISCO - Intel Corp. plans to follow Monday's mobile processor launch with four more chips for portables slated for release over the next few months, according to information posted inadvertently on Dell Inc.'s Web site Monday.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  BugTraq: DEEP SEA PHISHING: Internet Explorer / Outlook Express. Sender: http-equiv at excite dot com [1 at malware dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Microsoft Bounty Helps Nail Sasser Suspect
14.  Sasser Variant Appears
15.  Blog :: When a Conference becomes a Con

7:23:34 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Nortel: Video demand to spur faster DSL. Telephone companies will have to provide much faster DSL speeds to meet the demands of video and keep cable competitors at bay, according to a Nortel Networks exec.
2.  Briefly: MCI posts $388 million loss. Plus: PeopleSoft buyout liability nears $2 billion...Intel invests in JBoss...i2 settles shareholder lawsuits...Google polishes up Blogger site.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Extended Systems Launches Mobile Sales App (NewsFactor). NewsFactor - Mobile middleware provider Extended Systems (Nasdaq: XTND) has introduced OneBridge Mobile Sales, an applications package targeting the growing number of enterprise sales professionals on the move. The product includes modules for contacts, opportunities and reporting, and integrates with a broad array of back-end applications.
4.  Microsoft to Launch Arcade Games for Xbox (Reuters). Reuters - Microsoft Corp. (MSFT.O) on Monday said it will offer a lineup of arcade, puzzle and card games on its Xbox Live online service, targeted at infrequent video game players.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Practical File System Design with the Be File System
6.  Videogame Character Threatens National Security?
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
7.  Experts: Timing of new Sasser worm raises questions. BOSTON - The release of a new version of the Sasser worm calls into question claims by some German authorities that they have the sole author of the worm in custody, according to antivirus experts.
8.  Judge sets date for PeopleSoft versus Oracle trial. NEW YORK - While Oracle Corp. prepares to face off with the U.S. Department of Justice in June in a California court battle over its proposed acquisition of PeopleSoft Inc., its legal team will also need to plan for a November confrontation with PeopleSoft in another California courtroom.
9.  RightNow files to join IPO parade. NEW YORK - Customer service ASP (application service provider) RightNow Technologies Inc. filed Monday to join the parade of tech companies planning IPOs (initial public offerings) this year.
10.  MCI struggles through first quarter. MIAMI - MCI Inc., fresh out of bankruptcy, lost no time in reporting disappointing financial results Monday for its first quarter, ended March 31, 2004. It saw its revenue decline and its bottom line change from black to red compared with the first quarter of 2003.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
11.  News: 'Sasser' creator launched damage-limiting version before arrest. The Associated Press By Geir Moulson
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  BugTraq: RE: a litle bypass with IE. Sender: Eric Norbut [eric at se-gi dot com]
13.  BugTraq: a litle bypass with IE. Sender: Nuno Costa [webcenter at sapo dot pt]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  TrendMicro OfficeScan Inappropriate Default Permissions
15.  Sasser Worm ftpd Remote Buffer Overflow Exploit (port 5554)
16.  efFingerD 0.2.12 Buffer Overflow
17.  Eudora is susceptible to a fraudulent URL
18.  NJ: No wires can mean no safety "In a single mile, only 12 of 58 houses with wireless computer n...
19.  Ohio: Wi-Fi easy hacker target "Parked outside a swank Narberth block, it took a computer consul...
20.  The Register: BBC develops 'alternative' codec "The BBC says that already the system gives a two...
21.  Net-Security: Microsoft Windows IPSec Vulnerabilty "Windows is verifying the authenticity of an ...
22.  Security Focus: Automating Windows Patch Mngt - Part III

6:23:15 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Jon Stewart on US torturers. Lisa Rein has posted two amazing clips from the Daily Show on the Iraq torture scandal. X-NAS-Bayes: #0: 4.09578E-118; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 600 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

4.8MB QuickTime Link to Rob Courddry On The US Torture Of Iraqi Prisoners, 9.8MB QuickTime Link to Jon Stewart on Giant Messopotamia

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Intel Launches Three Laptop Processors (AP). AP - Intel Corp. launched three new microprocessors for laptop computers Monday as the chip-making giant widened its mobile technology marketing blitz to include consumers as well as businesses.
3.  Disney to Publish 'Chicken Little,' 'Narnia' Games (Reuters). Reuters - The Walt Disney Co. will publish a range of video games to accompany "Chicken Little," its first-ever fully computer-animated film, the company said on Monday.
4.  Intel Launches Advanced Notebook PC Processor (Reuters). Reuters - Intel Corp. (INTC.O), the world's largest chip maker, unveiled on Monday a new mobile processor for notebook computers that boosts performance while keeping battery life roughly the same as previous versions.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  In-Flight Wi-Fi Makes its Debut
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
6.  Notebook makers release PCs for Intel's Dothan. BOSTON - A slew of notebook PC vendors lined up behind Intel Corp.'s three new Dothan Pentium M processors on Monday with new and updated systems that feature the improved chip.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Bad laws, bad code, bad behavior
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
8.  BugTraq: Re: a litle bypass with IE. Sender: [nbriscoe at cix dot co dot uk (Neil Briscoe)]
9.  BugTraq: msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh. Sender: Rafel Ivgi, The-Insider [theinsider at 012 dot net dot il]
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
10.  BBC develops 'alternative' codec. With wavelets, 'Dirac' lessens lossiness By Faultline .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  WORM_BAGLE.AB
12.  WORM_BAGLE.AA
13.  WORM_SPYBOT.MA
14.  WORM_CYCLE.A
15.  WORM_AGOBOT.FU
16.  WORM_AGOBOT.TT
17.  Newest Pattern: 887
18.  No cameras at prison-abuse trial
19.  Renegade cleric's office destroyed
20.  Getting Back in Charge of Storage Purchasing
21.  'Critical' Buffer Overflow Found in Eudora
22.  AirDefense Tackles Bluetooth Security
23.  NetIQ Suite Delegates Windows Administration Tasks
24.  SSL VPNs Start Making Sense
25.  Cyber-Crime Laws Hurt More Than They Help
26.  Sasser.D Worm Hits Internet
27.  Worm Creator Sent Damage-Limiting Version
28.  Bad laws, bad code, bad behavior

