Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Friday, July 09, 2004
 

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
1.  phpGroupWare hook_admin.inc.php Path Disclosure
2.  phpGroupWare hook_home.inc.php Path Disclosure
3.  phpGroupWare class.holidaycalc.inc.php Path Disclosure
4.  phpGroupWare setup.inc.php.sample Path Disclosure
5.  phpGroupWare index.php Calendar Date Variable XSS
6.  phpGroupWare tables_update.inc.php Arbitrary Command Execution

11:28:57 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Dems Credential Bloggers; GOP Will, Too (AP). AP - More than 30 independent Web journalists have been accredited to cover the Democratic convention, and the Republicans said Friday they'll also credential so-called bloggers.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Build Your Own Bluetooth Hearing Aid
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  GeoTrust vs. VeriSign: An SSL Controversy
4.  Mozilla Patches Vulnerability
5.  Brief: Mozilla moves to fix security vulnerability
6.  Convention security to test new DHS operations center

10:28:38 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Briefly: Accenture says federal probe looming. roundup Plus: IBM tweaks e-mail for midsize businesses...Apple says buy laptop and iPod, get $200...Veritas faces investor lawsuit...China's phone exports skyrocket.
2.  Accenture says federal probe looming. The technology services giant says the U.S. Securities and Exchange Commission plans an informal investigation of an incident involving the company.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Oracle, Regulators Square Off in Filings (Reuters). Reuters - The U.S. Justice Department's lawsuit to block Oracle Corp.'s $7.7 billion hostile takeover of PeopleSoft Inc. relies on deeply flawed assumptions and "absurd conclusions" about the business software market, Oracle said in a post-trial filing on Friday.
4.  Mozilla Gains on IE (PC World). PC World - Study shows Microsoft has lost a percentage of market share to open source browser.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  DIY Cruise Missile Designer Turns Freelance

9:28:17 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  My DRM talk in Portuguese. Börje Karlsson has translated my DRM talk into Portuguese! X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2848 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Link

2.  Mac OS X Tiger: a new dawn of the browser war. In this week's NTK Danny O'Brien breaks the most exciting -- and underreported -- news about the forthcoming version of Mac OS X, called "Tiger":

Why have so few people noticed the key element of Tiger? Dashboard provides javascript access to some safe operating system stuff, like drawing primitives on the window canvas. And then, when you load the gadgets up *in Safari*, you get the same access. Meanwhile, Apple made a deal with Opera and Mozilla the same week to add enough to the browser plugin API to provide the same javascript objects on other platforms and browsers. And they all forked off from the W3C last month to set their own standard committee, WHAT-WG. For creating web applications. Just like Joel Spolsky was asking them to do. So we have low-level (but not insecure) javascript access to the desktop, an open (but non-W3C) standard, and cross-platform plugins to support it. DON'T YOU PEOPLE UNDERSTAND? It's BROWSER WARS II - ELECTRIC BOOGALOO!

Link

3.  Illustrated Story of Copyright online. Alex sez, "The now out of print The Illustrated Story of Copyright is now available online. Unfortunately it's not under any sort of Creative Commons license. The permissions page is here. Personally I find the current online layout a little bit hard to read and confusing, this is the sort of thing that could really be improved if only people were allowed to 'remix' it for better legibility." (I agree)

Link

(Thanks, Alex!)

4.  Hilariously self-referential/recursive Fark photoshopping contest. Mack sez, "Fark is hosting a magnificently self-imploding thread of Photoshop mashups based on the New York Post's erroneous July 6 headline proclaiming that John Kerry had chosen Dick Gephardt as his running mate. Scroll down and let the thread's developing visual syntax make you dizzy ..." Link

(Thanks, Mack!)

5.  Park ranger threatens to arrest Eldred for handing out free Waldens. Eric Eldred, an Internet Bookmobile driver and poster child for the public domain, was threatened with arrest for handing out free copies of Walden at Walden Pond:

Yesterday (July 8, 2004) I took the Internet Bookmobile to Walden Pond in

Concord, Mass. It was the 150th anniversary of H. D. Thoreau's book

"Walden." The Thoreau Society had a dawn to dusk reading.

After an hour of having readers print and take away free copies of "Walden,"

I was asked by the Walden Pond Reservation police to pack up and leave

and threatened with arrest. I left.

The park supervisor (Denise Morrissey, 978-369-3254) told me I could

not pass out free literature without a permit. And she would not give me

a permit because, as she explained, the state park gets money from a

concession by the Thoreau Society, which operates a store that sells

"Walden"--and I was competing with them by giving away free copies.

There is no place to park at Walden Pond except in the state parking

lot, for which I paid $5.

Link

6.  July 13 is Computer Ate My Vote day.

Verified Voting, a nonprofit devoted to fighting paperless electronic voting machines, is holding a national day of "Computer Ate My Vote" protest on July 13. They're asking sites to display a badge and help fight the good fight. See the page below for info on rallies and events in your state.

Link


7.  Send free SMS from iChat. It's now easy and free to send SMSes via iChat: " simply type Shift-Command-N for a 'New Chat with Person,' and enter the phone number in the above format [+16175551212]. When you send the message, you'll receive confirmation from AOL that it was sent."

Link

(via EvHead)

8.  Big Thunder Mountain is b0rked again. Disneyland's Big Thunder Mountain has jumped the tracks again (last year it killed someone) -- there are plenty of first person accounts and photos.

Link

(via Waxy)

9.  Every US presidential TV ad from 1952 to present. Arlen sez, "This site has (I think all) of the television ads from 1952 to the present. You can view them broken down by year, the type of commercial (BackFire, Biographical, Fear, Real-people). It is interesting that, while less slick, ads haven't changed all that much, and the rhetoric seems just as strong (at least to me). It is also quite amusing to see things such as Carter's ad accusing Reagan of being a Flip-Flopper on, of all things, nuclear proliferation."

Link

(Thanks, Arlen!)

