Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Thursday, May 13, 2004
 

----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
1.  Skyscrapers in Cyberspace: Maps and History Online. Maps have become a popular method of displaying a museum's collection, as seen on the web sites of the Skyscraper Museum and the Theban Mapping Project. By Matthew Mirapaul.
2.  In the Arts, Tech for Tech's Sake Can't Compete With Originality. Setting aside something so ephemeral as aesthetic achievement, we're confronted with the fact that films that look strikingly new often perform strikingly well at the box office. By John Rockwell.
3.  Adapting a Company's Tools and Selling Them to Others. A startup in Wayne, Pa. seems to prove that commercially valuable software can be found in established American companies. By Gary Rivlin.
4.  Strong Sales Bolster Dell, but Operating Margins Dip. Dell reported record earnings for its first quarter, citing surging international sales and strong demand from United States corporations. By Laurie J. Flynn.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  Tapwave to Add Outlets for Handheld Game Device (Reuters). Reuters - Handheld gaming company Tapwave, which makes a personal digital assistant designed to play video games, will expand its retail presence beyond a deal with CompUSA to include Amazon.com Inc. and a third major retailer, the company said on Thursday.

11:27:47 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Engadget does E3. Pete Rojas says, "Engadget has been going overboard with our coverage of E3, and we've got a roundup with all of the news, reports from the showfloor, and tons of photos." Link
2.  More photos from video game launch party, Playboy mansion. Here are the rest of the images I shot at the Playboy video game launch party on Tuesday evening, at the Playboy mansion.
Link to photo gallery, Link to previous BoingBoing post.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  Game companies tweak online plans. Game software and hardware companies are cooling on the idea of subscription-based games and instead see big potential in minitransactions.
4.  Search engines delete adware company. Yahoo and Google disable links to controversial adware maker WhenU after the company is accused of engaging in unauthorized practices aimed at boosting its search rankings.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  Some Upcoming Video Games Include Sex (AP). AP - The hot new creation at the world's top video game convention may be procreation. Amid the thousands of new products at the Electronic Entertainment Expo featuring shooting, racing, punching, slashing and pummeling, a handful of upcoming titles like "The Sims 2" and "Playboy: The Mansion" have focused on "love" — or at least the physical act of it — as the player's main goal.
6.  ICANN Dispute Tests New Internet Services (AP). AP - When the company under contract to run much of the Internet's core decided last fall to launch a new online search service, it saw an opportunity to help lost Web surfers find their way.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  RIAA Loss Report Contradicts Nielsen Sales Record
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
8.  I'm looking forward to Paul Graham's Hackers & Painters; it sounds similar to the ideas that caused me to start Hack the Planet. (BTW Oreilly, can we have the table of contents in HTML?)
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  HP bags brace of service companies. Thickening ITSM fold By Ashlee Vance .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  chmexec.txt
11.  Cheap Wi-Fi DoS Attack Described by AusCERT
12.  W32.HLLW.Gearbug@mm
13.  W97M.Adren
14.  W32.Gaobot.ZX

10:27:28 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Commentary: Novell surfs the open-source wave. Forrester Research says Linux and open source seem to have energized Novell's user and partner community and may give Novell a chance to undo its most fundamental error vis-a-vis Microsoft.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  CEO: Yahoo! Feeds on Competitive Threats (AP). AP - After watching online search engine leader Google Inc. dominate business headlines for weeks, Yahoo! Inc. used a series of executive presentations Thursday to remind analysts the company is an Internet powerhouse determined to grow even bigger.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Lithium-Sulfur Batteries Unveiled
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
4.  Timothy Appnel: Movable Type 3.0 and Eating. The moral of this story is not that the Internet is full of bad people (I knew that already), but that releasing a free version of your software does not provide any information about how many people are willing to pay for it. And if no one is willing to pay for your product it's time to find another business.
5.  Eric Miller wants Atom to be developed in W3C instead of IETF. This sounds reasonable except for the risk that the W3C would screw up Atom by tying it into the Semantic Web. Danny Ayers adds that "The W3C get things done", but that doesn't count if the resulting specs are unimplementable.
6.  Space.com: Private Rocket SpaceShipOne Makes Third Rocket-Powered Flight. I love the part where the flight computer crashed so Melvill just eyeballed it.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Full Disclosure: Locking up Internet Explorer "Restarting IE is required after clicking on the l...
8.  Security Tracker: Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's ...
9.  Diceware: Passphrase Home Page "a method for picking passphrases that uses dice to select words ...
10.  Computer Weekly: Sasser worm highlights IT's patching dilemma "Concerns about software patching ...
11.  POA: Outlook Expresss 6.00
12.  Do Pirates Deserve a Windows Update?
13.  Red alert over Symantec firewall flaw
14.  New flaw takes Wi-Fi off the air
15.  AS.MW2004.Trojan
16.  New worm targets Sasser code flaw
17.  Security and 64-bits coming to Intel's Prescott in June
18.  Guide :: Linux Forensics Software
19.  Guide :: PC Forensics Software
20.  Guide :: PDA Forensics Tools and Techniques
21.  Guide :: Kerberos Implementation, Part 2
22.  Guide :: Kerberos Implementation
23.  Guide :: Colinux, Part 2
24.  Symantec Multiple Firewall Remote DNS KERNEL Overflow Vulnerability
25.  Symantec Multiple Firewall NBNS Response Processing Stack Overflow Vulnerability
26.  Symantec Multiple Firewall DNS Response Denial of Service Vulnerability
27.  Symantec Multiple Firewall NBNS Response Remote Heap Corruption Vulnerability
28.  Opera Telnet URI Handler File Creation/Truncation Vulnerability

9:27:08 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Nielsen Rating System points to possible deceit in RIAA sales figures. Avalon suggests that sales aren't down, only shipments are. How can that be possible? Simple: in the past, the RIAA always shipped considerably more units than were sold. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Privacy jam on California highway. A Web site that posts photos of carpool lane violators is taken offline after drawing rancor from critics.
3.  Worm feeds on Sasser-infected computers. Computers compromised by the Sasser worm may be vulnerable to a scavenging program that exploits a flaw in the software left behind by the worm, a security researcher warns.
4.  Intel shoots for dual-cores, wireless profits. At the company's spring analyst meeting, executives outline Intel's plans, which include delivering dual-core chips and expanding in markets such as wireless communications.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  FCC Proposes Using Empty TV Slots for Wireless (Reuters). Reuters - New wireless communications services could be deployed using vacant television airwaves in cities and rural areas, under a proposal issued by the U.S. Federal Communications Commission on Thursday.
6.  Yahoo Says Ready for Rivals, Sees Growth Ahead (Reuters). Reuters - Yahoo Inc. (YHOO.O) is ready for the next round of online competition as the Internet media company faces numerous rivals, including Web search leader Google Inc., Yahoo Chief Executive Terry Semel on Thursday told analysts.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Via-based Handheld Game Console Runs PC Games
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
8.  Cellular group: Number porting causing few problems. WASHINGTON - Cellular telephone carriers should be ready for a second deadline for allowing number portability, but many rural wireline telephone companies are trying to get out of the national portability rules, officials with the Cellular Telecommunications and Internet Association (CTIA) said in a briefing Thursday.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
9.  Security and 64-bits coming to Intel's Prescott in June. BOSTON - Later this year, Intel Corp. will turn on security features and 64-bit extensions within the Prescott core as it ships PC and server processors based on Prescott and the Grantsdale chipset in the second half of the year, Intel President and Chief Operating Officer Paul Otellini said during Intel's spring analyst meeting Thursday in New York.
10.  New worm targets Sasser code flaw. BOSTON - A new Internet worm is spreading by exploiting a flaw in the Sasser worm, according to an alert issued Thursday.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
11.  Dell beat itself in the first quarter. We'll print HP into submission By Ashlee Vance .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  Aus CERT: Denial of Service Vulnerability in IEEE 802.11 Wireless Devices "allows for a trivial ...
13.  Yahoo: Security Holes Make VOIP a Risky Business "Hackers can spoof SIP and IP addresses and hij...
14.  Linux Exposed: Understanding and Attacking DNS
15.  Net Security: Infosecurity Europe 2004 A Record Breaking Success!
16.  Net Security: HNS learning session - introduction to computer forensics "the need and importance...
17.  Court takes gag off antispam service
18.  [security bulletin] SSRT4722 rev.0 HP-UX Mozilla denial of service
19.  Other Worms Bypass Microsoft Sasser Fix
20.  Five More Under Investigation Over Sasser Virus
21.  'Sasser' Worm Tip of the PC Bug Invasion
22.  Groups Seek Legal Copying of DVDs
23.  Security dominates XP Service Pack 2
24.  Body of Evidence
25.  Dueling for Dollars
26.  Same Ship, Different Day
27.  What's Your Frequency
28.  Text Message to Düsseldorf 5-0: He Went That Way
29.  How Does Your Company Control Dangerous Digital Cargoes?
30.  Red Hat iptables -m Rate Limit Bypass
31.  Nokia Voyager Web Admin Server Long URL Overflow
32.  FreeBSD libkvm Open File Descriptor Memory Read
33.  IEEE 802.11 Wireless LANs Can Be Disrupted By Remote Users Within Transmission Range
34.  New Worm Targets Sasser-Infected Systems
35.  Elsewhere: New Worm Exploits Sasser Flaw
36.  News: States Speed up Spyware Race
37.  HNS Learning Session: Introduction to Computer Forensics

