Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Friday, May 21, 2004
 

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Cisco: Code Theft Does Not Increase Risk (AP). AP - The publication of some of Cisco Systems Inc.'s proprietary software blueprints does not create an increased security risk to the equipment that powers much of the Internet, the company said.
----------------------------------------------------------------------
Hack the Planet
----------------------------------------------------------------------
2.  Byte and Switch: Chelsio Debuts 10-GigE HBA. With three TOE announcements in three weeks, I wonder if there's another boom-bust cycle coming.
3.  eWeek: Blogging Technology Going Open Source.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  E-voting system is banned in California
5.  Canada drops census deal over privacy concerns
6.  Privacy International to hold meeting on national identity card
7.  EU to sign agreement on PNR transfer to the U.S.
8.  New telecommunications act in Germany
9.  New freedom of information law in the Ukraine
10.  Recommended reading: privacy and biometrics
11.  [Swedish] Utbildningar för personuppgiftsombud
12.  Conference Report - Security and Privacy Symposium
13.  EC backs 'privacy violation' deal with US
14.  Wal-Mart attracts more RFID flak
15.  Poll suggests ID card backlash
16.  'Whispering keyboards' could be next attack trend
17.  Legoland uses RFID for finding lost kids
18.  Protector Plus 7.2.F02
19.  Security Guidance Kit v1.0, English
20.  Norton AntiVirus Virus Definitions May 19, 2004
21.  Ad-aware referencefile 01R306 19.05.2004
22.  Security Enhancements for Remote Access at Microsoft
23.  avast! Virus Cleaner Tool 1.0.191
24.  Norton Virus Definitions May 20, 2004
25.  The Cleaner Database v3580
26.  CVS Remote Entry Line Heap Overflow Root Exploit (Linux/FreeBSD)
27.  CVS Remote Entry Line Heap Overflow Root Exploit (Solaris)

11:25:38 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Mark's Japan Journal: Day 3. 8am in Tokyo (4pm LA time). I got about six hours of sleep last night, and I'm feeling pretty good right now. (Of course, I just downed an excellent double espresso, so the caffeine is talking right now.) X-NAS-Bayes: #0: 6.41292E-249; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 929 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Despite the typhoon warnings, Yesterday's weather couldn't have been better. The sky was blue, the temperature was mild. I guess the typhoon ran out of juice really fast.

I woke up spaced-out and stupid. I looked in the mirror and was surprised at how glassy my eyes looked. But I wanted to travel around the city, to do some research on the article I'm writing. First, though, I wanted to go to Harajuku and Yoyogi park to take pictures of those crazy kids in the their Elegant Gothic Lolita and Trappist Monk - Rocket Scientist Hybrid getups. I didn't see too many, but I took some pictures of a few kids, who studiously ignored me, the big dopey gawking gaijin with a camera.

But my heart wasn't in it. I was much more interested in checking out the official uniforms almost everyone in Japan wears. Of course the schoolkids all wear uniforms. The girls have the traditional sailor uniforms, and a lot of the boys have these dark blue Chinese-looking jackets with the cylindrical collars and big round buttons. (Why are so many schoolkids always walking around in the middle of the day here? Don't they have classes to attend? Do they get breaks from school at odd hours that allow them to roam the streets?)

I saw a large crowd of "Beauty College" students pouring out of a building. They looked about 17 years old. About half were boys. They had nifty two-tone smock-like uniforms. They raced each other into a 7-Eleven and filled the place up. I took some great pictures of them packed in there.

I went the the big park near Harajuku (Meji something) and saw a worker in a smart gray uniform and pith helmet raking up leaves from the wide, tiny-pebbled, path leading to the Shinto temple. His rake was hand-made bamboo, and the business end of it fanned out about three feet. He had a large woven basket filled with other wooden park-cleaning implements, that looked like the came from the 17th century. I love the way Japan mixes ancient stuff with the brand new.

Back in the shopping area of Harajuku, another uniformed guy was on his knees, wiping one of the ubiquitous outdoor vending machines. He was making the surface *squeak*. After that, I noticed all the vending machines were spotless. The Japanese love to keep things clean. (The day before, two people in yellow raincoat uniforms were walking down a narrow shopping street, picking up wet cigarette butts with poles that have pincers on the end, and depositing the butts in a plastic bag. They were obsessive about it. They didn't even have Walkmans on. -- they were focusing solely on getting every last cigarette butt picked up.)

I spent the rest of the day taking pictures of people in different uniforms. It seems like they have at least four varieties of cops here, judging by the color and style of their caps and jackets.

I was looking forward to getting back to my hotel room so I could upload a "Uniforms of Japan" photo gallery. I am using some new software to deal with digital images, and when I extracted the images from the camera, the application zapped all 45 photos from the camera's memory stick. A full day of photo taking, gone in an electrostatic femtosecond. (I'm not going to say which application it is until I get an explanation from the guy who wrote it.)

I'm headed back to the US today, so unless something bizarre happens on the train to Narita, this will be my last Japan Journal dispatch.

Your faithful scribe -- Mark
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Oracle, DOJ Describe Software Market for Judge (Reuters). Reuters - The U.S. Justice Department and Oracle Corp. on Friday gave a "technology tutorial" to the federal judge who will hear the government's suit to block Oracle's $7.7 billion hostile bid for rival PeopleSoft Inc.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Things You Can Do With A Giant Fresnel Lens
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
4.  News: Apple patches critical Mac OS X hole. The company claims customers were never put at risk by the well-known and easily exploited bug.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Apple Says OS X Vulnerable to Security Breach (Reuters)
6.  Flight Centre Deploys Cisco Storage Area Networking, Wireless and Security Solution to Manage Surging Information Growth
7.  The_Basics_of_Shellc..>
8.  sa11678.txt