5:22:54 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Intel's Dothan chips officially debut. Say goodbye to the clockspeeds! Intel introduces the Pentium M 735, 745, and 755, their first CPUs to be marketed sans clock speed reference By Eric Bangeman.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Regulators dial in on AT&T prepaid calls. The long-distance giant said the FCC is reviewing its method of selling some prepaid calling cards, which could leave AT&T on the hook for more than a half billion in unpaid fees.
3.  RightNow joins IPO conga line. The subscription software company joins the likes of search engine leader Google, gay Web portal PlanetOut and online bookseller Alibris with plans for an initial public offering of its stock.
4.  Sasser continues to strike. German police have nabbed the worm's author, but a new version is making its way around the Internet.
5.  Intel launches Dothan, new naming scheme. The chipmaker launches its new Pentium M chip family, along with a new naming system that de-emphasizes clock speed.
6.  PeopleSoft buyout liability nears $2 billion. The company's get-out-of-hostile-takeover card, played via a money-back guarantee to customers, could hike the cost of Oracle's proposed $9.4 billion bid.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  Siebel's Next Chapter (NewsFactor). NewsFactor - As the smoke clears following Tom Siebel's (Nasdaq: SEBL) bombshell that he was stepping down as CEO of the firm he built over the last 11 years, analysts, competitors and customers are wondering what is next for Siebel -- the company that has, for better or worse, defined CRM as we know it today.
8.  IBM Takes On Microsoft with New Desktop Strategy (NewsFactor). NewsFactor - In a bid to wrest control of the corporate desktop market from Microsoft (Nasdaq: MSFT), IBM (NYSE: IBM) has unveiled a new software strategy that enables workers to access a full complement of business applications from enterprise data centers.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  Project Grizzly Bear-Proof Suit Up For Auction
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
10.  RFID buzz creates market for services. The recent push by retailers to introduce radio frequency identification (RFID) tagging into supply chains has not only sparked a frenzy of RFID-related activity by suppliers needing to satisfy retailer demands, it has also created a market for service providers offering to aid in implementation.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
11.  Microsoft virus bounty leads to Sasser arrest. 43591A multi-million dollar Microsoft Corp. reward program to encourage people to identify computer virus writers has led to the arrest of a teenager in Germany on suspicion of writing the Sasser computer worm.
12.  Sasser, Phatbot arrests coordinated, but not linked. A 21-year-old German man was arrested and has admitted to creating the ubiquitous and dangerous Trojan horse programs Agobot and Phatbot, but is not connected to the German author of the Sasser Internet worm, a police spokesman said.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
13.  BugTraq: Emule 0.42e Remote Denial Of Service Exploit. Sender: Rafel Ivgi, The-Insider [theinsider at 012 dot net dot il]
14.  Vulns: Sun Java Runtime Environment Unspecified Remote Denial Of Service Vulnerability. The Java Runtime Environment (JRE) is the virtual Java platform on which all Java applications are run. It is provided by Sun Microsystems for a number of platforms, inc...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
15.  Topspin hopes to hit winner with VFrame. Server virtualization, anyone? By Ashlee Vance .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
16.  Faut-il mettre plus de qualité dans les correctifs ?
17.  Le Cert publie un livre sur la sécurisation système et réseau
18.  Sasser worm creator may have launched damage-limiting version before arrest (Canadian Press)
19.  Kolab Server slapd.conf Root Password Disclosure
20.  Exim sender_verify Overflow
21.  Exim header_syntax Overflow
22.  efFingerD sockFinger_DataArrival DoS
23.  efFingerD Malformed Packet DoS
24.  FuseTalk adduser.cfm Create Arbitrary Account
25.  Linux CLOSE_WAIT TCP Networking DoS
26.  OpenSSH Symbolic Link 'cookies' File Removal
27.  Microsoft IIS Cookie Variable Information Disclosure
28.  Squid Proxy MSNT Auth Helper Overflow
29.  OpenSSL ASN.1 Client Certificate Buffer Overflow
30.  L'auteur présumé du virus Phatbot, placé en détention provisoire

4:22:35 PM    comment []

----------------------------------------------------------------------
Digital Identity World
----------------------------------------------------------------------
1.  The Digital ID World Newsletter - May 6, 2004 Issue
----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
2.  IBM's Lotus Workplace to take on Microsoft Office. IBM to offer server-based alternative to Microsoft Office, Priced at US$2 per user per month, users will be able to download what they need, work offline, and synchronize automatically on next log-in. By Eric Bangeman.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
3.  Stanislaw Lem is cranky!. Stanislaw Lew, the king of Polish Science Fiction, is alive, cranky and well, and this interview with him makes me want to go re-read Solaris. X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 598 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Bush is seeking reelection. His advisers remembered the effect of the first landing on the Moon, and proposed a repeat, but on a grander scale. So Mars came in handy. It will take at least 20 years to prepare a flight to Mars. Bush, however, is>Link

(via Beyond the Beyond)

4.  MPAA's Bizarro-world logic. Fritz Attaway, the MPAA's vice president who shows up at all the DRM meetings, explains to the press how the world works in Bizarroland, where being able to make a backup of your DVDs is bad for you.

"There is no right in the copyright law to make backup copies of motion pictures, so the whole argument that people should have the right to make backup copies of DVDs has no legal support whatsoever," said Fritz Attaway, executive vice president of the MPAA.

"It's against consumers' interests to permit devices that make backup copies," he added, "because there is no way that a device can distinguish between a backup copy for personal use and making a copy for friends, family acquaintances or even selling on the street corner."

Link

(Thanks, Brian!)

5.  Persian photoblog: Those Sexy Iranians. Hossein Derakshan says, "I've launched my photoblog, titled "vagrantly." Here's the latest image post, about the Islamic dress code and Nicholas Kristof's New York Times column this weekend about 'sexy Iranians.'"
No one has challenged the cleric's rule more effectively than these young Iranian girls. They have totally changed the Islamic dress code during the past five years. The half-sliced heads of the mannequins are results of Islamic laws that prohibit making identical statues to humans.
Link to Hoder's photoblog post. And coincidentally, BoingBoing's own Cory says from the U.K., "Spotted at the Brick Lane Bengali new year's festivities in London: a little girl in a couture Calvin Klein headscarf."Link to 80K jpeg image.
6.  Kevin Sites Iraq blog: "Paying Back in Blood". Blogger and MSNBC combat correspondent Kevin Sites is in Iraq, and has posted a new entry to his blog today.

When he was nine years old Carlos Gomez crossed the Rio Grande from Mexico to the U.S. with his father, mother and two sisters. They had heard stories about the opportunities in America, dreamed about them, wanted them so badly they ran through oncoming traffic on the 805 freeway to get to them. They didn't stop until they reached San Diego. Fear, fatigue and La Migra slowly fading into the southern horizon like their homeland.

They stayed. Dealt with the slurs--beaners, greasers, wetbacks. Overcame them. Paid back America's opportunities with hard, menial labor. Made a fraction of what citizens and legal immigrants made--but never complained.

And 12 years later, in Falluja, Iraq, Marine Lance Corporal Gomez would pay it back again--but this time with his blood.

Link, Discussion Forum
7.  Pixel-counting can un-redact government docs. A Luxembourgian/Irish security research team have presented a paper on a technique for identifying words that have been blacked out of documents, as when government docs are published with big strikethroughs over the bits that are sensitive to national security. The technique doesn't work on monospace fonts like Courier, but the State Department's recent font guidelines require that all docs be published in Times New Roman, which decodes like a charm.

hey found the number of pixels that had been blacked out in the sentence: "An Egyptian Islamic Jihad (EIJ) operative told an xxxxxxxx service at the same time that Bin Ladin was planning to exploit the operative's access to the U.S. to mount a terrorist strike." They then used a computer to determine the pixel length of words in the dictionary when written in the Arial font.

The program rejected all of the words that were not within three pixels of the length of the word that was probably under the blacked-out area in the document.

The software then reduced the number of possible words to just seven from 1,530 by using semantic guidelines, including the grammatical context. The researchers selected the word "Egyptian" from the seven possible words...