8:26:48 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Microsoft shares Windows tools via open source. The software powerhouse releases into the open-source community a series of pre-existing templates that developers can freely modify.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Microsoft Disputes $258 Mln Legal Fee (Reuters). Reuters - Lawyers seeking $258 million in legal fees from Microsoft Corp.'s (MSFT.O) $1.1 billion class action settlement in California are asking for too much, the world's largest software maker said on Thursday.
3.  Digital Camera Shipments Seen Up 39 Percent (Reuters). Reuters - Global shipments of digital cameras, driven by enthusiasm over the film-less devices, are expected to climb some 39 percent in 2004 and top 100 million units by 2008, according to an industry report.
4.  CEO: Yahoo! Feeds on Competitive Threats (AP). AP - After watching online search engine leader Google Inc. dominate business headlines for weeks, Yahoo! Inc. used a series of executive presentations Thursday to remind analysts the company is an Internet powerhouse determined to grow even bigger.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  2nd Multi-Format 128kbps Public Listening Test
6.  Anti-HIV Virus Developed
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
7.  Dell Q1 revenue, net income up sharply once again. BOSTON - Dell Inc.'s first-quarter revenue and net income soared on strong sales of high-margin products such as servers and notebooks, the company said Thursday.
8.  Critical 802.11 wireless flaw identified. A serious wireless network technology flaw that could lead to the breakdown of some critical infrastructures in just five seconds has been identified by Queensland University of Technology's (QUT) Information Security Research Centre, a finding that is likely to have worldwide ramifications.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
9.  Elsewhere: New Worm Exploits Sasser Flaw. A new Internet worm is spreading by exploiting a flaw in the Sasser worm, according to an alert issued this week. X-NAS-Bayes: #0: 5.27191E-163; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 756 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The new worm is tentatively named Dabber. It takes adv...

10.  News: States Speed up Spyware Race. State lawmakers' eagerness to crack down on Internet "spyware" could force the federal government to move sooner than expected to pass its own law, despite misgivings in the Bush administration and among technology executives.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
11.  BugTraq: POA: Outlook Expresss 6.00. Sender: http-equiv at excite dot com [1 at malware dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  BEA WebLogic weblogic.xml Reverts To Default Permissions
13.  Windows Me HSC hcp:// URL XSS
14.  Icecast HTTP Basic Authorization DoS
15.  FuseTalk banning.cfm Ban Arbitrary User
16.  Cisco Aironet Web Interface Arbitrary Modification
17.  eMule Web Interface POST Content Length DoS
18.  Outpost Firewall Incomplete Request DoS
19.  Sweex Wireless Broadband Router Configuration Leakage
20.  Zoneminder Query String Overflow
21.  Linksys BEF Series Routers BOOTP DoS
22.  Opera onUnload Address Bar Spoofing
23.  Columnists: Secure by Default
24.  Enterprise IT Toolkit for the Week of 5/13/04
25.  The Security Risk of Keyboard Clicks
26.  'Whispering keyboards' could be next attack trend
27.  802.11 WiFi Denial of Service Exploit Discovered
28.  AA-2004.02 -- Denial of Service Vulnerability in IEEE 802.11 Wireless Devices
29.  Rand Report Says Geospatial Data Not Big Threat
30.  Rand: Feds protect maps
31.  Suing the Pants Off Spammers
32.  Company shuts down Malaysian-hosted website showing beheading

7:26:27 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  BEA misses analyst expectations. Revenue from the company's software licenses drops 2 percent to $120 million.
2.  Briefly: BEA misses analyst expectations. Plus: BellSouth streamlines VoIP services...Bush names new FTC chairman...Defense Dept. asked to hand over Iraq images for Web...Call for visa reform to aid U.S. research.
3.  PalmOne updates software for Treo 600 smart phone. Among the issues addressed are enhancements to the browser and e-mail program as well as enhancements designed to improve the device's "audio-quality reliability."
4.  Yahoo boosts free e-mail storage to 100MB. The Web portal also will begin offering "virtually unlimited storage" for its paid e-mail customers.
5.  Dell's box score: Earnings meet expectations. The PC giant delivers first-quarter 2005 earnings that match earlier projections, as growth in international sales and printer sales help the company build on its recent momentum.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  ICANN Dispute Tests New Internet Services (AP). AP - When the company under contract to run much of the Internet's core decided last fall to launch a new online search service, it saw an opportunity to help lost Web surfers find their way.
7.  About 2.6 Million U.S. Consumers Move Phone Numbers (Reuters). Reuters - Roughly 2.6 million U.S. consumers have moved their telephone number between wireless carriers or between a wireless phone and a home telephone since November, U.S. Federal Communications Commission officials said on Thursday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
8.  Justice Department Censors ACLU Web Site
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
9.  Security and 64-bits coming to Intel's Prescott in June. BOSTON - Later this year, Intel Corp. will turn on security features and 64-bit extensions within the Prescott core as it ships PC and server processors based on Prescott and the Grantsdale chipset in the second half of the year, Intel President and Chief Operating Officer Paul Otellini said during Intel's spring analyst meeting Thursday in New York.
10.  Tools give applications the green light. LAS VEGAS -- Network management is digging into the sweet spot of application performance optimization, as more enterprises move critical applications to the Internet. Here at NetWorld+Interop 2004, Internap, 8e6, and Pivia introduced technology designed to give applications priority within the network.
11.  Gov't change not likely to affect IT in India. BANGALORE, INDIA - The fall of Atal Bihari Vajpayee's government in India surprised the IT industry there, particularly because most exit polls predicted that the prime minister's Bharatiya Janata Party (BJP) and its allies would cobble together a majority in parliament.
12.  New worm targets Sasser code flaw. BOSTON - A new Internet worm is spreading by exploiting a flaw in the Sasser worm, according to an alert issued Thursday.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
13.  Columnists: Secure by Default. Why "Secure By Default" is a step in the right direction.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
14.  BugTraq: [security bulletin] SSRT4722 rev.0 HP-UX Mozilla denial of service. Sender: Boren, Rich (SSRT) [rich dot boren at hp dot com]
15.  Vulns: Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability. Internet Explorer is reportedly affected by a XML parsing denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed...
16.  Vulns: Linux Kernel Panic Function Call Buffer Overflow Vulnerability. The panic() function call of the Linux kernel has been reported prone to a buffer overflow vulnerability. X-NAS-Bayes: #0: 4.29355E-268; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 755 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The vulnerability is reported to present itself when an unboun...

17.  Vulns: EMule Web Control Panel Denial Of Service Vulnerability. eMule is a freely available, open source peer-to-peer file sharing application. eMule uses the eDonkey file sharing protocol. It is available for the BSD, Linux, Microsof...
18.  Vulns: McAfee ePolicy Orchestrator Server Remote Code Execution Vulnerability. McAfee ePolicy Orchestrator (ePO) is a product designed to remotely manage various policies and antivirus products. It is available for the Microsoft Windows operating sy...
19.  Vulns: NetCache/Data ONTAP Remote Undisclosed Denial Of Service Vulnerability. Network Appliance NetCache is a caching appliance. Data ONTAP is an enterprise data management operating system; it will integrate with Unix and Unix variants and Microso...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
20.  Survey finds most professional geeks are men. Shock results stun world By Lucy Sherriff .
21.  McDonald's breaks IT barriers with McAsian web site. Asians love green tea and fries By Ashlee Vance .
22.  New flaw takes Wi-Fi off the air. Jam today and jam tomorrow By Drew Cullen .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
23.  Officials admit Iraq interrogations violated Geneva Conventions
24.  Antivirus Firms Warn Of Growing 'Bot' Networks
25.  Wallon worm uses Yahoo, MS to spread
26.  Why Are Virus Writers So Tough To Catch? (NewsFactor)
27.  sa11604.txt
28.  linksys-dhcp-exploit..>
29.  Vulnérabilités critiques pour les produits de sécurité de Norton
30.  La LEN adoptée, une transcription frileuse de la directive européenne
31.  Five More Under Investigation Over Sasser Virus

6:26:08 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Archaeologists claim discovery of the Library of Alexandria. Polish-Egyptian archaeologists are claiming to have found the original site of the Library of Alexandria, replete with large lecture halls capable of holding some 5,000 students. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Japanese poop-and-scoop reminders. X-NAS-Bayes: #0: 4.15644E-184; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 754 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

This is a gallery of Japanese poop-and-scoop nagware signs. They rawk.

Link

(Thanks, Tim!)


