Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Tuesday, May 11, 2004
 

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Nextel Says Compromise Won't Work (washingtonpost.com). washingtonpost.com - Nextel Communications Inc. yesterday told the Federal Communications Commission it won't accept a compromise being discussed by the commission, which has spent more than two years trying to find a way to minimize cellular call interference with public safety communications.
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
2.  Google Blog vs. Google Weblog. Time for a PageRank showdown.
3.  Continuing their strategy of selling Exchange Server licenses, Ximian/Novell released the Evolution Exchange Connector under the GPL.
4.  ThinkPad T42, sweet. But if you have to ask, you can't afford it.
5.  Looks like the new "Dothan" Pentium M can easily overclock to 2.4 GHz and compete with desktop CPUs.
6.  "We will firewall Napster at source - we will block it at your cable company, we will block it at your phone company, we will block it at your [ISP]. We will firewall it at your PC." --Sony
7.  Broadcom Announces BroadSAFE Security, Enabling More Secure Networks Through Strong Identity and Key Management Capabilities.
8.  Trusted Computing Group Developing New, Open Trusted Network Connect Specification to Ensure Endpoint Integrity.
9.  Last week Jon Johansen cracked the new version of Apple's FairPlay DRM and now a new version of PlayFair (renamed to Hymn) is out.
10.  GameSpot: Sony gives glimpse of PS3 processor at E3. "[Sony] will manufacture a high-end workstation using the Cell CPU. Planned for release at the end of 2004, the workstation will use the CPU's capabilities to provide users with the tools for complex rendering, physics, modeling, behavior, rendering, and analysis." Hopefully it won't go the way of the GScube.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Help and Support Center Remote Code Execution (MS04-015)
12.  Combating Internet Worms
13.  wallon.a (di rupo maybe)
14.  W32.Wallon.A@mm
15.  FreeBSD getnameinfo Function Long Hostname DoS
16.  FreeBSD Multiple System Call Integer Signedness Memory Access
17.  FreeBSD syncache/syncookie TCP Socket DoS
18.  CuteNews comments.php cutepath Variable Arbitrary Command Execution
19.  CuteNews search.php cutepath Variable Arbitrary Command Execution
20.  CuteNews shownews.php cutepath Variable Arbitrary Command Execution
21.  FreeBSD /etc/rc Symlink Delete Arbitrary File

11:24:28 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Wet Magazine scans from 1978. wet Wet was a graphically innovative magazine that predated zines. I remember seeing some copies in the early 80s and liking the design a lot. The guys who made Wet later went on to write the Graphic Design Cookbook, which I used as inspiration for the print edition of bOING bOING. Designer Jennifer Sharpe (daughter of famed street prankster Mal Sharpe) has uploaded two complete issues to her site. Link (Thanks, Sean!)
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Google blog somewhat less than 'bloggy'. The search king and Blogger owner debuts a company Web log that promises "regular, bloggy things." But a post on Google's recent expansion to India is apparently a bit too offhand.
3.  Apple wins iTunes interface patent. The Mac maker wins a patent for the interface of its iTunes music software, underscoring the growing importance of the multimedia business for the company.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Canon to Pull Out of Analog Camcorders (Reuters). Reuters - Japanese camera and office equipment giant Canon Inc said on Wednesday it would pull out of the analog camcorder business this year and focus on the growing market for digital video cameras instead.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  FireWire Gets Ready to Go Wireless
6.  Cisco Applies For Patents To Secured TCP
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  Sulphur fuels battery breakthrough. Queue here for Li-S By Andrew Orlowski .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  [ GLSA 200405-03 ] ClamAV VirusEvent parameter vulnerability

10:24:07 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Market share key to Microsoft's Wi-Fi exit. The software giant's decision to dump its wireless networking gear business came amid sliding market share and profit margins, analysts say.
2.  No ruling yet on Novell-SCO suit dismissal. The federal judge hearing the case sets no date to decide on Novell's motion to dismiss the SCO Group's slander suit.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Life-Ruining Browser Hijackers
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
4.  IBM looks to modernize Cobol. IBM is looking to modernize Cobol applications by bridging its mainframe-oriented Cobol and WebSphere products to EJB and service-oriented architectures.
5.  Judge hears arguments in Novell-SCO suit. A federal judge heard arguments from Novell Inc. and The SCO Group Inc. in a Utah court Tuesday in the "slander of title" case brought by SCO against Novell last January.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
6.  BugTraq: [ GLSA 200405-03 ] ClamAV VirusEvent parameter vulnerability. Sender: Thierry Carrez [koon at gentoo dot org]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Full Disclosure: Locking up Internet Explorer "Restarting IE is required after clicking on the l...
8.  Security Tracker: Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's ...
9.  Microsoft patches new Windows flaw
10.  New Sasser variant indicates copycat script kiddie
11.  Re: NISCC Vulnerability Advisory 236929: Vulnerability Issues in TCP
12.  Re: a litle bypass with IE
13.  Text of Taguba's opening remarks
14.  Sasser Author Comes Clean (NewsFactor)
15.  FreeBSD brouted Multiple Local Overflow
16.  11 May W32/Wallon-A
17.  Óäàëåííîå èñïîëíåíèå êîäà â Help and Support Center
18.  HTML_WALLON.A
19.  [ GLSA 200405-04 ] OpenOffice.org vulnerability when using DAV servers
20.  Orange County Hacker Alters Grades
21.  Microsoft Warns of 'Important' Windows Flaw (Reuters)
22.  Yet another Sasser worm appears
23.  April shower of Microsoft vulnerabilities ends in May

9:23:48 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Sun completes 'Niagara' chip design. Sun Microsystems has completed the design of its Niagara processor, a crucial product in the server maker's effort to keep its own UltraSparc chip family competitive, a source familiar with the project says.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Intel's Dothan Debuts (NewsFactor). NewsFactor - Intel (Nasdaq: INTC) has launched three new Pentium M processors -- the first mobile chips built on the chip giant's 90-nanometer fabrication technology -- designed to improve the performance of its Centrino line. Centrino has proven to be very successful, says IDC analyst Roger Kay, noting that it now comprises some 28 percent of Intel's sales volume.
3.  Xbox to Get Online Video-Phone Upgrade (AP). AP - Users of Microsoft Corp.'s Xbox Live online gaming network can already talk to each other remotely while logged in — but soon they'll be able to see their fellow players' faces and "tickle" each other, too.
4.  Microsoft Warns of 'Important' Windows Flaw (Reuters). Reuters - A flaw in Microsoft Corp.'s (MSFT.O) almost universally used Windows operating system could allow hackers to take control of a PC by luring users to a malicious Web site and coaxing them into clicking on a link, the company warned on Tuesday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  The Ultimate All-In-One Storage Solution
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
6.  BugTraq: [ GLSA 200405-04 ] OpenOffice.org vulnerability when using DAV servers. Sender: Thierry Carrez [koon at gentoo dot org]
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  Novell opens GPL bridge to MS Exchange. But Redmond dues still payable By Andrew Orlowski .

8:23:27 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Judge ties antispammer's hands. SpamCop is issued a temporary restraining order that prevents it from interfering with messages sent by an alleged junk e-mailer. Industry watchers express concern.
2.  Report: DSL growth best ever. DSL providers added the greatest number of new residential customers in history last quarter but only marginally gained market share against cable rivals, says a new study.
3.  Networking industry looks ahead. As the NetWorld+Interop show gets under way, MCI's chief talks up the appeal of Internet Protocol.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Phone Switching Delays Likely in U.S. Rural Areas (Reuters). Reuters - Phone subscribers in many U.S. rural areas may not be able to keep their old numbers when switching their home phone to a wireless service later this month, because local companies are trying to delay adoption of new rules, a regulatory official said on Tuesday.
5.  MCI Envisions Online Future (PC World). PC World - Deal to offer Live Office via MCI Net is a hint of things to come, Capellas says.
6.  Nintendo Unveils New Handheld, Next Console Coming (Reuters). Reuters - Japanese video gamemaker Nintendo Co. Ltd. (7974.OS) on Tuesday took the wraps off its new handheld game machine with two screens in a bid to fend off Sony Corp's (6758.T) entry into the portable gaming market.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  E3 - Nintendo Shows DS Details, Realistic Zelda
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
8.  Internet giant's profits up 23%. Technology heavyweight Cisco Systems reports third quarter rises in profits and sales topping 20%.
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
9.  Virus arrests continue, as do worms
10.  Sasser copycats get busy
11.  Microsoft corrects: no XP SP2 for pirated copies
12.  RSA founders give perspective on cryptography
13.  Analyst: security woes add to Windows cost
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  MDKSA-2004:043 - Updated apache2 packages fixes a denial of service vulnerability in mod_ssl
15.  Linux Kernel sctp_setsockopt() Integer Overflow
16.  ISS Targets SMBs With Managed Security Service
17.  Sasser worm creator apparently programmed new version shortly before arrest (Canadian Press)

7:23:07 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Best Ghostbusters prop replica EVAR. X-NAS-Bayes: #0: 2.58994E-200; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 653 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

This guy spent six months building this elaborate replica Ghostbusters pack, with powered blinkenlights and a multicolored flashlight cannon and lots of other swell features, and now he's selling it on eBay. Don't miss the video and build-diary!