Link

(Thanks, Wendy!)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
8.  Briefly: Intel invests in JBoss. Plus: i2 settles shareholder lawsuits...Google polishes up Blogger site...Sun says Kodak's Java suit set for Sept....Luminary joins open-source insurers.
9.  Survey: IT managers say they'll increase spending. Information technology managers expect to increase their spending by 2.4 percent in 2004, according to a survey by Forrester Research. That's up from the 1.7 percent rise projected six months ago.
10.  Can Microsoft bounty put paid to viruses?. Microsoft claims its reward program was responsible for the arrest of the suspected author of the Sasser worm, but some experts say money alone will not clear up security problems.
11.  Nortel joins convergence push with new MPLS router. Nortel Networks announces a new router designed to help carriers deliver voice, video and data services over a single network.
12.  Intel's Dothan sets sail. The chip giant launches the new design with three new laptop chips. It also outlines a push to equip more consumer-oriented notebooks with wireless networking capabilities.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
13.  Hall of Fame Voting For Computer Museum of America
14.  HP to Offer Custom Compaq Gaming PCs
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
15.  IBM puts Workplace at center of managed apps vision. NEW YORK - IBM is looking to broaden its Workplace architecture for component-based application delivery beyond the Lotus portfolio in which Workplace got its start. IBM software head Steve Mills outlined Monday how a forthcoming rich-client platform from IBM can be used as a hub to deliver to end-users a variety of applications centrally managed on servers, including applications from Microsoft Corp.'s Office suite.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
16.  Home Users Most Vulnerable to Sasser Worm Claims Network Associates
17.  Icsa Labs Certifies Nvidia Firewall
18.  German Teen Admits Making The 'Sasser' Internet Worm
19.  Sasser strikes back despite arrest
20.  Cherry Devices to Include Fingerprint Identification Capabilities from Isl Biometrics
21.  CyberGuard on the attack
22.  Hacking danger worsens
23.  Foundry turns up heat on high-end security range
24.  [ GLSA 200405-01 ] Multiple format string vulnerabilities in neon 0.24.4 and earlier
25.  PaX DoS proof-of-concept
26.  OUTLOOK 2003: OuchLook
27.  a litle bypass with IE
28.  [ GLSA 200405-02 ] Multiple vulnerabilities in LHa
29.  Monit 4.1 remote shell exploit (HTTP)
30.  RE: An undetectable Online Bank Vulnerability?
31.  Arbitrary code inclusion in phpShop
32.  Elsewhere: Security threats raise concerns about Bluetooth
33.  Elsewhere: Can Microsoft's virus bounty fight organised crime?
34.  Infocus: Automating Windows Patch Mngt: Part III
35.  News: New version of Sasser undermines lone coder theory
36.  Despite arrest, new variant of Sasser worm appears
37.  Symantec does mail gateway security
38.  DMCA challenge to be considered this week
39.  German police arrest Sasser worm suspect
40.  New version of Sasser undermines lone coder theory
41.  FTC fines porn spammers $112k
42.  Patriot Act and FDIC used in phishing scam
43.  The accidental arbiter
44.  Winny P2P Software Creator Arrested
45.  California County Sues State Over E-Vote Ban
46.  Boucher's DMCRA To Get A Hearing On May 12
47.  Congressional Hearing Called on Fair Use; 321 Studios President Asked to Testify
48.  What's Being Done About Nuclear Security
49.  Feds Answer Calls for Nuke Safety
50.  Slashdot | Phatbot Author Arrested In Germany
51.  Breaking RSA Keys by Listening to Your Computer
52.  Sasser Author Under Arrest, Say German Police
53.  RFID MasterCard
54.  MasterCard® PayPassTM: Coming to a Wallet Near You
55.  Free Software Tracking a Stolen Computer?
56.  Comcast Plans Cable Boxes with Integrated Wi-Fi and Snooping
57.  Slashdot | Evoting in the News
58.  Spyware Becoming Worst Tech Support Problem
59.  Wired News: Sick of Spam? Prepare for Adware

3:22:18 PM    comment []

----------------------------------------------------------------------
Digital Identity World
----------------------------------------------------------------------
1.  The Digital ID World Newsletter - April 8, 2004 Issue
2.  The Digital ID World Newsletter - April 15, 2004 Issue
3.  The Digital ID World Newsletter - April 22, 2004 Issue
4.  The Digital ID World Newsletter - April 29, 2004 Issue
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
5.  Study: Home networking on the upswing. The spread of broadband is driving the growth of home networking, according to data released by In-Stat/MDR.
6.  Intel invests in JBoss. The chipmaker gives an undisclosed sum to the open-source software maker and says it will provide technical resources for Java 2 Enterprise Edition certification.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  Sprint to Spend Over $100 Mln on Rate Plan Ads (Reuters). Reuters - Sprint Corp. said on Monday it would spend more than $100 million on its costliest wireless advertising campaign to date, in an effort to explain a new rate plan aimed at keeping customers from leaving.
8.  First Tests of Intel's New Pentium M (PC World). PC World - Vendors snap up 'Dothan' for speedy notebooks with long battery life.
9.  Study: Many Federal Sites Not Terror Risks (AP). AP - Federal officials should consider reopening public access to about three dozen Web sites withdrawn from the Internet after the Sept. 11, 2001, attacks, a government-financed study says, because the sites pose little or no risk to homeland security.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
10.  Mars & The Teachable Moment
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
11.  Sasser, Phatbot arrests coordinated, but not linked. A 21-year-old German man was arrested and has admitted to creating the ubiquitous and dangerous Trojan horse programs Agobot and Phatbot, but is not connected to the German author of the Sasser Internet worm, a police spokesman said.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
12.  Elsewhere: Security threats raise concerns about Bluetooth. Potential security risks posed by the Bluetooth wireless technology are prompting some IT managers to rein in use of Bluetooth-equipped mobile phones and PCs on their net...
13.  Elsewhere: Can Microsoft's virus bounty fight organised crime?. Microsoft is claiming that its $250,000 reward was responsible for the Sasser author's arrest, but experts say money alone will not stop the virus and spam problem X-NAS-Bayes: #0: 2.45059E-073; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 597 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Micr...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  [MAJ] Vulnérabilité dans la gestion des messages SNMP des routeurs Cisco
15.  [MAJ] Vulnérabilité dans la gestion des messages SNMP des routeurs Cisco
16.  Worm Creator Sent Damage-Limiting Version (AP)
17.  Suspected Phatbot computer worm inventor held in Germany (AFP)
18.  FreeBSD vfs_cache Memory Consumption DoS
19.  10 May W32/Agobot-QA
20.  Sasser: Firmen prüfen Schadenersatz-Forderungen

2:21:56 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Game accessory sales up slightly, study says. Market research company NPD Group sees a 10 percent increase in first-quarter sales of game devices. Game pads, steering wheels and stick controllers account for much of the growth.
2.  Bad laws, bad code, bad behavior. CNET News.com's Declan McCullagh explains why laws regulating technology often invoke an even more powerful rule: the law of uninintended consequences.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Landmark Overhauls Management Tools (Ziff Davis). Ziff Davis - Buffalo Brewpub sees rapid ROI with IBM hardware and Aloha point-of-sale software.
4.  NTT DoCoMo sharply lower after warning price war to hurt profits (AFP). AFP - Shares in NTT DoCoMo, Japan's largest mobile phone service provider, slumped after its announcement that a fierce price war will hurt its operating profit in the current year.
5.  2003 Online Content Spending Up Almost 19 Percent (Reuters). Reuters - Spending by U.S. consumers for online content rose almost 19 percent to $1.56 billion in 2003 from 2002, largely fueled by increases in the two top categories, the Online Publishers Association and comScore Networks said on Monday.
6.  Gmail Has Potential As Enterprise Platform (Ziff Davis). Ziff Davis - With certain added capabilities, Google's Web mail offering could be used as a corporate mail service.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Ask About Running Windows Software in Linux
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
8.  Games showcase hits Los Angeles. The latest hardware and software developments in video gaming are showcased at E3 in Los Angeles.
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
9.  Microsoft virus bounty leads to Sasser arrest. A multi-million dollar Microsoft Corp. reward program to encourage people to identify computer virus writers has led to the arrest of a teenager in Germany on suspicion of writing the Sasser computer worm.
10.  BI bigwigs ramp up platforms. BI vendors Firstlogic, IBM, Informatica, and SAS Institute are all working to broaden the reach of their respective BI platforms via extensions to their product lines focused on data integration.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
11.  DMCA challenge to be considered this week
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
12.  Elsewhere: German Net Worm Writer May Have Been Helping Mom. BERLIN (Reuters) - A German whiz-kid who confessed to writing a crippling computer worm that caused chaos around the world may have been trying to help his mother's small...
13.  Infocus: Automating Windows Patch Mngt: Part III. The final installment of this series discusses two alternative, low cost tools to manage the application of patches to Windows systems, and also provides information on the upcoming, revised Software Update Services (SUS) from Microsoft.
14.  News: New version of Sasser undermines lone coder theory. The appearance of a new version of the infamous Sasser worm shortly after the arrest of its admitted author has fuelled speculation that its creator worked with other virus writers.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
15.  BugTraq: [ GLSA 200405-02 ] Multiple vulnerabilities in LHa. Sender: Thierry Carrez [koon at gentoo dot org]
16.  BugTraq: OUTLOOK 2003: OuchLook. Sender: http-equiv at excite dot com [1 at malware dot com]
17.  BugTraq: PaX DoS proof-of-concept. Sender: Michel Blomgren [michel at cycom dot se]
18.  BugTraq: Monit 4.1 remote shell exploit (HTTP). Sender: Michel Blomgren [michel at cycom dot se]
19.  Vulns: Microsoft Internet Explorer Unconfirmed Memory Corruption Vulnerability. A potential memory corruption vulnerability has been identified in Microsoft Internet Explorer that may result in a denial of service condition in the browser. X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 596 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The issue...