----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  Court takes gag off antispam service. A San Francisco judge lifts a temporary restraining order against SpamCop that prevented it from interfering with messages sent by OptIn, which is suing the antispam blocklist.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  RightNow IPO: Room To Play (NewsFactor). NewsFactor - The announcement of yet another initial public stock offering in the CRM industry -- RightNow Technologies -- is both exciting and nerve-wracking for software vendors.
5.  MCI, Microsoft Join on Office Live Meeting (NewsFactor). NewsFactor - MCI and Microsoft (Nasdaq: MSFT) plan to jointly develop and market communication and collaboration products that feature Microsoft Office Live Meeting, starting with MCI's next iteration of its Net Conferencing services.
6.  Novell Delivers Enterprise Support for Linux (NewsFactor). NewsFactor - Further establishing its position as a major player in the Linux realm, Novell (Nasdaq: NOVL) is offering enterprise-level support for the company's line of Linux products, ranging from the server to the desktop.
7.  Microsoft Bids Adieu to Wi-Fi Hardware (NewsFactor). NewsFactor - Microsoft (Nasdaq: MSFT) is ditching its branded wireless hardware business, which consisted of base stations, USB adapters, notebook and desktop adapters and switches.
8.  FCC Endorses Expanding Wireless Services (AP). AP - Federal regulators endorsed a plan Thursday to tap unused television airwaves to bring high-speed Internet connections and other wireless technologies to more people, especially in rural areas.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  Rutan's SpaceshipOne Hits 200,000 Feet
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
10.  IBM seeks Power developers. IBM on Monday will roll out developer resources for the company’s Power microprocessor architecture, with the goal of building what the company describes as a community of innovation around the platform.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
11.  HNS Learning Session: Introduction to Computer Forensics
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
12.  Red alert over Symantec firewall flaw. Four bugs rated as 'potentially devastating' By John Leyden .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Wallon Worm Deceives Users (PC World)
14.  Fedora: OpenSSL Denial of service vulnerability
15.  Fedora: mc Multiple vulnerabilities
16.  Red Hat: kernel Multiple vulnerabilities
17.  Red Hat: ipsec-tools Multiple vulnerabilities
18.  Mandrake: apache2 Denial of service vulnerability
19.  Gentoo: ClamAV Privilege escalation vulnerability
20.  Gentoo: OpenOffice.org Format string vulnerabilities
21.  Debian: exim-tls Buffer overflow vulnerabilities
22.  SCO Group: OpenServer Bad X authorization configuration
23.  Mandrake: rsync Directory traversal vulnerability
24.  Slackware: apache Multiple vulnerabilities
25.  Gentoo: utempter Insecure temporary file vulnerability
26.  NetBSD: systrace Privilege escalation vulnerability
27.  OpenBSD: procfs Incorrect bounds checking vulnerability
28.  Debian: mah-jong Denial of service vulnerability
29.  CNet: Illuminating blacked-out words "European researchers at a security conference in Switzerla...
30.  13 May Troj/StartPa-AE
31.  sa11532.txt
32.  05.12.04.txt
33.  Opera Telnet URI Handler Vulnerability also applies to other browsers
34.  SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues

5:25:47 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Longhorn goes to pieces. Some much-hyped features of Microsoft's next major release of Windows are being cut back, while others may debut ahead of schedule, CNET News.com has learned.
2.  Security group warns of flaw in wireless protocol. The Australian Computer Emergency Response Team issues an advisory warning companies that their wireless networks could be disrupted by an attacker with a handheld device.
3.  Broadband leaps ahead of AOL. For the first time, broadband customers surpass the number of people who subscribe to America Online, a sign of the growing influence of high-speed Net services.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Sun Completes 'Niagara' Design (Ziff Davis). Ziff Davis - The company has finished designing its next-generation UltraSPARC processor, a move that industry observers say puts Sun on track for delivering the chip in late 2005 or early 2006.
5.  Microsoft Disputes $258 Mln Legal Fee (Reuters). Reuters - Lawyers seeking $258 million in legal fees from Microsoft Corp.'s (MSFT.O) $1.1 billion class action settlement in California are asking for too much, the world's largest software maker said on Thursday.
6.  SCO, Novell Trade Legal Moves (Ziff Davis). Ziff Davis - Novell tries to get SCO's Unix copyright claims dismissed while SCO attempts to get this particular case moved from the federal court to a Utah state court.
7.  FCC Proposes Using Empty TV Slots for Wireless (Reuters). Reuters - New wireless communications services could be deployed using vacant television airwaves in cities and rural areas, under a proposal issued by the U.S. Federal Communications Commission on Thursday.
8.  Gateway, Integraph Settle Patent Suit (PC World). PC World - PC maker agrees to license Clipper memory technology.
9.  Yahoo Says It's Ready for Rivals, Sees Online Ads Up (Reuters). Reuters - Yahoo Inc. (YHOO.O) is ready for the next round of online competition as the Internet media company faces numerous rivals, including Web search leader Google Inc., Yahoo Chief Executive Terry Semel on Thursday told analysts.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
10.  Modded XBox The Ultimate Multimedia PC?
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
11.  Court backs off pro-spam ruling. BOSTON - A California federal court dissolved a restraining order against SpamCop.net, one day after issuing an order preventing the antispam service from warning ISPs (Internet service providers) about complaints of unsolicited commercial ("spam") e-mail coming from their networks.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
12.  Wallon worm uses Yahoo, MS to spread. Antivirus software companies issued warnings and software updates on Tuesday and Wednesday for a new worm, Wallon, that uses deceptive Web links to Yahoo.com to trick users into downloading malicious programs.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
13.  Elsewhere: Security dominates XP Service Pack 2. Eighty per cent of changes focused on security as Microsoft prepares for operating system upgrade X-NAS-Bayes: #0: 2.69817E-253; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 753 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Security changes in Windows XP Service Pack 2 will plug a gap that has ...

14.  Elsewhere: Wallon worm uses Yahoo, MS to spread. Antivirus software companies issued warnings and software updates on Tuesday and Wednesday for a new worm, Wallon, that uses deceptive Web links to Yahoo.com to trick use...
15.  News: Child porn case highlights browser hijack risks. Browser hijacking programs can redirect users to pornographic websites. But could these malicious programs also lead to false accusations of possession of child pornography?
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
16.  BugTraq: Opera Telnet URI Handler Vulnerability also applies to other browsers. Sender: Jannes [ddos at arcor dot de]
17.  BugTraq: SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues. Sender: Sym Security [secure at symantec dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  Symantec Patches Firewall Flaws
19.  Hunt For Sasser Authors Widens
20.  Microsoft Denies Reports That Windows XP SP2 Will Run On Pirated Systems
21.  Group Warns Of Wireless DoS Attack Vulnerability
22.  Vulnerabilities in Symantec Products, Dabber Worm, Empty .zip File Attachments
23.  eEye.symantecDNS1.tx..>
24.  eEye.symantecDNS2.tx..>
25.  eEye.symantecNBNS1.t..>
26.  eEye.symantecNBNS2.t..>
27.  Symantec Firewall Products Multiple Critical Vulnerabilities
28.  IEEE 802.11 Wireless Devices Denial of Service Vulnerability
29.  Vulnérabilités critiques pour les produits de sécurité Norton

4:25:29 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  New Google service challenges Yahoo Groups. Called Google Groups 2, the service lets people create, search and sift through e-mail mailing lists. People can also subscribe to and monitor groups of interest.
2.  Semel raises Yahoo's subscriber goal. In a display of confidence, chief Terry Semel raises his company's target for paid users by 50 percent.
3.  Personal video recorders on fast-forward growthwise. Worldwide shipments of PVRs more than tripled in 2003 as the gadgets finally caught on with consumers, research released by In-Stat/MDR says.
4.  CitySearch teams with Overture. In another sign that local search is the rage, the companies team to let Yahoo-owned Overture run ads in CitySearch's local listings.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Secure Architectures with OpenBSD
6.  SCO Caught Copying
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Debian: mah-jong Denial of service vulnerability
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
8.  News: New flaw takes WiFi off the air. Vandals could jam nearby wireless networks with ease, researchers find.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
9.  Vulns: National Science Foundation Squid Proxy Internet Access Control Bypass Vulnerability. Squid is a freely available, open source web proxy software package. It is designed for use on the Unix and Linux platforms. X-NAS-Bayes: #0: 2.60639E-158; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 752 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Squid proxy has been reported to be affected...

10.  Vulns: MailEnable Mail Server HTTPMail Remote Heap Overflow Vulnerability. MailEnable is a commercially available POP3 and SMTP server for the Windows platform.

The 'Professional' and 'Enterprise' editions of MailEnable are reported to be prone...

----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
11.  HNS learning session: introduction to computer forensics
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
12.  EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow
13.  Re: NISCC Vulnerability Advisory 236929: Vulnerability Issues in TCP
14.  EEYE: Symantec Multiple Firewall Remote DNS KERNEL Overflow
15.  EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service
16.  Security dominates XP Service Pack 2
17.  Mac Trojan Set Loose-More to Come? (Ziff Davis)
18.  IETF Mulling Changes to Secure TCP
19.  SpamCop gets gagging order lifted
20.  Vier Sicherheitslücken in Symantecs Personal Firewall
21.  Symantec Multiple Firewall Remote DNS KERNEL Overflow
22.  Symantec Multiple Firewall NBNS Response Remote Heap Corruption
23.  Symantec Multiple Firewall DNS Response Denial-of-Service
24.  Symantec Multiple Firewall NBNS Response Processing Stack Overflow
25.  Wallon virus wrecks Windows Media Player
26.  eEye - Symantec Multiple Firewall Vulnerabilities: NBNS Response Processing Stack Overflow | DNS...
27.  EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption
28.  Showhelp() local CHM file execution
29.  Re: surfboard1.1.6 local exploit.
30.  [ GLSA 200405-05 ] Utempter symlink vulnerability
31.  [SECURITY] [DSA 503-1] New mah-jong packages fix denial of service
32.  [slackware-security]apache (SSA:2004-133-01)
33.  German Police Round Up More Sasser Suspects
34.  HNS learning session: introduction to computer forensics
35.  Private blamed in abuse probe requests leave

3:25:08 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Microsoft server roadmap outfitted with lots of rest areas. Microsoft today laid out its 5-year plan for its server line, leading up to and including Longhorn Server. The announcement breaks quite a bit of silence as to when Longhorn Server is expected to ship and what features it may contain. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Usenet as Atom feed. Google is beta-testing Google Groups2, a service that publishes Usenet newsgroups as Atom feeds, which ban be read in your favorite Atom/RSS reader (I use Shrook). X-NAS-Bayes: #0: 4.61693E-257; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 751 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Link

(via Dan Gillmor)

3.  This weekend in SF, join Xeni at Wired NextFest. If you're anywhere near San Francisco this weekend, join me at the inaugural edition of Wired Magazine's NextFest.