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
10.  Oracle, DOJ file antitrust legal briefs. Documents rehash four weeks of courtroom testimony; More enticing briefs expected on Monday.
11.  Oracle v. DOJ: Ellison cites survival instinct. special coverage The Justice Department said Oracle's unwelcome bid for PeopleSoft was about market dominance. Oracle says it's about staying alive.
12.  SCO still wants info from IBM. Linux foe seeks more documents, names Big Blue programmers and says what it wants from Torvalds.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
13.  Video and Software Downloads Overtaking Music
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
14.  DOJ keeping tabs on Longhorn development. U.S. antitrust enforcers have started to track Microsoft Corp.'s development work on Longhorn, the successor to Windows XP, in a move to ensure that the vendor won't violate the final judgment in the government's antitrust case.
----------------------------------------------------------------------
InfoWorld: Security
----------------------------------------------------------------------
15.  You know you've got a browser problem when …. The U.S. Department of Homeland Security, otherwise known as Dancing with Big Brother, tells the world to stop using the Web browser you fought long and hard to tie into your operating system. That’s what happened to beleaguered Microsoft when the department's Computer Emergency Readiness Team (CERT) recently recommended users switch to alternate browser platforms to avoid the security holes in IE caused largely by ActiveX.
16.  SpamAssassin proves to be an effective engine for battling spam. SpamAssassin has proven itself to be a cost-effective and valuable open source weapon in the war on spam. But it’s also a complex solution. Capitalizing on SpamAssassin’s strengths, a number of companies have incorporated it into commercial products, adding extra features and much easier installation and manageability.
17.  Finding a cure for viral cells. Last month, one of the first known viruses to hit a cellular phone was found on Nokia Series 60 handsets. News of the event came from two sources: Kaspersky Labs in Moscow and Symantec in Santa Monica, Calif. The insidious bug, known as Epoc.cabir, displays a message — “caribe-Vz/29 !” — and installs eight files into a directory. The viral code runs each time the phone is restarted and attempts to send itself to the first Bluetooth-enabled device it finds — even a printer.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
18.  BugTraq: MDKSA-2004:067 - Updated ethereal packages fix multiple vulnerabilities. Sender: Mandrake Linux Security Team [security at linux-mandrake dot com]
19.  Vulns: Qualcomm Eudora MIME Attachment Spoofing Vulnerability. Eudora is a popular graphical e-mail client for Microsoft Windows and Apple Macintosh computers offered for free by Qualcomm.

It is reported that Eudora is susceptible t...


8:28:04 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Google recruits eggheads with mystery billboard. No name, no reason, but if you could do the math, the search firm asked for your resume.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Apple's Panther Update Treads New Ground (Ziff Davis). Ziff Davis - An advance seed of the update to Mac OS X 10.3 is now in testers' hands, and it's said to include updates to networking, graphics, FireWire, Bluetooth and more.
3.  Will Microsoft Deliver on Security? (PC World). PC World - Amid software snafus, company prepares to tout security at annual partners' conference.
4.  US music behemoth WMG teams up with mobile phone group for song downloads (AFP). AFP - US recording giant Warner Music Group (WMG) announced it was teaming up with a wireless company to exploit the lucrative musical mobile phone ringtone market.
5.  Dems Credential Bloggers; GOP Will, Too (AP). AP - More than 30 independent Web journalists have been accredited to cover the Democratic convention, and the Republicans said Friday they'll also credential so-called bloggers.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  Cardboard WiFi Antenna Upgrade
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
7.  SCO: IBM 'mischaracterizes' lawsuit. The SCO Group Inc. on Thursday submitted written arguments explaining why a Utah judge should not issue a summary judgment dismissing its multibillion-dollar lawsuit against IBM Corp.

ADVERTISEMENT

Download Strategic Value of Moving to Linux Business White Paper
Find out how your company can reduce IT costs or improve efficiency, you are probably considering Linux and what role it will play in your company.

8.  Tools to tame XML content. IBM later this month will demonstrate Project Cinnamon, the company's content management technology designed to ease document management and storage through XML tagging.
9.  Oracle hints at grid upgrades to come. Oracle foreshadowed improvements to its grid strategy, including updates to the Oracle Database 10g and the company’s enterprise management tools, during an interview with InfoWorld last week.
10.  Olympic-size security demands advance planning. If there's one thing the Atos Origin team understands as lead contractor for the Olympic IT infrastructure, it's that you must learn from your mistakes.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
11.  Mozilla Patches Security Hole
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
12.  BugTraq: RE: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!]. Sender: Eric McCarty [eric at lawmpd dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Fedora: 2: im-sdk Insecure temporary file vulnerability
14.  Mandrake: ethereal Multiple vulnerabilities
15.  Gentoo: Ethereal Multiple vulnerabilities
16.  9 Jul W32/Rbot-AS
17.  9 Jul W32/Agobot-WD

7:27:37 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Alleged Hacker Now Works for Microsoft (AP). AP - A man accused of hacking into search engine company AltaVista's computer systems about two years ago is now employed by Microsoft Corp., reportedly working on search technology.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Software Companies - Merge or Die?
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
3.  Oracle, DOJ lay out case in court papers. With the trial stage over in the U.S. government's effort to block Oracle Corp.'s hostile takeover of PeopleSoft Inc., lawyers for the two sides filed court papers late Thursday that bring the case nearer to its conclusion.
4.  The Olympics network: faster, stronger -- and redundant. ATHENS, GREECE -- A steady stream of taxis grinds up the hill to the headquarters of the Athens Olympic Committee headquarters, on the northern edge of the city. In the lobby it's all bustle as visitors mill around the accreditation desk and pass through security controls. But on the second floor the glass-walled technology operations center sits idle -- most of the 135 seats in the control room are empty, and all but one of the screens on the video wall are dark.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
5.  HNS Audio Learning Session: Digital Certificates Explained
6.  Mandrake: ethereal Multiple vulnerabilities
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
7.  BugTraq: Re: Microsoft Word Email Object Data Vulnerability. Sender: http-equiv at excite dot com [1 at malware dot com]
8.  Vulns: PureFTPd Accept_Client Remote Denial of Service Vulnerability. PureFTPd is an FTP server based on Troll-FTPd and designed with a focus on security. It is available for the BSD and Linux operating systems. X-NAS-Bayes: #0: 5.28294E-149; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2815 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

PureFTPd is reported prone...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
9.  Security Tracker: Linux IA64 Floating Point Register Access Control Error May Disclose Informati...
10.  Secunia: Mozilla Fails to Restrict Access to "shell" "The shell: URI handler is inherently insec...
11.  Var Business: 5 security myths "Like water, hackers take the path of least resistance"
12.  Mozilla: What Mozilla users should know about the shell: protocol security issue "Today, the Moz...
13.  ZDNet UK: 2004 - Internet Explorer's year of shame "Internet Explorer has been springing securit...
14.  CRN: E-Mail Security Puts PGP In Spotlight
15.  Brief: Mozilla moves to fix security vulnerability