20.  Vulns: Trend Micro OfficeScan Weak Default Permissions Vulnerabilities. Trend Micro OfficeScan is an enterprise-level centrally managed antivirus solution. It is commercially available for the Microsoft Windows platform.

It has been reporte...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
21.  Orange UK sorts German roaming snag. Trying times By Tim Richardson .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
22.  Cyber-Crime Laws Hurt More Than They Help (Ziff Davis)
23.  Sasser Variant Appears (PC World)
24.  Wurm Cycle.A wirbt für Menschenrechte
25.  Symantec Client Firewall Products Denial of Service Vulnerability
26.  Sun Solaris "sendfilev()" Extended Library Function DoS
27.  McAfee ePolicy Orchestrator Command Execution Vulnerability
28.  Linux Kernel CPUFREQ Proc Handler Kernel Memory Disclosure
29.  Internet Explorer and Windows Explorer Long Share Overflow
30.  MPlayer and xine-lib RTSP Handling Multiple Vulnerabilities
31.  Midnight Commander mc Multiple Unspecified Vulnerabilities
32.  Apple QuickTime QuickTime.qts Heap Overflow Vulnerability
33.  Mac OS X Security Update Fixes Multiple Critical Vulnerabilities
34.  Check Point VPN-1 Products ISAKMP Buffer Overflow Vulnerability
35.  Alerte - Découverte d'une faille au coeur même du protocole TCP
36.  Une nouvelle faille de sécurité pour Windows et Internet Explorer
37.  le Correctif MS04-011 buggué, et exploitation massive de la faille lsass
38.  Le ver Sasser exploite la vulnérabilité Windows LSASS (MS04-011)
39.  L'auteur du virus Netsky prétend être le créateur de Sasser
40.  Les dangers de certaines failles Mac OS X sous-estimés par Apple
41.  1,5 million d'utilisateurs ont téléchargé l'outil Microsoft anti-Sasser
42.  La loi sur l'économie numérique définitivement adoptée par les députés
43.  L'auteur présumé du virus Sasser arrêté et déjà libéré !
44.  Sasser.e : Nouvelle version, malgré l'arrestation de l'auteur présumé
45.  TCP Connection Reset Remote Windows 2K/XP Attack Tool
46.  TCP Connection Reset Remote Exploit (By Paul A. Watson)
47.  Microsoft IIS 5.x SSL PCT Remote Windows 2k/XP Exploit (MS04-011)
48.  Windows Lsasrv.dll buffer overflow Remote Exploit (MS04-011)
49.  HP Web JetAdmin 6.5 Remote Root Exploit (Linux / Windows)
50.  Windows Lsasrv.dll Remote Universal Exploit XP/2K (MS04-011)
51.  X-Chat 1.8.0-2.0.8 socks5 Remote buffer overflow Exploit
52.  Monit 4.1 HTTP Request Remote Buffer Overrun Exploit
53.  Sasser Worm ftpd Remote Buffer Overflow Exploit (port 5554)
54.  Cry to beat iris scanners
55.  Linux Security Week - May 10th 2004
56.  Hacking danger worsens
57.  Sasser strikes back despite arrest
58.  CyberGuard on the attack
59.  Sasser strikes back
60.  Denver lawyer calls reservist a scapegoat
61.  Guardian Digital Security Solutions Win Out At Real World Linux
62.  Software Security Start-Up Aims to Pre-Empt Hackers (Reuters)
63.  Microsoft IIS Inappropriate Cookie Handling Error
64.  Microsoft IIS Inappropriate Cookie Handling Error
65.  Microsoft Outlook Predictable File Location Weakness
66.  Microsoft Outlook Predictable File Location Weakness
67.  efFingerD Denial of Service Vulnerabilities
68.  efFingerD Denial of Service Vulnerabilities
69.  Gentoo update for LHA
70.  Gentoo update for LHA
71.  Gentoo update for neon
72.  Gentoo update for neon
73.  TrendMicro OfficeScan Weak Permissions
74.  TrendMicro OfficeScan Weak Permissions
75.  Linux Kernel IO Bitmap Access Permissions Inheritance Vulnerability
76.  Linux Kernel IO Bitmap Access Permissions Inheritance Vulnerability
77.  NukeJokes SQL Injection Vulnerabilities
78.  NukeJokes SQL Injection Vulnerabilities
79.  IBM Parallel Environment Sample Code Privilege Escalation Vulnerability
80.  IBM Parallel Environment Sample Code Privilege Escalation Vulnerability
81.  Eudora URL Obfuscation Issue
82.  Eudora URL Obfuscation Issue
83.  Microsoft Internet Explorer and Outlook URL Obfuscation Issue
84.  Microsoft Internet Explorer and Outlook URL Obfuscation Issue
85.  SSL VPN Trumps IPSec at Alexza
86.  How We Tested: SSL VPN Appliances
87.  Patches Aren't to Be Trusted
88.  Clientless VPN Gateway 4420
89.  9400 Secure Application Switch
90.  NetScreen-SA3000
91.  SureWare A-Gate AG-600
92.  CA Wants Focus Back on Products
93.  DS-3 Gear Theft Knocks Out Service

1:21:37 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Warrants are security measures. Bruce Schneier's latest op-ed asks us to consider the warrant process -- where a cop has to show evidence and follow procedure before invading your privacy -- is itself a security measure. X-NAS-Bayes: #0: 4.67886E-204; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 595 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

What we need are corresponding mechanisms to prevent abuse. This is the proper question: "Should we allow law enforcement to use new technology without any judicial oversight, or should we demand that they be overseen and accountable?" And the Fourth Amendment already provides for this in its requirement of a warrant.

The search warrant - a technologically neutral legal requirement - basically says that before the police open the mail, listen in on the phone call or search the bit stream for key words, a "neutral and detached magistrate" reviews the basis for the search and takes responsibility for the outcome. The key is independent judicial oversight; the warrant process is itself a security measure protecting us from abuse and making us more secure.

