|
2006-08-30
Wine0
(TOPIC::humour)
Posted by DCR 2006-08-30
2006-08-28
This weeks links
(TOPIC::links)
Make a Survival Kit out of an Altoids Tin
Fitting inside an altoids tin, this kit is easy to keep on hand at all times
This is ideal for anyone who wants to have the essential survival gear along each time
they head into the field. Everything fits in the Altoids tin (above). It fulfills all
the component groups (see “Make Your Own,” last slide) except for shelter and protection,
but add a survival blanket to your pocket and you’ll be covered.. ...
Make a Survival Kit out of an Altoids Tin (and Two More Life-Saving DIY Projects) [Field & Stream]
What's On Your Thumbdrive?
"Nowadays, we need to support not only people at the office, but friends, family, friends
of the family, family of the friends... you name it! They all run Windows to a degree and there
are many tools to help you when assisting. Personally, I have a thumb-drive with removable memory
cards. One of them has a small bootable Linux, the other one is filled with ready to use Windows
utilities (CPU-Z, Ultra-Edit32), DOS utilities I've been collecting over the years, and Unix-style
utilities (ps.exe, kill.exe, and others) ported to Windows, without the need for a layer like Cygwin.
I also have a copy of the install files for AVG, Spybot, Sygate and the likes. But, even though I
think I have many great tools, I'm sure I do not know about a lot of great others to help diagnose
and solve problem. So I ask you, what's on your thumb-drive?"
What's On Your Thumbdrive? [Slashdot]
Is your luch safe?
... As for the least likely lunch bandits, Buffini said, it's managers because of the scrutiny
they're under from all sides, as well as "hero" departments like information technology,
which come to your aid when you're down. ...
Stolen lunches? Substitute cat food for tuna on wheat [chron.com]
Posted by DCR 2006-08-28
Update by DCR 2006-08-30
2006-08-25
Patching updates
(TOPIC::security.patch)
Intel wireless
Intel initially issued a big file (100MB) that you had to download, but at least it
upgraded everything on your machine, if it needed upgrades.
After rebooting in the next few days I noticed that my machine is a bit slower then it was.
A look at Task manager output, or excellent Process Explorer from Sysinternals showed that
a process called S24EvMON.exe is using quite a bit of CPU, ... [1]
I cannot replicate this issue on my DELL D810 using the updated Intel drivers set,
my call at this stage is to patch the machines and deal with any machines that show these
symptoms as they arise.
MS06-042 reissue
My previous advice was: Where required keep MS06-042 applied, it fixes more bugs than it creates.
This issue may lead to an additional buffer overrun condition only affecting Internet
Explorer 6 Service Pack 1 customers that have applied the original version of that update
released August 8th, 2006. The security issue is documented in the Vulnerability Details
section as Long URL Buffer Overflow – CVE-2006-3869. Internet Explorer 6 Service Pack 1
Customers should apply the new update immediately. [2]
When it appears - rePATCH! The last patch was at least a step 'better' than an unpatched
machine, this should return the machine to a better state. (What, you're still using IE
for web browsing! Get thee to a nunnery!!)
Time to re-apply the patch on Internet Explorer 6 Service Pack 1 for Windows XP Service
Pack 1 (all versions) and Windows 2000 (all versions) [2]
As we are *all* on XP-SP2 and IE-SP2 we shouldn't see this patch ... we are all patched to
this level aren't we guys?
PowerPoint Zero-Day?
According to the new information this is not 0-day vulnerability, it is related to
patched MS06-012. [3]
Ahhh, grasshopper the ZEN of patch often and patch early.
Posted by DCR 2006-08-25
2006-08-25
Snakes LAPTOPS on a Plane
(TOPIC::security)
We have just finished with the DELL D810 battery issue, and not suprisingly considering
they also use SONY battery units, Apple has announced their own BBQ laptop specials;
Apple Announces Recall of Batteries Used in Previous iBook and PowerBook Computers
Due To Fire Hazard [1]
WASHINGTON, D.C. - The U.S. Consumer Product Safety Commission announces the following
recall in voluntary cooperation with the firm below. Consumers should stop using recalled
products immediately unless otherwise instructed.