Link

(via Gizmodo)


----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Microsoft patches new Windows flaw. The software company says the security hole, which could enable an attacker to remotely execute malicious code, poses an "important" risk.
----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
3.  Cisco Reports Strong Quarterly Results. Cisco reported stronger-than-expected results for its fiscal third quarter today as corporate demand for networking gear improved. By The Associated Press.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Sony, IBM Partner for Digital Media Workstations (Reuters). Reuters - Sony Corp. (6758.T) and IBM Corp. (IBM.N) on Tuesday said they would work together to develop computer workstations for creating advanced digital content like movies and video games, running the secretive "Cell" processor that they have jointly designed.
5.  Netflix Stock Up on Recent Subscriber Growth (Reuters). Reuters - Shares of Netflix Inc. (NFLX.O) gained 9 percent by midafternoon on Tuesday following a recent round of analyst research and reports of continued subscriber growth at the online DVD rental service.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  The Confusion
7.  Privacy in the Woods?
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
8.  MCI's Capellas looks to all-IP future. LAS VEGAS - MCI Inc.'s Web conferencing offering with Microsoft Corp. introduced Tuesday is just the beginning of a move to let users make PCs into phones, MCI President and Chief Executive Officer Michael Capellas said in a keynote address Tuesday at the Networld+Interop conference in Las Vegas.
9.  Lieberman calls for new outsourcing ideas. WASHINGTON - The U.S. government needs to address recent growth in offshore outsourcing with new ideas, including wage-loss insurance paid for by companies that use offshore outsourcing, and a bipartisan commission focused on ways the U.S. can remain competitive despite lower wages offered by other nations, U.S. Senator Joe Lieberman said Tuesday.
10.  Gateway fires back at HP while Q1 net loss widens. In separate patent-related announcements, Gateway Inc. said Monday its first-quarter loss was about $6 million wider than it had reported, and that it has filed several counterclaims against Hewlett-Packard Co. (HP) in a patent lawsuit between the two companies.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
11.  Steady Cisco posts strong Q3 results. Sales on the up and up By Ashlee Vance .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  RE: a litle bypass with IE
13.  MDKSA-2004:042 - Updated rsync packages fixes potential to write outside of directory tree.
14.  [SECURITY] [DSA 502-1] New exim-tls packages fix buffer overflows
15.  Re: Somebody exploiting (badly designed) yahoo service?
16.  Solaris pam_ldap Authentication Module NULL Password Bypass
17.  CNet: Holy security wars
18.  FCW: NIST suggests VoIP caution "IP telephony, or voice over IP, poses significant security prob...
19.  ZDNet: Author leaves warning in latest Sasser worm "Antivirus companies discovered a fifth versi...
20.  Business 2.0: Hacking the Xbox "What open-source enthusiasts can teach Microsoft about unlocking...
21.  The Register: MS spells it out - pirates can, can't install WinXP Sp2
22.  The Register: Talking capacitors could blab to code breakers "The sounds made by capacitors on m...
23.  Zone-H Defacement: hq.cnrf.navy.mil
24.  About-Netsecurity: Why You Should Encrypt Your Email "And Some Tips For How To Do It"
25.  PC Magazine: Symantec Anti-virus Corporate Edition "The business version of Symantec's well know...
26.  PC Magazine: Group Test - Corporate Anti-virus Tools - Editor's Choice
27.  Customer Highlights and Technology Innovation Fact Sheet: Fiscal Year 2004 Third Quarter
28.  Help and Support Center Remote Code Execution (MS04-015)
29.  Understanding TCP Reset Attacks, Part I

6:22:48 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Fast DSL: when will it hit the US market?. A Nortel Networks executive claims that competitive pressures will lead telcos to make the infrastructure improvements necessary for 20Mbps DSL. Is he right? By Eric Bangeman.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Feebs' security advisory about kingpin who turns out to be a video-game character. The FBI issued a terrorist warning after receiving a tip on an evil millionaire -- who turned out to be a character in a video game. X-NAS-Bayes: #0: 7.18615E-214; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 652 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

It was the lead item on the government's daily threat matrix one day last April. Don Emilio Fulci described by an FBI tipster as a reclusive but evil millionaire, had formed a terrorist group that was planning chemical attacks against London and Washington, D.C. That day even FBI director Robert Mueller was briefed on the Fulci matter. But as the day went on without incident, a White House staffer had a brainstorm: He Googled Fulci. His findings: Fulci is the crime boss in the popular video game Headhunter. "Stand down," came the order from embarrassed national security types.

Link

(via Lawmeme)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  Eolas strikes back; Microsoft prepares appeal. The University of California and Eolas file a response to the U.S. Patent and Trademark Office, two months after the office issued a rare re-examination of the Eolas browser patent that has Microsoft scrambling.
4.  Infravio spiffs up Web services registry idea. In an effort to set itself apart in the immature Web services management field, Infravio is releasing a product that it calls a Web services marketplace for finding available services and controlling their use.
5.  Sony cuts PlayStation price to $150. At the E3 game conference in Los Angeles, the entertainment giant also talked about its upcoming handheld game player and the Cell processor it is developing with Toshiba and IBM.
----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
6.  Congress Looking at 'Video Voyeurism'. Lawmakers want to make taking surreptitious photos and other illicit uses of video technology a federal crime punishable by up to a year in jail. By The Associated Press.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  Cisco Posts Profit, But Shares Slip (Reuters). Reuters - Cisco Systems Inc. on Tuesday posted higher quarterly profit on rising demand among corporate customers for its networking gear, but shares fell in after-hours trading as investors had hoped for even stronger results.
8.  Microsoft Asks Court to Fine Lindows Again (PC World). PC World - Software giant says Web site still displays Lindows name.
9.  23 percent profit jump for Cisco (AFP). AFP - Strong demand for wireless networks and Internet telephony helped drive Cisco Systems' profit higher by 23 percent to 1.2 billion dollars in the most recent quarter, the company said.
10.  Activision, Id Set Summer Launch for 'Doom 3' (Reuters). Reuters - Video game publisher Activision Inc. (ATVI.O) and games developer id Software on Tuesday said that the highly anticipated game "Doom 3" will be released this summer.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
11.  E3 - Sony Drops PS2 To $149, Shows PSP, Hints At PS3
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  BugTraq: Linux Kernel sctp_setsockopt() Integer Overflow. Sender: Shaun Colley [shaunige at yahoo dot co dot uk]
13.  BugTraq: Re: Somebody exploiting (badly designed) yahoo service?. Sender: Charles Mansmann [charles dot mansmann at mail dot tju dot edu]
14.  Vulns: Adam Webb NukeJokes Module For PHP-Nuke Multiple Input Validation Vulnerabilities. Adam Webb NukeJokes is a freely available module for PHP-Nuke. PHP-Nuke is a popular open source web based content management system.

It has been reported that the Nuke...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
15.  Microsoft Issues Just One Patch For May
16.  11 May W32/Agobot-IJ
17.  sasserftpd.c
18.  monit41.pl
19.  Microsoft patch voor kritiek lek in Windows XP / 2003
20.  Sasser F blames it on Bill
21.  PING: Outlook 2003 Spam
22.  Somebody exploiting (badly designed) yahoo service?
23.  W32.Gaobot.AJD
24.  Slashdot | Cry To Beat Iris Scanners
25.  Cry to beat iris scanners
26.  Top Port: www 80

5:22:27 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Sony PSP shots from E3 via Gizmodo. Joel Johnson says the first Sony PSP shots from E3 are now up on Gizmodo, and promises much more soon. Such a tease. Link
2.  Sonic fabric dress -- wearable music instrument. BoingBoing reader Michael Corrado points us to a website featuring...
Fabric made from woven audiotape, readable by gloves containing tape heads. Dress made for Jim Jon Fishman of Phish, which composed song about dress's debut. Fishman used dress to create music next night. Vegas, May 2004
Link

Update: BoingBoing reader Gary writes, "If you want to hear the results yourself (nothing too impressive ... yet), you can go here and download the concert (during the performance of "Love You"). You might also be pleasantly suprised that Phish is happy to transmit full soundboard quality with no DRM."

3.  New deck for digital DJs. sl-dz1200 Finally, Technics has caught up with (and passed?) Pioneer in the CD-DJ arena. The SL-DZ1200 has the look-and-feel of Technics 1200s, the vinyl workhorse for DJs, but also includes digital features like looping and an SD card slot for MP3 playback. I'll take two please. Link
4.  Tarantino endorses Chinese Internet piracy of Kill Bill. Quentin Tarantino thinks that Internet movie piracy isn't all bad: X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 651 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

In the case of China, I'm glad they're pirating [Kill Bill]. In a closed Communist country I'd rather be seen than not seen.

Link

5.  Hugo nominated fiction online. Here's a list of this year's Hugo Award nominees, with links to the full text of the nominated works for those that are online (all the short works but one are on the Web! None of the novels, though).

Link

6.  OS X Spir-o-graph painting app.

Cosmic Painter is a GPLed MacOSX application that allows you to paint on a "spinning" canvas, screating a Spir-O-Graph-like effect, which is then animated. The results are, well, trippy. I just fell down a rabbit hole looking at and playing with the samples.

Link

(Thanks, FunWithStuff!)