Link

2.  Biting the bullet. A woman in Irvine, California claimed she bit into a hot dog and ended up chomping down on a live 9 mm bullet. Police opened the rest of the hot dog packages at the Costco store that sold the woman the wiener but didn't find any more bullets. Meanwhile, the woman, suffering from a tummy ache, visited a hospital where x-rays revealed another round inside her stomach. Link

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  IBM plans Web-based desktop software. Big Blue announces new software intended to take on Microsoft in the market for desktop business applications.
4.  HP debuts RFID services. Hewlett-Packard unveils launch and test services to help companies get the ball rolling on radio frequency identification projects.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  Security threats raise concerns about Bluetooth (MacCentral). MacCentral - Potential security risks posed by the Bluetooth wireless technology are prompting some IT managers to rein in use of Bluetooth-equipped mobile phones and computers on their networks.
6.  Google Unveils Redesigned Blogger.com (Reuters). Reuters - Google Inc., the No. 1 Web search company that recently announced plans to go public through a Dutch auction, on Monday rolled out a new design of its Blogger service that enables users to self-publish Web content.
7.  Get Ready for Some Hand-to-Hand Combat (washingtonpost.com). washingtonpost.com - Cue up the "dueling handhelds" theme: The video game wars are starting anew, with competitors Nintendo and Sony in a fierce fight for victory on the handheld gaming battlefield.
8.  Software Security Start-Up Aims to Pre-Empt Hackers (Reuters). Reuters - A pair of small U.S. technology firms said on Monday they have struck a deal to market software intended to defend corporate computer networks by scanning for possible security flaws before they can be targeted by hackers and viruses.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  The Face Detector
10.  Thawte Founder Launches Open Source Campaign
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
11.  Despite arrest, new variant of Sasser worm appears. Despite the arrest Friday of the suspected author of the Sasser worm that affected millions of computers worldwide last week, a new variant of the worm appeared Sunday, according to computer security organizations.
12.  Symantec does mail gateway security. Symantec Corp. plans to announce on Monday an update to its Mail Security for SMTP product that offers new features for cleaning up after mass mailing worms and identifying trusted mail domains, as well as improved capabilities for detecting unsolicited commercial ("spam") e-mail messages.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
13.  Linux Security Week - May 10th 2004
14.  Linux Security Week - May 10th 2004
15.  Suse: Live CD 9.1 Passwordless superuser
16.  Suse: kernel Multiple vulnerabilities
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
17.  EC opens ears on e-money directive. Suggestions on a postcard, please... By John Oates .
18.  T-Mobile wins Heathrow hotspot siting. Wi-Fi to be installed in other UK airports too By Tony Smith .
19.  PalmOne preps Treo 600 code update. Bug fixes coming this week By Tony Smith .

12:21:15 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Fat-destroying pill?. One way to treat obesity may be to starve the fat cells. University of Texas researchers have designed a drug that selectively kils the blood vessels that supply white fat cells. Massively fat mice given the drug lost 30 percent of their weight in one month. Eventually, the researchers told New Scientist, a similar approach could be used to help obese humans. Link X-NAS-Bayes: #0: 8.19704E-062; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 594 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

2.  Noise Pop mix tapes. Noise Pop, San Francisco's gem of an indy music festival, and KQED are streaming various underground musicians' playlists-du-jour. The latest selections come from Greg Ashley, a Bay Area psych-folk artist whose exquisite taste ranges from Leonard Cohen to Os Mutantes. Link (Thanks, Birdman!)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  i2 settles shareholder lawsuits. The software company, which has been plagued by accounting problems, will pay a total of $84.9 million, half of which will come from its insurance policy.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Sony's Connect Music Service Offers Fair Pricing, Little Else (washingtonpost.com). washingtonpost.com - If anybody can get Internet music downloads right, it should be Sony Corp. The company has years of experience selling records, consumer electronics and personal computers -- and it's had plenty of time to study earlier digital-music ventures.
5.  Professor Arrested on Software Suspicion (AP). AP - A Japanese professor who advocates free file sharing on the Internet was arrested Monday on copyright-related charges for developing and offering software that lets people swap movies and video games, police said.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  Perens Talks About Open Source Risk Management
7.  IBM To Announce Web-Based Desktop Apps
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
8.  Illegal film downloads triple. The number of internet users illegally downloading films and TV series triples, a survey suggests.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
9.  FreeBSD: crypto_heimdal Heap overflow vulnerability
10.  Mandrake: proftpd Access control escape vulnerability
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
11.  Intel pumps VC cash into JBoss. Java play By John Oates .
12.  IBM bangs drum for client middleware. New software architecture By John Oates .
13.  BT will compensate customers for Manchester blaze. Not to blame, though By Tim Richardson .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  Symantec Strengthens Mail Gateway (PC World)
15.  Virus Creator May Have Made New Version (AP)
16.  German Net Worm Writer May Have Been Helping Mom (Reuters)
17.  Suppression de fichiers et déni de service dans Crystal Report
18.  Fuite d'Information possible lors du traitement des cookies par les script ASP (Microsoft IIS)
19.  Duitse tiener verantwoordelijk voor Sasser worm
20.  Microsoft helpt bij arrestatie Sasser auteur
21.  Bende Oost-Europese internetoplichters opgepakt
22.  Ook auteur Phatbot / Agobot gearresteerd
23.  Nieuwe versie van Sasser verwijdertool
24.  Service Pack 2 ook voor illegale Windows
25.  Chinees hackt Taiwanese oppostie website
26.  Kritiek lek in IIS 5.0 makkelijk te misbruiken
27.  250 000 US-Dollar Belohnung
28.  Sicherheits-Patches auch für Raubkopierer
29.  Sasser FTP Exploit
30.  Bush stands by Rumsfeld
31.  Red Cross: Mistreatment routine at Iraq prison
32.  Mise en place des moyens d'authentification dans les aéroports
33.  Attention aux ratures
34.  MetaFrame enrichi de solutions de sécurité

11:20:58 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Intel to launch Dothan, new naming system. The chip, which was originally expected early this year, is the most recent in the company's Pentium M family of processors for laptops, and it will be named according to a new system that de-emphasizes clock speed.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Eclipse Developers Reap Design Awards (Ziff Davis). Ziff Davis - Despite having spun out the Eclipse consortium into an independent Eclipse Foundation, IBM continues to invest in the organization and its technology, particularly in attracting developers to the platform through competitions.
3.  Red Hat Offers Desktop (Ziff Davis). Ziff Davis - Red Hat Desktop is targeted at users running Windows 98, NT and 2000 who are anticipating the end of support for their Microsoft platforms.
4.  NTT DoCoMo sharply lower after warning price war to hurt profits (AFP). AFP - Shares in NTT DoCoMo, Japan's largest mobile phone service provider, slumped after its announcement that a fierce price war will hurt its operating profit in the current year.
5.  DVR popularity vexes TV industry (SiliconValley.com). SiliconValley.com - It's more than just this season's passing of "Friends," "Frasier" and "The Practice" that has the television industry worried about what we'll be watching in seasons to come.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  de Icaza: Rest of World Will Force US Into Linux
7.  PowerBook Disassembly Guide
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
8.  Despite arrest, new variant of Sasser worm appears. Despite the arrest Friday of the suspected author of the Sasser worm that affected millions of computers worldwide last week, a new variant of the worm appeared Sunday, according to computer security organizations.
9.  Symantec does mail gateway security. Symantec Corp. plans to announce on Monday an update to its Mail Security for SMTP product that offers new features for cleaning up after mass mailing worms and identifying trusted mail domains, as well as improved capabilities for detecting unsolicited commercial ("spam") e-mail messages.
10.  Intel launches Dothan laptop chips. Intel launched three updated versions of its Pentium M processors, a line of chips for laptop computers, on Monday as the company looks to build on its success with wireless Internet access using laptop PCs.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
11.  Cry to beat iris scanners
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  Vulns: Qualcomm Eudora Embedded Hyperlink Buffer Overrun Vulnerability. Qualcomm Eudora is reported to be prone to a remotely exploitable buffer overrun vulnerability. X-NAS-Bayes: #0: 3.17511E-198; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 593 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The issue is exposed when an excessively long hyperlink to a file resou...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
13.  Japanese P2P founder arrested. Copyright rap for Winny P2P software author By John Leyden .
14.  Hate websites continue to flourish. More nastiness than ever, says SurfControl By electricnews.net .
15.  321 lookalike punts DVD copy software. Naughty, naughty By Faultline .
16.  BBC develops 'alternative' codec. 'Dirac' utilises wavelet technology By Faultline .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
17.  German Net Worm Writer May Have Been Helping Mom (Reuters)
18.  Trotz Verhaftung neue Sasser-Variante im Umlauf
19.  Sasser-Festnahme: So kam Microsoft dem Autor auf die Schliche
20.  Buffer Overrun in Checkpoint VPN Code
21.  Survey asks users: Is GMail(tm) Evil or Cool?

