BLOG

BLOG

Visible Procrastinations
DCR Last Updated

30 Aug 2006




 

2006-08-30
Wine0
(TOPIC::humour)

 

Posted by DCR 2006-08-30

 

2006-08-28
This weeks links
(TOPIC::links)

Make a Survival Kit out of an Altoids Tin
Fitting inside an altoids tin, this kit is easy to keep on hand at all times
This is ideal for anyone who wants to have the essential survival gear along each time they head into the field. Everything fits in the Altoids tin (above). It fulfills all the component groups (see “Make Your Own,” last slide) except for shelter and protection, but add a survival blanket to your pocket and you’ll be covered.. ...

Make a Survival Kit out of an Altoids Tin (and Two More Life-Saving DIY Projects) [Field & Stream]

What's On Your Thumbdrive?
"Nowadays, we need to support not only people at the office, but friends, family, friends of the family, family of the friends... you name it! They all run Windows to a degree and there are many tools to help you when assisting. Personally, I have a thumb-drive with removable memory cards. One of them has a small bootable Linux, the other one is filled with ready to use Windows utilities (CPU-Z, Ultra-Edit32), DOS utilities I've been collecting over the years, and Unix-style utilities (ps.exe, kill.exe, and others) ported to Windows, without the need for a layer like Cygwin. I also have a copy of the install files for AVG, Spybot, Sygate and the likes. But, even though I think I have many great tools, I'm sure I do not know about a lot of great others to help diagnose and solve problem. So I ask you, what's on your thumb-drive?"
What's On Your Thumbdrive? [Slashdot]

Is your luch safe?
... As for the least likely lunch bandits, Buffini said, it's managers because of the scrutiny they're under from all sides, as well as "hero" departments like information technology, which come to your aid when you're down. ...
Stolen lunches? Substitute cat food for tuna on wheat [chron.com]

 

Posted by DCR 2006-08-28
Update by DCR 2006-08-30

 

2006-08-25
Patching updates
(TOPIC::security.patch)

Intel wireless

Intel initially issued a big file (100MB) that you had to download, but at least it upgraded everything on your machine, if it needed upgrades. After rebooting in the next few days I noticed that my machine is a bit slower then it was. A look at Task manager output, or excellent Process Explorer from Sysinternals showed that a process called S24EvMON.exe is using quite a bit of CPU, ... [1]

I cannot replicate this issue on my DELL D810 using the updated Intel drivers set, my call at this stage is to patch the machines and deal with any machines that show these symptoms as they arise.

MS06-042 reissue
My previous advice was: Where required keep MS06-042 applied, it fixes more bugs than it creates.

This issue may lead to an additional buffer overrun condition only affecting Internet Explorer 6 Service Pack 1 customers that have applied the original version of that update released August 8th, 2006. The security issue is documented in the Vulnerability Details section as Long URL Buffer Overflow – CVE-2006-3869. Internet Explorer 6 Service Pack 1 Customers should apply the new update immediately. [2]

When it appears - rePATCH! The last patch was at least a step 'better' than an unpatched machine, this should return the machine to a better state. (What, you're still using IE for web browsing! Get thee to a nunnery!!)

Time to re-apply the patch on Internet Explorer 6 Service Pack 1 for Windows XP Service Pack 1 (all versions) and Windows 2000 (all versions) [2]

As we are *all* on XP-SP2 and IE-SP2 we shouldn't see this patch ... we are all patched to this level aren't we guys?

PowerPoint Zero-Day?

According to the new information this is not 0-day vulnerability, it is related to patched MS06-012. [3]

Ahhh, grasshopper the ZEN of patch often and patch early.

 

Posted by DCR 2006-08-25

 

2006-08-25
Snakes LAPTOPS on a Plane
(TOPIC::security)

We have just finished with the DELL D810 battery issue, and not suprisingly considering they also use SONY battery units, Apple has announced their own BBQ laptop specials;

Apple Announces Recall of Batteries Used in Previous iBook and PowerBook Computers Due To Fire Hazard [1]
 
WASHINGTON, D.C. - The U.S. Consumer Product Safety Commission announces the following recall in voluntary cooperation with the firm below. Consumers should stop using recalled products immediately unless otherwise instructed.
 