6:27:18 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Illegal movie downloads on the rise, says the MPAA. 25% of all Internet users have downloaded motion pictures illegally, according to the MPAA. Are downloads really costing them money, though? By Eric Bangeman.
2.  Man accused of stealing AltaVista code working at Microsoft. Last week a man who had worked for AltaVista was arrested by the FBI on charges that he illegally accessed computers and source code belong to AltaVista in March and June 2002, after leaving the company. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Domino's IPO: Not As Tasty As It Smells (BusinessWeek Online). BusinessWeek Online - Hungry for an IPO? With Google in the wings and first-day pops such as those lately at software makers Blackboard (NasdaqNM:BBBB - News) (up 43%) and Salesforce.com (NYSE:CRM - News; 56%), it's only natural to feel greed's pang. Now, Wall Street wants you to save an appetite for the initial public offering coming soon from a familiar name: Domino's Pizza.
4.  Sluggish Software Sales Show Malaise (AP). AP - The U.S. economy is steaming ahead, but many of the nation's biggest business software makers seem to be sputtering. The malaise, amplified this week by a chorus of warnings about lackluster quarterly sales, is raising doubts about whether the software industry will ever regain the vigor of its heyday.
5.  Democrats Approve Blogger Credentials (AP). AP - More than 30 independent Web journalists have been accredited to cover the Democratic convention, and the Republicans said Friday they'll also credential so-called bloggers.
6.  Microsoft Worker Charged with Taking AltaVista Data (Reuters). Reuters - A Microsoft Corp. (MSFT.O) employee working on the world's largest software maker's search initiative was arrested last week on charges that he stole source code from the AltaVista search engine two years ago, authorities said on Friday.
7.  FCC Boss Launches Blog Aimed at High-Tech Industry (Reuters). Reuters - U.S. Federal Communications Commission Chairman Michael Powell has started his own Web log, or blog, to reach out to the high-tech community and bypass the scores of Washington lobbyists who typically skulk around his office.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
8.  Korean Bipedal Robot Kit
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
9.  Catching up with Wietse Venema, creator of Postfix and TCP Wrapper

5:26:57 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Et Cetera: TGIF. Round up, including: Dell PCs with Linux in Europe? Not quite: a reseller is adding Linux. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Is Siebel on the Rocks? Or Is Siebel About To Rock? - Part 4 (NewsFactor). NewsFactor - CRM market maker Siebel Systems (Nasdaq: SEBL) is standing at a crossroads these days.
3.  Flaw Detected in Mozilla Browser (NewsFactor). NewsFactor - Just when Windows users thought it was safe to move away from Internet Explorer and its litany of security issues, a flaw has been detected in Mozilla, the open-source alternative to Microsoft's (Nasdaq: MSFT) widely used browser.
4.  FCC Approves Nextel Wireless Spectrum Swap (NewsFactor). NewsFactor - The U.S. Federal Communications Commission (FCC) on Thursday approved a controversial spectrum swap with wireless carrier Nextel (Nasdaq: NXTL), designed to resolve interference problems associated with public-safety radio systems.
5.  MP3 Device Makers Could Be Next (NewsFactor). NewsFactor - Critics say it is a chilling proposal, but if the Inducing Infringement of Copyrights Act, currently in the Senate, were to become law, manufacturers of digital-music devices could be held liable for illegal downloading of music.
6.  Mozilla Security Nightmare Begins (NewsFactor). NewsFactor - Just when Windows users thought it was safe to move away from Internet Explorer and its litany of security issues, a flaw has been detected in Mozilla, the open-source alternative to Microsoft's (Nasdaq: MSFT) widely used browser.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
7.  Star Trek XI: Romulan Wars?
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
8.  BugTraq: Re: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!]. Sender: Tom Spencer [tom at mojohosting dot com]
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  George Michael in negative chat room scandal!!. Media-like anger triggers ego shutdown
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  Automated Caller ID / ANI Spoofing
11.  Linux Advisory Watch - July 9th 2004
12.  Security hole found in Mozilla browser
13.  Mozilla Security Nightmare Begins
14.  Reports | Automated Caller ID / ANI Spoofing
15.  Mozilla Flaw Lets Links Run Arbitrary Programs
16.  TREND MICRO's free online virus scanner
17.  WORM_RBOT.CL
18.  WORM_DEDLER.A
19.  TROJ_BANCOS.AO
20.  WORM_RBOT.CF
21.  PE_LOVGATE.AC
22.  TROJ_STRTPAGE.IX
23.  TROJ_DYFUCA.M
24.  TROJ_IMISERV.C

4:26:37 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Battling for bio art. The drama continues in the case of University at Buffalo professor Steve Kurtz, a member of the Critical Art Ensemble. Kurtz has been under investigation since May when police--who Kurtz called to his home after he awoke to find his wife dead of a heart attack--discovered biological materials used in the respected artist's work. (More background here.) Yesterday, Kurtz was charged with four counts of mail and wire fraud with a maximum prison sentence of 20 years each. Professor Robert Ferrell, chair of the Department of Human Genetics at the University of Pittsburgh's School of Public Health, was also indicted for helping Kurtz obtain a bit of harmless bacteria. X-NAS-Bayes: #0: 3.35674E-152; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2812 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

"I am absolutely astonished," said Donald A. Henderson, Dean Emeritus of the Johns Hopkins University School of Hygiene and Public Health and resident scholar at the Center for Biosecurity of the University of Pittsburgh Medical Center. Henderson was awarded the Presidential Medal of Freedom by President Bush for his work in heading up the World Health Organization smallpox eradication program and was appointed by the Bush administration to chair the National Advisory Council on Public Preparedness.



"Based on what I have read and understand, Professor Kurtz has been working with totally innocuous organisms... to discuss something of the risks and threats of biological weapons--more power to him, as those of us in this field are likewise concerned about their potential use and the threat of bio-terrorism." Henderson noted that the organisms involved in this case--Serratia marcescens and Bacillus atrophaeus--do not appear on lists of substances that could be used in biological terrorism.

Link
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Veritas faces investor lawsuit. Storage-software maker gets hit with an investor lawsuit in the wake of its earnings warning.
3.  Apple: Buy laptop and iPod, get $200. Company offers college students a $200 rebate when they buy an Apple notebook computer along with an iPod.
4.  IBM tweaks e-mail for midsize businesses. New software, called IBM Lotus Domino Messaging Express, takes aim at Microsoft's Exchange.
5.  Briefly: IBM tweaks e-mail for midsize businesses. roundup Plus: Apple says buy laptop and iPod, get $200...Veritas faces investor lawsuit...China's phone exports skyrocket...Novell joins government purchasing plan.
6.  Report: WiMax won't take off soon. Much-hyped broadband wireless technology won't break big for another five years, analysts say.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  Hong Kong Officials Bust Software Pirates (AP). AP - Customs officials busted an alleged software piracy syndicate Wednesday and said they will try to freeze the counterfeiters' assets.
8.  Museum to Offer Photos of Art to Download (AP). AP - Art lovers may soon be able to dial "M" for masterpiece. The State Hermitage Museum plans to offer cell phone users an opportunity to have reproductions of the museum's masterpieces on their screens, the museum's director said Wednesday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  419 Scam Blow-by-Blow
10.  A Six-Step Plan for Apple
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
11.  Elsewhere: Lovgate Worm Comes Back to Life. A new variant of the Lovgate worm has been discovered infecting PCs globally, according to security bulletins by major security firms including Symantec and McAfee.