10:25:17 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Busted MP3 player wrapped around soda can causes airplane bomb scare. Wireless guru Mike Outmesguine says: X-NAS-Bayes: #0: 3.59851E-112; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 925 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A bomb scare occured on an America West passenger plane in Phoenix Arizona this week. Fox 11 News covered the story with people on the ground and a chopper in the air. The Fox11AZ website has 3 videos (about 8 minutes total) online... Re-live the tension! What caused the bomb scare? "An MP3 player wrapped around a soda can." So, next time you de-plane a plane, don't forgot to take your Coke and iPod with you. Check those seat pockets!
Link
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Microsoft wants to meld antispam proposals
3.  Google names 31 underwriters
4.  Will number switching cut corporate costs?
5.  Technology 101: Oracle Judge gets tutorial
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  Samsung Claims Largest LCD HDTV (PC World). PC World - Flat-panel LTP468W is first to offer 1920-by-1080 screen resolution.
7.  Apple Says OS X Vulnerable to Security Breach (Reuters). Reuters - Apple Computer Inc. (AAPL.O), long considered to be relatively immune to the security holes and viruses that plague longtime rival Microsoft Corp.'s Windows, said on Friday a security hole in its software leaves users' computers vulnerable to attack.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
8.  More From Tanenbaum
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
9.  Good-bye PCI, hello PCI Express. One of the most comprehensive refreshes of Intel architecture will start rolling out this summer. The PCI Express bus will replace current I/O interfaces, such as PCI for device interconnects and AGP8X for graphics, on all servers, workstations, desktops, notebooks, and communications devices.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  Tandberg Acquires Tech for IP Videoconferencing Across Firewalls (Ziff Davis)
11.  NetChat GET Request Overflow
12.  Zen Cart login.php Multiple Variable SQL Injection
13.  phpMyFAQ index.php Multiple Variable Arbitrary Command Execution
14.  Java Secure Socket Extension Server Certificate Validation Error
15.  Culture shock
16.  Security as an immune system
17.  Security appliances wrestle with blanket coverage
18.  RNA sniffs out network intrusions
19.  Innovators to Watch in 2005
20.  E-mail encryption as easy as remembering who you are
21.  CoreStreet targets massively scalable validation
22.  Microsoft Urged To Make Security Upgrades More Widely Available

9:25:00 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Mother of all vintage robot toy websites. Robot1968 is a kickass vintage robot toy website offering info on...
X-NAS-Bayes: #0: 3.26845E-184; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 924 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

the history of robots and cinematic mechanised figures, inventory with over 2000 photos of all the robot toys from 1940 till now, info on all robot companies from japan-germany-usa and hong kong, vintage arcade games to play, links to all the robot world, forum to talk to other collectors and artists, music and fun!

Link (Thanks, theo)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Apple issues Mac OS X security patch
3.  Microsoft wants to meld anti-spam proposals
4.  Judge orders Microsoft to search its systems
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  Time Warner Says AOL 'Stabilized' (Reuters). Reuters - Time Warner Inc. (TWX.N) top executives on Friday told investors that its Internet unit America Online had "stabilized," but deflected questions over a possible bid to purchase bankrupt cable operator Adelphia Communications Corp. (ADELQ.PK)
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  IBM tells SCO to Put Up or Shut Up
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
7.  Culture shock. There are times when being a columnist is rewarding. Every now and then you get an e-mail reporting that something you said solved a problem for a reader or that the mere power of your words changed the reader’s life. (Well, I guess those don’t happen very often in technology publications.)
8.  Security as an immune system. Long before blaster and slammer invaded the enterprise, Steven Hofmeyr was convinced that traditional security approaches were inadequate to fend off such attacks.
9.  Security appliances wrestle with blanket coverage. To someone responsible for the network security of an SMB (small to midsize business), a one-box solution that handles every enterprise security function is a hot commodity. Naturally, the all-in-one security appliance aims to provide the required level of effectiveness without the complexity and expense of layered security products and dedicated staff. And that’s a hugely attractive prospect in today’s Wild Wild Web, where worm infections, Trojan horse invasions, and exploits of security holes are constant threats.
10.  RNA sniffs out network intrusions. When Martin Roeschcreated Snort, his original intention was significantly more modest than the industry standard for intrusion detection that the work became.
11.  Innovators to Watch in 2005. The world is always watching for nascent technologies that will rise to solve problems and push the boundaries. This year, some of the most promising ideas are originating from people you may be reading about for the first time but certainly not the last: Dr. Paul Terry, creator of affordable high-performance computing at Cray Canada; Hideya Kawahara, a Sun engineer developing a 3-D-desktop interface; Mark Maiffret, a 23-year-old chief hacking officer of eEye Digital; Niklaas Zennström and Janus Friis, co-founders of p-to-p VoIP (voice over IP) software company Skype; and Pete Manca and Ben Sprachman of Egenera, builders of virtual datacenters. These names and companies are worth remembering.
12.  E-mail encryption as easy as remembering who you are. Most people wouldn’t dream of sending business and personal documents in an unsealed envelope, but every day millions of unencrypted e-mails containing equally sensitive information cross the Internet. The reason is simple: Until encryption becomes as easy to use as an envelope is to lick, few will bother.
13.  CoreStreet targets massively scalable validation. All computer and network security begins with authentication. Once you identify someone, by whatever means, the focus shifts to authorization, or what CoreStreet’s President Phil Libin calls validation. Are the credentials still valid? Is the authenticated person allowed to read this document or enter that airplane cockpit?
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
14.  Vulns: Multiple Vendor URI Protocol Handler Arbitrary File Creation/Modification Vulnerability. A vulnerability has been identified in multiple products from multiple vendors that may allow a remote attacker to create or modify arbitrary files; these issues relate t...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
15.  WORM_SCANBOT.A
16.  BKDR_MAROON.A
17.  [ GLSA 200405-16 ] Multiple XSS Vulnerabilities in SquirrelMail
18.  Re: Non-logged Brute Force Attack Vulnerability for Fantastico-Created Databases on cPanel Based Hosts
19.  Top Port: microsoft-ds 445

8:24:39 PM    comment []

----------------------------------------------------------------------
Penny Arcade!
----------------------------------------------------------------------
1.  They Hail From Canidon.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Apple patches vulnerability in Safari (MacCentral). MacCentral - Apple Computer Inc. issued an update on Friday to fix a reported security hole in its Safari Web Browser. The venerability, which was classified as "Extremely Critical" by security firm Secunia, allowed the execution of malicious code on the users computer.
3.  Google Co-Founders Hold 16 Pct. Stakes (AP). AP - Google Inc. co-founders Larry Page and Sergey Brin each own nearly 16 percent of the Internet search engine leader that they launched nearly six years ago — stakes expected be worth at least $3 billion apiece after the company's initial public offering of stock.
4.  Comcast Turns On Microsoft TV (PC World). PC World - Tech giant leaps into TV Land with major rollout of its interactive DVR software.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Hayabusa Earth Flyby Swings Toward Asteroid
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
6.  Tibco, webMethods tout BAM. Tibco software and webMethods are both boosting their profiles in BAM (business activity monitoring). Meanwhile, Oracle revealed plans to jump into the BAM fray this summer.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Cisco: Code Theft Does Not Increase Risk (AP)
8.  New Bobax Variants Exploiting LSASS Vulnerability to Spread