Name of Product: Rechargeable, lithium-ion batteries with cells manufactured by Sony for certain previous iBook G4 and PowerBook G4 notebook computers only.
 
Units: About 1.1 million battery packs (an additional 700,000 battery packs were sold outside the U.S.)
 
Battery Cell Manufacturer: Sony Energy Devices Corp., of Japan
 
Computer Manufacturer: Apple Computer Inc., of Cupertino, Calif.
 
Hazard: These lithium-ion batteries can overheat, posing a fire hazard to consumers.
 
Incidents/Injuries: Apple has received nine reports of batteries overheating, including two reports of minor burns from handling overheated computers and other reports of minor property damage. No serious injuries were reported.
 
Description: The recalled lithium-ion batteries were used with the following computers: 12-inch iBook G4, 12-inch PowerBook G4 and 15-inch PowerBook G4. Consumers should remove the battery from the computer to view the model and serial numbers labeled on the bottom of the unit.
 
...

 

Apple has determined that certain lithium-ion batteries containing cells manufactured by Sony Corporation of Japan pose a safety risk that may result in overheating under rare circumstances. The affected batteries were sold worldwide from October 2003 through August 2006 for use with the following notebook computers: 12-inch iBook G4, 12-inch PowerBook G4 and 15-inch PowerBook G4.
 
... [2]

Safety first for carry-on Dells [3]
 
Qantas is issuing an advisory to all passengers on its flights on the safe use of Dell notebooks following the recall of 4.1 million batteries announced by the PC manufacturer last week.
 
The airline said that although passengers would be allowed to carry their Dells either as checked or cabin baggage, they could only use them on battery power or through the aircraft power supply available in some first and business class cabins once they have first removed the batteries from the unit.
 
Qantas said cabin crew would be advising passengers of the measures which apply to any computer affected by the recall, that has not yet had the battery replaced.
 
...

Will QANTAS apply their DELL policy [4] to the Apples? We'll see ...

 

Posted by DCR 2006-08-25

 

2006-08-23
Podcasting: Recording a podcast
(TOPIC::podcast)

After looking into the technical side of publishing and serving a Podcast (newsfeed) it is time to look at the actual creation of the content for a podcast. 5, 4, 3, 2 ,1 ... recording!

There is nothing new in creating Podcasts, people have been recording audio for many years. In general the rule is the better the recording equipment and planning - the better the result (think 'garage band session' vs 'recording studio master')

An alternate way of thinking about Podcasts is to think that you are producing a pre-recorded radio show.

Recording Studio

You need to optimise your recording environment to produce the best results for your budget. In most environments cash will be the limiting factor; if this is the case you do not want to have a *mega expensive* microphone plugged into a cheap sound card as you waste the functionality of the microphone. All of the elements of the kit should be matched to ensure that you have optimise your expenditure.

Software
I strongly recommend Audacity with the LAME MP3 encoder plugin dll

Audacity is a free audio editor which lets you mix tracks and perform other sound editing functions, such as recoding, playing, importing and exporting sounds WAV, AIFF and MP3 files. When mixing tracks, there's no drag and drop like some of the more sophisticated brand programs, but if you're prepared to use cut, copy and paste you'll be able to mix tracks together, or apply effects to your recordings. It also has a built-in amplitude envelope editor, a customisable spectrogram mode and a frequency analysis window for audio analysis applications. Built-in effects include Bass Boost, Wahwah, and Noise Removal and it also supports VST plug-in effects.

 

LAME is an LGPL MP3 encoder. The Open source development model allowed to improve its quality and speed since 1999. It is now an highly evolved MP3 encoder, with quality and speed able to rival state of the art commercial encoders.

Noise
Do you need proper acoustical isolation, absorption and diffusion? Is background noise leaking into the environment? Can you use soft furnishings to provide an 'OK' environment? Is the space a write-off to the extent that you should look for a new venue?

Technique
Proper techniques do help. Remember cringing as *that* singer ate the microphone, or as *that* announcer kept the microphone down at their waist?
Get some lessons/advice; trial different techniques to see what works for you.