Name of Product: Rechargeable, lithium-ion batteries with cells manufactured by Sony for
certain previous iBook G4 and PowerBook G4 notebook computers only.
Units: About 1.1 million battery packs (an additional 700,000 battery packs were sold
outside the U.S.)
Battery Cell Manufacturer: Sony Energy Devices Corp., of Japan
Computer Manufacturer: Apple Computer Inc., of Cupertino, Calif.
Hazard: These lithium-ion batteries can overheat, posing a fire hazard to consumers.
Incidents/Injuries: Apple has received nine reports of batteries overheating, including
two reports of minor burns from handling overheated computers and other reports of minor
property damage. No serious injuries were reported.
Description: The recalled lithium-ion batteries were used with the following computers:
12-inch iBook G4, 12-inch PowerBook G4 and 15-inch PowerBook G4. Consumers should remove
the battery from the computer to view the model and serial numbers labeled on the bottom
of the unit.
...
Apple has determined that certain lithium-ion batteries containing cells manufactured
by Sony Corporation of Japan pose a safety risk that may result in overheating under
rare circumstances. The affected batteries were sold worldwide from October 2003
through August 2006 for use with the following notebook computers: 12-inch iBook G4,
12-inch PowerBook G4 and 15-inch PowerBook G4.
... [2]
Safety first for carry-on Dells [3]
Qantas is issuing an advisory to all passengers on its flights on the safe use
of Dell notebooks following the recall of 4.1 million batteries announced by the
PC manufacturer last week.
The airline said that although passengers would be allowed to carry their Dells
either as checked or cabin baggage, they could only use them on battery power or
through the aircraft power supply available in some first and business class cabins
once they have first removed the batteries from the unit.
Qantas said cabin crew would be advising passengers of the measures which apply to
any computer affected by the recall, that has not yet had the battery replaced.
...
Will QANTAS apply their DELL policy [4] to the Apples? We'll see ...
Posted by DCR 2006-08-25
2006-08-23
Podcasting: Recording a podcast
(TOPIC::podcast)
After looking into the technical side of publishing and serving a Podcast (newsfeed)
it is time to look at the actual creation of the content for a podcast.
5, 4, 3, 2 ,1 ... recording!
There is nothing new in creating Podcasts, people have been recording audio
for many years. In general the rule is the better the recording equipment and
planning - the better the result (think 'garage band session' vs
'recording studio master')
An alternate way of thinking about Podcasts is to think that you are producing
a pre-recorded radio show.
You need to optimise your recording environment to produce the best results for
your budget. In most environments cash will be the limiting factor; if this is the case
you do not want to have a *mega expensive* microphone plugged into a cheap sound card as
you waste the functionality of the microphone. All of the elements of the kit
should be matched to ensure that you have optimise your expenditure.
Software
I strongly recommend Audacity
with the LAME
MP3 encoder plugin dll
Audacity is a free audio editor which lets you mix tracks and perform other
sound editing functions, such as recoding, playing, importing and exporting
sounds WAV, AIFF and MP3 files. When mixing tracks, there's no drag and drop
like some of the more sophisticated brand programs, but if you're prepared
to use cut, copy and paste you'll be able to mix tracks together, or apply
effects to your recordings. It also has a built-in amplitude envelope editor,
a customisable spectrogram mode and a frequency analysis window for audio
analysis applications. Built-in effects include Bass Boost, Wahwah, and
Noise Removal and it also supports VST plug-in effects.
LAME is an LGPL MP3 encoder. The Open source development model allowed to
improve its quality and speed since 1999. It is now an highly evolved MP3
encoder, with quality and speed able to rival state of the art commercial
encoders.
Noise
Do you need proper acoustical isolation, absorption and diffusion?