Firs...

12.  Elsewhere: Microsoft Employee Suspect In AltaVista Hacking. Microsoft employee Laurent Chavet was arrested last week on allegations that he had illegaly accessed former employer AltaVista's computer system.

According to a report ...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Katt Cries: Unchain My Art!
14.  9 Jul W32/Rbot-DE
15.  9 Jul Troj/HacDef-F

3:26:17 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Windows XP Service Pack 2, Release Candidate... 3?. Sources are now saying that enough issues were discovered in Release Candidate 2 that the company is preparing yet another RC, likely to be enumerated as 3. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  Unwired Hump Rug. No, silly, not that kind of hump rug. Neither shag nor shagging to be found here. FunFurde is an awesome new furniture design blog (a topic close to my heart, because my sis and I run this online office furniture company together). This post about a laptop-friendly floor-level lounger is a perfect example of why the site's bookmarkworthy:

"The KLOC Floor Lounger from Ligne Roset is basically a padded rug with a built-in hump. If you're thinking, 'There must be more to it than that' then you're thinking too hard. Rug. Hump. That's all you get."

Now, if only you could cram a wireless access point under that thing... Link

3.  SENT phonecam art show opens tomorrow -- Saturday -- in LA. X-NAS-Bayes: #0: 9.6621E-216; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2811 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Last night, Sean Bonner, Caryn Coleman and I finished setting up the SENT phonecam art show installation at LA's Standard Hotel Downtown. 25 invited artists contributed images taken with Motorola V600s. The participants are as diverse as they are talented: photographers, indie photobloggers, two famed filmmakers, a billionaire b-ball team owner, and a celeb or two or three.

The work looks incredible, regardless of how they shot it -- two artist shots from SENT are shown at left. Tattooed LA gangstaz lean out of low-rider cars. A girl gazes into the eye of a phone. White vapor rises off dark water in a Hollywood pool. A needle drops into a black vinyl groove. Little slices of digital life. Lovely stuff.

As I watched Caryn tack invited participants' photos along the wall in a grid resembling a gigantic SMS message (come to the show, you'll see what I mean), all I could think of was this: what's fascinating about people using new gadgets like phonecams to make art isn't the gadget. Human beings need to communicate just like we need to breathe, eat, and drink water. As new tools emerge, the way we communicate changes -- but the need to connect with each other, and reflect on the visual, sensual, tactile world around us remains the same.

If you're in LA, please join us tomorrow night from 7-10pm for the big public opening event -- the first time invited artists' phonecam pics will be shown. We'll be on the 4th floor of the Downtown LA Standard Hotel, 550 South Flower Street. Or, stop by Sunday 11 through Saturday 17 from 12-5pm and check out the show. More details here.

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
4.  Dog days in the enterprise sector. It's not such a hot time to be selling software to corporate customers--as earnings warnings from Unisys, Computer Associates, PeopleSoft and others show.
5.  Week in review: Hard times for software. Warnings to Wall Street suggest that the "soft" in software could stand for the sector's recent financial performance.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  GPS on Mars?
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
7.  Vulns: JAWS Multiple Input Validation Vulnerabilities. JAWS is a content management system used for building websites.

JAWS is reported prone to multiple vulnerabilities. The issues result from insufficient sanitization of u...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  Nominet board results in. Fresh blood at top of the UK registrar
9.  Computer Security: a handbook for the ordinary user. Book review Empowering Harry Homeowner
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
10.  Linux IA64 Floating Point Register Access Control Error May Disclose Information to Local Users
11.  BugTraq: Re: Can we prevent IE exploits a priori?
12.  BugTraq: [ GLSA 200407-08 ] Ethereal: Multiple security problems

2:25:57 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  What tech does Induce Act endanger?. Ernest Miller says: X-NAS-Bayes: #0: 7.69468E-225; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2810 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The INDUCE Act will make "whoever intentionally induces" copyright infringement liable for that infringement. Unfortunately, the definition of "intentionally induces" is extremely broad and the proposed law would give copyright holders (such as the RIAA and MPAA) tremendous flexibility in suing developers of new technology and effectively quashing progress that the copyright holders don't like. To foster reasoned debate on this topic, I'm inaugurating a new daily feature at The Importance Of ..., called "Hatch's Hit List." Each entry will give an actual example of a new and innovative device or technology that would be threatened by the INDUCE Act.
Link
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Briefly: China's phone exports skyrocket. roundup Plus: Novell joins government purchasing plan...D-Link antennas expand Wi-Fi range...PalmOne opens Mac center...Samsung audio players to support Audible.
3.  Unisys to miss targets, but SAP is upbeat. The IT services company seems to be following the trend toward bleak second-quarter results, but SAP paints a rosy picture.
4.  Verizon, MetroPCS snare more air. Bankrupt NextWave puts wireless spectrum licenses up for auction. Verizon snaps up New York airwaves; MetroPCS hones in on Florida.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
5.  SAP Defies Software Earnings Slump (Reuters). Reuters - Europe's largest software maker, SAP AG (SAPG.DE), on Friday said it expected second quarter revenue to rise 9 percent, defying a rash of warnings of lower results from rivals and sending SAP shares as much as 5 percent higher.
6.  FCC OKs Plan to Swap Nextel's Bandwith (AP). AP - A plan aimed at ending cell phone interference that has affected hundreds of public safety systems around the country won approval Thursday from federal regulators.
7.  Americans Object to War Images Online (AP). AP - Half of Americans object to the online availability of graphic war images, though millions have actively sought them out, a new study finds.
8.  Lovgate Worm Comes Back to Life (PC World). PC World - New variants disable antivirus software, open a back door on infected PCs.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  Fifth HOPE Conference Underway
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
10.  France lends support to new open-source license. PARIS - Researchers at three French government-funded research organizations this week revealed something they hope will increase the spread of free, open source software in the country: a new license they say is compatible with the Free Software Foundation Inc.'s GNU General Public License (GPL).
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
11.  Security hole found in Mozilla browser
12.  Gentoo: Ethereal Multiple vulnerabilities
13.  Fedora: 2: im-sdk Insecure temporary file vulnerability
----------------------------------------------------------------------
SecurityFocus News
----------------------------------------------------------------------
14.  Elsewhere: Security flaw found in Mozilla browser. Developers on the open-source browser have released a fix for a vulnerability that affected PCs running Windows XP Developers at the open-source Mozilla Foundation have...
15.  Elsewhere: Scob code still widespread, says security expert. More than 100 web servers are still distributing the "Scob" malicious code, first identified two weeks ago as code used in a widespread attack to plant Trojan horse progr...
16.  News: Mozilla bug rears its head. A popular browser for Windows is subject to a security hole that creates a means for hackers to run malicious code on vulnerable machines. But this time, the vulnerability involves Mozilla and Firefox browsers - not Internet Explorer.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
17.  BugTraq: Re: Can we prevent IE exploits a priori?. Sender: Thor Larholm [thor at pivx dot com]
18.  BugTraq: [ GLSA 200407-08 ] Ethereal: Multiple security problems. Sender: Kurt Lieber [klieber at gentoo dot org]
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
19.  Thus shares hit by profit warning. Company blames broadband revolution
20.  Archive.org suffers Fahrenheit 911 memory loss. Opinion Online fire extinguished
21.  Iraq domain owner convicted. Bayan Elashi and his four brothers face 10 years in US jail
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
22.  TREND MICRO's free online virus scanner