10:20:36 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Microsoft's MSN to Team With Fox Sports (AP). AP - Microsoft Corp.'s MSN online division is teaming with Fox Sports to create a cobranded sports Web site and is ending a similar partnership with ESPN.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Linux Kernel 2.6.6 Released
3.  Camera Phone Tips
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
4.  Wraps come off Phantom console. Catch up with the latest news from the world of video gaming.
5.  X-rays to be stored on computer. Every hospital in England is to get new X-ray technology designed to speed up diagnosis and treatment.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
6.  Guardian Digital Security Solutions Win Out At Real World Linux
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  Sun and Veritas bury the hatchet. Licensing love-in By Datamonitor .
8.  Nokia quits WiMAX Forum. Shock move by enthusiastic founder member By Wireless Watch .
9.  BT in broadband free flight promo. Get connected, then leave country By Tim Richardson .
10.  FTC fines porn spammers $112k. A small price to pay? By Jan Libbenga .
11.  Japanese P2P founder arrested for copyright offences. Academic busted for writing Winny P2P software By John Leyden .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  Microsoft IIS Inappropriate Cookie Handling Error
13.  Microsoft Outlook Predictable File Location Weakness
14.  efFingerD Denial of Service Vulnerabilities
15.  Gentoo update for LHA
16.  Gentoo update for neon
17.  TrendMicro OfficeScan Weak Permissions
18.  NukeJokes SQL Injection Vulnerabilities
19.  IBM Parallel Environment Sample Code Privilege Escalation Vulnerability
20.  HNS Newsletter issue 212 has been released
21.  Combating the cyber criminals
22.  Combating Internet worms
23.  Microsoft IIS Inappropriate Cookie Handling Error
24.  A guide to centralized spam and virus filtering
25.  Microsoft IIS Inappropriate Cookie Handling Error
26.  A guide to centralized spam and virus filtering
27.  Microsoft Outlook Predictable File Location Weakness
28.  Cyber-crime laws hurt more than they help
29.  Microsoft Outlook Predictable File Location Weakness
30.  Hand over security
31.  efFingerD Denial of Service Vulnerabilities
32.  efFingerD Denial of Service Vulnerabilities
33.  Gentoo update for LHA
34.  Gentoo update for LHA
35.  Gentoo update for neon
36.  Gentoo update for neon
37.  TrendMicro OfficeScan Weak Permissions
38.  TrendMicro OfficeScan Weak Permissions
39.  NukeJokes SQL Injection Vulnerabilities
40.  NukeJokes SQL Injection Vulnerabilities
41.  IBM Parallel Environment Sample Code Privilege Escalation Vulnerability
42.  IBM Parallel Environment Sample Code Privilege Escalation Vulnerability

9:20:16 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Briefly: Google polishes up Blogger site. Plus: Sun says Kodak's Java suit set for Sept...Luminary joins open-source insurers...SAP adds Adobe tech to forms application...PeopleSoft-Oracle trial set for November.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Group to Label Video Games That Teach (AP). AP - Does "The Sims" video game accurately depict human psychology? Does a train simulator like "Railroad Tycoon" broach some basic engineering ideas? A group of educators, developers and game publishers believe they might.
3.  Wi-Fi Phones May Help Cut Calling Costs (AP). AP - Now that some Wi-Fi "hot spots" have grown into broader neighborhood "hot zones," the next wave is waiting: Phones and gear that send conversations over wireless Internet networks — for free or at a fraction of the cost of traditional calls.
4.  German Net Worm Writer May Have Been Helping Mom (Reuters). Reuters - A German whiz-kid who confessed to writing a crippling computer worm that caused chaos around the world may have been trying to help his mother's small PC Help business, state prosecutors said Monday.
5.  Sega to Co-Publish 'Matrix Online' Video Game (Reuters). Reuters - The U.S. arm of Japanese video game publisher Sega Corp. (7964.T) on Monday said it has struck a deal with Warner Bros. Interactive Entertainment to co-publish an online game based on the "Matrix" movies.
6.  Infinium Labs Sets Launch for Phantom Console (Reuters). Reuters - Infinium Labs Inc. (IFLB.OB), the long-secretive video-game company, on Monday took the wraps off of its Phantom gaming console and service, setting a Nov. 18 launch for the system designed to play conventional PC games on televisions.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Is eBay Worse Than Early Sears Catalogs?
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  Intel launches Dothan with Pentium M price cuts. The 90nm 7xx series ships By Tony Smith .
9.  AMD to parade Socket 939 at Computex. Chips at show shocker By Tony Smith .
10.  Sony US music service an 'embarrassment'. Damning report By Tony Smith .
11.  Oops! BT bills man £25,000 for cut cable. Garden fence project totals 2km of fibre optic By Tim Richardson .
12.  Ebookers sales up but jobs down. Turns a profit in skinny quarter... By John Oates .
13.  Cisco offers WLAN switching. Finally putting pressure on start-ups By Wireless Watch .
14.  New version of Sasser undermines lone coder theory. Worm turns up after arrest of prime suspect By John Leyden .
15.  E-voting promises US election tragicomedy. Brace yourselves By Thomas C Greene .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
16.  Courier Mail: Arrest could crack open PC virus ring "one of the most significant cybercrime arre...
17.  Info World: Wi-Fi security standard to require new hardware "802.11i uses AES encryption"
18.  Microsoft: Microsoft Reward Program Helps Lead to Information Resulting in Arrest Related to Sas...
19.  ZDNet AU: Does a virus gang own the Internet? "Should we thank Skynet for releasing a relatively...

8:19:57 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  How to be a poet. Jim Henley writes some damned sensible advice on how to become a poet -- advice that applies just as readily to becoming any kind of writer. X-NAS-Bayes: #0: 6.72596E-280; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 590 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Start by slavishly imitating poets you admire. This is the opposite of the standard advice that you need to concentrate on "finding your own voice." Don't take this wrong, _____, but fuck your own voice. Your own voice will take care of itself as your craft matures. Your own voice will, if you're going to have one, insist on emerging. In the meantime, learn the craft. Learn the vocabulary and practice of meter. Learn rhyme schemes. Learn the ways that free verse gets written that yet contains music. Reread poets you admire, read about them and then read the poets they get compared to.

Link

(via Electrolite)

2.  TheyRule: applying information design to corporate directorships. TheyRule is a brilliant Flash app that allows you to interactively explore and map the interlocking directorships of the most powerful corporations in the world. They've just relaunched a 2004 edition with currect data.

They Rule allows you to create maps of the interlocking directories of the top companies in the US in 2004.

The data was collected from their websites and SEC filings in early 2004, so it may not be completely accurate - companies merge and disappear and directors shift boards.

Link

(via Oblomovka)

3.  Blogger redesign notes. Blogger has relaunched today, with standards-compliant templates, comments with spamblocking, streamlined blog creation, and page-per-post -- the kind of things that we've come to expect from a modern blogging tool. The redesign was executed by the arch-geniuses of Stopdesign and Adaptive Path, and it shows. This is a beautiful redesign, both in terms of look-and-feel and approachability for novices. Here're project leader Doug Bowman's notes on the redesign:

The rounded corners seen throughout the Blogger redesign (and in several of the user templates) make use of an expansion of the Sliding Doors technique written for A List Apart last year. The Blogger design is a fixed width, which means most of the modules of the site exist at pre-defined widths. Since the width of each module is known, one image is used for the top-left and top-right corners of a module, and another image is used for the bottom-left and bottom-right corners. The images are called in as background images for two nested elements. Since these two elements contain all the text of the module, they expand infinitely as the module grows in height. Think of it as Sliding Doors turned on their sides.