Hardware
This is where things become difficult ... what conditions are imposed by the physical space where you make your recordings. (Also remember that we are not creating an audio CD, the recording will be compressed to an MP3 format)

Initial requirements;

  • Microphone
  • Headphones
  • Soundcard

The starting point is a good set of headphones, and a USB microphone. Why USB? USB microphones tend to avoid many on the noise issues associated with using the 3.5mm jack microphones in a PC environment. Less line-noise = better recording. The USB microphone also allows you to use a standard soundcard as you will only be using it for listening to the playback.

Additions;

  • Microphone stand or boom
  • preamp/Mixing desk for multiple inputs
  • Input filters: Compressor/clipper/noise-gate

Editing
As with the written word the quality of the editing process reflects strongly on the finished audio product. There is a reason that the post production can take longer than the actual recording session :)

 

Posted by DCR 2006-08-23

 

2006-08-22
Podcasting: expanding the information in the feed
(TOPIC::podcast, xml, itunes)

Apple extends the RSS version 2.0 syntax with some custom <itunes:item>content</itunes:item> tags. [1]

For example to indicate Adult content;

<itunes:explicit>yes</itunes:explicit>

Is displayed in iTunes as; (eg. SecondCast feed [2])

The Apple extensions are as follows;

<itunes:explicit> - Channel & Item
<itunes:subtitle> - Channel & Item
<itunes:summary> - Channel & Item
<itunes:author> - Channel & Item
<itunes:keywords> - Item
<itunes:duration> - Item
<itunes:owner> - Channel
<itunes:name> - Channel (for owner, required)
<itunes:email> - Channel (for owner, optional)
<itunes:image> - Channel & Item (artwork 300x300 pixel, jpg, png uncompressed)
<itunes:block> - Channel & Item (block display in directory)

NOTE: All fields will be truncated to 255 unicode characters, except for <itunes:summary>

Staying with the secondCast example from above, let's look at the first item in the feed file "Secondcast 1"

<item>
	<title>Secondcast: 1 "Power Lines"</title>

	<link>
	http://www.secondcast.com/podcasts/secondcast-ep01-64.mp3
	</link>

	<description>
	Lordfly Digeridoo, Aimee Weber, Cristiano Midnight, Walker Spaight, and 
	Johnny Ming discuss life as a public figure in SL, intellectual property, 
	and forum drama.
	</description>

	<itunes:subtitle>Episode 1</itunes:subtitle>

	<itunes:explicit>yes</itunes:explicit>

	<itunes:summary>
	Lordfly Digeridoo, Aimee Weber, Cristiano Midnight, Walker Spaight, and 
	Johnny Ming discuss life as a public figure in SL, intellectual property, 
	and forum drama.
	</itunes:summary>

	<author>johnny@secondcast.com</author>

	<pubDate>Sun, 19 Feb 2006 16:17:55 -0500</pubDate>

	<category>Talk Radio</category>

	<enclosure url="http://www.secondcast.com/podcasts/secondcast-ep01-64.mp3" 
	length="01:09:26" type="audio/mpeg"/>

	<itunes:keywords>
	secondlife, secondcast, linden lab, lordfly, aime weber, walker spaight, 
	cristiano midnight, anshe chung, eletric sheep
	</itunes:keywords>
</item>

This produces the following information in iTunes;

 

Posted by DCR 2006-08-22

 

2006-08-22
Rollover
(TOPIC::soe)

Back in May this year I had a quick look at machine rollovers and disposal schedules [1]. I am now looking at the same data from a slightly different perspective.

In terms of Lab Rollover dates, our machines are rolled over after 3 years, for their W+1 (warranty + 1) year they are re-deployed outside of the lab environment.

For 2007 we will be re-deploying from DM211 (Evo530), DM809 (iMac 15" Lampshade), DM208-MM (3 x Mac G4 towers) into the W+1 category. The MM Lab machines will be sold. We will

Replacements for 2007:
Windows - DM211 (11 units) - HP dc7600 ?
Apple - DM809 (30 units), DM208 (4 units) - iMac Intel 17" ?