----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
7.  Capellas: Net telephony is the future. MCI chief Michael Capellas tells an Networld+Interop crowd that the post-bankruptcy carrier is banking on the Internet Protocol and similar technologies as it rebuilds itself.
8.  Reuters picks up RSS syndication technology. The format lets Web sites and bloggers receive free feeds of Reuters.com headlines and republish one-line descriptions of stories.
9.  Novell extends open-source push. For the second time, the company has released the source code of a once-proprietary software package that makes it easier to substitute Linux for Microsoft's Windows.
----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
10.  Electronic Arts Embraces Xbox Live. The market-leading game publisher says it will bring its games, including the "Madden" football franchise, to Microsoft's online service. By David Becker, Staff Writer, Cnet News.com.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
11.  Single New Security Alert From Microsoft For May (Ziff Davis). Ziff Davis - Windows XP/2003 Help system could execute attack code. In contrast to last month's flood of severe problems, a single "Important" vulnerability in some Windows versions, and re-released of two previous ones.
12.  Netflix Stock Up on Recent Subscriber Growth (Reuters). Reuters - Shares of Netflix Inc. (NFLX.O) gained 9 percent by midafternoon on Tuesday following a recent round of analyst research and reports of continued subscriber growth at the online DVD rental service.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
13.  Evan Williams Posts Official Google Blog
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
14.  April shower of Microsoft vulnerabilities ends in May. BOSTON - April showers brought May flowers, at least that appears to be the story from Microsoft Corp. on the issue of software security vulnerabilities.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
15.  Yet another Sasser worm appears. A new version of the Sasser Internet worm, Sasser-F, appeared on Monday, despite claims by German authorities to have arrested the sole author of that worm on Friday.
16.  April shower of Microsoft vulnerabilities ends in May. BOSTON - April showers brought May flowers, at least that appears to be the story from Microsoft Corp. on the issue of software security vulnerabilities.
----------------------------------------------------------------------
O'Reilly Weblogs
----------------------------------------------------------------------
17.  Bruce Schneier on Security Tradeoffs. Bruce Schneier: we need to weigh the costs vs. the benefits of measures taken to ensure our security. "Much of what is being proposed as national security is a bad security trade-off. It's not worth it, and as consumers we're getting ripped off."...
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
18.  BugTraq: MDKSA-2004:043 - Updated apache2 packages fixes a denial of service vulnerability in mod_ssl. Sender: Mandrake Linux Security Team [security at linux-mandrake dot com]
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
19.  DMCA challenge to be considered this week
20.  Lottery scams new flavour of the month
21.  Why computer security's so primitive
22.  Spec in works to secure wireless networks
23.  Understanding TCP reset attacks
24.  Customize this feed. Add more items, descriptions, time stamps, select your version of RSS, aggregate several feeds... Check out NewsIsFree's premium syndication services!
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
25.  Microsoft Windows Help and Support Center URL Validation Vulnerability
26.  Elsewhere: Tech Players Push for Anti-Virus Spec
27.  Elsewhere: Symantec stops frustrating virus-notification alerts
28.  Microsoft Windows Help and Support Center URL Validation Vulnerability
29.  Extended Enforcement
30.  The Latest from Las Vegas
31.  Brocade Plugs into BladeCenter
32.  CyberFusion 5.5
33.  Single New Security Alert From Microsoft For May

4:22:08 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  PC gaming convergence rears its head at E3. Consoles are hot right now, and others are desperately hoping to get in on the party. The ever-so-litigious Infinium Labs has announced a November 18th release date for their PC-based gaming console, the Phantom. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  IBM switches on Brocade for blade servers. Brocade Communications Systems is set to offer two Fibre Channel switches that fit into IBM BladeCenter server enclosures, giving Big Blue's blades another way to access storage area networks.
3.  Start-up brings Net telephony to cell phones. A new gadget from i2 Telecom allows cell phone users to tap into VoIP technology.
4.  E3 play-by-play. The Electronic Entertainment Expo gaming conference gets under way in Los Angeles with Sony trimming the price tag on its PlayStation 2. Also: A groundswell of gamers.
5.  Wireless photos, video hit some static. New U.S. guidelines meant to free up wireless e-mails with attached photos and videos are getting a mixed reception from carriers.
6.  Microsoft, Lindows face off in Dutch court. Microsoft is demanding the open-source software company be hit with a fine in excess of $100,000 per day for allegedly infringing on the Windows trademark.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  HEI Leaps on Erroneous Google Ownership Report (Reuters). Reuters - HEI Inc. (HEII.O) shares jumped nearly 40 percent early on Tuesday after the maker of microelectronic and software systems was incorrectly identified in a news report as holding warrants in Internet search engine Google Inc.
8.  Sony, IBM Partner for Digital Media Workstations (Reuters). Reuters - Sony Corp. (6758.T) and IBM Corp. (IBM.N) on Tuesday said they would work together to develop computers for creating movies and video games, running the secretive "Cell" processor they have jointly designed.
9.  Al Qaeda Leader Beheads U.S. Civilian, Web Site Says (Reuters). Reuters - Al Qaeda's leader in Iraq beheaded an American civilian and vowed more killings in revenge for the abuse of Iraqi prisoners, an Islamist Web site said Tuesday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
10.  Bitkeeper News Redux
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
11.  Macromedia links Breeze to directories. Macromedia this week began shipping “solution accelerators” for the Macromedia Breeze Web-based collaboration system, which feature sample code and documentation to integrate Breeze functionality with a user’s existing directory services, intranet applications, and portal pages.
12.  If you host it they will come, say CRM vendors. The online CRM space is suddenly getting crowded as two more CRM vendors, Kana and Entellium, are launching hosted services this week.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
13.  Understanding TCP Reset Attacks, Part I
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
14.  Elsewhere: Symantec stops frustrating virus-notification alerts. They were wrong, and they were annoying, so now they've been stopped X-NAS-Bayes: #0: 1.23279E-248; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 633 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Symantec has shown the way for other antivirus firms to finally end the proliferation of false user...

----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
15.  BugTraq: [SECURITY] [DSA 502-1] New exim-tls packages fix buffer overflows. Sender: [joey at infodrom dot org (Martin Schulze)]
16.  BugTraq: PING: Outlook 2003 Spam. Sender: http-equiv at excite dot com [1 at malware dot com]
17.  BugTraq: Somebody exploiting (badly designed) yahoo service?. Sender: Aleksandar Milivojevic [alex at milivojevic dot org]
18.  Vulns: OpenSSL Denial of Service Vulnerabilities. Three security vulnerabilities have been reported to affect OpenSSL. Each of these remotely exploitable issues may result in a denial of service in applications which us...
19.  Vulns: OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability. OpenSSL is a freely available, open source implementation of Secure Socket Layer tools. It is available for the Unix, Linux, and Microsoft platforms.

A problem has been...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
20.  Newest Pattern: 889
21.  Network Security Basics
22.  RSA founders give perspective on cryptography
23.  Holy security wars
24.  New Content Filtering Service Introduced by Fortinet
25.  DHS and UK ID card biometric vendor in false ID lawsuit
26.  Symantec Upgrades Its SMTP E-mail Security Product
27.  StompSoft Introduces Internet and Email Security Software
28.  Microsoft Updates Sasser Clean-up Tool
29.  Trusted Computing Group Pushes Open Spec
30.  The Digital ID World Newsletter - March 11, 2004 Issue
31.  The Digital ID World Newsletter - March 18, 2004 Issue
32.  The Digital ID World Newsletter - March 25, 2004 Issue
33.  The Digital ID World Newsletter - April 1, 2004 Issue
34.  May Microsoft Patches Available

3:21:46 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Sony cuts PlayStation 2 price to $149, action on the Xbox heats up. Saying it was time for a more attractive price for the casual gamer, Sony has responded finally to the latest round of Xbox cuts by slashing the PlayStation 2 from US$179 to $149. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Why Steve Jobs is still important. After writing off Apple's co-founder way back when, Forrester CEO George Colony is ready to eat his words.
3.  Sony slashes PlayStation price to $150. At the E3 game conference in Los Angeles, the entertainment giant also talked about its upcoming handheld game player and the Cell processor it is developing with Toshiba and IBM.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Dutch Patients Start Using Online Nursing (AP). AP - Bert Ooms raised his 80-year-old body in bed, adjusted his catheter, and clicked his television remote control to set up a Web cam connection.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Novell To Release Ximian Connector Under GPL
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
6.  Yet another Sasser worm appears. A new version of the Sasser Internet worm, Sasser-F, appeared on Monday, despite claims by German authorities to have arrested the sole author of that worm on Friday.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
7.  Vulns: EFFingerD Remote Buffer Overflow Vulnerability. efFingerD is a finger protocol server for the Microsoft Windows platform. X-NAS-Bayes: #0: 3.78401E-086; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 632 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

efFingerD has been reported prone to a remote buffer overflow vulnerability. The problem occurs...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  UK gov planning switch to e-voting for 2007?. Pop Idol factor beats security, claims report By John Lettice .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
9.  Sasser-Wurm für Mutter programmiert
10.  Erste Schadensersatzansprüche gegen Sasser-Autor
11.  Sasser Author Comes Clean
12.  Symantec, Network Associates Size Up Channel
13.  eScan 2003 Internet Security Suite

2:21:27 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Sony unveils music player to unseat the iPod's dominance. Sony has updated its VAIO line across the board, from desktops to notebooks. They've also taken the wraps off of their new portable music player. The company that brought us the Walkman would now like to introduce you to the VAIO Pocket VGF-AP1. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Shirky: Cameraphones are today's Gutenberg press. Clay Shirky has written an excellent entry on the appearance of unmediated photos from the Iraqi front on a Friendster-like service called YAFRO. He likens this -- and other instances of undmediated communication -- to the Protestant Reformation. X-NAS-Bayes: #0: 2.26284E-301; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 631 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The spread of images from Iraq, both relatively plain ones like most of what's on the YAFRO blogs to the horrifying images of torture and abuse from the Abu Ghraib prison are all part of the removal of bottlenecks that will change the political structure in ways we can't predict.