7:24:17 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Implantable RFIDs for nightclub VIPs. Club kids who want VIP status at the popular Baja Beach Club in Barcelona can now get implanted with a radio frequency identification (RFID) tag. For 25 euro, customers can have an Applied Digital Solutions VeriChip, the size of a grain of rice, injected into his or her upper arm. Makes it easier to run a tab. Link (via my journal at TheFeature.com)
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  XP, Exchange take center stage at TechEd
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Artists mix it up with file sharers (USATODAY.com). USATODAY.com - A sampling of creative ways entertainers have approached the file-sharing question:
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Microsoft Submits Email Caller ID to the IETF
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
5.  News: Cisco: Source code theft does not increase risk. The Associated Press By Matthew Fordahl
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
6.  Vulns: APSIS Pound Remote Format String Vulnerability. APSIS Pound is a reverse-proxy and load-balancer service. X-NAS-Bayes: #0: 1.68027E-030; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 921 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

APSIS Pound has been found to be prone to a remote format string vulnerability. The problem presents itself whe...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Porn spam must now be labeled
8.  TROJ_BANCOS.O
9.  Spam Foes Worry New FTC Rule Not Enough
10.  NetIQ Integrates Security Offerings
11.  Ballmer Throws Down the Security Gauntlet

6:23:58 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Google's desktop bet
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Microsoft Ordered to Search for Evidence (AP). AP - A federal judge ordered Microsoft Corp. to search for evidence a vice president told employees in 2000 to destroy e-mails, an attorney for a company suing the software giant said Friday.
3.  Injunction Issued Vs. DVD-Copying Maker (AP). AP - A California company that specializes in encryption technology has obtained the latest court order barring a Missouri company's sale of popular DVD-copying software.
4.  Cisco: Code Theft Does Not Increase Risk (AP). AP - The publication of some of Cisco Systems Inc.'s proprietary software blueprints does not create an increased security risk to the equipment that powers much of the Internet, the company said Friday.
5.  IBM Drops Gloves in Database War with Oracle (Reuters). Reuters - IBM is taking off its kid gloves.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  Monsanto Wins Case Over Patented Canola
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Porn spam must now be labeled
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  Symantec Warns Of Flaw In Antivirus Program
9.  FBI On The Hunt For Spammers
10.  Phishing Attacks Still Rising

5:23:37 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Briefly: SportsLine up for sale?
2.  Blu-ray group looks for wider support
3.  Vonage finds another landline partner
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  IBM-Siebel Partnership Expands Again (NewsFactor). NewsFactor - The ties between infrastructure behemoth IBM (NYSE: IBM) and CRM industry titan Siebel (Nasdaq: SEBL) seem to be getting stronger by the day.
5.  Analyst: SAP Developments Herald New Chapter (NewsFactor). NewsFactor - As one of the mammoths of the enterprise-software world, SAP (NYSE: SAP) serves as a bellwether for the industry. And this year is no exception, especially with the race on for second place in the highly competitive software market, and the drawn-out struggle between Oracle (Nasdaq: ORCL) and PeopleSoft over Oracle's hostile-takeover bid.
6.  IBM Seeks Slam Dunk in SCO Case (NewsFactor). NewsFactor - IBM (NYSE: IBM) continues to push for the dismissal of a copyright-infringement lawsuit brought against the company by the SCO Group, requesting a partial summary judgment in the U.S. district court hearing the case in Salt Lake City, Utah.
7.  BlackBerry Connect Available for Palm OS (NewsFactor). NewsFactor - PalmSource (Nasdaq: PALM) and Research In Motion (Nasdaq: RIMM) (RIM) have made good on their December 2003 announcement of plans to make BlackBerry Connect available to Palm OS licensees. The companies showcased the result of the joint development effort at the Wireless Enterprise Symposium.
8.  Apple Spins iPod into Separate Unit (NewsFactor). NewsFactor - Apple (Nasdaq: AAPL) Computer has reorganized its internal operations along product lines, creating units that concentrate on the iPod and Macintosh system development.
9.  Assistant of Ore. Sen. DeWine Is Fired (AP). AP - An entry-level staff assistant to Sen. Mike DeWine, R-Ohio, was fired Friday after an Internet journal of her sexual exploits was made public this week.
10.  Cisco Says Software Stolen, But No Damage Occurred (Reuters). Reuters - Cisco Systems Inc. (CSCO.O) acknowledged some of its source code was stolen and then posted to the Internet, but added that no damage has resulted from the theft.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
11.  Sailing the Wine Dark Sea
12.  JBoss's Fleury Abjures Astroturfing
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
13.  DHS privacy director: We're paying attention. WASHINGTON - Peter Sand, the new director of privacy technology at the U.S. Department of Homeland Security (DHS), walked into a lunch meeting with what could have been a hostile crowd and told privacy advocates the agency is working hard to make sure privacy rights are respected as the DHS fights terrorism.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
14.  CVS flaw has Linux vendors rushing out patches. Linux vendors have rushed to distribute patches for a critical flaw in CVS, a widely used program for collaborating on software development, that could allow a malicious user unauthorized access to development code.
15.  Microsoft eyeing merger of two secure e-mail specs. After submitting its Caller ID e-mail authentication specification to the Internet Engineering Task Force (IETF) earlier this week, Microsoft Corp. is now in detailed discussions to merge the specification with another, called Sender Policy Framework, or SPF.
16.  DHS privacy director: We're paying attention. WASHINGTON - Peter Sand, the new director of privacy technology at the U.S. Department of Homeland Security (DHS), walked into a lunch meeting with what could have been a hostile crowd and told privacy advocates the agency is working hard to make sure privacy rights are respected as the DHS fights terrorism.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
17.  Elsewhere: Spammers get fussy as zombie army grows. Is your Internet connection actually worth infecting? The Bobax worm tests PCs first to see if they'll be good spam zombies X-NAS-Bayes: #0: 4.96361E-174; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 900 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The Bobax worm, which is less than a week ol...