I worked with Wired Magazine to produce a series of panels, presentations, and "fireside chats" at the event -- guests include Andrew Stanton from Pixar, "Doom" creator John Carmack, Space Adventures CEO Eric Anderson, X-Prize founder Peter Diamandis, James Luyten of Woods Hole Oceanographic Institute, Xcor CEO Jeff Greason, NASA Space Architect Gary Martin, robotics guru Rodney Brooks, and creators of the film "Sky Captain and the World of Tomorrow."

The event is presented by General Electric, and takes places Friday through Sunday at Fort Mason center in SF. Tickets are affordable and available. It's a family-friendly event aimed at consumers and deep geeks alike... think Epcot Center meets 1904 World's Fair. Robots, rocket ships, and an abundance of geektastic eye candy. Going to be great. See you there!
Link

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
4.  Intergraph, Gateway settle Pentium patent suit. Gateway agrees to pay Intergraph at least $10 million to settle a suit alleging that Pentium-based Gateway PCs violated patents involving an Intergraph chip called Clipper.
5.  HP buys IT training firms. Hewlett-Packard has taken over two IT training and consulting companies, a move designed to add bulk to the technology giant's services line-up.
6.  Vonage VoIP hits RadioShack stores. The consumer electronics retailer is selling Net telephony packages in nearly 4,000 of its stores.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  IBM Partners to Add 'Expertise' to Compliance Software (Ziff Davis). Ziff Davis - More than 20 of IBM's partners are supporting compliance software that helps customers meet government and industry regulations.
8.  Google Bets the House on Banner Ads (washingtonpost.com). washingtonpost.com - valign="top">9.  Marines Want More Bomb-Finding Robots, Armor (Reuters). Reuters - Major hostilities in Iraq officially ended a year ago, but increasingly sophisticated homemade bombs, aggressive snipers and changing weather conditions are creating a challenge for troop suppliers.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
10.  More on Global Dimming
11.  Two Congressmen Push for DMCA Amendments
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
12.  FBI Investigating Cyber-extortion
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
13.  Vulns: Open WebMail Remote Command Execution Variant Vulnerability. Open WebMail is an open-source web mail package written in Perl.

A vulnerability has been reported in Open WebMail that allows a remote attacker to execute arbitrary com...

14.  Vulns: Tutorials Manager Multiple Remote SQL Injection Vulnerabilities. Tutorials manager is a web-based application designed to allow for the management and presentation of various tutorials. It is freely available for Unix and Unix variant...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
15.  Further Sasser arrests but no charges in Germany
16.  Symantec, Norton need vital patches in next 24 hours
17.  Windows Server 2003: Hardware-Based Security
18.  Elsewhere: 'Whispering keyboards' could be next attack trend
19.  Elsewhere: Symantec patches critical firewall flaws
20.  News: New flaw takes WiFi off the air
21.  Bluetooth SIG Meets to Discuss Security Issues
22.  NIST Validates OpenSSL Algorithms

2:24:49 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Video Voyeurism Prevention Act on way to becoming US law. The House Judiciary Committee approved a bill yesterday that would make the use of camera phones and other image-capturing devices illegal when such uses are aimed at what's being termed as "video voyeurism." By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Put on Your PJs and Run Playboy. Wired News just published a story about the Playboy game launch, written by my colleague Daniel Terdiman. Photos include some that I shot at the Playboy Mansion the other night, including the image below: Hef and companions testing out the game, and liking it.
[T]his November, anyone with a PC, PlayStation 2 or Xbox will have the opportunity to put on Hef's smoking jacket and lord over his mansion. Game publishers Arush Entertainment and Groove Games will release Playboy: The Mansion, a video game that puts players in the virtual footwear of the publishing tycoon. "You can create your own Playboy magazine and throw your own parties," Hefner said.

Given that it's E3 week in Los Angeles, the game was the center attraction at a party at the real-life Playboy mansion Tuesday night -- that is, if it were possible to ignore a bevy of Playboy playmates, bunnies and naked models adorned with body paint designed to look like bikinis.

Think of the game as SimHef. Players take the reins of the Playboy empire, initially concentrating on getting the first issue of a faux Playboy on newsstands. They have to play Hef as a businessman, making financial decisions, developing fame and creating the kinds of personal, professional and romantic relationships Hefner did on his way to the top.

Link
3.  Orange Mobile's robotic adherence to idiotic rules. Yesterday was a momentous occasion: it was the day I received my first UK bank statement, and was therefore able to do my bit to consummate England's national love affair with the utility bill. I mean, seriously: this is a country where you can walk into a shop to get a mobile phone or an ID card and say, "I have in this hand a fistful of credit cards and in this hand, a pristine Canadian passport," and have the clerk sniff and say, "I'm sorry sir, but without a gas bill, we simply won't be able to help you" (when I went to Citibank with the details of my Citibank US and Citibank Canada accounts, I was told to come back with a FedExed note from my boss attesting to my address, because of the "know your customer" rules -- apparently, an original signature on letterhead confers a depth of knowledge that mere years-long in-house financial records can't convey).

Yesterday was the day I hied myself off to the Tottenham Court Road to go shopping for a mobile phone. I knew exactly what I wanted: a Sony-Ericsson P900 with the O2 75 plan, which gets me 1000 minutes and several texts for only two or three times what comparable service would cost in the US (English mobile phones are very feature-rich, come with lovely high-speed data service, and cost so much to use that it's hard to believe that there's really anyone using the advanced features -- not at £4 a megabyte!).

The man in the Carphone Warehouse gave me the hookup, set up my account, called their credit department, and told me I'd have to pay a £150 deposit to go a-roaming in Europe. This is steep, but I can hack it. I gave him the nod, and then he passed me the contract to sign and went off to get my new phone. That's when he discovered that he'd run right out of P900s. I walked the length of the Tottenham Court Road strip and couldn't locate a P900 (or, indeed any phone with more than 12 buttons) for love or money.

But eventually, my luck changed. An Orange store staffed with friendly and knowledgeable clerks had P900s in stock and they were happy to take my money. We went through the signup rigamarole again -- took hours -- and then they called it in.

No dice. All of Orange's account sign-up computers were down. I went away and came back, but the computers were still down. The clerk confided that this happened a lot to Orange's overtaxed billing computers. I thought that it was a little weird that I was about to trust this company with my telephony when they couldn't even manage the IT necessary to reliably sign up a new customer, but shrug, they had the phone and I needed it, and besides, they'd match O2's rates for me. They sent me away and asked me to return the next day.

It was a waste of time.

I came back today, and after an hour more of hemming and hawing, this is what transpired: Orange would give me a phone with e £75 deposit, but I would have to wait 90 days before I'd be allowed to roam with the phone. I pointed out that I travelled two or three weeks out of every month, and this would render this (very expensive) phone very useless to me. I asked to speak to a supervisor. No dice. I offered to leave the same deposit I'd been asked for at O2. Even fewer than no dice -- "We don't know who you are, we can't give you roaming." I offered a bigger deposit. I offered to show the (enormous, promptly paid) cellular bills from my last year with Nextel. The deed to my condo in Toronto. The letter of reference from Yale. The Wired masthead. My US credit-report.

A waste of time.

It's the rules, they said. And please stop asking to speak to the credit department: they're not "customer-facing" and they're getting annoyed. You're annoying them.

Right, I thought, I'll call the press-relations department. I spoke to them at length -- flatteringly enough, they'd heard of me. So, what's the problem, I asked. Well, we can't do this because it's too risky to extend roaming to someone with no credit. I have credit. And it's what everyone does. Not O2. But you could ring up big bills with our roaming partners and stick us with them. I could call Tokyo and leave the phone off the hook for 24h without leaving England's shores and rack up just as big a liability for you..

At the end of the day, it came to this: These are our rules. We will stick to them. We will not make exceptions to them. We will hug them to our bosom beyond any kind of rationality or reason.

I am such a goddamned telephone junkie. I'm no Joi Ito with his $3,500 GPRS bills, but I've been spending $200 or $300 on cellular telephone damned near every month since 1992. I am every mobile carrier's dream. Any rational carrier would jump at my business.

But Orange isn't rational. It doesn't have a business plan, it has a bunch of superstitions to which it rigidly hews regardless of circumstance -- the media person I was speaking to reported that she'd spoken to their head of customer care, who wouldn't budge; this intransigence goes right to the top.