Audio-Visual refits for 2007:
DM809 - requires controllers and 2 x projectors (IWB)

 

Posted by DCR 2006-08-22

 

2006-08-15
Amorphophallus titanum
(TOPIC::botany)

The Brooklyn Botanic Garden's gigantic "corpse flower" is flowering;

BBG's Spectacular Titan Arum Is Blooming [1]
The titan arum (Amorphophallus titanum) is one of the world's most remarkable plants. Native to tropical forests in Sumatra, it produces a monstrous four- to nine-foot-tall flower head, which releases a monstrous stench of putrefaction at peak bloom (another name for the plant is the corpse flower!). The species rarely flowers in cultivation—the last time one bloomed in New York was 1939. However, Brooklyn Botanic Garden's ten-year-old specimen recently began to flower. It's in peak bloom right now!!

Webcam: Visit this page to catch the excitement via webcam. All the fun, none of the stink! The image is automatically updated every minute.

Photo Gallery: Visit this page to see the daily photo collections.

 

Posted by DCR 2006-08-15

 

2006-08-10
MS06-040
(TOPIC::security, patch)

MS06-040 is being actively exploited via BotNet. It is important to have ALL of our machines patched for MS06-040 as soon as possible. I have been scanning our subnets looking for machines that have not been updated.

I am using the Class C virsion of eEye's Retina MS06-040 NetApi32 Scanner

Retina MS06-040 NetApi32 Scanner
Retina MS06-040 NetApi32 Scanner

 

Posted by DCR 2006-08-11
Update by DCR 2006-08-15

 

2006-08-10
This weeks links
(TOPIC::links)

TIME.com: 50 Coolest Websites
How do we select our finalists? We evaluate hundreds of candidates—some suggested by readers, colleagues and friends, others discovered during countless hours of surfing. Many of this year's choices are shining examples of Web 2.0: next-generation sites offering dynamic new ways to inform and entertain, sites with cutting-edge tools to create, consume, share or discuss all manners of media, from blog posts to video clips. Think we missed one? Send us your thoughts and we'll post a selection of your comments online. There's always next year.
50 Coolest Websites [TIME.com]

Zombie Alphabet
Simply type in a phrase and press GO ...
http://e-zombie.com/

Tip of the Day: Logbooks
Over the years I found the use of a logbook, either on paper or electronically an essential instrument in managing (security of) devices. They can be useful for more than just managing security but they shine during emergencies. Since most emergencies with devices involve loss of either Confidentiality, Integrity, or Availability, the use of these logbooks is highly related to security. In some organizations the system or network administrators are the ones who are in the best position to keep them up to date and working properly, sometimes making it hard to coordinate with a different set of security people.
...

Tip of the Day: Logbooks [SANS]

Govts pose greatest threat to web privacy: Google
Web search leader Google, which stores vast amounts of data on the web-surfing habits of its users, sees government intrusions rather than accidental public disclosures of data as the greatest threat to online privacy, its chief executive has said.
...

Govts pose greatest threat to web privacy: Google [ABC News Online]

 

Posted by DCR 2006-08-10
Update by DCR 2006-08-16

 

2006-08-10
Patch Management
(TOPIC::security, patch, patch tuesday)

With the discussions we are having at the moment regarding patch release and deployment this is a very timely posting on the SAN site.

Surviving the monthly patch cycle [1]
... There are basically a few tactics to this in use. What strikes me in the responses we got: most of those writing in value not breaking applications significantly more than patching before you get hit with an exploit. Perhaps there is a lot work left to be done in order to convince (upper) management of the risks of patching late as patching even an hour after the worm or the targeted exploit hit you might cost the company significantly more than losing a few hours left and right over a not so critical system not being 100% healthy with a new patch. ...

Approaches;

  1. Just patch (If something breaks, fix it)
  2. Test on limited scale, roll out carefully (Get a feel for how it works in your environment then release.)
  3. Test applications thoroughly (Testing applications to the end is next to impossible, for critical servers only?)
  4. Fully features planned rollouts (a roll-out plan that covers a long time before they come full circle and start over.)
  5. Divide and conquer (divide the to be patched machines in different categories and tackle each differently.)