Is background noise leaking into the environment?
Can you use soft furnishings to provide an 'OK' environment?
Is the space a write-off to the extent that you should look for a new venue?
Technique
Proper techniques do help. Remember cringing as *that* singer ate the microphone,
or as *that* announcer kept the microphone down at their waist?
Get some lessons/advice; trial different techniques to see what works for you.
Hardware
This is where things become difficult ... what conditions are imposed by the physical
space where you make your recordings.
(Also remember that we are not creating an audio CD, the recording will be compressed
to an MP3 format)
Initial requirements;
- Microphone
- Headphones
- Soundcard
The starting point is a good set of headphones, and a USB microphone.
Why USB? USB microphones tend to avoid many on the noise issues associated with
using the 3.5mm jack microphones in a PC environment. Less line-noise = better
recording. The USB microphone also allows you to use a standard soundcard as you will only be
using it for listening to the playback.
Additions;
- Microphone stand or boom
- preamp/Mixing desk for multiple inputs
- Input filters: Compressor/clipper/noise-gate
Editing
As with the written word the quality of the editing process reflects strongly on
the finished audio product. There is a reason that the post production can
take longer than the actual recording session :)
Posted by DCR 2006-08-23
2006-08-22
Podcasting: expanding the information in the feed
(TOPIC::podcast, xml, itunes)
Apple extends the RSS version 2.0 syntax with some custom
<itunes:item>content</itunes:item>
tags. [1]
For example to indicate Adult content;
<itunes:explicit>yes</itunes:explicit>
Is displayed in iTunes as; (eg. SecondCast feed [2])
The Apple extensions are as follows;
<itunes:explicit> - Channel & Item
<itunes:subtitle> - Channel & Item
<itunes:summary> - Channel & Item
<itunes:author> - Channel & Item
<itunes:keywords> - Item
<itunes:duration> - Item
<itunes:owner> - Channel
<itunes:name> - Channel (for owner, required)
<itunes:email> - Channel (for owner, optional)
<itunes:image> - Channel & Item (artwork 300x300 pixel, jpg, png uncompressed)
<itunes:block> - Channel & Item (block display in directory)
NOTE: All fields will be truncated to 255 unicode characters, except for <itunes:summary>
Staying with the secondCast example from above, let's look at the
first item in the feed file "Secondcast 1"
<item>
<title>Secondcast: 1 "Power Lines"</title>
<link>
http://www.secondcast.com/podcasts/secondcast-ep01-64.mp3
</link>
<description>
Lordfly Digeridoo, Aimee Weber, Cristiano Midnight, Walker Spaight, and
Johnny Ming discuss life as a public figure in SL, intellectual property,
and forum drama.
</description>
<itunes:subtitle>Episode 1</itunes:subtitle>
<itunes:explicit>yes</itunes:explicit>
<itunes:summary>
Lordfly Digeridoo, Aimee Weber, Cristiano Midnight, Walker Spaight, and
Johnny Ming discuss life as a public figure in SL, intellectual property,
and forum drama.
</itunes:summary>
<author>johnny@secondcast.com</author>
<pubDate>Sun, 19 Feb 2006 16:17:55 -0500</pubDate>
<category>Talk Radio</category>
<enclosure url="http://www.secondcast.com/podcasts/secondcast-ep01-64.mp3"
length="01:09:26" type="audio/mpeg"/>
<itunes:keywords>
secondlife, secondcast, linden lab, lordfly, aime weber, walker spaight,
cristiano midnight, anshe chung, eletric sheep
</itunes:keywords>
</item>
This produces the following information in iTunes;
Posted by DCR 2006-08-22
2006-08-22
Rollover
(TOPIC::soe)
Back in May this year I had a quick look at machine rollovers and
disposal schedules [1]. I am now looking at the same data from a slightly
different perspective.
In terms of Lab Rollover dates, our machines are rolled over after 3 years, for their
W+1 (warranty + 1) year they are re-deployed outside of the lab environment.