And it isn't just military affairs, its politics and business and everything else, from attempts to coordinate evidence of Apple's manufacturing errors (previously handled case-by-case, but now becoming a kind of grass-rooots class action protest, to Apple's horror) to the distributed amicus brief on the SCO case conducted by the Linux community to the recent right of Americans to get their medical records on request and within 30 days to the publication of spoilers for popular TV shows. (Read this last link now — its from the Times and goes away in 5 days, and although on the surface its about TV, its really a musing on life in a fully disclosed culture.)

Link

3.  Internet Archive's Petabox: a 1,000 terabyte array.

The Internet Archive has just installed its first Petabox, "a machine designed to safely store and process one petabyte of information (a petabyte is a million gigabytes)." Bookmark this entry and come back to it in five years, when you get a Petabox's worth of storage (with, say, high-resolution scans of the contents of the entire Library of Congress) free under the lid of your lucky Super Big Gulp.

Link

(via Hack the Planet)


4.  Bill O'Reilly trying to bury his Fresh Air interview. Terry Gross conducted an extraordinary interview with notorious demagogue Bill O'Reilly on her Fresh Air last October (listen here). Now, O'Reilly is withholding permission for NPR to relicence portions of the program. Please tell all your friends about this interview and get them to listen to it, so that O'Reilly's plan to bury the interview backfires and this becomes the definitive O'Reilly interview of all time.

Link

5.  Joe Bussard's basement tapes. bussardJoe Bussard has 20,000 vintage 78 rpm records from the 1920s and 1930s in his basement. For $15, Joe will put together a custom cassette compilation for you of 20 tunes from his collection, perhaps the largest of its kind in the world. I wish Joe and his friends would rip all of his 78s so he could sell MP3 CDs of these ultra-rare recordings. Here's a great NPR All Things Considered piece on Joe Bussard from last year.
"'The truest form you'll ever hear in American music is on these records,' Joe says. 'It was put there, and it's remained there for seventy years. It hasn't changed.'"
Link
6.  Lieberman's lunatic comments. Fake democrat Joe Lieberman sucked up to his true allies during Rumsfeld's testimony before the Senate Armed Services Committee last week.

LIEBERMAN: Thank you, Mr. Chairman.

Mr. Secretary, the behavior by Americans at the prison in Iraq is, as we all acknowledge, immoral, intolerable and un-American. It deserves the apology that you have given today and that have been given by others in high positions in our government and our military.

I cannot help but say, however, that those who were responsible for killing 3,000 Americans on September 11th, 2001, never apologized. Those who have killed hundreds of Americans in uniform in Iraq working to liberate Iraq and protect our security have never apologized.

Here's what Atrios says about it: "Lieberman is making one of two points. Either he's just saying 'USA! Not quite as bad as the worst people on the planet!' Or, he's saying 'I just want to point out that some brown people unconnected to this event did some bad things!'" Link

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
7.  Network Associates joins standards group. As part of the Trusted Computing Group, the security software company aims to work on open standards for technologies designed to protect data and networks.
8.  Openwave snaps up U.K. rival. The two cell phone messaging software makers plan to close the deal by July.
9.  Briefly: Openwave snaps up U.K. rival. Plus: Panel to weigh digital copyright laws...MCI posts $388 million loss...PeopleSoft buyout liability nears $2 billion...Intel invests in JBoss.
10.  Study: Portable gamers to nearly double by 2009. Competition in hardware and content is pushing growth of dedicated and hybrid game devices, according to a JupiterResearch study that also found a surprising percentage of women among adult game players.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
11.  Congress Looking at 'Video Voyeurism' (AP). AP - Cell phone cameras are useful for the unusual moment that demands a picture, like when a congressional aide pulled one out of a pocket to get a snapshot of Michael Jackson strolling the halls of Congress.
12.  Boys Prefer Video Games to Toys, Study Says (Reuters). Reuters - Boys would rather play a "G.I. Joe" video game than with "G.I. Joe" action figures, a new study finds.
13.  British Police Arrest 13 Suspected of Child Porn (Reuters). Reuters - British police arrested 13 people on Tuesday suspected of downloading and distributing child pornography over the Internet, in raids across London involving 100 officers.
14.  IBM strategy offers Office alternative (SiliconValley.com). SiliconValley.com - IBM introduced a new software strategy Monday that could loosen Microsoft's grip over desktop office software.
15.  Sony Cuts PlayStation 2 Price to $149 (Reuters). Reuters - Sony Corp. (6758.T) (SNE.N) on Tuesday said it would cut the price of its market-leading PlayStation 2 video game console to $149 from $179, saying it was time for a price more attractive to the casual gamer.
16.  Computers and Humans Mesh in Mobile Query Service (Reuters). Reuters - A new mobile phone service is challenging big Internet search engines by providing exact answers to any question, such as the number of steps of the Empire State building, the 1928 manager of British football club Chelsea or which color hat to put on in the morning.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
17.  FairPlay v2 Reversed, Playfair Back Online
18.  DOOM III This Summer
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
19.  Elsewhere: Experts: Timing of new Sasser worm raises questions. The release of a new version of the Sasser worm calls into question claims by some German authorities that they have the sole author of the worm in custody, according to ...
20.  Elsewhere: Tech Players Push for Anti-Virus Spec. A group of big-name technology firms has announced plans to develop an open specification to help stop the scourge of network viruses, worms, denial-of-service attacks (d...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
21.  Infinium to launch $199 Athlon XP console 18 Nov. Free with subscription By Tony Smith .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
22.  Porn scam netted 900,000 users, $37.5 million dollars and 11 years in jail
23.  3 Detroit students charged after school computers hacked and grades changed
24.  Analyst: Security Woes Add to Windows Cost
25.  Body found in Baghdad identified as U.S. worker
26.  Abuse blamed on lack of leadership
27.  BT begins major security token rollout
28.  Talking capacitors could blab to code breakers
29.  Âðåä è ïîëüçà îò âèðóñîïèñàòåëåé
30.  Sasser Author Comes Clean
31.  German Phatbot Arrest Follows Sasser Bust
32.  Sasser Author Comes Clean
33.  YELLOW ALERT: WORM_WALLON.A
34.  Why You Should Encrypt Your Email

1:21:07 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Microsoft backtracks on SP2 availability for unlicensed users. Sunday we reported that Microsoft was building Service Pack 2 for Windows XP in such a way that all users, licensed and unlicensed, could use it. The company has since denied the veracity of the statement made by one of its employees. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Playfair is back!. Playfair is the iTunes music player that removed the restrictions from the music you bought from Apple. It was hounded off Sourceforge by Apple's lawyers, and then it relocated to a server in India, only to be removed again at Apple's behest. Now it's back a third time, still hosted in India, with a new name: "hymn" (Hear Your Music aNywhere). X-NAS-Bayes: #0: 3.57931E-193; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 630 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

playfair has been renamed to hymn (hear your music anywhere) and is back online with the legal backing of FSF India. It has been updated with the latest FairPlay code from VideoLAN.

Link

(Thanks, Jon!)

3.  Godzilla vs. Camp. Last night, I watched the original, unedited Godzilla from 1954 that's finally being shown for the first time on the big screen in the US. No absurdist dubbing. No Raymond Burr. This subtitled re-release restores 40 minutes of director Ishiro Honda's vision that was chopped out of the US release. Of course, some of the melodrama and special effects are still worth a chuckle, but this is not our childhood's Godzilla. Honda's film is a post-Nagasaki cautionary tale. And Godzilla is no joke. Link

4.  A Scanner Darkly casting continues. Richard Linklater has lined up quite a list of stars for his Hollywood adaptation of Philip K. Dick's A Scanner Darkly. So far, Winona Ryder, Robert Downey Jr., Woody Harrelson, and Rory Cochran have signed on to join (gulp) Keanu Reeves in the lead as an undercover cop with drug-induced schizophrenia. Link (Thanks, Dave!)

5.  New issue of Neural. The new issue of Italian tech/art/culture magazine Neural is out. It looks to be another dense collection of articles about edgy hacktivism, electronic music, and digital art, including pieces on musician Ryoji Ikeda and anti-corporate activist Brian Holmes. Neural interviewed Mark way back in 1994! Link

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
6.  Microsoft readies XP update giveaway. The software maker says it plans to make its Service Pack 2 for Windows XP available at no charge, but remains coy about the exact nature of "XP Reloaded."
7.  RSA launches identity manager. The security software maker's product is designed to help companies securely exchange digital identities of their customers with partners and other enterprises.
8.  Sony makes over Vaio line. Additions to the product line include the "Vaio Pocket," a portable music player designed to compete with Apple's iPod.
9.  MCI taps Microsoft's Net meeting software. The telecommunications service provider signs a deal to use Microsoft Office Live Meeting software to power its Net Conferencing service
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
10.  Xbox Gears Up to Challenge PlayStation (PC World). PC World - Microsoft focuses on online content, announces new games from EA.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
11.  E3 - First Nintendo DS Pic
12.  Refresh your Memory: Advanced Graphics Algorithms
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
13.  DHS and UK ID card biometric vendor in false ID lawsuit
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
14.  Elsewhere: Security comes from the top. Companies will struggle to maintain effective IT security if senior managers are not seen to take the topic seriously

Imagine a perfect situation, in which you work for ...