So Orange has lost my business, and to hell with them. As soon as O2 gets some P900s in stock, I'll gladly give them the 150 quid and get signed up and running.

And I think I've figured out why the Orange shop is the only place in town with any phones in stock: they make life so miserable for anyone who tries to buy one that you'd have to be flat-out desperate to take one off their hands.

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
4.  BellSouth lessens VoIP hardware requirements. The new service will be powered in part by Lucent equipment housed in BellSouth's network, lessening the hardware purchases required for customers.
5.  Briefly: BellSouth streamlines VoIP services. Plus: Bush names new FTC chairman...Defense Dept. asked to hand over Iraq images for Web...Call for visa reform to aid U.S. research...No ruling yet on Novell-SCO suit.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  Microsoft confirms delay of Virtual PC 7 (MacCentral). MacCentral - Microsoft Corp.'s Macintosh Business Unit (MacBU) confirmed that the upcoming version of Virtual PC would not ship with Office 2004 when it is officially released next week. The new version of Virtual PC will be the first compatible version of the Windows emulator available for owners of Apple's Power Mac G5.
7.  Sony launches portable PlayStation (AFP). AFP - Sony Computer Entertainment unveiled its new portable PlayStation game consoles to be marketed globally early next year aimed at a segment dominated by the Nintendo Gameboy.
8.  Cisco's Job Shocker (washingtonpost.com). washingtonpost.com - Silicon Valley, prepare for an earthquake.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  Toronto Open Source Conference Report
10.  Egyptian Linux Advocates' Replies
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
11.  Internet giant's profits up 23%. Technology heavyweight Cisco Systems reports third quarter rises in profits and sales topping 20%.
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
12.  Wallon worm uses Yahoo, MS to spread. Antivirus software companies issued warnings and software updates on Tuesday and Wednesday for a new worm, Wallon, that uses deceptive Web links to Yahoo.com to trick users into downloading malicious programs.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
13.  Elsewhere: 'Whispering keyboards' could be next attack trend. OAKLAND -- Listen to this: Eavesdroppers can decipher what is typed by simply listening to the sound of a keystroke, according to a scientist at this week's IEEE Symposiu...
14.  Elsewhere: Symantec patches critical firewall flaws. For the third time this year, Internet security company Symantec has had to release patches to plug critical security flaws in many of its popular antivirus and firewall ...
15.  News: New flaw takes WiFi off the air. Vandals could jam nearby wireless networks with ease, researchers find.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
16.  BugTraq: Showhelp() local CHM file execution. Sender: roozbeh afrasiabi [roozbeh_afrasiabi at yahoo dot com]
17.  BugTraq: Re: surfboard1.1.6 local exploit.. Sender: Meredydd [meredydd at everybuddy dot com]
18.  BugTraq: [SECURITY] [DSA 503-1] New mah-jong packages fix denial of service. Sender: [joey at infodrom dot org (Martin Schulze)]
19.  BugTraq: [ GLSA 200405-05 ] Utempter symlink vulnerability. Sender: Kurt Lieber [klieber at gentoo dot org]
20.  Vulns: PaX 2.6 Kernel Patch Denial Of Service Vulnerability. PaX is an anti-intrusion kernel level patch for Linux based operating systems. It provides functionality to help prevent arbitrary code execution that may result from mem...
21.  Vulns: AIX Getlvcb Command Line Argument Buffer Overflow Vulnerability. AIX getlvcb is a utility used to display logical volume control block information. X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 734 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

getlvcb has been reported to be prone to a buffer overflow vulnerability. The issue pr...

22.  Vulns: PHPShop Remote PHP Script Execution Vulnerability. phpShop is a typical web-based shopping cart solution. It is freely available for Unix and Unix variants as well as Microsoft Windows based operating systems.

Reportedl...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
23.  MS roadmaps Longhorn Server and beyond to 2/4 year beat. Now predictable - but only as a prediction By John Lettice .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
24.  VoIP Can Be Vulnerable To Hackers, Too
25.  Antivirus companies muting false alarms
26.  The lessons of Sasser
27.  McAfee DAT 4360
28.  McAfee SuperDAT 4360
29.  Norton AntiVirus Virus Definitions May 12, 2004
30.  Wallon Worm Skirts Around Windows Patch Release
31.  Symantec, Norton need vital patches in next 24 hours
32.  Fundamentals: Password Madness
33.  DMCA Revisions 'Legalize Hacking'
34.  Spec in Works to Secure Wireless Networks
35.  BlueTooth Hacking For Fun and Profit
36.  Phatbot arrest throws open trade in zombie PCs
37.  Crackers declare cyberwar on USA
38.  MS îòêðûëà èñõîäíèêè WTL
39.  CIA concludes al-Zarqawi decapitated Berg
40.  Rumsfeld makes surprise visit to notorious Iraq prison
41.  Agnitum Outpost Firewall Pro Can Be Crashed By Remote Users Sending a Sustained Packet Flood

1:24:28 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Disaster-play at home. Former guest blogger Todd Lappin points us to a professional moulage kit, perfect for simulating your own brutal wounds and accident scenarios in the privacy of your own home. For $549, you get a convenient carrying case filled with such essentials as:

* 1 foreign body protrusion

* 1 eyeball

* 1 eviscerated intestines

* 2 crushed feet

* 1 plexiglass pk for simulated "glass in wound"

* 1 roll tape

* and lots more!

What a great gift! Link

2.  Beauty and the Breast. Audrey-Samsara-still
Manuel Schmettau says:

"An artwork (video) by my friend Amy Jenkins, featuring her daughter breastfeeding and falling asleep, has been called "distasteful" and removed from an exhibition at Salvatore Ferragamo's 5th Avenue store. (Ferragamo originally invited Amy to create the piece for their store's art gallery on the second floor.)

X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 733 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

When asked to "create an artwork using inspiration from objects in their store," Amy was promised complete artistic freedom. Hesitant at first, she explored the store and fell in love with a little pair of red shoes, which turned out to be called the "Audrey" shoes (they were originally designed for Audrey Hepburn.) As her daughter is also named Audrey, she felt it was fate to accept the invitation. It was not a commercial commission, and she financed the production of the video herself.

Amy would love to show this piece elsewhere, unfortunately it was made specially for their 42" widescreen monitor (a costly item that she doesn't own!) Her hope is that "The Audrey Samsara" will soon be shown at a more open-minded venue."

The New York Daily News ran an item about the controversy. Link
3.  Indian voting machines compared with Diebold's. On the eve of the first Indian election run with electronic-voting machines, a technologist called "smz" has posted an in-depth comparison between Diebold's voting machines and the ones in use in India.

The System is a set of two devices running on 6V batteries. One device, the Voting Unit is used by the Voter, and another device called the Control Unit is operated by the Electoral Officer. Both units are connected by a 5 meter cable. The Voting unit has a Blue Button for every candidate, the unit can hold 16 candidates, but up to 4 units can be chained, to accommodate 64 candidates. The Control Units has Three buttons on the surface, namely, one button to release a single vote, one button to see the total umber of vote casted till now, and one button to close the election process. The result button is hidden and sealed, It cannot be pressed unless the Close button is already pressed.

The voting unit has a list of candidate's names and their Party Symbols pasted on the surface, and a Blue button to cast a vote faces ever candidate's name. The Party Symbols (like a Lotus, an elephant, a horse etc.) are approved by the election commission to be unique, All political parties use these symbols while campaigning, and illiterate people can identify their candidates by looking at his symbol, and pressing the blue button in front of his symbol.

Link

(Thanks, smz!)

4.  Doing it like rabbits. Swatch installed a Times Square billboard advertising their new Bunnysutra watch emblazoned with cartoon illustrations of "happy bunny positions." Predictably, plenty of people are offended. Here's a link to a an article with a slideshow of the billboard images. And a Flash demo of the watch, featuring Swatch's new "Touch" technology. ("Touch The dial. Pick A Position.") And, a New York Post article filled with quotes from the aforementioned angry Americans. Link (Thanks, Vann!)
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
5.  Handheld gaming matures. Nintendo and Sony look to attract an older, freer-spending class of gamers with new devices that differ from one another in several critical areas.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  802.11b wireless flaw identified (MacCentral). MacCentral - A serious wireless network technology flaw has been identified that could lead to the breakdown of some critical infrastructures. The flaw, which was discovered by the Queensland University of Technology's (QUT) Information Security Research Centre, affects the 802.11b standard.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  H2G2 Film Website
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
8.  Berg video website shut down. A Malaysian server shuts down the site which first posted video of the American contractor's beheading.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
9.  Further Sasser arrests but no charges in Germany. Police in Lower Saxony, Germany, arrested five young men on Tuesday in connection with the Sasser Internet worm but all have been released without charge, a police spokesman said Thursday.
10.  Symantec, Norton need vital patches in next 24 hours. Almost the entire range of Symantec Corp. security software, from Norton Internet Security through to the Symantec Firewall require urgent updates, the company has warned, after a series of four extremely critical vulnerabilities were found by security company eEye Digital Security Inc.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
11.  Phatbot arrest throws open trade in zombie PCs
12.  Crackers declare cyberwar on USA
13.  OpenBSD: procfs Incorrect bounds checking vulnerability
14.  Slackware: apache Multiple vulnerabilities
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
15.  BugTraq: EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow. Sender: Marc Maiffret [mmaiffret at eeye dot com]
16.  Vulns: Linux Kernel Local IO Access Inheritance Vulnerability. The Linux kernel implements various functions for granting access to IO resources including 'ioperm()'. This function manipulates io_bitmap pointers for access to system...
17.  Vulns: Microsoft Windows LSASS Buffer Overrun Vulnerability. Microsoft Windows LSASS (Local Security Authority Subsystem Service) is prone to a remotely exploitable stack-based buffer overrun vulnerability. This service provides ...
18.  Vulns: Icecast Server Base64 Authorization Request Remote Buffer Overflow Vulnerability. Icecast is a freely available, open source streaming audio server. Icecast is available for the Unix, Linux, and Microsoft Windows platforms.