For 2007 we will be re-deploying from DM211 (Evo530), DM809 (iMac 15" Lampshade),
DM208-MM (3 x Mac G4 towers) into the W+1 category. The MM Lab machines will be sold.
We will
Replacements for 2007:
Windows - DM211 (11 units) - HP dc7600 ?
Apple - DM809 (30 units), DM208 (4 units) - iMac Intel 17" ?
Audio-Visual refits for 2007:
DM809 - requires controllers and 2 x projectors (IWB)
Posted by DCR 2006-08-22
2006-08-15
Amorphophallus titanum
(TOPIC::botany)
The Brooklyn Botanic Garden's gigantic "corpse flower" is flowering;
BBG's Spectacular Titan Arum Is Blooming [1]
The titan arum (Amorphophallus titanum) is one of the world's most remarkable plants.
Native to tropical forests in Sumatra, it produces a monstrous four- to nine-foot-tall flower
head, which releases a monstrous stench of putrefaction at peak bloom (another name for the
plant is the corpse flower!). The species rarely flowers in cultivation—the last time one
bloomed in New York was 1939. However, Brooklyn Botanic Garden's ten-year-old specimen recently
began to flower. It's in peak bloom right now!!
Webcam:
Visit this page to catch the excitement via webcam. All the fun, none of the stink!
The image is automatically updated every minute.
Photo Gallery:
Visit this page to see the daily photo collections.
Posted by DCR 2006-08-15
2006-08-10
MS06-040
(TOPIC::security, patch)
MS06-040 is being actively exploited via BotNet. It is important to have ALL of our
machines patched for MS06-040 as soon as possible. I have been scanning our subnets
looking for machines that have not been updated.
I am using the Class C virsion of eEye's
Retina MS06-040 NetApi32 Scanner
Retina MS06-040 NetApi32 Scanner
Posted by DCR 2006-08-11
Update by DCR 2006-08-15
2006-08-10
This weeks links
(TOPIC::links)
TIME.com: 50 Coolest Websites
How do we select our finalists? We evaluate hundreds of candidates—some suggested by readers,
colleagues and friends, others discovered during countless hours of surfing. Many of this year's
choices are shining examples of Web 2.0: next-generation sites offering dynamic new ways to
inform and entertain, sites with cutting-edge tools to create, consume, share or discuss all
manners of media, from blog posts to video clips. Think we missed one? Send us your thoughts
and we'll post a selection of your comments online. There's always next year.
50 Coolest Websites [TIME.com]
Zombie Alphabet
Simply type in a phrase and press GO
...
http://e-zombie.com/
Tip of the Day: Logbooks
Over the years I found the use of a logbook, either on paper or electronically an essential
instrument in managing (security of) devices. They can be useful for more than just managing
security but they shine during emergencies. Since most emergencies with devices involve loss
of either Confidentiality, Integrity, or Availability, the use of these logbooks is highly
related to security.
In some organizations the system or network administrators are the ones who are in the best
position to keep them up to date and working properly, sometimes making it hard to coordinate
with a different set of security people.
...
Tip of the Day: Logbooks [SANS]
Govts pose greatest threat to web privacy: Google
Web search leader Google, which stores vast amounts of data on the web-surfing habits of
its users, sees government intrusions rather than accidental public disclosures of data as
the greatest threat to online privacy, its chief executive has said.
...
Govts pose greatest threat to web privacy: Google [ABC News Online]
Posted by DCR 2006-08-10
Update by DCR 2006-08-16
2006-08-10
Patch Management
(TOPIC::security, patch, patch tuesday)
With the discussions we are having at the moment regarding patch release and deployment
this is a very timely posting on the SAN site.
Surviving the monthly patch cycle [1]
... There are basically a few tactics to this in use. What strikes me in the responses we got:
most of those writing in value not breaking applications significantly more than patching
before you get hit with an exploit. Perhaps there is a lot work left to be done in order
to convince (upper) management of the risks of patching late as patching even an hour after
the worm or the targeted exploit hit you might cost the company significantly more than
losing a few hours left and right over a not so critical system not being 100% healthy
with a new patch. ...