Mike wrote in on their strategy: "Simple strategy really:

  1. obtain patches, vet requirements and deploy to a QA environment, containing like for like hosts; exchange, SQL, IIS, workstation builds etc
  2. test, monitor, test, monitor...
  3. deploy to a pre-production group
  4. monitor, monitor, monitor
  5. deploy to primary production group
  6. monitor
  7. push out to remaining hosts/workstations.
The time scale for deployment is fairly aggressive with immediate introduction for 'critical' updates." [1]

If you have a security architecture in place, including network segregation;

  1. General clients: not mission critical, could be patched as soon as the patches are available. Any issues are resolved once they occur.
  2. Non-critical servers: patch machines if you see no problems reported, or you could just roll them out and be ready to roll back if you see problems.
  3. Mission critical servers should have many layers protecting them from evil, even from internal users. They should also not be exposed to most of the internal machines and they could remain unpatched or even isolated for a long while.

In our little corner of the internet:

  • EXPOSURE (1): Foremost we should acknowlege that our machines are not heavily protected. Our machines sit out there on the internet using routable IP addresses. We rely on a carefully balance interplay of patching, antivirus and local firewall.
  • EXPOSURE (2): Our mobile users are NOT highly IT literate, every PDA and laptop that wanders onto a wireless network, or conects to external machine increases our exposure (sometimes exponentially).
  • SOE for General clients: the advantage of sticking to SOE software is that patches are tested against these applications reasonably quickly; if there is an issue a single solution can be developed and deployed. If it's not SOE (or if it is a rare or low support SOE item) you may be on your own
  • SERVERS: Thankfully all of our WinTel servers are Non-critical servers and as such can be patched and then problems resolved
  • LCG: allows for some extent of test and release style patch evaluation. This allows for testing on a limited scale.
  • AUDIT: evaluation of who is patched and to what level ... need better reporting

 

Posted by DCR 2006-08-08
Technorati Tags:   Del.icio.us Tags:   Flickr Tags:   Wikipedia:  

 

2006-08-09
Patch Tuesday Wednesday
(TOPIC::MS Patch, Geek)

08 August 2006 - Patch Tuesday
Welcome to another 'Patch Tuesday', this months show bag contains the following fun products; Critical (9) Important (3)

Note that MS06-040 is flagged as Addresses a critical security problem this is due to this vulnerability being actively exploited.

Bulletin KB number Description Severity Impact
MS06-040 921883 Vulnerability in Server Service Could Allow Remote Code Execution Critical Remote Code Execution
MS06-041 920683 Vulnerability in DNS Resolution Could Allow Remote Code Execution Critical Remote Code Execution
MS06-042 918899 Cumulative Security Update for Internet Explorer Critical Remote Code Execution
MS06-043 920214 Vulnerability in Microsoft Windows Could Allow Remote Code Execution [Outlook express] Critical Remote Code Execution
MS06-044 917008 Vulnerability in Microsoft Management Console Could Allow Remote Code Execution [Win2K] Critical Remote Code Execution
MS06-045 921398 Vulnerability in Windows Explorer Could Allow Remote Code Execution Important Remote Code Execution
MS06-046 922616 Vulnerability in HTML Help Could Allow Remote Code Execution Critical Remote Code Execution
MS06-047 921645 Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution [Office & VBA] Critical Remote Code Execution
MS06-048 922968 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution [PowerPoint] Critical Remote Code Execution
MS06-049 920958 Vulnerability in Windows Kernel Could Result in Elevation of Privilege [Win2K] Important Elevation of Privilege
MS06-050 920670 Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution Important Remote Code Execution
MS06-051 917422 Vulnerability in Windows Kernel Could Result in Remote Code Execution Critical Remote Code Execution
  920103 Update for InfoPath 2003   non-security
  890830 Malicious Software Removal Tool (MSRT)   monthly update
  920907 Outlook 2003 Junk E-Mail Filter Update   monthly update

In our environment:
i.) MS06-44 and MS06-49 only apply to Win2K, and as such are less important in our environment as we should have no W2K in production; where we have W2K it should be deployed.
ii.) MS06-45 and MS06-50 are classed as IMPORTANT, these should be deployed anyway.
iii.) The remaining patches are CRITICAL and should be depolyed in our environment as they affect software included in our SOE

 

Posted by DCR 2006-08-09
Technorati Tags:   Del.icio.us Tags:   Flickr Tags:   Wikipedia:  

 

2006-08-08
Mayon volcano.
(TOPIC::google earth)

Volcanic eruption: Philippines residents face an imminent eruption of the rumbling Mayon volcano. The volcano is found in the province of Albay in the Bicol Region. Legazpi City is the top tourist destination in Bicol as it lies 15 kilometers southeast of Mayon Volcano, one of the Philippines' most famous volcano.