A vulnerability has been i...

19.  Vulns: Qualcomm Eudora Embedded Hyperlink URI Obfuscation Weakness. It has been reported that the Qualcomm Eudora MTA is prone to a URI obfuscation weakness that may hide the true contents of a link. The problem occurs when a user@locatio...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
20.  Business slow to embrace wireless. Confusion, fear, security concerns By Datamonitor .
21.  Industry warms to BT's LLU price cuts. Room for further reductions, though By Tim Richardson .
22.  Good for you, good for Microsoft - here comes WinXP SP2. You know it makes sense... By John Lettice .

12:24:07 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Conn. Man Fined for Downloading Music (AP). AP - A federal judge has ordered a Bristol man to pay more than $4,000 for downloading five songs from the Internet.
2.  Qualcomm Offers Chips to Allow 6-Megapixel Cameras (Reuters). Reuters - Mobile phone technology provider Qualcomm Inc. (QCOM.O) on Wednesday unveiled a new line of chips with ultra-high resolution camera features and said it was making inroads in advanced new markets.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Running Video Cards in Parallel
4.  Swedish Carbon-Fiber Stealth Ship Runs NT
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
5.  Symantec, Norton need vital patches in next 24 hours. Almost the entire range of Symantec Corp. security software, from Norton Internet Security through to the Symantec Firewall require urgent updates, the company has warned, after a series of four extremely critical vulnerabilities were found by security company eEye Digital Security Inc.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
6.  Fundamentals: Password Madness
7.  Spec in Works to Secure Wireless Networks
8.  DMCA Revisions 'Legalize Hacking'
9.  BlueTooth Hacking For Fun and Profit
10.  Red Hat: kernel Multiple vulnerabilities
11.  Gentoo: ClamAV Privilege escalation vulnerability
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  Vulns: Monit Overly Long HTTP Request Buffer Overrun Vulnerability. Monit is a utility for the Linux and Unix operating systems that is designed to monitor processes, devices, files, and directories. The application makes use of an HTTPS ...
13.  Vulns: APSIS Pound Remote Format String Vulnerability. APSIS Pound is a reverse-proxy and load-balancer service. X-NAS-Bayes: #0: 4.96719E-147; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 732 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

APSIS Pound has been found to be prone to a remote format string vulnerability. The problem presents itself whe...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
14.  Data transfer without tears. Stob Or cheese. Of any description By Verity Stob .
15.  Ofcom hails BT wholesale price cuts. Adjudicator hired to bang heads By Tim Richardson .
16.  SpamCop gets gagging order lifted. Twist in SpamCop versus Spam King lawsuit By John Leyden .
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
17.  Wallon virus wrecks Windows Media Player
18.  Acoustic cryptanalysis
19.  NetWorld+Interop security briefing
20.  Symantec patches four critical firewall flaws
21.  German police raid five homes in Sasser case
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
22.  Security demands big-picture view, Chambers says
23.  Child porn case highlights browser hijack risks
24.  German police raid five homes in Sasser case
25.  Fastest Rising: 25 smtp
26.  Top Port: ftp 21
27.  13 May W32/Agobot-JI
28.  Symantec Introduces Its Latest Firewall Offering
29.  A third of UK corporates open to hackers
30.  Feds combine smart card buys
31.  A third of UK corporates open to hackers
32.  US considers "legalising hacking" with copyright ruling
33.  Why are virus writers so tough to catch?
34.  Microsoft to battle spyware
35.  Wallon virus wrecks Windows Media Player
36.  Acoustic cryptanalysis
37.  NetWorld+Interop security briefing
38.  Symantec patches four critical firewall flaws
39.  German police raid five homes in Sasser case
40.  Wallon Worm Skirts Around Windows Patch Release (Ziff Davis)

11:23:48 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Symantec patches critical firewall flaws. For the third time this year, the company issues patches for many of its antivirus and firewall products in order to fix serious security flaws.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Google to Distribute Image Ads, Plans Email List Service
----------------------------------------------------------------------
[O.S.S.R]
----------------------------------------------------------------------
3.  Why Are Virus Writers So Tough To Catch?
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  FBI anti-terror network scares experts. 'Not on a path to success' By John Oates .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Australische Forscher entdecken neue WiFi-Sicherheitslücke
6.  Neuer Wurm löscht Windows Media Player
7.  Déni de service dans Oracle 9i Application Server et Oracle 9i Database Server (SOAP XML DTD)
8.  Survivor website bevat drie Trojaanse paarden
9.  Extreem kritiek lek in Symantec / Norton software
10.  SpamCop moet 'spam koning' met rust laten
11.  Cheval de Troie sur Mac OS ?
12.  Network Associates rejoint le Trusted Computing Group
13.  Début de la révision de la loi américaine sur la protection des droits d'auteur, le Data Millenium Copyright Act ( DMCA ) de 1998.
14.  NetBSD Systrace Privilege Escalation Vulnerability
15.  phpShop Arbitrary File Inclusion Vulnerability
16.  MailEnable Professional HTTPMail Service Buffer Overflow Vulnerabilities
17.  eMule Web Interface Negative Content Length Denial of Service
18.  Microsoft Windows Help and Support Center URL Validation Vulnerability
19.  Icecast Basic Authorization Denial of Service Vulnerability
20.  SCO OpenServer Insecure Default XHost Access Controls
21.  Gentoo update for ClamAV
22.  Gentoo update for OpenOffice
23.  BEA WebLogic "weblogic.xml" May Reset to Default Permissions
24.  BEA WebLogic Admins and Operators May be Able to Stop the Service
25.  Microsoft Outlook External Reference Vulnerability
26.  Debian update for exim-tls
27.  OpenPKG update for apache
28.  Red Hat update for ipsec-tools
29.  Red Hat update for kernel
30.  Zoneminder Query String Buffer Overflow Vulnerability
31.  OpenBSD procfs Integer Overflow Vulnerability
32.  Linksys BEF Series Routers DHCP Vulnerability
33.  Zoneminder Query String Buffer Overflow Vulnerability
34.  OpenBSD procfs Integer Overflow Vulnerability
35.  Linksys BEF Series Routers DHCP Vulnerability
36.  SB04-035: Summary of Security Items from January 21 through February 3, 2004
37.  SB04-049: Summary of Security Items from February 4 through February 17, 2004
38.  SB04-058: CyberNotes for February 3 through February 23, 2004
39.  SB04-063: Summary of Security Items from February 18 through March 2, 2004
40.  SB04-077: Summary of Security Items from March 3 through March 16, 2004
41.  SB04-133: Summary of Security Items from April 28 through May 11, 2004
42.  Bugwatch: Worm wars
43.  Wallon löscht Windows Media Player
44.  Suche nach Sasser-Komplizen

10:23:28 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  The Security Risk of Keyboard Clicks
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
2.  Sneak peak at latest GTA game. Catch up with the latest news from the world of video gaming.
3.  BT to cut broadband charge. BT is to cut the price of broadband access for its rivals by 70%, ahead of an Ofcom move on competition.
4.  US moves to ban furtive photos. US law-makers back a bill to ban 'up-skirt' photos and other furtive snaps using devices like camera phones.
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
5.  Kagermann: Committed to enterprise services. NEW ORLEANS -- The message came a bit late but it was loud and clear: SAP AG is charging ahead with its approach to a service-oriented architecture and users should start thinking now about ways to join the drive.
6.  Security demands big-picture view, Chambers says. LAS VEGAS -- Highlighting security as a key case in point, Cisco Systems Inc. President and Chief Executive Officer John Chambers told a full house at Networld+Interop on Wednesday evening that networks need to be built with an overall architecture instead of with a series of point products.
7.  Further Sasser arrests but no charges in Germany. Police in Lower Saxony, Germany, arrested five young men on Tuesday in connection with the Sasser Internet worm but all have been released without charge, a police spokesman said Thursday.
8.  HP buys two companies to bolster services. Hewlett-Packard Co. (HP) has acquired two companies to boost its staff and offerings in the area of IT service management.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  BT wins interconnect appeal. Vodafone out of pocket By John Oates .
10.  Student uncovers US military secrets. 'Felt-tip pen' censorship cracked By Lucy Sherriff .

9:23:09 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Library of Alexandria dug up. The ruins of the Library of Alexandria have been discovered: X-NAS-Bayes: #0: 1.22363E-163; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 729 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Announcing their discovery at a conference being held at the University of California, Zahi Hawass, president of Egypt's Supreme Council of Antiquities, said that the 13 lecture halls uncovered could house as many as 5,000 students in total.