----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
18.  BugTraq: [ GLSA 200405-16 ] Multiple XSS Vulnerabilities in SquirrelMail. Sender: Rajiv Aaron Manglani [rajiv at gentoo dot org]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
19.  AntiOnline Spotlight: Our Intern Is a Hacker!
20.  Frühwarnsystem erahnt IT-Bedrohungen
21.  Bund leidet unter Spam
22.  clsid.txt
23.  e107flaw.txt
24.  snmpdadv.txt
25.  snsadv72.txt
26.  Biometric ID card trial kicks off in Glasgow
27.  [SNS Advisory No.72] Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability
28.  RE: Internet explorer .clsid vulnerability
29.  Stupid Phishing Tricks
30.  Re: Question About Ethics and Full Disclosure
31.  Re: Non-logged Brute Force Attack Vulnerability forFantastico-Created Databases on cPanel Based Hosts
32.  e107 web portal Referers HTTP Injection
33.  MDKSA-2004:046-1 - apache-mod_perl packages are now available
34.  [OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync)
35.  Eudora 6.1.1 attachment spoof, LaunchProtect

4:23:18 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  AOL previews new e-mail software
2.  SportsLine up for sale?
3.  Tracker keeps tabs on e-mail readers
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Alibris Withdraws Auction-Based IPO (Reuters). Reuters - Online bookstore Alibris said on Friday that it would not proceed with its initial public offering after its auction-based IPO did not produce attractive prices.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Become a Professional Gamer
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
6.  Microsoft eyeing merger of two secure e-mail specs. After submitting its Caller ID e-mail authentication specification to the Internet Engineering Task Force (IETF) earlier this week, Microsoft Corp. is now in detailed discussions to merge the specification with another, called Sender Policy Framework, or SPF.
----------------------------------------------------------------------
SecurityNewsPortal.com HomelandSecurity.com
----------------------------------------------------------------------
7.  India's Secret Army of Ad Clickers - Rupees and Dollar$ for Clicks
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
8.  Vulns: Microsoft Internet Explorer CSS Style Sheet Memory Corruption Vulnerability. A vulnerability identified in Internet Explorer may allow an attacker to cause the application to crash. The issue presents itself when the browser attempts to process an...
9.  Vulns: Omnicron OmniHTTPD Get Request Buffer Overflow Vulnerability. OmniHTTPD is a Web server for Microsoft Windows operating systems. X-NAS-Bayes: #0: 7.23401E-100; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 899 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Reportedly OmniHTTPD is affected by a GET request buffer overflow vulnerability. This issue is due to...

10.  Vulns: KDE Konqueror Embedded Image URI Obfuscation Weakness. Konqueror is a freely available, open source web browser distributed and maintained by the KDE project. It is available for the UNIX and Linux operating systems.

It is ...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Symantec Eyes Enterprise with Brightmail Buy
12.  Exploit code reported for CVS Vulnerability

3:22:57 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Nokia pumps more research dollars into China
2.  Why Carly's been dissed
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Verbatim Spins Out Dual-Layer DVD+R Discs (PC World). PC World - Discs pack almost twice the capacity of predecessors, work with most current drives.
4.  DVD rentals blast off as old and new forms of delivery unite (AFP). AFP - DVD rentals are booming, boosted by the growing popularity of new Internet-based subscription services that bring the video shop into the home.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  THX-1138 Finally Coming to DVD
6.  Mozilla's Mini-Me
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
7.  Open Source Users Unaffected by Sasser Worm
----------------------------------------------------------------------
SecurityNewsPortal.com HomelandSecurity.com
----------------------------------------------------------------------
8.  India's Secret Army of Ad Clickers - Rupees and Dollar$ for Clicks Keywords : advertising advertisements Internet marketing computer crime hackers virus trojans hacking business fraud Google ads scams
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
9.  BugTraq: [OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync). Sender: OpenPKG [openpkg at openpkg dot org]
10.  Vulns: phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability. phpMyFAQ is a web based content management system. X-NAS-Bayes: #0: 2.64513E-133; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 898 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

phpMyFAQ is prone to an arbitrary file disclosure vulnerability that can allow a remote attacker to gain access to pot...

11.  Vulns: Multiple Perl Implementation System Function Call Buffer Overflow Vulnerability. ActiveState Perl and Perl for cygwin are both reported to be prone to a buffer overflow vulnerability.

The issue is reported to exist due to a lack of sufficient bounds...

12.  Vulns: Zen Cart Login.PHP SQL Injection Vulnerability. Zen Cart is a freely available web-based shopping cart application. It is implemented in PHP with a MySQL database back end and will run on Unix and Unix variants as wel...
13.  Vulns: SGI IRIX rpc.mountd Remote Denial of Service Vulnerability. rpc.mountd is an RPC server that handles NFS file system mount requests.

SGI IRIX is prone to a remote denial of service vulnerability. This vulnerability affects the ...

14.  Vulns: Multiple Perl Implementation Duplication Operator Integer Overflow Vulnerability. Practical Extraction and Reporting Language (Perl), is a scripting language that is written by Larry Wall. Perl is ported to many platforms.

ActiveState Perl is reported...

15.  Vulns: DSM Light Explorer.EXE Directory Traversal Vulnerability. DSM light is a web-based file browser application. It is implemented in PHP and will run on Unix and Unix variants as well as Microsoft Windows.

DSM Light has been repo...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
16.  The dot-com revival begins in the Midwest. Easy as lotto By Ashlee Vance .
17.  Biometric ID card trial kicks off in Glasgow. Smile better for the nice databank, dearie By Lucy Sherriff .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  Elsewhere: U.S. May Get a Privacy Czar
19.  Elsewhere: Athens Olympics braces for cyberattacks
20.  News: Firm names 'statistically likely' terrorists
21.  Une vulnérabilité mineure dans Outlook 2003
22.  TREND MICRO's free online virus scanner
23.  WORM_AGOBOT.WR
24.  A97M_SADAMI.A
25.  WORM_SDBOT.XD
26.  BKDR_HAXDOOR.C
27.  TROJ_HAXDOOR.C
28.  VBS_BAGLE.Z
29.  HTML_BAGLE.Z
30.  WORM_BAGLE.X
31.  Newest Pattern: 893

2:22:38 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  iPod/torture mashups in NYC. X-NAS-Bayes: #0: 1.27979E-125; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 897 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

These Iraqi torture/iPod ad mashups are appearing around NYC.

Link

(Thanks, Rich!)

2.  Jungle Boat movie from Disney. Disney is making a new ride-based movie, this time from The Jungle Boat Cruise. Let's hope it's more like the Pirates of the Caribbean than the Haunted Mansion movie (shudder).

Link

(via Waxy)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  IDC: Games, video to fuel Europe's mobile market
4.  Shopping sites ring up higher sales
5.  Orbitz to launch revamped Web site
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  Spamming for Dollars (washingtonpost.com). washingtonpost.com - Fighting spam has turned into such a big business that anti-spam companies are becoming a hot commodity of their own.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Schizophrenia Experiences and Suggestions?
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
8.  CVS flaw has Linux vendors rushing out patches. Linux vendors have rushed to distribute patches for a critical flaw in CVS, a widely used program for collaborating on software development, that could allow a malicious user unauthorized access to development code.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
9.  Elsewhere: U.S. May Get a Privacy Czar. To protect the privacy and civil liberties of Americans, the federal government may get a privacy czar if two congressional representatives have their way.