Mayon in GoogleEarth
Want to locate it quickly? Try MayonVolcano.kml

 

Posted by DCR 2006-08-08
Technorati Tags:   Del.icio.us Tags:   Flickr Tags:   Wikipedia:  

 

2006-08-08
Jedi time?
(TOPIC::census)

Today is the day that the Jedi come out and play. Supposedly 10,000 people are required to claim that their religion is "Jedi" on the Australian national census to be held tonight for "Jedi" to be recognised as an official religion in Australia; (How Ron L. Hubbard is that?). It didn't work in 2001, so I doubt it will work this time around ... maybe the force is stronger with this one?

ABS recognises that people have a wide range of belief systems [1]
If your belief system is "Jedi" then answer as such on the census form. But if you would normally answer Anglican or Jewish or Buddhist or something else to the question "what is your religion?" and for the census you answer "Jedi" then this may impact on social services provision if enough people do the same.


Luke, feel the power ...
Oh, and by the way the Census can be completed online :)

The five years have come and gone and once again the Australian Bureau of Statistics (ABS) is asking us all for information about where we live, who we live with, how much we earn and what, if any, our religious beliefs are.
 
In 2001, an email campaign successfully encouraged 70,509 Australians to report their religion as Jedi, the powerful religious force attributed to Luke Skywalker in the Star Wars movies. [3]


Feel the power of the Dark Side!
Bloody Sith!

The Dark Side all right -- couldn't access eCensus with Firefox v1.5.0.6 and had to use IE. Not happy Jan!

 

Posted by DCR 2006-08-08

 

2006-08-04
Vista - a view from the trenches
(TOPIC::vista)

...

Is Windows Vista ready? [1]
No. God, no. Today's Windows Vista builds are a study in frustration, and trust me, I use the darn thing day in and day out, and I've seen what happens when you subject yourself to it wholeheartedly. I think I've mentioned the phrase "I could hear the screams" on the SuperSite before. My wife said that to me one day, and she was referring to the sound of me barking some primeval curse at my desktop PC as it succumbed to Vista's stupid slowdowns, crashes, and hang ups for the umpteenth time. She, more than anyone, knows the frustration I've experienced because of Windows Vista. But even she doesn't know the details. They would bore her, frankly. She's normal like that.
-- Paul Thurrott

 

Posted by DCR 2006-08-04

 

2006-08-04
Patch Tuesday, a Heads Up.
(TOPIC::security)

A *heads up* for this months Patch Tuesday offerings from Microsoft;

Microsoft Security Bulletin Advance Notification [1]
Updated: August 3, 2006
...
On 8 August 2006 Microsoft is planning to release:
 
Security Updates
• Ten Microsoft Security Bulletins affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. Some of these updates will require a restart.
• Two Microsoft Security Bulletins affecting Microsoft Office. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.
 
Microsoft Windows Malicious Software Removal Tool
• Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.
Note that this tool will NOT be distributed using Software Update Services (SUS).
 
Non-security High Priority updates on MU, WU, WSUS and SUS
• Microsoft will not release any NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS).
• Microsoft will release two NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
...

 

Posted by DCR 2006-08-04

 

2006-08-03
SECURITY: A few issues today
(TOPIC::security,wlan,firefox)

i.) Intel WLAN Vulnerabilities

Intel Centrino Vulnerabilities [1]
...
Below are the summaries of the affected platforms
Intel® Centrino Wireless Driver Malformed Frame Remote Code Execution
      * Intel® PRO/Wireless 2200BG Network Connection
      * Intel® PRO/Wireless 2915ABG Network Connection

  Intel® PROSet/Wireless Software Local Information Disclosure
      * Intel® PRO/Wireless 2100 Network Connection
      * Intel® PRO/Wireless 2200BG Network Connection
      * Intel® PRO/Wireless 2915ABG Network Connection
      * Intel® PRO/Wireless 3945ABG Network Connection

  Intel® Centrino Wireless Driver Malformed Frame Privilege Escalation
      * Intel® PRO/Wireless 2100 Network Connection

  The details of which drivers are listed on the pages and we recommend you look there.
  ...