1:25:38 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Toshiba may be leaving the PDA market; Is the PDA dead?. In early June we learned that Sony was putting the hold on PDA development in all markets outside of Asia. Now it looks like Toshiba is going to back out, too. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
2.  DIY astronomical images. heic0412cThe European Space Agency, the European Southern Observatory, and NASA just released a free Photoshop plug-in that gives anyone access to archival astronomical images and spectra from the Hubble Space Telescope, the Spitzer Space Telescope, and others: X-NAS-Bayes: #0: 0; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2809 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

"If there is anything that unites astronomy, it is the worldwide use of a single file format - nearly all the images of stars and galaxies produced by telescopes on the ground and in space are stored as so-called FITS files. Unfortunately this file format has been accessible to very few people other than professional scientists using highly specialised image-processing tools."

The ESA/ESO/NASA Photoshop FITS Liberator provides direct access to the full 16-bit color images. For example, this image of the planetary nebula NGC 5979 was made with the FITS Liberator by compositing four individual exposures taken through various filters. Link

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
3.  Chip industry spending on upswing, report says. The chip industry has been pouring money into capital spending this year but the trend won't last forever, according to Gartner.
4.  Linux services go mainstream. By 2008, businesses in Western Europe will more than double their spending on support for the open-source OS.
5.  China's phone exports skyrocket. China exported 51 million mobile phones worth $4.9 billion in the first five months of 2004, according to the Chinese government.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
6.  Source: Japan Likely Won't Fine Microsoft (AP). AP - In a largely symbolic move, Japan's trade watchdog will issue a warning against Microsoft Corp. next week, but likely won't fine the software giant, a commission official said Friday.
7.  iPod Playlist party comes to England (MacCentral). MacCentral - iPod-DJ.com is taking iPod playlists to a whole new level. On August 7, iPod-DJ.com will host a party in London, England where the guests will be the DJ for the night.
8.  Video, Software Downloads Overtake Music (AP). AP - Music is no longer the download of choice for Internet file swappers, according to a new study on online file sharing.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
9.  Microsoft Responds to IE Criticism
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
10.  Groove touts performance in updated Virtual Office. Collaboration software vendor Groove Networks Inc. next week plans to announce an updated version of its flagship software, which it said will offer better security, improved performance and new ease-of-use features.Previously known as Groove Workspace 2.5, Groove Virtual Office 3.0 has faster launch times and allows multiple Groove project workspaces to be opened without a noticeable performance hit, according to Andrew Mahon, director of strategic marketing at the Beverly, Mass.-based company. The product also includes a new on-screen launch bar, where contacts with other collaborators can be managed from a single place, as well as synchronization capabilities that allow users to automatically share folders on their Windows machines with other users.In addition to Groove's existing forms-editor tools, the 3.0 release includes 10 forms templates designed to allow users to more quickly use standard forms for their collaboration projects.On the server side, the newest version of the software includes third-party private-key infrastructure security, as well as built-in auditing capabilities and backup functions.Richard Prather, CIO and vice president of technology for CARE, said the worldwide humanitarian relief agency began using Groove last year for about 70 relief workers in Central America and about 40 IT staffers. He's pleased with how it allows remote workers to do their jobs even if an online connection isn't immediately available. Users can take advantage of Groove's off-line work capabilities and then sync up automatically with other group members when they're able to go online, he said.That is a big benefit in remote locations where online connections and even electricity can be frequently cut off, Prather said. The application is also easy to use and intuitive -- even for users without a lot of computer experience, he said.The Groove software is part of a five-nation pilot project called "Information Anywhere" that Atlanta-based CARE is conducting over six months "to determine how to operate in a very decentralized environment with no or poor connectivity," he said.Another user, Glen Johnson, director of the U.S. State Department Iraq Transition Management staff in Washington, said Groove was chosen for a pilot project by his agency primarily because it offers better security. "No (competing products) other than Groove secured the data in transit and on the desktop," Johnson said.Ethan Schoonover, e-business director in Asia for London-based advertising agency Lowe & Partners Worldwide, said some 300 workers at his company have been using Groove for preparing ad pitches, managing accounts and performing strategic research.Version 2.5 of the software works as advertised, and many of the new features in Version 3 are a "great example of a company really listening to user feedback and implementing requested features," Schoonover said.Ease of use is a big plus, he said. "Even our technophobe users could get the hang of it and get comfortable with it," Schoonover said. "Groove 3.0 has cleaned up and streamlined the (user interface), and overall performance is radically improved. Launch of Groove, launch of workspaces, messaging is all significantly faster. This alone addresses a key issue with 2.5, that it was sometimes sluggish. The 3.0 memory footprint seems to be smaller in our initial review, which reduces its impact on older systems."With user data stored on the user's machine and automatically synced when online, "this is the killer app for us," Schoonover said.David Marshak, an analyst at The Patricia Seybold Group Inc. in Boston, said Groove's key strength is that it combines real-time online collaboration capabilities with off-line workspaces. "The integration ... is much better than anyone else has even attempted," he said.Peter O'Kelly, an analyst at Burton Group in Boston, said Groove's natural competitors include Lotus Notes/Domino, which was invented by Groove's founder, Ray Ozzie, and other products such as Microsoft Corp.'s SharePoint and Macromedia Inc.'s Breeze. But none match Groove's exact feature set of security, collaboration and online/off-line work capabilities."It really is at a sweet spot with a combination of features that no one else has completely," O'Kelly said.Pricing starts at $179 per user for Virtual Office Professional Edition, with hosted relay and management services starting at $40 per user a year. Customers can also choose to host their own Groove servers, starting at $9,995 per server per year.
11.  SAP expects Q2 revenue to rise. German business software vendor SAP AG said Friday it expects software revenue to increase 15 percent in the second quarter, compared to the same period a year earlier.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
12.  Linux Advisory Watch - July 9th 2004
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
13.  BugTraq: Mozilla Security Advisory 2004-07-08. Sender: [dveditz at cruzio dot com]
14.  BugTraq: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!]. Sender: Bipin Gautam [visitbipin at hotmail dot com]
15.  BugTraq: Re: Can we prevent IE exploits a priori?. Sender: Jason Coombs [jasonc at science dot org]
16.  BugTraq: Re: Microsoft and Security. Sender: [Valdis dot Kletnieks at vt dot edu]
17.  Vulns: Zoom Model 5560 X3 ETHERNET ADSL Modem Default Backdoor Account Vulnerability. Zoom Model 5560 X3 ETHERNET ADSL Modem is an ADSL modem, router, and gateway appliance with an Ethernet interface.