Reps. Kendri...

10.  Elsewhere: Athens Olympics braces for cyberattacks. The Athens Olympics organizers are bracing themselves for a wave of cyberattacks once the games are under way, but insist that a physical breach of security still represe...
11.  News: Firm names 'statistically likely' terrorists. The Associated Press By Brian Bergstein
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  BugTraq: Eudora 6.1.1 attachment spoof, LaunchProtect. Sender: [psz at maths dot usyd dot edu dot au (Paul Szabo)]
13.  BugTraq: e107 web portal Referers HTTP Injection. Sender: Chinchilla [kingchinchilla at hotmail dot com]
14.  Vulns: Neon WebDAV Client Library Format String Vulnerabilities. Neon is a client side library supporting HTTP and WebDAV interfaces. It is freely available under the GNU Public License for Unix and Unix variants.

It has been reporte...

15.  Vulns: CVS Client RCS Diff File Corruption Vulnerability. CVS is the Concurrent Versions System, which is a freely available open-source version management package. It is available for the Unix and Linux operating systems.

A v...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
16.  UK's RAF planned WMD delivery via 'pigeons of death'. Lofty goals By John Lettice .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
17.  Outlook flaw hinders secure remote access
18.  UK Residents Able to Take Part in Biometric Identification Smart Card Scheme
19.  New abuse images more graphic
20.  Arrests in beheading of American
21.  Elsewhere: Hacker group gets dose of own medicine
22.  WORM_SCANBOT.A
23.  Guide :: Linux Forensics Software
24.  Guide :: PC Forensics Software
25.  Guide :: PDA Forensics Tools and Techniques
26.  Guide :: Kerberos Implementation, Part 3
27.  Guide :: Kerberos Implementation, Part 2
28.  Guide :: Kerberos Implementation
29.  Guide :: Colinux, Part 2
30.  Guide :: Colinux
31.  Blog :: Support the SASSER worm author!
32.  Blog :: About this Cisco business...
33.  Blog :: The opiate for the people

1:22:18 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Holy Vandals, Holy Grail. An historic monument in central England that may hold the key to the location of the Holy Grail was damaged by vandals on Tuesday. The BBC reports that "a gang of youths climbed on top of The Shepherd's Monument at Shugborough Hall" and started smashing away.
"The Shepherd's Monument is of international importance, both as a work of art and because of the legend that a baffling inscription on the monument provides clues to the true location of the Holy Grail," said the home's general manager Richard Kemp.
Interestingly, the vandalism came on the heels of a visit by former code-breakers from War II intent on cracking the 10-letter puzzle. The Shepherd's Monument is discussed in depth in the book Holy Blood, Holy Grail, inspiration for The Da Vinci Code. Link to a National Public Radio piece about the code-breakers. Link to the BBC story on the vandalism. (Thanks, Kev!)
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Via Technologies touts low-power chip
3.  Briefly: Via Technologies touts low-power chip
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Nokia to Up China Research, Development (AP). AP - Nokia, the world's biggest cell phone maker, said Friday it will significantly expand its research and development operations in China.
5.  Comcast Turns On Microsoft TV (PC World). PC World - Tech giant leaps into TV Land with major rollout of its interactive DVR software.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  What's Your Terrorism Quotient?
7.  SETI@home Turns Five Today
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
8.  World Championship Rugby. BBC Sport reviews the latest oval ball offering, World Championship Rugby.
9.  Online glitch hits student loans. Students may have missed a deadline for asking for a loan because of delays to a new online application process.
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
10.  Elsewhere: Hacker group gets dose of own medicine. An alliance called Hackers Against America (HAA) has received a dose of its own medicine with its own website having been defaced, according to information at the defacem...
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
11.  BugTraq: RE: Internet explorer .clsid vulnerability. Sender: Thor Larholm [thor at pivx dot com]
12.  BugTraq: [SNS Advisory No.72] Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability. Sender: [snsadv at lac dot co dot jp (snsadv)]
13.  BugTraq: Stupid Phishing Tricks. Sender: http-equiv at excite dot com [1 at malware dot com]
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
14.  CA flirts with white box makers. Free software, boys! By Ashlee Vance .
15.  Columbia debris tested for re-entry stress. Material loaned for analysis By Lucy Sherriff .
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
16.  U.S. may get a privacy czar
17.  Malware analysis for administrators
18.  Athens Olympics braced for wave of cyberattacks
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
19.  Four held in beheading of American
20.  21 May OF97/Exedrop-C
21.  21 May W32/Agobot-IY
22.  Do We Suffer From Wi-Fi Security Paranoia?
23.  Symantec Eyes Enterprise with Brightmail Buy

12:21:59 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Lessig lecture in London, May 27. Larry Lessig is speaking on London on the 27th of May at the Royal Geographical Society, SW7. X-NAS-Bayes: #0: 5.79845E-235; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 895 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Lawrence Lessig will put forward in this lecture the hypothesis that innovation and experimentation thrive when ideas and culture can be freely exchanged and circulated. These freedoms are under threat. He proposes that the erosion of constitutional and  civil rights carries with it profound consequences for all those involved in  the arts and the business of ideas.

Flash Link

2.  Erik Davis consults on A Scanner Darkly!. Boing Boing pal Erik Davis sends us this exclusive bit of insider insight into the Hollywood adaptation of Philip K. Dick's surreal SF novel "A Scanner Darkly":

"This spring, I had the opportunity to read and consult on Richard Linklater’s screenplay for Philip K. Dick’s A Scanner Darkly, which is set to start filming this July. As I love many of Linklater’s films, this was a great honor, although much less funny than the New Yorker’s description of me as a “Dick expert.” Expert or no, I can tell you that I have every reason to believe that Linklater’s film will be what Dickheads everywhere have been waiting for: the first “real” “authentic” PKD movie. While the film updates the historical vibe from paranoid 70s to paranoid 00s, the script is dark and tart, funny and faithful. Nearly all the dialogue is drawn from the novel, and the few changes sharpen Dick’s themes rather than squelch them. Linklater has kept the story dark, and haunted by rumors of God.

As has been reported, Keanu Reaves will play Bob Arctor, the Orange County narc who goes schizo after being assigned to spy on himself. Linklater has been planning this project for years; it was Reaves’ interest in the story that finally got the ball rolling. As has been already noted, Winona Ryder, Robert Downey Jr., Woody Harrelson, and Rory Cochrane round out the cast, though it also needs to be mentioned that these are some of the most famous druggies in Hollywood. Actually, I don’t know anything about Rory’s personal habits, but he sure spouted convincing cannabinoid bon mots in Dazed & Confused.