The 2915ABG chipset is used in the DELL latitude D810 laptop (our SOE model) and by default our Driver Version is 9.0.0.61. (** NOTE: the HP NC8000 uses an HP W500 and is not affected)
Currently an update is NOT available via Windows Update for the D810.

[Intel Centrino Vulnerabilities]

The DELL Support website has Intel (R) PRO/Wireless 2200BG Network Connection, (R) PRO/Wireless 2915ABG Network Connection, (R) PRO/Wireless Network Connection, v.10.1.1.3 (TIC 113763), A12 Release Date: 5/17/2006

The Intel site says that affected versions are All prior to 10.5 with drvr 9.0.4.16, so this DELL version will not help
:( This leaves us with no OEM driver and the need to go with the generic Intel release; "Intel(R)PROSetWirelessSoftwareVer10.5.0.0.exe"

After an install anb some testing the "Intel(R)PROSetWirelessSoftwareVer10.5.0.0.exe" appears to be a good installation and works well on the D810.

[Intel(R)PROSetWirelessSoftwareVer10.5.0.0]

Recommendation: In our environment, due to the nature of MUWIRLESS and the untrusted locations that our laptop fleet can venture into, it is my recommendation to install the generic Intel 10.5.0.0 software.

ii.) Mac wireless issues

Hijacking a Macbook in 60 Seconds or Less [5]
...
While those device driver flaws are particular to the Macbook -- and presently not publicly disclosed -- Maynor said the two have found at least two similar flaws in device drivers for wireless cards either designed for or embedded in machines running the Windows OS. Still, the presenters said they ultimately decided to run the demo against a Mac due to what Maynor called the "Mac user base aura of smugness on security."
...
But according to Maynor and Ellch, this attack can be carried out whether or not a vulnerable targeted laptop connects with a local wireless network. It is, they said, enough for a vulnerable machine to have its wireless card active for such an attack to be successful. That's a trivial demand, given that most wireless devices embedded in laptops these days are switched on by default and are configured to continuously seek out available wireless networks.
...

Recommendation: In our environment we should;
1.) Turn off the wireless card, and bluetooth,
2.) Watch for patches.

iii.) FireFox update

Firefox 1.5.0.6 is a stability update that is part of our ongoing program to provide a safe Internet experience for our customers. We recommend that all users upgrade to this latest version.

  • Fixed an issue with playing Windows Media content (mms://)

Release Date: August 2, 2006 [4]

[FireFox 1.5.0.6]

Recommendation: In our environment we should be running Firefox 1.5.x with autoupdate enabled. Our fleet should update themselves, laptops should be checked during standard patching.

 

Posted by DCR 2006-08-03

 

2006-08-02
A Quick Guide to desktop Videoconf : Part II
(TOPIC::videoconf,)

More toys ... SightSpeed 5.0 (Build 5016). There are clients for Windows and Mac. There are two plan options; a free 'Basic Service' plan, and a monthly premium 'Pro Service' plan that comes in at US$4.95/month or US$49.95/year. For my testing I have gone with the free 'Basic Service' account

New SightSpeed Features Challenge Skype and Slingbox [2]
...
SightSpeed has developed a new, proprietary video codec for person-to-person video calling that offers 30 frames per second video streaming with almost no latency. You'll need a broadband connection that's capable of 128Kbps download speeds in order to get those numbers, but that's fairly standard in urban areas these days. Ryan Singel from Wired News has tested the service, and he says that the clarity is fantastic. Other initial reports, like this review of the beta from PC Mag, claim that SightSpeed's video service is the best in the industry. Better than Yahoo, AOL, Skype, and iChat.
...

[SightSpeed]

[SightSpeed]

[SightSpeed]
Fishtank test

And another review for Windows Live Messenger;

Windows Live Messenger Review [5]
...
If you haven't been paying attention to Windows Live Messenger, listen up. It's not just for the kiddies anymore. Yes, the new version allows you to perform text chats with your contacts, and you can trigger annoying Winks and Nudges, though such things could get you killed in certain neighborhoods. And yes, you can share files using a new peer-to-peer feature called Sharing Folders, which the grandmothers over at the RIAA will no doubt have a field day with. Windows Live Messenger is exactly what you'd expect from an IM application. It's also a lot more. If you're interested in the basics, check out my preview. This time around, we're going to look at some new stuff, and I'll explain why I think it is that Windows Live Messenger could soon become the center of the way I communicate with the people I most care about at work and home. ...
--Paul Thurrott