The Zoom Model 5560 X3 ETHERNET ADSL Modem is reported...

18.  Vulns: rident.pl Symbolic Link Vulnerability. rident.pl is an application that allows hosts to connect to servers requiring ident without disclosing any local information.

A symbolic link vulnerability has been iden...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
19.  Toshiba bows out of PocketPC arena?. Reports stack up
20.  Strategy Boutiques invade Japan. LogoWatch Seeing red in Yokohama
21.  Building bugs in double-quick time. Never mind the quality, feel the speed
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
22.  Bioscrypt Technology Tapped for Biometric Trials at US Marine Corps Base Quantico
23.  New Online Security Tool Ships from Aladdin
24.  Software Makers: Soon They'll Be Fewer
25.  Suspect works at Microsoft

12:25:17 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Bait-cars play theme from "Cops" during bust. Cops in Minnesota and Ohio have developed a fleet of "bait cars" -- cars left on the street with the keys in the ignition as a honeypot for snagging car thieves. The cars are equipped with hidden cameras and satellite trackers for evidence gathering and apprehension, and with specially fitted car-radios that play the theme from "Cops" during the bust itself.

I remember the Toronto cops once tried a bait-bike and were quite successful, snagging dozens of bike-thieves in a short time, but had to give it up because the bait-bike got stolen while the cops were busy arresting someone for trying to steal it. X-NAS-Bayes: #0: 7.3317E-193; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2808 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Link

(via Engadget)

2.  Blindfolded man performing Mario Bros music on a piano. Here's a video of an Asian man wearing a blindfold, performing a very sprightly rendition of the theme and atmospheric music from Super Mario Brothers on a piano. His work on the atmospheric music is particularily inspired.

7.6MB WMV Link

(Thanks, Robert!)

3.  Bloggers' summer reading list. Phil Gyford asked a bunch of bloggers (including me) what they're reading this summer and compiled the results:

Danny O’Brien

I’m currently reading Little Bear’s New Friend by the Reader’s Digest Young Editions collection, and Moo, Baa (La La La) by Sandra Boynton. When I’m after something less demanding (or less demanding than Ada demanding that I read the above), I’ve been skimming:

David McCullough’s John Adams. I’ve started this by looking up Ben Franklin in the index, and working back. All the people I admire in the American revolution seemed to have been somewhat creeped out by John “Sedition Act” Adams, so I’m going to enjoy seeing what the other side has to say.

Link

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
4.  Aiming for iPod (Ziff Davis). Ziff Davis - With its sleek white-and-silver body and innovative scroll strip, the Creative Zen Touch audio player has the popular Apple iPod clearly in its sights.
5.  Known Trojan Still Plagues Web Servers (PC World). PC World - Security firm finds servers still doling out malicious 'Scob' code identified in June.
6.  TomTom on the Go (Ziff Davis). Ziff Davis - The TomTom Go takes TomTom's personal navigation software and integrates it into a convenient, car navigation solution.
7.  Wireless War Winner and Losers (washingtonpost.com). washingtonpost.com - The wireless wars are expected to intensify with the Federal Communications Commission's decision yesterday to hand Nextel Communications a valuable swath of spectrum and overhaul a number of regulations governing competition in the wireless industry.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
8.  Wi-Fi by Rail, Bus or Boat
----------------------------------------------------------------------
InfoWorld: Top News
----------------------------------------------------------------------
9.  Mozilla moves to fix security vulnerability. The Mozilla Foundation has urged users of its open-source Mozilla Application Suite, Firefox browser and Thunderbird e-mail client to download a small patch to work around a security vulnerability discovered Thursday.
----------------------------------------------------------------------
LinuxSecurity.com
----------------------------------------------------------------------
10.  Automated Caller ID / ANI Spoofing
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
11.  UK firm offers to double Wi-Fi range for a tenner. Flat-pack 'Flatenna' to the fore
12.  Japanese to tag schoolkids. My first RFID
13.  Pink pound flexes muscle online. It was five years ago today... 9 July 1999
14.  Free Software Foundation Europe wants your money. Putting the price tag on free software
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
15.  Security tool could prevent iPod risk
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
16.  Microsoft Short on Specifics to IE Questions
17.  Security hole found in Mozilla browser
18.  Security tool could prevent iPod risk
19.  Electronic Signatures: The Proof Is in the Process

11:24:58 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Commentary: Hop on the bus?. An enterprise service bus can help companies meet basic integration requirements, but there are limits to what a commercial ESB product can do without custom-developed extensions.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Mozilla Fixes Security Flaw (PC World). PC World - Updates to Windows versions of Firefox, Thunderbird repair hole uncovered this week.
3.  Nextel Must Pay at Least $3.2 Billion for Airwaves (washingtonpost.com). washingtonpost.com - The Federal Communications Commission ordered Nextel Communications Inc. to pay at least $3.2 billion as part of a complex compromise that gives the wireless phone company a slice of valuable airwaves while freeing up crowded frequencies for public safety agencies.
4.  Edward C. Baig: Personal Tech - Tired of Internet Explorer's risks? Try one of these browsers (USATODAY.com). USATODAY.com - The Web browser nearly everyone uses has gaping security holes. That's why security experts are recommending people ditch Microsoft's Internet Explorer and seek an alternate browser.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  USA PATRIOT Act Survives Amendment Attempt
6.  More on Inflatable Space Hotels
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
7.  Vulns: Apache Mod_SSL SSL_Util_UUEncode_Binary Stack Buffer Overflow Vulnerability. mod_ssl provides an interface for accessing the OpenSSL libraries from within Apache. X-NAS-Bayes: #0: 1.08193E-080; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2807 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A stack-based buffer overflow has been reported in the Apache mod_ssl module.

Th...