During my time at Linklater’s pine-forested getaway pad outside of Austin, which features a pagoda, a huge stone tower, and many pinball machines, I got to meet the genius team whose digital rotoscoping helped make Waking Life one of the few masterpieces of the new millennium. These are definitely the guys you want to bring Bob Arctor’s scramble suit to life."

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  Gateway aiming for profitability in '05
4.  Briefly: Gateway aiming for profitability in '05
5.  Week in review: Code breaking
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  E-Commerce Sales Fell in First Quarter (Reuters). Reuters - U.S. retail sales over the Internet fell 11.4 percent in the first quarter of 2004, but rose 28.1 percent over the same period a year earlier as consumers increasingly relied on e-commerce to make purchases, a government report showed on Friday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Napster Launches UK Music Service
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
8.  Helping hand for net novices. A new IT skills programme specially designed for those intimidated by technology is unveiled in Northern Ireland.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
9.  Do We Suffer From Wi-Fi Security Paranoia?
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
10.  Vulns: PrimeBase SQL Database Server Insecure Installation Temporary File Creation Vulnerability. PrimeBase SQL Database Server is a database implementation that is available for Unix/Linux variants as well as Microsoft Windows platforms.

PrimeBase SQL Database Serve...

11.  Vulns: PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability. PrimeBase SQL Database Server is a database implementation that is available for Unix, Linux, and Microsoft Windows platforms.

A problem has been reported in the storage...

12.  Vulns: Blue Coat Systems SGOS Private Key Disclosure Vulnerability. Blue Coat Systems Security Gateway OS (SGOS) 3.x devices are prone to a vulnerability that could cause the private encryption key to be disclosed to unauthorized parties....
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
13.  'Silver Surfers' day targets the over-50s. Seeking to end digital exclusion By Lucy Sherriff .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  Sybase CEO: Unwired Enterprise Requires Aggressive Apps (Ziff Davis)

11:21:39 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Why dis Fiorina?
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Oracle, Microsoft getting friendly (SiliconValley.com). SiliconValley.com - Pragmatism won out over acrimony Thursday when software giants and longtime rivals Microsoft and Oracle announced a new partnership for technology development, the first formal agreement between the two companies.
3.  German gov't probing surge in spam e-mails (AFP). AFP - The German government said that it was being hit by a surge of unwanted spam e-mails and was now investigating to establish if it was being deliberately targeted.
4.  FTC Requiring Labels on Explicit Spam (AP). AP - Sexually explicit Internet spam must now carry a warning label. A Federal Trade Commission rule went into effect Wednesday requiring that unsolicited commercial e-mail that contains sexually oriented material include the words "SEXUALLY EXPLICIT" in the subject line.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  FBI Plans Spammer Smackdown
6.  Internet Grocery Shopping Slowly Gaining Ground
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
7.  Nokia expands in China with high hopes for CDMA. Nokia Corp. on Friday rolled out its plans for a mutipronged expansion program into the lucrative Chinese mobile phone market as the company seeks to keep up with its increasingly aggressive competitors.
----------------------------------------------------------------------
[O.S.S.R]
----------------------------------------------------------------------
8.  The ever-evolving virus
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  Medical imaging research awarded £4.5m. Grant will improve breast cancer screening By Lucy Sherriff .
10.  Chip and PIN gathers pace. Preparing for January liability shift By John Leyden .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Failles dans CVS et Subversion, les systèmes de gestion de projets
12.  Une faille critique et non patchée pour Mac OS X et Safari
13.  California town for sale on eBay finally sold
14.  Data mining firm names 'statistically likely' terrorists
15.  Virus help fund gets closed down
16.  Mac Hole Has Users, Hackers Abuzz
17.  Board members warned over security shortfalls
18.  Hacker group gets dose of own medicine
19.  Do We Suffer From Wi-Fi Security Paranoia?
20.  Athens Olympics braced for wave of cyberattacks
21.  vsftpd Connection Handling Denial of Service Vulnerability
22.  vsftpd Connection Handling Denial of Service Vulnerability
23.  vsftpd Connection Handling Denial of Service Vulnerability

10:21:19 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Net aficionados grovel to test Google's e-mail (USATODAY.com). USATODAY.com - Google's controversial Gmail e-mail service, under invitation-only testing on the Internet, is the toughest ticket in town.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Intel Sued for Patent Infringement
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Drugs come to online games. Catch up with the latest news from the world of video gaming.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  Tech firm seeks $500m for Intel patent 'violation'. Pentium... er... II under threat By Tony Smith .
5.  Replacement kit dominates world PC sales. Upgrades to account for more than half of new PC sales By Tony Smith .
6.  Belgacom to launch DSL interactive TV. Alcatel on board for VDSL service By Jan Libbenga .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Linux Kernel e1000 Network Driver Kernel Memory Disclosure Vulnerability
8.  Novell NetWare TCP Connection Reset Denial of Service
9.  Novell NetWare TCP Connection Reset Denial of Service
10.  Spam, Viruses Top Messaging Concerns
11.  Yahoo Releases E-Mail Standard to Fight Spam
12.  Counterpane Unveils Security Services For SMBs

9:20:58 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Nokia expands research and development in China (AFP). AFP - Finnish mobile phone giant Nokia said it would expand its research and development activities in China, boosting cooperation with Chinese universities and swelling the number of phones designed and developed in the country.
2.  Microsoft Office Focuses on Collaboration (AP). AP - The latest Macintosh edition of Microsoft Corp.'s Office suite does text, e-mail, spreadsheets and presentations with aplomb. Then again, so did its previous versions.
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Over 50s urged to catch net bug. Events are taking place across the UK to encourage the older generation to go online.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  Could Patriot unjam US garage doors?. Letters Plus, universe theory gets butt kicked By Lucy Sherriff .
5.  Sasser fan club stops rattling tin. Fundraising abandoned at under $100 By John Leyden .
6.  Blu-ray founders rename, open group to new members. Blu-ray Disc Association to lead tech's consumer push By Tony Smith .
7.  Net surrogate mum jailed for two years. 'Cynical and callous fraud' By Lester Haines .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  CEOs seek security collaboration
9.  Remotely updating BlackBerries
10.  U.S. May Get a Privacy Czar
11.  Website Hackers Against America gehackt
12.  Cycle worm, het zoveelste politieke virus
13.  Exploiten van Mac OS X lekken uitgelegd
14.  Windows XP Service Pack 2 mogelijk gratis in winkels
15.  Service Pack 2 voor ISA Server 2000
16.  Cisco vraagt patent aan voor TCP security update
17.  patriottistische hacker bekent schuld
18.  Hoe stop je virussen? Bouw een "killer bot"
19.  Kritiek lek in Concurrent Versions System
20.  Olympische spelen klaar voor cyberaanvallen
21.  Sasser fan club stops rattling tin

8:20:37 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Hybrid fruit photoshopping. X-NAS-Bayes: #0: 9.98511E-234; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 891 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Today on Worth1000's photoshopping contest: hybrid fruit.