For modules requiring a border, the two images are modified to include top and bottom borders connecting the two corners. A third element gets nested in the HTML that uses left and right borders which connect top and bottom corners.

This design posed many other challenges when building it out, specifically because we wanted to allow the text and each of the design elements (header, modules) to be as flexible and scalable as possible. The markup construction was tricky and required compromises in several places. As is evident with the rounded corner modules, extra divs were necessary for each background image called in. In CSS3, border images will certainly help eliminate the need for extra elements. And I’ve been pressuring Tantek to get the CSS Working Group to consider allowing us to set multiple background images on one HTML element.

Link

(via EvHead)

4.  Japan jails academic for writing P2P app. A Japanese academic who wrote an anonymous P2P app has been arrested for "abetting infringement." This is the kind of perversion of justice we're accustomed to seeing in the US and Norway -- disappointing that the Japanese have so thoroughly bridged the copyright hysteria gap. The programmer faces three years in prison for writing code that allows for anonymous file-transfers. We can only hope that the team that led Microsoft's operating-system effort will be next, followed by the AppleShare team and the pesky authors of ftp.

Mr Isamu Kaneko, a 33-year-old assistant professor at the prestigious University of Tokyo, was arrested on suspicion of developing and offering free downloads on his Web site file-sharing software called Winny, Kyoto Prefectural (state) police said on condition of anonymity.

He is also accused of helping two Japanese men arrested in November on charges of disseminating movies and games on the Internet with Winny, police said.

Link

(via /.)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
5.  Minidrives to make big splash. By the end of the year, diminutive hard drives are going to start to become downright common, thanks to planned releases of portable music players and video cameras.
6.  Google preps new tool to juice revenue. The search engine giant plans a keyword service that will let advertisers automatically tap obscure terms and phrases, CNET News.com has learned.
7.  Makers of white-box supercomputers hit their stride. The growing popularity of Linux is making smaller companies such as Linux Networx, California Digital and Optimus household names among buyers of supercomputers.
8.  Google's man behind the curtain. Craig Silverstein is director of technology at Google, which, these pre-IPO days, may very well be the search company's most important job.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
9.  Hollywood at the controls (USATODAY.com). USATODAY.com - Vin Diesel is hoping for two blockbusters this summer: One is his Chronicles of Riddick, the special-effects-laden sci-fi sequel to his 2002 movie Pitch Black. The other is the Chronicles of Riddick: Escape From Butcher Bay Xbox video game that premieres just before the June 11 movie.
10.  Yahoo focuses on 'integrating the network' (USATODAY.com). USATODAY.com - In the newest version of Yahoo's instant-messenger program, users can do a lot more than chat. From the little Yahoo Messenger screen, subscribers can access online radio, stock quotes, news and weather, games and online searches.
11.  HP to Launch Built-To-Order Gaming PC (Reuters). Reuters - Seeking to take advantage of the fast-growing video game market, Hewlett-Packard Co. on Monday said it would begin to offer built-to-order custom personal computers for game enthusiasts.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
12.  Salesforce.com: Another Valley IPO
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
13.  Sony US music service an 'embarrassment'. Too many wrongs, too few rights By Tony Smith .
14.  PalmOne Zire 31. Reg Review Colouring the consumer PDA market By Tony Smith .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
15.  New password stealing Trojan discovered
16.  BigPond still coy about Sasser impact
17.  ACA, AHTCC team up to fight spam
18.  FreeBSD healthd Local Overflow
19.  Seven Security Technologies To Watch
20.  Fortifying PDF documents
21.  The buck stops at the top
22.  Finding chinks in the armor
23.  Problème sur le CD d'installation de S.u.S.E. LINUX 9.1 Personal Edition
24.  Problème de permission de l'antivirus Trendmicro OfficeScan dans ses versions antérieures à la 6.5
25.  Sasser-Programmierer in Deutschland festgenommen
26.  SPRING 2004 ISSUE AVAILABLE
27.  Saftware DE: Backup of the Nokia 6310i [and Ericsson T610, T68i] via Bluetooth "plug'n'play, no ...
28.  Apple responds to Trojan Horse Advisory (MacCentral)

7:19:34 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Sumitomo Elec to Market Superconductive Wire (Reuters). Reuters - Sumitomo Electric Industries Ltd said on Monday it would soon start mass production of cost-competitive, superconductive wire capable of transmitting 130 times the electricity deliverable by a normal copper wire.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Winny P2P Software Creator Arrested
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Football fans get phone action. Football fans will be able to follow all the action from Euro 2004 on their mobile phones.
4.  Games jamboree hits Los Angeles. The latest hardware and software developments in video gaming are showcased at E3 in Los Angeles.
5.  Web worm tests network security. More serious security problems could follow in the wake of the Sasser worm, say experts.
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
6.  Microsoft bangs the 64-bit drum. Microsoft used its annual WinHEC (Windows Hardware Engineering Conference) last week to get aggressive about 64-bit computing.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  Sony unveils tiny wireless pen PC. Reg Kit Watch Look, ma, no keyboard By Tony Smith .
----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
8.  Sasser Worm Suspect Confesses. German police have arrested an 18-year-old man suspected of creating the Sasser computer worm. Police say he may have produced the Nevsky virus and be connected to the Skynet group of virus-writers.
9.  Cost of Airport Security Tech. Officials are weighing the expense of better technologies for screening airline passengers against the business costs of travel delays. More efficient systems are in place at a few airports, but who pays for upgrades at others?
10.  E3, the Sequel: Video Game Expo. The suspense that usually accompanies a major gathering of the video game industry is watered down as the Electronic Entertainment Expo gets underway in Los Angeles this week. It's all about sequels.
11.  Endless Summer, on Demand. Kerry Black is bringing world-class waves to the malls of America. Grab your board -- surf's up 6 a.m. to midnight, 365 days a year. By Carl Hoffman from Wired magazine.
12.  On-Demand Games a Phantom No More. The long-awaited Phantom Gaming Service -- which lets customers rent or buy PC games online -- will go on sale in November. Infinium Labs hopes to attract 'lapsed' gamers who don't have time to cruise the aisles at the mall. By Kourosh Karimkhany.
13.  Blood Feud Kills Off Fat Cells. Cancer researchers looking for a way to kill tumors found a way to knock off fat cells in mice, cutting off their blood supply with a peptide. By Kristen Philipkoski.
14.  EBay's Growth Just Beginning. Meg Whitman, eBay's chief executive, says the company has more international and small-business markets to tap. And it's weighing in on issues like taxation and stock-option expensing. Michael Grebb reports from Washington, D.C.
15.  Climate Change Out of the Blue. Contrails -- those wispy trails left in the sky by airplanes -- may play a part in warmer U.S. temperatures, according to a recent NASA study. By Douglas Page.
16.  When Old Convictions Won't Die. Private employee-screening companies cobble together national databases for criminal background checks, and job applicants lose out on work due to crimes -- including expunged convictions -- they thought were not traceable. By Joanna Glasner.