15.  Elsewhere: Holy security wars. What is with the technology industry's propensity for fighting religious wars over products and technologies?

It seems that there are always new battles being fought, a...

16.  News: Lottery scams new flavour of the month. Lottery scam emails are increasing at an alarming rate, according to Fraudwatch International, the Australian website that protects consumers from identify theft. Last month FraudWatch International received over 1000 variations, double the number of phishing email scams.
17.  News: Sasser copycats get busy. Copycat virus authors have released a pair of worms targeted at the same vulnerability in Microsoft's operating system exploited by the infamous Sasser worm.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
18.  Brocade burrows into IBM blades. Plugged in and switched on By Ashlee Vance .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
19.  New Sasser version may be circulating
20.  Birthday Arrest May Save Sasser Virus Youth from Jail
21.  New version of Sasser undermines lone coder theory
22.  German Net Worm Writer May Have Been Helping Mom
23.  Virus war tests Microsoft's devotion to security
24.  Can Microsoft's virus bounty fight organised crime?
25.  'Sasser' creator launched damage-limiting version before arrest
26.  Holy security wars
27.  Nortel: Video demand to spur faster DSL
28.  Microsoft says bye-bye to Wi-Fi
29.  Microsoft Says: No XP SP2 for Pirated Copies
30.  Colubris Adds Secure Voice-over-Wi-Fi To Access Lineup
31.  FaceTime Delivers IM Security And Compliance Management
32.  Outside Review Pans FBI Computer Upgrade
----------------------------------------------------------------------
About Internet/Network Security
----------------------------------------------------------------------
33.  Why You Should Encrypt Your Email. You wouldn't send your credit card information on the back of a picture postcard, so why would you send it in a plain-text, unencrypted email message? This short article points out the reasons why you should encrypt and / or...

12:20:47 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  McDonalds trademarks phrase "I am Asian". McDonalds recently launched a bizarre new marketing campaign to attract Asian and Pacific Islander Americans "living on the rim." [Ed note: ahem] BoingBoing reader Modesty Verve, who points us to the campaign's website, says "Even stranger is the company's assertion of a trademark right on the phrase "I am Asian"!" Link
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Microsoft Kills Wi-Fi Product Line (PC World). PC World - No reason given for decision to stop producing wireless networking gear.
3.  Xbox Masters the Electronic Arts (washingtonpost.com). washingtonpost.com - The Electronic Entertainment Exposition kicks off in Los Angeles in a few hours, but already some of the gaming industry's biggest guns have announced landmark partnerships.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Linux Filesystems Benchmarked
5.  Sony PC/DVR Incorporates 7 Tuners & 1TB HD
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
6.  Doom 3 set for summer release. Catch up with the latest news from the world of video gaming.
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
7.  Government ouster leaves IT jittery in Indian state. BANGALORE, INDIA -- The government of Chandrababu Naidu, the tech-savvy chief minister of the South Indian state of Andhra Pradesh, was defeated Tuesday by a landslide, making the IT industry, including a number of multinationals with operations there, a trifle jittery.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
8.  Vulns: MyWeb HTTP Server GET Request Buffer Overflow Vulnerability. MyWeb HTTP server is a web server available for the Windows operating system. X-NAS-Bayes: #0: 2.01626E-124; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 629 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A vulnerability has been reported for MyWeb HTTP server. The problem occurs due to insuffic...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  MS spells it out: pirates can, can't install WinXP Sp2. That's cleared things up then By John Lettice .
10.  Chinese make beautiful spam music. Ode to perlite - wonder material By Lester Haines .
11.  EU broadband growth outpaces US. Need to 'maintain momentum' By Tim Richardson .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  Chinees hackt Taiwanese oppositie website
13.  Windows IPSec lek niet voldoende onderkend
14.  Alarmerende toename loterij zwendel
15.  Tieners plegen steeds meer cybermisdaden
16.  Geen Service Pack 2 voor illegale Windows XP
17.  Browser hijackers maken meer kapot dan je lief is
18.  Sasser shows network flaws (USATODAY.com)
19.  Sasser copycats get busy
20.  eMule Web Interface Negative Content Length Denial of Service
21.  DHS and UK ID card biometric vendor in false ID lawsuit
22.  eMule Web Interface Negative Content Length Denial of Service
23.  The Digital ID World Newsletter - April 8, 2004 Issue
24.  The Digital ID World Newsletter - April 15, 2004 Issue
25.  The Digital ID World Newsletter - April 22, 2004 Issue
26.  The Digital ID World Newsletter - April 29, 2004 Issue
27.  The Digital ID World Newsletter - May 6, 2004 Issue
28.  Sasser Outbreak Demonstrates Need for Quick Patch Response
29.  Sinister Sasser
30.  Security Policy a Paper Tiger
31.  Despite arrest, new variant of Sasser worm appears
32.  Suspect arrested in Phatbot, Agobot malware case
33.  Sasser arrest seen as small step in cybercrime fight
34.  11 May W32/Agobot-JO
35.  phpShop Arbitrary Code Inclusion Vulnerability
36.  BT begins major security token rollout
37.  Sasser Shows Network Flaws

11:20:28 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Congress Targets Cell Phone Cameras (AP). AP - Cell phone cameras are useful for the unusual moment that demands a picture, like when a congressional aide pulled one out of a pocket to get a snapshot of Michael Jackson strolling the halls of Congress.
2.  Xbox to Get Online Video-Phone Upgrade (AP). AP - Users of Microsoft Corp.'s Xbox Live online gaming network can already talk to each other remotely while logged in — but soon they'll be able to see their fellow players' faces and "tickle" each other, too.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Alan Turing, the Inventor of Software
4.  Patents and the Penguin
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
5.  Microsoft files new case against Lindows. The international trademark battle between Microsoft Corp. and Lindows Inc. continues to generate work for lawyers and the courts, with the software giant once again asking a Dutch court to fine Lindows €100,000 ($118,570) a day, the open source software vendor said Tuesday.
6.  Microsoft teams with MCI to deliver Office Live Meeting. Microsoft Corp. is teaming with communications giant MCI Inc. to deliver Web conferencing and collaboration services featuring its Microsoft Office Live Meeting, the companies said Tuesday.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Holy security wars
----------------------------------------------------------------------
[O.S.S.R]
----------------------------------------------------------------------
8.  Sasser copycats getting busy
9.  Microsoft says bye-bye to Wi-Fi
----------------------------------------------------------------------
SecurityNewsPortal.com HomelandSecurity.com
----------------------------------------------------------------------
10.  3 Detroit students charged after school computers hacked and grades changed... That time of year again
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
11.  Vulns: SSMTP Mail Transfer Agent Multiple Format String Vulnerabilities. ssmtp is a mail transfer agent designed to run on the Linux platform. X-NAS-Bayes: #0: 7.57814E-131; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 628 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

It has been reported that the ssmtp is prone to multiple remote format string vulnerabilities. The...

12.  Vulns: Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability. Sendmail is prone to a buffer overrun vulnerability in the prescan() function. This issue is different than the vulnerability described in BID 7230. The issue exists in...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
13.  Official Nintendo DS console pic appears on Web. Dual-screen Gameboy in all its glory By Tony Smith .
14.  Nvidia ships TV, PVR cards to US, Europe. Personal Cinema on your PC By Tony Smith .
15.  IT suppliers survey - your votes count. Another pulse check on the IT barometer By Team Register .
16.  Dream Direct warns on profits. Pesky postmen to blame... By John Oates .
17.  Talking capacitors could blab to code breakers. Motherboard clues to private encryption keys By John Leyden .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  Viren-Charts für April: Agobot an der Spitze