Link


2.  Dumb tech-support explanations. Great open-mic question on Ask Slashdot: what's the worst bullishit "explanation" you've ever gotten from tech support?

My cable modem connection had stopped work. Given my ISPs track record, this was unremarkable, but after it continued for 2 days, I decided to call the tech support number. After supplying my ID number, the support person told me that my connection was intentionally shut off because I was broadcasting a widely-circulated Windows virus. I promptly informed the tech support person that I did not use the Windows operating system on any of my computers, and that I could not possibly have the virus I was accused of having.

The support rep immediately told me that I had the virus, and that they would not turn my connection back on until I jumped through their anti-virus hoops. I argued for almost 10 minutes with this neophyte that I could not use their Windows anti-virus on my Linux systems, and that even if I could, it would not do a damn bit of good. Did it matter? Of course not.

Finally, in order to get my connection back on, I agreed to perform their anti-virus tricks "to the best of my ability", and install Windows just so I could "remove the virus" from my system. The rep actually thought this was an excellent resolution to the problem, but for some reason didn't believe I would actually do it (could have been my vehement renouncements against the entirety of Microsoft's products). After another 5 minutes of cajoling, I convinced her to turn my connection back on so I could get the anti-virus tools, and access Windows Update.

Link

3.  Fox News lies with statistics. My cow-orker Jason Schultz identifies a nice bit of Fox statistical chicanery:

Among today's top stories, a new "Fox News Poll" that says 33% of those surveyed think the media is too easy on Kerry and 42% think the media is too tough on Bush. [Of course, if it were limited to FoxNews coverage, you'd probably see dramatically different numbers in the opposite direction.]

But let's just look at the numbers they've given us. 33% think the media is too easy on Kerry. That means 66% (or 2/3rds) think the media is fair or too tough on Kerry, right? Isn't that the real story?

Link

4.  Lessig lecture in London, May 27. Larry Lessig is speaking on London on the 27th of May.

Flash Link

5.  Report from UK ID Cards meeting at LSE. Phil sez, "My personal take on the Mistaken Identity public meeting re. UK ID cards at the London School of Economics yesterday."

Lord (Andrew) Philips of Sudbury, Liberal Democrat peer, was particularly good - especially in his detailed grasp of the system, e.g. regarding the nonsensical restriction of the powers of the Interception of Communications Commissioner, and his realistic take on the task ahead in persuading the 80-ish% that ID cards backed by a National Identity Register are a BAD IDEA.

He referred specifically to tackling the all-too-common "If you've got nothing to hide, you've got nothing to fear" argument and, although he didn't explicitly say the phrase, his comment "We're on no-one's list now" led me to think that "If you're not on their list, you won't exist" might imply/initiate a relevant counter-argument. [Wait for the T-shirt - I'm all for slogans!]

Link

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  FCC rule likely to hurt rural carriers (USATODAY.com). USATODAY.com - Starting Monday, cell phone customers in small and midsize markets will gain the same right their big-market cousins enjoy: They'll get to keep their numbers when they switch carriers.
7.  New on DVD (USATODAY.com). USATODAY.com - This week, classics fans can indulge themselves with Around the World in 80 Days (the Chan-free version), Walt Disney on the Front Lines and The Good, the Bad and the Ugly. Plus, the Greeks may not be ready for the Olympics, but you can start getting in the spirit with Miracle. Yeah, that's about the Winter games, but it's the best we got this week, people.
8.  Search Is On for Gmail Names (washingtonpost.com). washingtonpost.com - If you want a Gmail account, the new e-mail service from Google Inc., you'd better be ready to pony up or at least have something to offer -- some are willing to swap kung-fu lessons, medical advice or, say, an autographed picture of a master yodeler.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
9.  Linux Advisory Watch - May 21st 2004
10.  Athen prepares Olympic cybersecurity
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
11.  Vulns: Heimdal K5AdminD Remote Heap Buffer Overflow. Heimdal implements the Kerberos 5 network authentication protocols. The k5admind daemon provides the administrative interface to the Kerberos Key Distribution Center (KDC...
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
12.  Aliens: coming to a house near you soon. It was five years ago today... 21 May 1999 By Team Register .
13.  Sony to ship Wi-Fi LCD TV this autumn. LocationFree by name, nature By Tony Smith .
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
14.  Exceed Xconfig Setting Editing Restriction Bypass
15.  Exceed Xconfig Setting Editing Restriction Bypass
16.  Exceed Xconfig Setting Editing Restriction Bypass