 

Posted by DCR 2006-08-02
Update by DCR 2006-08-04

 

2006-08-02
This weeks links
(TOPIC::links)

OSS Watch Survey 2006
During February and March 2006, OSS Watch conducted a survey2 of UK Higher Education (HE) and Further Education (FE) institutions, looking at their attitudes and policies towards open source software (OSS). This was in many ways a repeat of a similar exercise that OSS Watch performed in October 2003.
...
Although only 25% of institutions mention OSS in an institutional policy, in practice 77% of institutions consider OSS when procuring software. ...

OSS Watch Survey 2006: Executive Summary [OSS Watch]

AUC Interactive Podcasting Presentation
AUC offers free Podcasting Workshops for University Staff.
The Apple University Consortium will be presenting two Interactive Podcasting Presentations in Melbourne (16th August) and Sydney (9th August) for University staff.
The content of the workshops is being specifically developed by Steve Doyle, our Professional Development Manager for Higher Education, to address issues pertaining to Podcasting in Universities. ...

AUC Interactive Podcasting Presentation : August 2006 [Apple Australia]

McAfee flaw discovered
San Francisco — Consumer versions of McAfee Inc.'s leading software for securing PCs is susceptible to a flaw that can expose passwords and other sensitive information stored on personal computers, researchers said Monday.
The vulnerability affects many of McAfee's most popular consumer products, including its Internet Security Suite, SpamKiller, Privacy Service and Virus Scan Plus titles, said Marc Maifrett, chief hacking officer at eEye Digital Security Inc., a competing maker of security products.

i.) McAfee flaw discovered [globeandmail.com]
ii.) Heads Up: new flaw in McAfee [SANS]

 

Posted by DCR 2006-08-02
Update by DCR 2006-08-04

 

2006-08-01
(TOPIC::politics, middle-east)

 

Analysis: Bush Mideast Stance May Flop [1]
...
Mehdi Noorbaksh, associate professor of international affairs at Harrisburg University of Science and Technology, said the United States miscalculated on two grounds in its stance on the Israel-Hezbollah violence.
 
"Buying time for the Israelis" allowed violence against Lebanese citizens to rise and turned the tide of world opinion against both Israel and the United States, he said. At the same time, the U.S. position helped fan support across the Arab world for Hezbollah.
...

The Google Maps Mania Blog directs us to a KML file that geographically documents events that have taken place in the past week on both sides of the Israel - Lebanon border.

Lebanon_July_2006.kmz
Google Map of Israel Lebanon Conflict (using KML) [2]
Viewed in GoogleEarth

Interesting work by Kathryn Cramer using GoogleEarth and Photoshop to Speculate on where Israel will attack on the ground [3]

Lebanon_July_2006.kmz
"Israeli Forces Push Through Lebanon Border" (from Lebanon looking towards Israel) [4]

Bush links fighting to war on terror [5]
...
Rice's maneuvering highlights the deepening crisis in which she now finds herself - by far the biggest in her tenure as America's top diplomat. By refusing to call for an immediate cease-fire, even in the face of the Qana bombing, Rice was teetering on the edge of a public relations disaster, particularly in the Arab world.
...

Mazen Kerbaj is a Beirut blogger who is posting illustrations and live improv as bombs drop;
mazen kerbaj's blog (Blogger)
mazen kerbaj's photos (flikr)

Rice turns up the heat on Israel [6]
...
Leading US neoconservative commentator Bill Kristol reflected the view of many in the Administration, when he said that Israel and the US had underestimated Hezbollah's strength and that both Israel and the US looked likely to be the losers in this conflict and Hezbollah and Iran the winners.
...

 

Posted by DCR 2006-08-01

 

Back to Top  

 


Contact ...

Making contact.
Email
Contents by: Darren Robertson     Maintained by: Darren Robertson

"Disclaimer: This page, its contents and style, are the responsibility of
the author and do not necessarily represent the views, policies or opinions of
The University of Melbourne."


Creative Commons License
Creative Commons
Some Rights Reserved 2004-2006
Darren Robertson