10:20:08 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  PlayFair defies Apple; Web site back up (MacCentral). MacCentral - The PlayFair free software project is back online, with both the maintainer of the project and the hosting service willing to face a legal challenge from Apple Computer Inc.
2.  Gateway Files Patent Suit Against HP (AP). AP - Gateway Inc. said Monday that it filed a patent infringement lawsuit against Hewlett-Packard Co., alleging that the computer hardware and software company violated five of its patents.
3.  Microsoft kills its Wi-Fi offerings (MacCentral). MacCentral - Microsoft Corp. has decided to stop producing wireless networking products and will discontinue its range of gear using the 802.11b wireless networking standard, also known by the Wi-Fi marketing name, the company announced Tuesday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  A Raft Of New Products From Sony Japan
5.  First Nintendo DS Pic
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
6.  Man sent gun in internet mix-up. A Canadian student who ordered an MP3 player over the internet from the US was sent a handgun instead.
7.  Magnetic therapy for spine injury. Magnetic therapy may help people with spinal cord injuries to regain movement and sensation.
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
8.  Microsoft drops its Wi-Fi offerings. Microsoft Corp. has decided to stop producing wireless networking products and will discontinue its range of gear using the 802.11b wireless networking standard, also known by the Wi-Fi marketing name, the company announced Tuesday.
9.  Open source app servers make headway. Enterprises shopping for a Java application server will soon have more reasons to look at open source software, with no less than three open source projects expected to be certified compatible with Sun Microsystems Inc.'s enterprise Java standard by the end of the year.
10.  IBM adds Brocade switches to BladeCenter. Two weeks after announcing plans to integrate an Ethernet switch from Cisco Systems Inc. into its BladeCenter servers, IBM Corp. on Tuesday will announce a similar deal with Brocade Communications Systems Inc. to create new integrated Fibre Channel switches for the same line of high-density servers.
----------------------------------------------------------------------
SecurityNewsPortal.com HomelandSecurity.com
----------------------------------------------------------------------
11.  Porn scam netted 900,000 users, $37.5 million dollars and 11 years in jail...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
12.  Infinium to launch $199 Athlon XP console 18 Nov.. Free with subscription By Tony Smith .
13.  Sony unveils colour 'iPod killer'. Reg Kit Watch Music and photos on the move By Tony Smith .
14.  European workers take to the streets. Mobile technology aids escape from office routine By Lucy Sherriff .
15.  DHS and UK ID card biometric vendor in false ID lawsuit. Right fingerprints, wrong felony and murder rap By John Lettice .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
16.  11 May W32/Sasser-F
17.  Sasser shows network flaws (USATODAY.com)
18.  phpShop Arbitrary File Inclusion Vulnerability
19.  MailEnable Professional HTTPMail Service Buffer Overflow Vulnerabilities
20.  phpShop Arbitrary File Inclusion Vulnerability
21.  MailEnable Professional HTTPMail Service Buffer Overflow Vulnerabilities
22.  CCCebit: Gemeinsamer Standbesuch bei Vitronic
23.  Chaosradio 90: SPAM
24.  Boycott MusicindustryBoycott Musicindustry
25.  demonstration against software patents
26.  Kundgebung gegen die unkontrollierte Einführung von RFID
27.  Datengarten 14 am 6. Mai in Berlin: "OpenBSD 3.5 Redundant Firewalling with QoS"
28.  GPN3 am 22./23. Mai in Karlsruhe
29.  Chaostreff Dresden: Symposium "DatenSpuren - Privatsphäre war gestern"Chaostreff Dresden: Symposium "DataTracks - Privacy was Yesterday"
30.  WORM_SPYBOT.KI

9:19:47 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Congress Targets Cell Phone Cameras (AP). AP - Cell phone cameras are useful for the unusual moment that demands a picture, like when a congressional aide pulled one out of a pocket to get a snapshot of Michael Jackson strolling the halls of Congress.
2.  Nintendo unveiling a new portable (USATODAY.com). USATODAY.com - Video game giant Nintendo, facing increased competition in the market for handheld entertainment, will have a new portable out this fall with twin color screens, sharper graphics and the feel of a PDA. The Nintendo DS - short for dual-screen - will be unveiled Tuesday morning at the annual Electronic Entertainment Expo game industry gathering.
3.  Sasser shows network flaws (USATODAY.com). USATODAY.com - The ability of a teenage German suspect arrested Friday to unleash the Sasser Internet worm underscores how vulnerable corporate networks remain, despite billions spent on security.
4.  REVIEW: CSI Returns to Computer Screen (AP). AP - CBS has done well turning the crime lab into popular entertainment. "CSI: Crime Scene Investigation" was first, then came "CSI: Miami." On the heels of last year's "CSI" video game comes another franchise spinoff for home computers: "CSI: Dark Motives."
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
5.  RSA founders give perspective on cryptography
----------------------------------------------------------------------
SecurityNewsPortal.com HomelandSecurity.com
----------------------------------------------------------------------
6.  Porn scam netted 900,000 users, $37.5 million dollars and 11 years in jail... Keywords: security hacking hackers fraud computer crime Internet police virus worms banking financial advertising military networking business credit cards
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
7.  Openwave buys Magic4. UK mobile data outfit gets the message By John Oates .
8.  NHS rolls out digital X-rays. Should speed diagnosis By Lucy Sherriff .
9.  Sasser copycats get busy. Saga continues with Sasser-F and Cycle-A By John Leyden .
10.  Erkki speaks on mobile regulations. EC turns 'scope on football rights, and more By John Oates .
11.  Gateway loss widens as patent lawsuit fund grows. Deal with HP in the offing? By Tony Smith .
12.  Porn scamster jailed for 11 years. Biggest Net fraud ever, apparently By Tim Richardson .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Security en de balans tussen risico en kosten
14.  Netwerk van virusschrijvers achter Sasser worm?
15.  Security risico door Bluetooth apparaten
16.  Kan Microsoft beloning einde aan virussen maken?
17.  Cybercrime wetten doen meer kwaad dan goed
18.  Microsoft: Patchen is geen lange termijn oplossing
19.  Sasser zal nog een jaar actief zijn
20.  ID Spoofing lekje in Internet Explorer en Outlook
21.  ID Spoofing lekje in Eudora
22.  Sun Solaris catman Temporary Files Race Condition and Symlink
23.  OpenSSH Multiple Key Type ACL Bypass
24.  US.biz practicing Homeland inSecurity
25.  Lottery scams new flavour of the month
26.  Nvidia brings hardware firewall to Athlon XP rigs
27.  Lottery scams new flavour of the month
28.  Why computer security's so primitive
29.  Spec in works to secure wireless networks
30.  Understanding TCP reset attacks
31.  Sicherheits-Experten: Mehr Viren-Autoren sollen hängen
32.  Recordable DVDs New Target of Hollywood
33.  Academics Patent P2P Spoofing
34.  Software Security Firms Aim to Preempt Hackers
35.  Microsoft Corrects: No XP SP2 for Pirated Copies

8:19:27 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Customers await Sun-Microsoft integration. Cooperation between Sun and Microsoft probably won't drastically alter the IT landscape, but it should eliminate some integration headaches.
2.  Diagnosing WebMD. While many dot-coms collapsed without a leg to stand on, WebMD survived with a steady stream of acquisitions that have given it three principal means of support, and a lot of options.
3.  Holy security wars!. Jon Oltsik says zealots are waging war for no reason in the field of information security. Intrusion detection and intrusion prevention, he says, work best in tandem.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  WIRELESS WONDER (SiliconValley.com). SiliconValley.com - Street sweepers and grandmothers in China are helping a Bay Area telecom company strike it rich.
5.  IBM strategy offers Office alternative (SiliconValley.com). SiliconValley.com - IBM introduced a new software strategy Monday that could loosen Microsoft's grip over desktop office software.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
6.  Under the skin of digital crime. Computers have become a key tool for the criminal classes, explains security expert Neil Barrett.
7.  US criticised over web controls. The US should reopen most of the websites shut down after September 11 because of terrorism fears, a report says.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
8.  Network Security Basics
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  European Council snubs software patent vote. De-fanged directive By Lucy Sherriff .
10.  Nvidia brings hardware firewall to Athlon XP rigs. nForce 2 upgrade By Tony Smith .
11.  Vodafone looks beyond 3G. Boss calls for new standards By John Oates .
12.  Openwave buys Magic4 for £80m. UK mobile data outfit gets the message By John Oates .
13.  MCI to axe 7,500 jobs. Blames 'adverse industry environment' By Tim Richardson .
14.  Sage results solid. More customers, more cash By John Oates .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
15.  « L'employeur ne peut pas exploiter un mail personnel contre un salarié », sauf si ...
16.  NetBSD Systrace Privilege Escalation Vulnerability
17.  German Police Snag Phatbot Author
18.  new bagle (ab) spreading
19.  Sasser.E: Autor hinterlässt Warnung
20.  Verity Ultraseek DOS Device Name Path Disclosure
21.  SLMail Malformed Command DoS
22.  Sun Solaris catman Arbitrary File Overwrite
23.  NetBSD Systrace Privilege Escalation Vulnerability
24.  InfoSec Writers: An Overview of Common Programming Security Vulnerabilities and Possible Solutio...
25.  Security Tracker: icecast Heap Overflow in Processing Basic Authentication "A remote user can ca...
26.  Security Tracker: Mac OS X TruBlueEnviroment Argument Processing Flaw "Lets Local Users Deny Ser...
27.  Computer World: Suspect arrested in Phatbot, Agobot malware case "A 21-year-old German man has a...
28.  Kernel Trap: Understanding TCP Reset Attacks, Part I
29.  Security threats raise concerns about Bluetooth
30.  Sinister Sasser
31.  Suspect arrested in Phatbot, Agobot malware case

7:19:08 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Intel Releases New Pentium M Processors
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: XFree86 Font Information File Buffer Overflow Vulnerability. XFree86 is a freely available open-source implementation of the X Window System. X-NAS-Bayes: #0: 1.14898E-127; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 624 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