A conspicuous feature of the rooms, he said, was a central elevated podium for the lecturer to stand on.

"It is the first time ever that such a complex of lecture halls has been uncovered on any Greco-Roman site in the whole Mediterranean area," he added.

"It is perhaps the oldest university in the world."

Link

(Thanks, Patrick!)

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Vietnam to Monitor Its Internet Users (AP). AP - Web surfers in Vietnam must abide by a number of new policies and restrictions, which come following a crackdown on cyber dissidents who used the Internet to speak out against the communist government, state-controlled media reported.
3.  Robot Sensors May Protect Drinking Water (AP). AP - A network of underwater robots beaming up a near real-time environmental profile of lakes, rivers and reservoirs could soon be on the prowl helping safeguard the nation's drinking water from sabotage.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
4.  Daughter inspires funky wheelchair. The boss of an aircraft industry firm has launched a new wheelchair he designed for his teenage daughter.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
5.  Security demands big-picture view, Chambers says. LAS VEGAS -- Highlighting security as a key case in point, Cisco Systems Inc. President and Chief Executive Officer John Chambers told a full house at Networld+Interop on Wednesday evening that networks need to be built with an overall architecture instead of with a series of point products.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
6.  US to ban up-skirt voyeur photos. Stealth porn clampdown protects privacy By Lucy Sherriff .
7.  Lastminute losses lessen. Confident on year... By John Oates .
8.  German police raid five homes in Sasser case. Dragnet widens By John Leyden .
9.  BT cleared for line rental hike. No immediate action from Ofcom By Tim Richardson .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  Network Associates Joins Open Industry Standards Organisation TCG
11.  13 May W32/Sdbot-IK
12.  Plusieurs vulnérabilités critiques dans le Client Firewall de Symantec
13.  MPAA Shaking At Ninth Circuit Oral Arguments
14.  LayerOne Technology Conference
15.  Survivor website bevat drie Trojaanse paarden
16.  Extreem kritiek lek in Symantec / Norton software
17.  SpamCop moet 'spam koning' met rust laten
18.  A third of UK corporates open to hackers
19.  Opera Browser Address Bar Spoofing Vulnerability
20.  Opera Browser Address Bar Spoofing Vulnerability
21.  Opera Browser Telnet URI Handler File Manipulation Vulnerability
22.  Opera Browser Telnet URI Handler File Manipulation Vulnerability
23.  Sweex Wireless Broadband Router Exposure of Configuration
24.  Sweex Wireless Broadband Router Exposure of Configuration
25.  Opera Browser Address Bar Spoofing Vulnerability
26.  Opera Browser Telnet URI Handler File Manipulation Vulnerability
27.  Sweex Wireless Broadband Router Exposure of Configuration

8:22:47 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Search engines take the stand. Judges are turning to Google and other search engines to check facts and look up information in cases--a trend that has some legal experts worried.
2.  South Korea's house of the future. Even with the privacy fears, the home-networking technology South Korea is promoting is hard to resist, CNET News.com's Michael Kanellos says.
3.  From nukes to Sarbanes-Oxley. Iron Mountain used to store corporate records in preparation for nuclear war. CEO Richard Reese is now applying that expertise to tracking e-mail for regulatory compliance.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  FCC may let Wi-Fi go between TV signals (USATODAY.com). USATODAY.com - Despite the objections of TV broadcasters, the Federal Communications Commission on Thursday is expected to propose allowing unlicensed wireless services to use vacant airwaves between TV stations.
5.  At E3, old stuff is new again (USATODAY.com). USATODAY.com - •Jade Empire (Bioware, for Xbox, spring 2005), an Xbox exclusive from the developers of Knights of the Old Republic, has the combination punch of a 3-D fighting game and a role-playing adventure. The martial arts are key here, and it all plays out (yes, there's a story) in a tale of revenge and revolt in a samurai-tinged world.
6.  Online Co. Shuts Down Site With Beheading (AP). AP - The al-Qaida-linked Web site that first posted a video of American civilian Nicholas Berg's beheading was shut down Thursday by the Malaysian company that hosted it — because it was drawing too much traffic.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  802.11 WiFi Denial of Service Exploit Discovered
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  Telewest cuts losses. Half a million broadband customers.. By John Oates .
9.  Child porn case highlights browser hijack risks. Cautionary tales By John Leyden .
10.  Official secure music scheme to kill all non-compliant formats. It was five years ago today... 13 May 1999 By Team Register .
11.  Exam cheats reveal MMS killer app. Similar to 'phone a friend' By Lucy Sherriff .
12.  IBM throws weight behind server-managed clients. Thick client bad, thin client bad? By IT-Analysis .
13.  Sage: more acquisitions ahead. Must buy to maintain growth By Datamonitor .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  Sending IPv6 Packets to Check Firewall Rules
15.  RSA launches ID manager
16.  Feds combine smart card buys
17.  Waarom virusschrijvers zo moeilijk te vinden zijn
18.  Walon worm sloopt Windows media speler
19.  Het grote gevaar van afluisterbare keyboards
20.  Duitse politie ondervraagt Sasser verdachten
21.  Authenticeren met Apache
22.  Outpost Firewall Denial of Service Vulnerability
23.  Outpost Firewall Denial of Service Vulnerability
24.  Outpost Firewall Denial of Service Vulnerability

7:22:29 AM    comment []

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  Daughter inspired 'fashion' wheelchair. The boss of an aircraft industry firm has launched a new wheelchair he designed for his teenage daughter.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability. IBM Parallel Environment for AIX has been reported prone to an undisclosed command execution vulnerability. The issue is reported to present itself within the /usr/lpp/pp...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  Europe slips behind on nano technology. Big rewards hang in the balance By Lucy Sherriff .
4.  Capgemini succumbs to rebranding madness. LogoWatch Whalesong, joss-sticks, synergy, thrust By Lester Haines .
5.  BT to slash LLU costs. Claims it will lead to greater competition By Tim Richardson .
----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
6.  Mexican Air Force Films UFOs. Pilots conducting drug surveillance over Campeche state filmed 11 unidentified flying objects in early March, after the UFOs appeared to surround the aircraft. Now, Mexican officials release the video.
7.  Put on Your PJs and Run Playboy. A video game coming out in November will let players fill Hugh Hefner's slippers. Also: Doom III will be released this summer.... Final Fantasy soundtrack goes high-class at the Los Angeles Philharmonic.
8.  Robots and the Rest of Us. What do you do about fear and loathing on the human-machine frontier? Convene a meeting of robot ethicists, of course. By Bruce Sterling from Wired magazine.
9.  U.S. Officials Sport Fake Degrees. More than 400 government employees, including many high-ranking officials, received fake degrees from diploma mills, according to congressional investigators. The findings spur calls for better means to vet academic credentials. By Ryan Singel.
10.  How Info-Overload Experts Unwind. Scientists and spiritualists who specialize in the art of avoiding information overload gather in Seattle to discuss better ways to escape the tyranny of cell phones and always-on Internet. Kendra Mayfield reports from Seattle.
11.  Microsoft to Battle Spyware. Microsoft says the upcoming release of Windows XP Service Pack 2 will make it much harder to sneak deceptive software onto users' computers. Is it game over for spyware authors? By Amit Asaravala.
12.  Film Raises Ire Over HIV Origins. A documentary that tracks the AIDS outbreak to the polio vaccine raises the hackles of scientists, who think it's more likely the deadly virus spread to humans through African monkey hunters. Kate Rope reports from New York.
13.  Tech Execs Lean Right. While the technology industry usually contributes roughly equal sums to Democrats and Republicans, the same can't be said of tech executives. In this year's presidential race, CEOs of the largest tech firms are largely backing Bush. By Joanna Glasner.
14.  Designer Virus Stalks HIV. Researchers have developed a potential novel treatment for AIDS -- a synthetic parasite virus. It's scary but awesome, they say. Kristen Philipkoski reports from Berkeley, California.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
15.  Exécution de code à distance dans le Centre d'aide et de support de Windows (MS04-015)
16.  [MAJ] Multiples vulnérabilités Oracle
17.  Word 2004 voor Mac demo blijkt Trojaans paard
18.  Build Windows XP SP2 weer per ongeluk online
19.  Microsoft Sasser tool nu ook voor F variant
20.  Hoe bescherm je je PC tijdens de vakantie
21.  Slow down the security patch cycle
22.  AirDefense sniffs out Bank of America Bluetooth-based ID system
23.  Bluetooth group downplays security risks
24.  Symantec Client Firewall Products Multiple Vulnerabilities
25.  Slackware update for apache
26.  Opera Telnet URL Processing Flaw Lets Remote Users Create or Overwrite Files
27.  Sweex Wireless Broadband Router Disclosed Administrative Password to Remote Users
28.  Symantec Client Firewall SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System
29.  Symantec Client Security SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System
30.  Norton AntiSpam SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System
31.  Fastest Rising: 1027 icq

6:22:07 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Photos from Clarke Award ceremony. X-NAS-Bayes: #0: 5.76695E-119; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 726 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Last night, the Arthur C Clarke Award for best sf novel published in the UK in 2003 -- Neal Stephenson won. Here are some photos from the event.

Link

(Thanks, Tony!)