6:19:16 AM    comment []

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  Ebookers' sales up but jobs to go. The internet-based holiday company says first-quarter sales are up nearly 50% but adds it is to shed jobs in Europe and India.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
2.  German police arrest Sasser worm suspect. Alleged Phatbot perp also nabbed By John Leyden .
3.  (Almost) everything may go, as Longhorn rushes to release. Rearranging the wish list By Andrew Orlowski .
4.  AMD to parade Socket 939 at Computex. Chips to be shown at show shock By Tony Smith .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  OpenSSL ASN.1 Parser Invalid Encoding DoS
6.  OpenSSL Kerberos SSL/TLS Handshake DoS
7.  OpenSSL SSL v2 Client Master Key Overflow
8.  OpenSSL TLS Infinite Loop DoS
9.  MyWeb HTTP GET Request Overflow DoS
10.  German Teenager Admits To Creating Sasser Worm (TechWeb)

5:18:55 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 10 May 2004.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  CA's Interim CEO Not Seeking Full-Time Post (TechWeb). TechWeb - Ken Cron, who stepped in after Sanjay Kumar was reassigned last month, says the software vendor is in no rush to name a full-time CEO--but that he's not a candidate for the job.
3.  SCO Investor Retreats (TechWeb). TechWeb - The software maker says Royal Bank of Canada has sold two-thirds of its investment in the company, which is fighting a legal battle to get licensing fees from Linux users.
4.  Wi-Fi Phones Could Be Next Money-Saver In Telecom (TechWeb). TechWeb - With hot spots turning into "hot zones," the next wave may be drawing near--phones and gear that send conversations over wireless Internet networks for little or no cost.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
5.  Ebookers sales up but jobs to go. The internet-based holiday company says first-quarter sales are up nearly 50% but adds it is to shed jobs in Europe and India.
6.  Google revamps blogging service. One of the leading names in blogging is overhauling its service in an attempt to catch up with rivals.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Book Review: Malicious Cryptography
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  Intel launches Dothan with Pentium M price cuts. The 90nm 7xx series ships at last By Tony Smith .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
9.  Watchdogs Push for RFID Laws
10.  ACLU Says No Go to No-Fly List
11.  Sasser-Wurm: 18-Jähriger aus Niedersachsen festgenommen
12.  Sasser-Autor entwickelte auch Netsky
13.  Sicherheitsloch in Eudora gestattet Programm-Ausführung
14.  Sasser: 18-Jähriger gesteht – weiterer Virenautor verhaftet
15.  Soldier will seek trial in Colorado
16.  Book Review: Malicious Cryptography

4:18:35 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Govt. Web Sites That Could Aid Terrorists (AP). AP - Rand Corp. researchers preparing a study for the National Geospatial Intelligence Agency found four federal government Web sites they believed might aid terrorists enough to warrant restricting public access to them. All four have been restricted.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  2ch: Japanese Web Forum As Social Vent
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  Vulns: Exim Sender Verification Remote Stack Buffer Overrun Vulnerability. Exim has been reported prone to a remotely exploitable stack-based buffer overrun vulnerability. X-NAS-Bayes: #0: 2.12279E-062; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 586 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

This is exposed if sender verification has been enabled in the agent a...

4.  Vulns: Exim Header Syntax Checking Remote Stack Buffer Overrun Vulnerability. Exim is reportedly prone to a remotely exploitable stack-based buffer overrun vulnerability.

This issue is exposed if header syntax checking has been enabled in the ag...


3:18:16 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Rambus tries a new licensing angle. The memory designer, which is suing manufacturers over their use of DDR memory, is now marketing technology that will help chipmakers adopt it.
2.  Windows Media Center continues overseas march. Microsoft plans to announce on Monday that its Media Center OS is moving into new countries, even as the software maker works to make it more ready for prime time.
----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
3.  For Google, Going Dutch Has Its Rewards and Its Risks. There may be pitfalls as well as opportunities in Google's proposed stock auction, both for investors and the company. By Saul Hansell.
4.  I.B.M. Takes Aim at Microsoft With Server-Based Software. I.B.M. plans to announce a software strategy for corporate desktop personal computers and hand-held devices - one that is firmly anchored in the company's strength in data centers. By Steve Lohr.
5.  New Undersea Cable Projects Face Some Old Problems. It has been several years since executives in the undersea cable industry had anything to cheer about, but a new cable project is under way. By Ken Belson.
6.  Video Fantasy Replaces Mozart (But Who's Keeping Score?). The Los Angeles Philharmonic beckons a new audience with its performance of music from the video game "Final Fantasy" on Monday. By Matthew Mirapaul.
7.  Illuminating Blacked-Out Words. Researchers at a conference in Switzerland have demonstrated computer-based techniques that can identify blacked-out words and phrases in confidential documents. By John Markoff.
8.  Cellphone Tax Produces Little for Cellphones. Little of the $440 million collected by New York State for a 911 cellphone service has actually gone to the program. By Edward Wyatt.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
9.  Three forces mobile rivals into cuts (FT.com). FT.com - The UK's established mobile operators have started to cut voice tariffs for their existing customers in response to growing competition from Three, the mobile operator pioneering services such as live video calls.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
10.  Google revamps blogging service. One of the leading names in blogging is overhauling its service in an attempt to widen its appeal.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  New Sasser Worm FTP exploit
12.  Microsoft reward snags suspected Sasser author
13.  'Modded' consoles sneak into Xbox Live
14.  9 May W32/Sasser-E
15.  In photos: Security experts, vendors face off on e-voting
16.  ITAA blasts e-voting critic, calls testimony 'misleading'
17.  Sasser outbreak demonstrates need for quick patch response
18.  Howard Schmidt opts out of bid for Congress
19.  Proposed bill seeks stronger privacy protection for offshore work
20.  Sasser worm suspect confesses to German police
21.  FreeBSD and NetBSD iBCS2 Kernel Memory Disclosure
22.  FreeBSD Invalid Signal Number DoS
23.  FreeBSD Invalid Signal Number Kernel Memory Modification
24.  FreeBSD realpath() Overflow
25.  e107 Login Name/Author Cross-Site-Scripting Vulnerablilty
26.  Police: Sasser suspect confesses
27.  Prison time for cyber stock swindler
28.  Sasser ups cost of Windows - Gartner
29.  Wi-Fi security standard to require new hardware
30.  Net watchers wary of Sasser fallout
31.  Quantum crypto gets a speed boost
32.  US falls hook, line & sinker for phishing
33.  Longhorn will feature 'secure' components
34.  Could a Worm on Mac or Linux Ever Get Traction?
35.  Microsoft reward snags suspected Sasser author
36.  Australian scientists claim breakthrough in teleportation
37.  A Quick Look at the Latest Longhorn Build
38.  Fixed-line texting is the next big thing, says report
39.  SARS may be spread by sweat

2:17:56 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Tiny theater in a box showcases the Bush administration doing the thing it does best. Bush admin. peep showArtist Mars Tokyo has created a 3" x 4" peep box entitled "The Theater of the Liars" featuring George W. Bush, Donald Rumsfeld, Dick Cheney, Paul Wolfowitz, and Colin Powell. Link (Thanks, s. mericle!)
2.  Music Plasma -- visual music search is pretty amazing. This visual music search engine lets you type in the name of an artist and it displays related artists. I thought I'd stump it by entering "Robert Crumb" (the cartoonist, who used to play tenor banjo in one of my favorite bands, The Cheap Suit Serenaders). I'll be damned if Music Plasma didn't display my very favorite musicians right next to his name. Link (Thanks, Anthony!)
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  IBM plans Web-based desktop software. Big Blue on Monday is expected to announce new software intended to take on Microsoft in the market for desktop business applications.
4.  Google polishes up Blogger site. Google plans to introduce on Monday a redesigned Web site for its personal publishing tool, Blogger.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  ExtremeTech Reviews Google's Gmail Beta

12:24:34 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 6/1/2004; 12:29:10 AM.
This theme is based on the SoundWaves (blue) Manila theme.
May 2004
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Apr   Jun