It has been reported that the XFree86 X Windows system is prone to a local buffer overf...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  European Council snubs software patent vote. De-fanged directive takes trip to dentist By Lucy Sherriff .
4.  EA and MS deal for online gaming. Differences patched up... By John Oates .
5.  Lottery scams new flavour of the month. Forget phishing By Jan Libbenga .
6.  Linux Programming by Example. Site Offer 30% off hands-on guide By Team Register .
7.  Nvidia brings h'ware firewall to Athlon XP rigs. nForce 2 gains packet processing core By Tony Smith .
8.  Rambus offers DDR controller cores. DDR, GDDR and - surprise - XDR support By Tony Smith .
----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
9.  Feds Answer Calls for Nuke Safety. For years, watchdog groups have argued in vain for new security measures at the nation's nuclear weapons labs. Finally, Energy Secretary Spencer Abraham appears to be listening. By Noah Shachtman.
10.  Monsanto Backs Off Bio-Wheat. Facing strong opposition from an American wheat industry afraid of losing its European customers, Monsanto decides to stop developing biotech wheat and focus instead on cotton and soybeans.
11.  European Shuttle Trial Successful. Although a manned European shuttle is still a good decade off, the successful landing of a prototype, says one enthusiast, 'gives us wind in our sails.'
12.  Copyright Arrest in Japan. A professor at Tokyo University faces up to three years imprisonment and a hefty fine after his arrest as a suspected developer of illegal file-sharing software.
13.  Manhattan Gets Pac-Man Fever. Students transplant Pac-Man from computer screens to the streets of Manhattan using cell phones and mapping software. Their professor says it's all about learning the principles of sound game design. Michelle Delio reports from New York.
14.  How to Get a Tech CEO's Goat. Want to piss off a CEO? Point out that the company's tech products are turning into commodities. By Nicholas G. Carr from Wired magazine.
15.  MIT Aims for the Bottom Line. Media Lab launches an initiative to develop cutting-edge consumer technologies -- called CELab -- but the focus is really on paying the bills. Mark Baard reports from Cambridge, Massachusetts.
16.  Play Games, Be Better Students?. Instead of taking away joysticks, schools should promote video games that teach critical thinking, a panel of educators and game designers says. But will school administrators dare to take the advice? Daniel Terdiman reports from Los Angeles.
17.  Dropping the Bomb on Google. Using Google to search for Jew returns an anti-Semitic site as the No. 1 result. So one Web surfer decided to do something about it, and it worked, for a while at least. By John Brandon.
18.  Browser Hijackers Ruining Lives. Malicious programs called browser hijackers install a lot of nasty stuff on people's computers -- primarily hard-core, borderline-illegal pornography. Some victims are facing firings, divorces and even criminal prosecution. By Michelle Delio.
19.  Hybrid Mileage Comes Up Short. Hybrid car owners who thought they'd be getting much better fuel effeciency than conventional cars have been disappointed. The problem isn't company claims, it's an outmoded EPA testing procedure. By John Gartner.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
20.  Déni de service dans la fonction decodeArrayLoop() de la Machine Virtuelle Java
21.  Deni de service dans Internet Explorer (traitement des URL 'file://')
22.  Buffer Overflow dans la fonction panic() du noyau Linux
23.  BKDR_LITTLEWTC.Z
24.  TROJ_BANKER.W
25.  NIST suggests VoIP caution

6:18:46 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Playfair is back!. Playfair is the iTuens music player that removed the restrictions from the music you bought from Apple. It was hounded off Sourceforge by Apple's lawyers, and then it relocated to a server in India, only to be removed again at Apple's behest. Now it's back a third time, still hosted in India, with a new name: "hymn" (Hear Your Music aNywhere). X-NAS-Bayes: #0: 5.40254E-101; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 623 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

playfair has been renamed to hymn (hear your music anywhere) and is back online with the legal backing of FSF India. It has been updated with the latest FairPlay code from VideoLAN.

Link

(Thanks, Jon!)

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Sony Takes Aim at Apple But iPod Seen Safe for Now (Reuters). Reuters - Sony Corp has created a buzz with the unveiling of a new digital music player, but analysts say it has a long way to go before it challenges the industry dominance of Apple Computer's popular iPod.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Fresh clients boost Sage profits. The accountancy software group unveils a 17% rise in half-year profits, helped by an influx of new customers.
4.  Xbox Live signs up games giant. Microsoft announces a deal to bring Electronic Arts' games to Xbox Live, as it reveals a release date for Halo 2.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
5.  China snubs US with 3G phone 'wonderchip'. Truce over By Andrew Orlowski .
6.  Infineon hires CEO from tyre maker. From rubber to silicon By Tony Smith .
7.  AMD sneaks out 90nm core in 130nm chip. The 'Odessa' file By Tony Smith .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  Washington Whispers - The Google Terrrorist
9.  Orbitz Sharing Customer Credit Card Information
10.  Consumer complaints about Orbitz - MWI
11.  Spyware Sneaks Into the Office
12.  FEATURE-Google under closer privacy scrutiny post-IPO
13.  Principles of privacy
14.  No reason to fear privacy invasion from library books
15.  NBTA Publishes Guide to Travel Data Privacy
16.  Review: McAfee AntiSpyware
17.  Lax privacy laws hit healthcare BPOs
18.  Proposed bill seeks stronger privacy Protection For Offshore Work
19.  Taking a Second Shot at Spammers
20.  Privacy rights rigid in Florida
21.  Petition aims to restore privacy
22.  GUARDING against the invasion of privacy
23.  Data dealer has questions to answer
24.  Security threats raise concerns about Bluetooth
25.  When Old Convictions Won't Die
26.  Cost of Airport Security Tech
27.  Bush praises Rumsfeld

5:18:35 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 11 May 2004.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Hosted CRM Vendor RightNow Files For IPO (TechWeb). TechWeb - The company says it has had 25 consecutive quarters of revenue growth and posted its first profit in the quarter ended March 31.
3.  IBM Launches Alternative To Microsoft Office (TechWeb). TechWeb - The server-based bundle of desktop applications runs on Linux, Windows, handheld computers and cell phones.
4.  Japan's Casio posts record profit on booming digital camera sales (AFP). AFP - Japanese consumer electronics maker Casio says strong digital camera sales propelled its net profit to a record high in the year to March and that it expected another year of strong profit growth.
5.  NTT DoCoMo develops world's smallest Internet-capable cellphone (AFP). AFP - Japan's top mobile phone service provider NTT DoCoMo Corp. has unveiled what it claims to be the world's smallest Internet-capable cellphone.
6.  Software Security Start-Up Aims to Pre-Empt Hackers (Reuters). Reuters - A pair of small U.S. technology firms said on Monday they have struck a deal to market software intended to defend corporate computer networks by scanning for possible security flaws before they can be targeted by hackers and viruses.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Cry To Beat Iris Scanners
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  US.biz practicing Homeland inSecurity. More honoured in the breach... By John Leyden .
9.  Europe space shuttle passes first test. Lands safely By Lucy Sherriff .
10.  Sun saves $315m by not expensing options. Safety in numbers By Ashlee Vance .
11.  Intel smiles on Dothan. Painless as possible By Andrew Orlowski .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  CERT Summary CS-2003-01
13.  CA-2003-11 : Multiple Vulnerabilities in Lotus Notes and Domino
14.  CA-2003-12 : Buffer Overflow in Sendmail
15.  CA-2003-13 : Multiple Vulnerabilities in Snort Preprocessors
16.  What is my Role in Information Survivability? Why Should I Care?
17.  Making a Compelling Business Case for Investing in Information Security
18.  Updated CSIRT Handbook
19.  CERT Summary CS-2003-02
20.  OCTAVE Implementation Guide
21.  Congressional Testimony
22.  IN-2003-01: Malicious Code Propagation and Antivirus Software Updates
23.  New CERT. Certification for Computer Security Incident Handlers
24.  CA-2003-14 : Buffer Overflow in Microsoft Windows HTML Conversion Library
25.  CA-2003-15 : Cisco IOS Interface Blocked by IPv4 Packet
26.  CA-2003-16 : Buffer Overflow in Microsoft RPC
27.  CA-2003-17 : Exploit Available for the Cisco IOS Interface Blocked Vulnerabilities
28.  CA-2003-18 : Integer Overflows in Microsoft Windows DirectX MIDI Library
29.  CA-2003-19 : Exploitation of Vulnerabilities in Microsoft RPC Interface
30.  IN-2003-02: W32/Mimail Virus
31.  CA-2003-20 : W32/Blaster worm
32.  W32/Blaster Recovery Tips
33.  CA-2003-21 : GNU Project FTP Server Compromise
34.  IN-2003-03: W32/Sobig.F Worm
35.  CA-2003-22 : Multiple Vulnerabilities in Microsoft Internet Explorer
36.  Use Care When Reading Email with Attachments
37.  OCTAVE-S Implementation Guide
38.  CERT Summary CS-2003-03
39.  Congressional Testimony
40.  CA-2003-23 : RPCSS Vulnerabilities in Microsoft Windows
41.  CA-2003-24 : Buffer Management Vulnerability in OpenSSH
42.  CA-2003-25: Buffer Overflow in Sendmail
43.  Press Release: Creation of US-CERT
44.  Digital Millenium Copyright Act (DMCA) Comments and Testimony
45.  IN-2003-04: Exploitation of Internet Explorer Vulnerability
46.  CA-2003-26 : Multiple Vulnerabilities in SSL/TLS Implementations
47.  State of the Practice of Computer Security Incident Response Teams
48.  Staffing Your Computer Security Incident Response Team  What Basic Skills Are Needed?
49.  New PGP Key
50.  CA-2003-27 : Multiple Vulnerabilities in Microsoft Windows and Exchange
51.  CA-2003-28 : Buffer Overflow in Windows Workstation Service
52.  New Tech Tip: Before You Connect a New Computer to the Internet
53.  System for Internet Level Knowledge (SiLK)
54.  CA-2004-01 : Multiple H.323 Message Vulnerabilities
55.  Updated CERT/CC Statistics
56.  IN-2004-01: W32/Novarg.A Virus
57.  CA-2004-02 : Email-borne Viruses
58.  Employment Opportunities
59.  Organizational Models for Computer Security Incident Response Teams
60.  What is a Distributed Denial of Service (DDoS) Attack and What Can I Do About It?
61.  IN-2004-02: W32/Netsky.B Virus
62.  Security Architecture: Detecting and Responding to Intrusions
63.  Information Assurance in Small Organizations
64.  Considering Operational Security Risks During System Development
65.  Sustaining Your Security Architecture
66.  CERT/CC Annual Report
67.  Advanced Information Assurance Handbook
68.  CERT/CC Current Activity
69.  BKDR_OPTIXPRO.16
70.  WORM_SASSER.F
71.  WORM_NETSKY.X
72.  An Overview of Common Programming Security Vulnerabilities and Possible Solutions
73.  Extended Enforcement
74.  Sidebar: Endpoint security software vendors and their products
75.  Technology Briefs
76.  Despite arrest, new variant of Sasser worm appears
77.  Suspect arrested in Phatbot, Agobot malware case
78.  Sasser arrest seen as small step in cybercrime fight
79.  Mandrake update for rsync
80.  Mandrake update for apache2
81.  FreeBSD readv() Integer Overflow Privilege Escalation
82.  FreeBSD readv() Integer Overflow DoS
83.  Mandrake update for rsync
84.  Mandrake update for rsync
85.  Mandrake update for apache2
86.  Mandrake update for apache2
87.  NatACL.20040508.tar...>
88.  1242.html
89.  Auth-sc.c
90.  upload-exec-shellcod..>
91.  emule042e.pl
92.  hatsquad.txt
93.  getlvcb.c
94.  phpshop_29-04-04.txt
95.  paxdos.c