2.  SETI@Vatican. The Vatican's official astronomer, Brother Guy Consolmagno, has given an interview in which he discusses the Vatican's thinking on what to do if alien intelligence is discovered.

We find an intelligent civilization and there's no way in creation we can communicate with them because they're so alien to us. We can't talk to dolphins now. In which case, we'll never know.

Second scenario: We find the intelligent civilization. We can communicate. We discover that they have the two essentials that theologians talk about for the human soul, intelligence and free will. They know who they are, they're self-aware, and they're able to do something about it. I think dogs are self-aware, but they don't have a whole lot of free will. Maybe computers are the same sort of thing. Human beings have to have both...

A third scenario: We find a dozen civilizations out there, and a bunch of Jehovah's witnesses go up and convert them all. At the end of the day, every civilization is Christian, except the human race is still not too sure about this. I mean, anything's possible.

Link

(via /.)

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Vatican Astronomer Comments On Extraterrestrials
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
4.  Games industry woos 'casual players'. The giants of the game world have set their sights on enticing a whole new generation of players.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
5.  Lawyers claim earth, sky and moon from Microsoft. That will be $258m, please. Oops, we forgot the expenses By John Oates .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  Twijfel over gearresteerde Agobot auteur
7.  Word 2004 voor Mac demo blijkt gevaarlijke malware
8.  Owens: No court access for detainees
9.  Hart: Make terror-readiness plain
10.  Denverite recalls Berg's days in Iraq
11.  "OFF THE HOOK" DVD-R NOW AVAILABLE
12.  Brevetabilité des logiciels
13.  Capellas Ponders Competition, Economy, Online Privacy (TechWeb)
14.  Symantec Unveils New Firewall, VPN For Windows, Solaris (TechWeb)
15.  Combating The Cyber Criminals
16.  Camphone used to cheat on exam
17.  Microsoft warns of 'important' Windows flaw
18.  Phatbot arrest throws open trade in zombie PCs
19.  German police raid homes in Sasser computer worm probe
20.  Experts: Timing of new Sasser worm raises questions
21.  Teen arrested for allegedly hacking computer to alter grades
22.  Wallon virus wrecks Windows Media Player
23.  Security Holes Make VOIP a Risky Business
24.  Microsoft delays Virtual PC 7 for Macs

5:21:48 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 13 May 2004.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  IBM Unveils Systems For Companies Seeking Low-Cost Storage (TechWeb). TechWeb - The disk- and tape-storage products are aimed at companies that need inexpensive storage to hold data for regulatory and compliance applications.
3.  Novell Offers Enterprise Support To Linux (TechWeb). TechWeb - Novell's Premium ServiceSM support program covers a customer's entire Linux environment, from servers to desktops to laptops.
4.  Sony Expects Initial Loss on PSP Handheld Device (Reuters). Reuters - Sony Corp. (6758.T) does not expect to make money on its new PlayStation Portable handheld games console at launch, due to the price of components and initial development costs, the head of Sony's U.S. games unit said on Wednesday.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
5.  Lastminute enjoys 'strong' growth. The online travel and leisure firm says business was buoyant during the January-to-March period, but losses increase.
6.  BT set to reduce broadband charge. BT is to cut the price of broadband access for its rivals by 70%, ahead of an Ofcom move on competition.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Securiteam: Sasser Worm Remote FTPD Buffer Overflow Exploit Code (Port 5554) "exploit code that ...
8.  Macworld Mac Trojan Horse Disguised as Word 2004 "deletes the Home folder on a Mac"
9.  AirDefense sniffs out Bank of America Bluetooth-based ID system
10.  Bluetooth group downplays security risks
11.  Yet another Sasser worm appears
12.  Microsoft warns of noncritical flaw in some versions of Windows
13.  Software security startup aims to pre-empt hackers
14.  NetBSD Security Advisory 2004-007: Systrace systrace_exit() local root
15.  Why Are Virus Writers So Tough To Catch?
16.  MPAA Shaking At Ninth Circuit Oral Arguments
17.  LayerOne Technology Conference

4:21:27 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Phobic photoshopping contest. X-NAS-Bayes: #0: 5.6732E-051; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 724 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Today's Worth1000 photoshopping contest is phobias, illustrated.

Link


----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Army gunning for game players. The U.S. Army says its free PC game has turned into one of its most effective informational tools and could even help train real soldiers.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Pirates Pillage China's Online Game Industry (Reuters). Reuters - Software pirates are gouging China's red-hot online games industry, offering identical games for free and undermining planned Nasdaq listings by companies long thought immune to copyright abuse.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Napster Gags University Over Fees
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  AirDefense sniffs out Bank of America Bluetooth-based ID system
6.  Bluetooth group downplays security risks
7.  Yet another Sasser worm appears
8.  Microsoft warns of noncritical flaw in some versions of Windows
9.  Software security startup aims to pre-empt hackers
10.  NEW 'OFF THE HOOK' ONLINE

3:21:07 AM    comment []

----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
1.  Hello, Pay Phone Information? Enthusiast Provides the Answer. In an age of cellphone ubiquity, one man's passion for pay phones has yielded entertaining and practical applications. By Ian Urbina.
2.  Google to Sell Type of Ad It Once Shunned. Google has decided to start selling ads with graphics, not on Google.com as yet, but on the sites of other Web publishers on which it sells advertising. By Saul Hansell.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  BugTraq: NetBSD Security Advisory 2004-007: Systrace systrace_exit() local root. Sender: NetBSD Security-Officer [security-officer at netbsd dot org]
4.  Vulns: Microsoft Outlook 2003 Predictable File Location Weakness. Microsoft Outlook 2003 is reported to be prone to store files that are specified in IMG tags in predictable locations, aiding in exploitation of other possible security v...
5.  Vulns: Microsoft Internet Explorer Embedded Image URI Obfuscation Weakness. It has been reported that Microsoft Internet Explorer is prone to a URI obfuscation weakness that may hide the true contents of a URI link. The issue occurs when an image...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  SUPPORT EFF!
7.  Stop the DirecTV Dragnet!
8.  RIAA v. The People: Ask Your Senators to Stand Up to the RIAA!
9.  Linux Users Unite: Stop SCO!
10.  Help Broaden the World IP Debate!
11.  Trojan trap set at 'Survivor' site

2:20:47 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Congress mulls revisions to DMCA. The U.S. Congress takes a step toward revising the Digital Millennium Copyright Act, which has attracted extensive criticism during the past six years.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Microsoft Reveals 'Important' Windows Flaw (NewsFactor). NewsFactor - Microsoft (Nasdaq: MSFT) is reporting a security vulnerability in the Windows XP and Server 2003 operating systems that could allow hackers to commandeer PCs by drawing users to a malicious Web site that contains a remote execution link.
3.  Google to Test Images in Web-Content Ad Program (Reuters). Reuters - Google Inc., which gets most of its revenue from simple text ads linked to key word searches, said on Wednesday it would begin testing richer graphic ads -- such as pictures and logos -- that would appear on the Web sites of its distribution partners.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Rand Report Says Geospatial Data Not Big Threat
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Microsoft Issues Single New Security Alert for May
6.  Wallon Worm Skirts Around Windows Patch Release
7.  Johansen Acquittal Final
8.  EFF Comments on Intel's LaGrande Technology Policy
9.  RIAA Announces "John Doe" Suits Against Filesharers
10.  DVDCCA Surrenders in Bunner DVD Descrambling Case
11.  Federal Judge Rules That Part of the USA PATRIOT Act Is Unconstitutional
12.  Court Overturns Ban on Posting DeCSS
13.  321 Studios Counts Down for Fair Use Rights
14.  European Parliament Adopts Controversial IP Enforcement Directive
15.  Orlando Court Orders Record Companies to File 25 Separate Lawsuits Against Accused Filesharers
16.  Electronic Frontier Foundation Files Comments on FBI Plan
17.  Electronic Frontier Foundation Announces New Patent Busting Campaign
18.  California Bans Insecure E-Voting Machines
19.  EFF Comments in FCC "Cognitive Radio" Proceeding
20.  EFF is Invited to Attend WIPO Meeting on Broadcasting Treaty
21.  EFF at DMCA Reform Hearing
22.  SB04-133: Summary of Security Items from April 28 through May 11, 2004
23.  Sending IPv6 Packets to Check Firewall Rules

1:20:28 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Cisco's Chambers headlines N+I. Cisco's charismatic chief executive officer uses his keynote speech at Networld+Interop tradeshow to say customers are more confident than he has seen them in a long time.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  MSN Teams Up With Fox Sports (AdWeek.com). AdWeek.com - MSN's multiyear, multi-million-dollar content partnership with Fox Sports--due to start July 1 --opens up ad-sales opportunities for the portal in the hugely popular sports vertical, previously unavailable under its expiring contract with ESPN.
3.  Germans Hunt for 'Sasser' Accomplices (AP). AP - German police said Wednesday they searched five apartments in northern Germany in an effort to track down suspected accomplices of an 18-year-old who confessed to creating the "Sasser" computer worm and the "Netsky" virus.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  Symantec Products Vulnerabilties / Worm Password List / Mailbag-Netsky

12:26:37 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 6/1/2004; 12:29:14 AM.
This theme is based on the SoundWaves (blue) Manila theme.
May 2004
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Apr   Jun