7:20:18 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  AT&T Wireless rejects Rogers (TheDeal.com). TheDeal.com - The U.S. cell-phone operator will auction its 34.1% stake in the company's wireless unit after rejecting an offer from its parent.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Bob Muglia on Longhorn Server, Linux and Blackcomb
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Web veteran turns to world of work. Small firms are being encouraged to join a club of net-connected companies.
4.  Gates backs blogs for businesses. Microsoft boss Bill Gates highlights the benefits of blogs in a speech to top business leaders.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
5.  TechnoDepot debuts the d:-) polo shirt. Cash'n'Carrion Must-have kit for cool techy dudes By Cash'n'Carrion .
6.  BT & Vodafone: uneasy bedfellows. 'Bluephone' converged handset alliance By Wireless Watch .
7.  Apple to slow annual OS X update rate. 'Unsustainable' schedule, says software chief By Tony Smith .
8.  Tech firms seeks $0.5bn for Intel patent 'violation'. Pentium... er... II under threat By Tony Smith .
9.  Cometa crash bursts hotspot bubble?. Analysis Public WLANs 'overhyped' By Wireless Watch .
----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
10.  New Dinosaur Stumps Scientists. A 50-foot-long sauropod recently unearthed in southern Montana has a mysterious second hole in its skull that leaves researchers baffled.
11.  Are You a Potential Terrorist?. A Florida company that helped the government launch Matrix also provided the feds with the names of 120,000 people who, according to its statistics, were likely terrorists.
12.  Spam Adversaries to Meet, Debate. Alleged spammer Scott Richter and SpamCop founder Julian Haight will meet next month to duke it out in a public debate. It could get nasty. By Amit Asaravala.
13.  California, Here We Come (Again). Ten of 14 counties that had their e-voting machines decertified by the state are close to meeting the secretary of state's stipulations for recertification. Some touch-screen machines will probably be ready for November elections after all. By Kim Zetter.
14.  Common Pollutant as Bad as PCBs?. PDBE contamination is on the rise, but no one's quite sure of the long-term impact. Also: Methane releases could heat things up.... Activists team up to save boreal forest. By Stephen Leahy.
15.  U.S. May Get a Privacy Czar. Congressional representatives introduce a bill that would require the federal government to create a chief privacy officer position. Every federal department and agency also would get a privacy head. By Kim Zetter.
16.  A Scan of the Headline Scanners. Aggregators -- otherwise known as RSS or news readers -- make life easier for people who browse dozens of news sites every day. Wired News kicks the tires of some of the most popular ones. By Ryan Singel.
17.  Gates Fetes America's Top CEOs. In his annual schmoozefest with top American CEOs, Microsoft chairman Bill Gates says technology still has a long way to go in improving productivity. The CEOs politely listen, then go about networking. Cydney Gillis reports from Seattle.
18.  For Speeders, Hybrids Suck Gas. One of the biggest selling points for hybrid cars is their fuel-efficiency, but some disappointed owners still have a case of the gas-pump blues. They're discovering that, just like with regular cars, driving styles dictate mileage. By John Gartner.
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
19.  How to stop viruses? Build a 'killer bot'
20.  Spam adversaries to meet, debate
21.  FBI plans spammer smackdown
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
22.  How to stop viruses? Build a 'killer bot'
23.  Spam adversaries to meet, debate
24.  FBI plans spammer smackdown
25.  18 killed in heavy fighting

6:19:58 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Steve Silberman's reading list for Allen Ginsberg's Beat Generation course. Boing Boing buddy Steve Silberman sez: "In 1977, poet Allen Ginsberg taught a course called "The Literary History of the Beat Generation" at Naropa Institute in Boulder, Colorado. I was in the course, and a couple of friends of mine and I just turned the suggested reading list into a gateway to the texts themselves. If you ever wished that your English-lit teacher had been the author of "Howl"..." Link
2.  John Shirley book signing in San Jose May 29. My friend John Shirley, author of Crawlers and Black Butterflies and screenwriter of The Crow, etc, will be reading from a new novella and signing at BAYCON 2004 - San Jose, California, the Doubletree hotel, May 29. Link
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  World's number two Internet power China has just one pct of global ad market (AFP). AFP - China may have the second-largest online population in the world but it only has about one percent of the global market for web advertising, state media reported.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  Capgemini scores big with TXU. 10-year, $3.5bn IT services contract By Datamonitor .
5.  TechnoDepot debuts the d:-) polo shirt. Cash'n'Carrion Must-have kit for cool techy engineer type dudes By Cash'n'Carrion .
6.  Esat BT to launch residential VoIP. Challenging Eircom By electricnews.net .
7.  Brightmail finds sanctuary with Symantec. MS anti-spam play still a threat By Datamonitor .
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
8.  How to stop viruses? Build a 'killer bot'
9.  Spam adversaries to meet, debate
10.  FBI plans spammer smackdown
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  How to stop viruses? Build a 'killer bot'
12.  Spam adversaries to meet, debate
13.  FBI plans spammer smackdown
14.  A Security Transfer Model based on Active Defense Strategy

5:19:37 AM    comment []

----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
1.  Linux Advisory Watch - May 21st 2004
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Five PC 'security guards' for a truly secure network
3.  The defense-in-depth approach to malware
4.  Seven words for understanding SIM
5.  Canadian online banking users fall victim to Trojan
6.  Surge in phishing attacks prompts calls for change
7.  Brightmail acquisition by Symantec seen as good for IT users
8.  News: Data mining firm names 'statistically likely' terrorists

3:18:27 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Open season on open source
----------------------------------------------------------------------
New York Times: Technology
----------------------------------------------------------------------
2.  Tellabs to Pay $1.9 Billion for Internet Equipment Maker. Tellabs said it would buy Advanced Fibre Communications for about $1.9 billion in cash and stock. By Reuters.
3.  Database Tagged 120,000 as Possible Terrorist Suspects. The "high terrorism factor" scoring system was also a critical selling point for the involvement of the database company, Seisint Inc., in another criminal information project. By The Associated Press.
4.  Oracle and Microsoft Cut a Software Deal. Two longtime rivals, Oracle and Microsoft, announced a partnership intended to help Oracle's databases work better with Microsoft's Windows operating system. By The New York Times.
5.  Tunes, Films and, Now, XP: A Remote Extends Its Domain. Consumers now have another clicker to add to their blooming bouquets of remote controls. SnapStream Media has just released the FireFly PC Remote, which can manipulate not only computers running Microsoft's Windows Media Center operating system, but standard PC's using Windows XP Home and Windows XP Professional as well. By J. D. Biersdorfer.
6.  Letters to the Editor. Google Mail and Prying Eyes.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  Search Is On for Gmail Names (washingtonpost.com). washingtonpost.com - If you want a Gmail account, the new e-mail service from Google Inc., you'd better be ready to pony up or at least have something to offer -- some are willing to swap kung-fu lessons, medical advice or, say, an autographed picture of a master yodeler.
8.  Microsoft, Oracle Set Software Agreement (Reuters). Reuters - Microsoft Corp. and Oracle Corp. announced a software development agreement on Thursday, signaling an improved relationship between the two corporate database software market rivals.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  AgroWaste Oil Plant Starts Production
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
10.  News: Data mining firm names 'statistically likely' terrorists. The Associated Press By Brian Bergstein
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Phishing scourge prompts calls for change
12.  CAN-SPAM law: Little impact so far
13.  Five PC 'security guards' for a truly secure network
14.  The defense-in-depth approach to malware

2:18:07 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Internet Lowers Real Estate Commissions (AP). AP - Real estate and mortgage brokers have less of a hold on clients from the start of the home-buying process, according to a national study which researchers at the University of Arkansas at Little Rock helped organize.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Worst Explanation From Tech Support?
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  MITNICK, WOZNIAK, BIAFRA TO HEADLINE FIFTH HOPE PROGRAM

12:25:28 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 6/1/2004; 12:29:22 AM.
This theme is based on the SoundWaves (blue) Manila theme.
May 2004
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Apr   Jun