4:18:17 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Why Blogger redirects some URLs. The new Blogger redirects a lot of its links through another server. Ev explains why: it's to keep down comment-spam, to avoid apportioning unwarranted PageRank, and to protect Google's intranet. X-NAS-Bayes: #0: 1.30548E-232; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 621 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Since blogger.com is linked from google.com, any sites we link to could pass on a fairly high PageRank value. (PageRank is one of the factors that determines what results show up in what order for searches.) In order to remove any possibility of unequal ranking of Blogger-powered blogs in the Google main search index, we send links through a URL from which Google knows to ignore PageRank. This way, Blogger blogs earn PageRank only on the basis of their content and other people linking to them, not because they're powered by a tool owned by Google.

Link

(via EvHead)

2.  Flickr adds image annotation.

Flickr -- the fantastic social image-sharing Web app from Ludicorp -- has added image annotation; you can draw boxes around bits of the photos you post and mark up the contents of each box. When a viewer mouses over the box, a tooltip pops up with the annotation. Super cool.

Link

(via Kottke)


3.  Sony's entertainment business is killing its electronics business. Derek Slater takes Sony to task over its new music-download service and iPod-like player.

Sony's acquisition of a couple of minor entertainment companies has had untold consequences. It's a poison pill that is killing Sony, one piece at a time.

Back from 1976-1984, Sony was the company that spent hundreds of millions on the defense of its VCR, bringing it all the way to the Supreme Court, arguing that the entertainment industry didn't have any right to its business-model; that if new technology could make the old business irrelevant, that was tough shit, and the movie companies needed to stop pewling and get with the program (they did, and made lots of money, besides).

But ever since Sony "aquired" Columbia, it's been acting like its electronics business was a minor business unit that couldn't afford to disrupt its precious entertainment arm (despite the fact that the entertainment arm's contributions to Sony's bottom line are minimal when compared to the gadget biz). When the first MP3 players appeared in the market, from little companies like Creative Labs, Sony brought out proprietary devices that played stupid formats like RealAudio and OpenAG, which no one wanted to hear. On the other hand, these formats did come with use-restrictions that kept Sony's music execs from getting too anxious and sad.

The result was that Creative Labs, a little outfit in Singapore, ate Sony's lunch, followed by a bunch of late diners to the table, including a bunch of no-name Korean companies, and most recently, Apple. Sony, who invented the walkman and made billions off of it, has now become an irrelevant player in the personal stereo market, with a market share that's barely a blip on the chart.

And Sony -- a company legendary for tis ability to refine its designs to capitalize on lessons learned in the market -- keeps on repeating the same mistakes, as Derek points out:

Apparently, Sony's hard drive player cannot play MP3s, WMA and (of course) Apple FairPlay-locked AAC. It only plays the Sony's proprietary ATRAC3 format; if it's like Sony's MiniDisc players, forcing consumers to convert to ATRAC3 also forces them to accept certain DRM restrictions. In related news, the Washington Post and New York Times both deemed Connect embarassing, noting its poor interface, proprietary DRM format and codec, copying restrictions ... too many to count.

Link

4.  Photoshop contest: images depicting motion.

Today's Worth1000 photoshopping contest: "Images depicting motion." There's some very nice stuff here.

Link


5.  Haunted Mansion costume for sale.

An eBay auction for a size 14 (shirt)/18 (skirt) female Haunted Mansion ride-attendant costume from Walt Disney World. Oh, to be a woman.

Link


----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  Despite German Teen Arrest, Sons of Sasser Live On
7.  Despite German Teen Arrest, Sons of Sasser Live On
8.  Despite German Teen Arrest, Sons of Sasser Live On
9.  Despite Teen Arrest, Sons of Sasser Live On
10.  SCO Group: apache Multiple vulnerabilities
11.  Slackware: lha Multiple vulneraiblities
12.  Debian: exim Buffer overflow vulnerabilities
13.  Conectiva: lha Multiple vulnerabilities
14.  FreeBSD: heimdal Cross-realm trust vulnerability
15.  FreeBSD: crypto_heimdal Heap overflow vulnerability
16.  Mandrake: proftpd Access control escape vulnerability
17.  Slackware: xine-lib Arbitrary code execution vulnerability
18.  Slackware: sysklogd Denial of service vulnerability
19.  Slackware: rsync Improper write access vulnerability
20.  Debian: flim Insecure temporary file vulnerability
21.  Slackware: libpng Denial of service vulnerability
22.  Debian: rsync Directory traversal vulneraiblity
23.  Suse: Live CD 9.1 Passwordless superuser
24.  Suse: kernel Multiple vulnerabilities

3:17:55 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  LotR furniture. X-NAS-Bayes: #0: 3.67645E-060; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 620 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

These guys sell (very, very, very expensive) hand-made oak furniture themed on the Lord of the RIngs movie.

Link

(Thanks, Dominic!)

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Tata to Buy Phoenix India Operations (AP). AP - India's largest software exporter Tata Consultancy Services plans to buy the Indian subsidiary of Connecticut-based asset management service provider Phoenix Companies, Inc., a company spokesman said Tuesday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  E3 - Microsoft, EA Go Live, Halo 2 Dated, Xbox Videophoned
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  icecast Heap Overflow in Processing Basic Authentication Lets Remote Users Crash the Service
5.  NukeJokes Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks
6.  Mac OS X TruBlueEnviroment Argument Processing Flaw Lets Local Users Deny Service
7.  Was the Windows Source Leak a Bust?
8.  Even 'Pirates' to Get XP SP2 Access?
9.  SCO TermVision Password Storage Weak Encryption
10.  Linux Kernel Zero Length IP Fragmentation DoS
11.  An Overview of Common Programming Security Vulnerabilities and Possible Solutions
12.  WORM_AGOBOT.WA
13.  Eudora Long URL Obfuscation
14.  suidperl FileSystem Mount Arbitrary Code Execution
15.  Mobilizing the enterprise

2:17:35 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  EA, Microsoft patch Xbox Live dispute. The market-leading game publisher says it will finally bring its games, including the "Madden" football franchise, to Microsoft's online service.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Study: Many Federal Sites Not Terror Risks (AP). AP - Federal officials should consider reopening public access to about three dozen Web sites withdrawn from the Internet after the Sept. 11, 2001, attacks, a government-financed study says, because the sites pose little or no risk to homeland security.
3.  Microsft, EA Link Up for Online Video Games (Reuters). Reuters - Microsoft Corp. (MSFT.O) and the world's largest video game publisher, Electronic Arts Inc. (ERTS.O), put their long-standing differences over online gaming behind them on Monday as EA said it would release more than a dozen games this year supporting Microsoft's Xbox Live.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  The Man Who (Really) Makes Google Tick
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
5.  Mobilizing the enterprise. The applications and infrastructure necessary to build a managed mobile enterprise have rapidly matured. Two such products — Extended Systems OneBridge Mobile Solutions Platform and Intellisync’s Mobile Suite — intrinsically push corporate e-mail and PIM (personal information manager) information to virtually any wired or wireless handheld device. And that’s where many enterprises kick off their mobile strategy.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  Understanding TCP Reset Attacks, Part I
7.  Spec in Works to Secure Wireless Networks
8.  ACA: first spam prosecutions in sight
9.  Microsoft Bounty Helps Land Worm Writer
10.  Symantec Upgrades Security Product for SMTP Gateways
11.  Security Expert: Cyber Attack Cycle Is Tightening
12.  Another Sasser Worm Appears Despite Teen's Arrest
13.  Fortinet Launches Web Filtering Service
14.  Despite German Teen Arrest, Sons of Sasser Live On
15.  Despite German Teen Arrest, Sons of Sasser Live On
16.  WORM_SDBOT.CM
17.  Despite German Teen Arrest, Sons of Sasser Live On
18.  Despite Teen Arrest, Sons of Sasser Live On
19.  The Goal of Computer Security

12:25:16 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 6/1/2004; 12:29:11 AM.
This theme is based on the SoundWaves (blue) Manila theme.
May 2004
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Apr   Jun