----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
8.  Oi, Saddo, show us your home page!. You want self-esteem? We'll give you self-esteem
9.  Anatomy of a 419 scam. Exclusive One victim's first-hand account of advance fee fraud
10.  Toshiba bows out of PocketPC arena?. Reports suggest that's what it's telling would-be customers

10:24:38 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Nextel gets controversial OK to swap spectrum (USATODAY.com). USATODAY.com - A long-awaited swap of wireless airwaves aimed at eliminating cell phone interference with public-safety radios in hundreds of cities was unanimously approved by the Federal Communications Commission Thursday.
2.  Yahoo doubles revenue, profit; analysts disappointed (USATODAY.com). USATODAY.com - Yahoo (YHOO) shares fell about 7.6% in trading Thursday after Wall Street investors were unimpressed with the Internet giant's second-quarter earnings report of a doubling of revenue and profit.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Solaris' Dtrace in Detail
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
4.  Mozilla bug rears its head. Safe haven invaded, patch issued, calm restored
5.  Vodafone defends buggy content filter. Brand protection or child protection?
6.  Oi, Saddo!, show us your home page. You want self-esteem? We'll give you self esteem
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Norton Virus Definitions July 8, 2004
8.  Ad-aware referencefile 01R331 08.07.2004
9.  NIST helps on security budgets
10.  Newest Pattern: 1.931.00
----------------------------------------------------------------------
About Internet/Network Security
----------------------------------------------------------------------
11.  Nessus and Corsaire Form Vulnerability Detection Alliance. Nessus is quite simply one of the best, if not the best, vulnerability scanners available today. It is one of a few security tools that are freely available as open source products and defy the logic that you get what...

9:24:17 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  FCC OKs Plan to Swap Nextel's Bandwith (AP). AP - A plan aimed at ending cell phone interference that has affected hundreds of public safety systems around the country won approval Thursday from federal regulators.
2.  'Kerry Edwards' Site Belongs to Bondsman (AP). AP - The Web site Kerry Edwards started two years ago to show the world photos of his toddler son has suddenly become hot property. The phones at the bail bonds business Edwards owns started ringing with calls from people and groups wanting his kerryedwards.com Web address even before Democratic presidential candidate John Kerry announced John Edwards as his running mate Tuesday.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  Daleks, details and a downed Tornado. Letters: Reg readers demonstrate aptitude for stamp collecting
4.  Vatican Library adopts RFID. Mass movement
5.  Mozilla bug rears its head. Safe haven invaded, patch issues, calm restored
6.  EC to probe 3G content shutout. Old media won't play ball
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
7.  Shorewall Insecure Temporary File Creation Vulnerability
8.  Gentoo update for shorewall
9.  SSLtelnet Error Logging Format String Vulnerability
10.  DiamondCS Process Guard Protection Features Disabling Vulnerability
11.  D-Link Router DHCP Request Flood DoS
12.  D-Link Router DHCP LEASETIME DoS
13.  TikiWiki MSIE Login Sequence Authentication Bypass
14.  TikiWiki File Galleries Restricted Filename Disclosure
15.  VServer ip_route_connect Leak
16.  Multiple Vendor Web Browser Frame Injection Spoofing

8:23:58 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Bait-cars play theme from "Cops" during bust. Cops in Minneapolis have developed a fleet of "bait cars" -- cars left on the street with the keys in the ignition as a honeypot for snagging car thieves. The cars are equipped with hidden cameras and satellite trackers for evidence gathering and apprehension, and with specially fitted car-radios that play the theme from "Cops" during the bust itself.

I remember the Toronto cops once tried a bait-bike and were quite successful, snagging dozens of bike-thieves in a short time, but had to give it up because the bait-bike got stolen while the cops were busy arresting someone for trying to steal it. X-NAS-Bayes: #0: 3.10761E-124; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2804 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Link

(via Engadget)

2.  More Thurl Ravenscroft novelty tunes. Here's another great novelty track from Thurl Ravenscroft, the lead baritone in the Haunted Mansion's themesong, and the voice of Tony the Tiger: it's Thurl and Roberta Lee performing a medley of "Wing Ding Ding" and "You Wanna Talk About Texas."

Link (scroll to page-bottom)

(Thanks, LondonFilter!)

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Watchdog backs broadband changes. Opening up BT's exchanges to rivals could make cheap net calls and affordable super-fast broadband a reality.
4.  BBC scores with Euro 2004 site. BBC Sport online attracted the most footie fans during the Euro 2004 tournament, according to net analysts.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
5.  IBM plans bus technology ride. Enterprise service bus technology is part of streamlining plan to move customers to cheaper, easier integration options.
6.  Microsoft's 1994 consent decree: Boon or bust?. Ten years after Bill Gates and Janet Reno shook hands, the jury is out on the real impact of their agreement.
7.  Homey, don't play that software upgrade. CNET News.com's Charles Cooper asks whether enterprise software makers are prepared to deal with a sucker-free software movement.
8.  The unheralded monopoly. CNET News.com's Michael Kanellos takes the measure of ARM, a chip designer that enjoys as formidable a monopoly as behemoths like Microsoft and Intel.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
9.  First Avenue Buys Teligent For $105 Million in Stock (washingtonpost.com). washingtonpost.com - First Avenue Networks, a wireless spectrum leasing company, agreed to pay about $105 million in stock for the assets of Teligent Inc., a Herndon company that was considered one of the area's rising stars during the dot-com boom.
10.  Ridge Warns of Election Terror Plot (AP). AP - A steady stream of intelligence, including nuggets from militant-linked Web sites, indicates al-Qaida wants to attack the United States to disrupt the upcoming elections, federal officials said Thursday.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
11.  CA misses sales target. Holds steady on profits
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
12.  Commentary: patched in 60 seconds
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
13.  Commentary: patched in 60 seconds

7:23:37 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Visiting every tube stop in Zone 1. Ewan, a Scotsman living in London, is moving back to Edinburgh, and before he does, he has resolved to visit every tube station in Zone 1, and he's inviting the general public along on his tube-crawl: X-NAS-Bayes: #0: 1.25987E-320; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2803 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Here's the deal, I'll be starting at 12.30 on a weekday in the last week of July (probably Friday the 30th July, but don't quote me just yet). If you'd like to join me as I rattle round Central London and visiting every station of note (and Hyde Park Corner) then make sure you're at Vauxhall Ticket Office for around 12.20 to find me.

Anyone wishing to set up a Rival team to try and beat me on the day is more than welcome, I'd only ask you to also start at Vauxhall with us. Once it's all over, we'll retire to a pub at around 4pm for a late lunch/early dinner, some farewell drinks, and I'll invite you all to the housewarming in Edinburgh.

Link

(Thanks, Ewan!)

2.  Help make a Wikipedia of Free Culture. Creative Commons is creating a "Wikipedia of Free Culture" with links and annotation for every bit of open-licensed material in the universe. You're invited to help.

Link

3.  National summit on community wireless networks. This August 20-22 will see the first large-scale conference for community wireless networking projects, held at the University of Illinois at Urbana-Champaign.

Making the Connection: The 2004 National Summit for Community Wireless Networks will be the largest community wireless networking event to date and will bring together technology and policy leaders, decision-makers, students, researchers, and other participants in wireless networking and community networking initiatives for the express purpose of discussing policy issues and practical solutions to problems facing community wireless networks.

Link

4.  Game Boy Advance music vending machine.

This beast is a music vending machine that sells tunes to play in your Game Boy Advance movie player. Gizmodo notes the deliciously superfluous giant mechanical dial on the front.

Link


----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
5.  LA puts controls on game cafes. Catch up with the latest news from the world of video gaming.
6.  Online film piracy 'set to rise'. One in four net users have illegally downloaded a film, says the US movie industry's trade body.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
7.  TeliaSonera buys Orange Denmark (TheDeal.com). TheDeal.com - The Swedish telecom pays $742 million to strengthen its No. 3 position in Denmark's mobile market.
8.  Vietnam Jails Dissident for On-Line 'Abuse' (Reuters). Reuters - Communist Vietnam, widening a crackdown on dissent, sentenced a literature professor on Friday to 19 months in prison for using the Internet to criticize its policies.
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
9.  Intel grows Socket T Celeron line-up. Cheaper CPUs to push Grantsdale further into more price-points
----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
10.  Feds OK Nextel Spectrum Swap. The Federal Communications Commission approves a plan to sell Nextel a band of spectrum in exchange for spectrum it uses now. The idea is to ensure public-service communication systems are interference-free.
11.  Patriot Act Wins House Vote. The Republican-led House stands by the Patriot Act, fending off an effort to roll back a section of the controversial law allowing authorities to investigate people's reading habits at bookstores and libraries.
12.  Stamping Out Good Science. Irrationality is clouding the minds of politicians, and thus endangering advances in science. By Lawrence Lessig from Wired magazine.
13.  Space Artistry in Bloom. Artist Martin Naroznik has a vision to boldly grow where no one has grown before, and NASA finds it fascinating. By Mark Baard.
14.  Transparent Desktop Opens Doors. Researchers have come up with a nifty virtual workspace/video conferencing system that functions with the Quartz graphics engine in Mac OS X. By Leander Kahney.
15.  Winwood: Roll With P2P, Baby. Grammy-winning rocker Steve Winwood took an unusual step to promote his latest album when he voluntarily released a song over peer-to-peer networks. So far, the experiment has enhanced record sales. By Katie Dean.
16.  NASA to Put 'Aura' Around Earth. The space agency's latest Earth-observing satellite, Aura, is slated to launch Sunday. Scientists say the mission will provide a trove of data about the atmosphere, from the ground up. By Amit Asaravala.
17.  Dirty Word Filters Prove Costly. Preventing disc jockeys and callers from uttering dirty words on the air doesn't come cheap for small stations. But companies that sell technology to delay broadcasts for a few seconds are doing very well indeed. By Randy Dotinga.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
18.  AU online movie piracy on the rise: Motion Picture Association of America
19.  Shorewall Insecure Temporary File Creation Vulnerability
20.  Gentoo update for shorewall
21.  SSLtelnet Error Logging Format String Vulnerability

6:23:17 AM    comment []

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  Code of conduct for LA game halls. Catch up with the latest news from the world of video gaming.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Wearable Customizable Displays
----------------------------------------------------------------------
The Register
----------------------------------------------------------------------
3.  Nextel vexes Verizon with $5bn spectrum swap. Safety first
4.  Patients, GPs to have a say on care record plans. Mama, we're all stakeholders now
5.  Intel preps autumn Pentium M price cuts. Laying the ground for 533MHz FSB versions
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  Mozilla Fails to Restrict Access to "shell:"
7.  VBS.Gaggle.E@mm

5:22:57 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 09 Jul 2004.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  CA's Preliminary Financials Lower Than Expected (TechWeb). TechWeb - Software vendor says revenue will show a year-over-year increase of around 8%.
3.  Using Open Source As A Weird Form Of Outsourcing (TechWeb). TechWeb - Software-maker Niku is opening most of the code in its project-scheduling app. The company believes it's a mature product and will concentrate on enhancing another app.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  5 GIs, one Iraqi killed
5.  "Tag-team" interrogations under fire
6.  Missing Marine safe at embassy

4:22:37 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Microsoft Working to Improve Office Search (Reuters). Reuters - Microsoft Corp. said on Thursday that it was working to include newer search technology in its Office family of applications, group vice president Jeff Raikes said on Thursday.

3:22:18 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Briefly: Novell joins government purchasing plan. roundup Plus: D-Link antennas expand Wi-Fi range...PalmOne opens Mac center...Samsung audio players to support Audible...Linksys expands reach of wireless networks.
2.  Novell joins government purchasing plan. The Linux operating system seller joins a U.S. government purchasing program called SmartBuy
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Amazon to Take Pre-Orders for Portable Media Center (Reuters). Reuters - Microsoft Corp. (MSFT.O) said on Thursday that online Web shopping site Amazon.com Inc. (AMZN.O) will begin taking orders for Portable Media Centers, a new line of portable devices for listening to music and viewing video content.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Halloween Solar Storm Nearing Heliopause
----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
5.  An answer to security questions
6.  Analyst: UN needs warriors in spam battle
7.  The convergence (or not) of security and operations event monitoring
8.  5 security myths
9.  Service Pack deux?
10.  NewsIsFree: Your own Advanced News Reader and Feed Publisher. Read news from thousands of news sources updated every 15 minutes on the most powerful news aggregator.
Create custom feeds with more items, descriptions, select your version of RSS...
Check out NewsIsFree's services!
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Getting Aggressive in Battling Spam
12.  Experts Question UN's Anti-Spam Plan
13.  Information Systems Misuse - Threats & Countermeasures
14.  Nortel Contivity HTTP Server cgiproc Arbitrary File Access
15.  The nuts and bolts of a security assessment
16.  Ten tips for implementing an acceptable Internet use policy
17.  Feds drag feet on cybersecurity, officials say
18.  Terrorists rely on tech tools, researcher finds
19.  GAO: Pentagon IT mismanagement wastes billions
20.  Lawsuit challenges Florida ballot-recount rules

2:21:58 AM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Another browser exploit: this time it's Mozilla. Recent browser security bulletins have focused on Internet Explorer. Now there is news of an exploit (with a patch available) for Mozilla browsers running on Windows XP. By Eric Bangeman.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Fujitsu Phone Calls on IP, Cellular Networks (PC World). PC World - 'Phone-shaped PDA' has Compact Flash slot for various cellular network cards.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  New Google Groups in Beta

12:29:17 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 7/26/2004; 12:30:18 AM.
This theme is based on the SoundWaves (blue) Manila theme.
July 2004
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Jun   Aug