Approaches;
- Just patch (If something breaks, fix it)
- Test on limited scale, roll out carefully (Get a feel for how it works in your environment
then release.)
- Test applications thoroughly (Testing applications to the end is next to impossible,
for critical servers only?)
- Fully features planned rollouts (a roll-out plan that covers a long time before they come
full circle and start over.)
- Divide and conquer (divide the to be patched machines in different categories and tackle
each differently.)
Mike wrote in on their strategy: "Simple strategy really:
- obtain patches, vet requirements and deploy to a QA environment, containing like for
like hosts; exchange, SQL, IIS, workstation builds etc
- test, monitor, test, monitor...
- deploy to a pre-production group
- monitor, monitor, monitor
- deploy to primary production group
- monitor
- push out to remaining hosts/workstations.
The time scale for deployment is fairly aggressive with immediate introduction for 'critical' updates."
[1]
If you have a security architecture in place, including network segregation;
- General clients: not mission critical, could be patched as soon as the patches are available.
Any issues are resolved once they occur.
- Non-critical servers: patch machines if you see no problems reported, or you could just roll
them out and be ready to roll back if you see problems.
- Mission critical servers should have many layers protecting them from evil, even from internal users.
They should also not be exposed to most of the internal machines and they could remain unpatched or
even isolated for a long while.
In our little corner of the internet:
- EXPOSURE (1): Foremost we should acknowlege that our machines are not heavily protected.
Our machines sit out there on the internet using routable IP addresses.
We rely on a carefully balance interplay of patching, antivirus and local firewall.
- EXPOSURE (2): Our mobile users are NOT highly IT literate, every PDA and laptop
that wanders onto a wireless network, or conects to external machine increases
our exposure (sometimes exponentially).
- SOE for General clients: the advantage of sticking to SOE software is that
patches are tested against these applications reasonably quickly; if there is an issue
a single solution can be developed and deployed. If it's not SOE (or if it is a rare or
low support SOE item) you may be on your own
- SERVERS: Thankfully all of our WinTel servers are Non-critical servers and as such
can be patched and then problems resolved
- LCG: allows for some extent of test and release style patch evaluation.
This allows for testing on a limited scale.
- AUDIT: evaluation of who is patched and to what level ... need better reporting
Posted by DCR 2006-08-08
 Technorati Tags:
patch_tuesday
 Del.icio.us Tags:
patch_tuesday
 Flickr Tags:
patch_tuesday
 Wikipedia:
patch_tuesday
2006-08-09
Patch Tuesday Wednesday
(TOPIC::MS Patch, Geek)
08 August 2006 - Patch Tuesday
Welcome to another 'Patch Tuesday', this months show bag contains the following
fun products; Critical (9) Important (3)
Note that MS06-040 is flagged as Addresses a critical security problem
this is due to this vulnerability being actively exploited.
| Bulletin |
KB number |
Description |
Severity |
Impact |
| MS06-040 |
921883 |
Vulnerability in Server Service Could Allow Remote Code Execution |
Critical |
Remote Code Execution |
| MS06-041 |
920683 |
Vulnerability in DNS Resolution Could Allow Remote Code Execution |
Critical |
Remote Code Execution |
| MS06-042 |
918899 |
Cumulative Security Update for Internet Explorer |
Critical |
Remote Code Execution |
| MS06-043 |
920214 |
Vulnerability in Microsoft Windows Could Allow Remote Code Execution [Outlook express] |
Critical |
Remote Code Execution |
| MS06-044 |
917008 |
Vulnerability in Microsoft Management Console Could Allow Remote Code Execution [Win2K] |
Critical |
Remote Code Execution |
| MS06-045 |
921398 |
Vulnerability in Windows Explorer Could Allow Remote Code Execution |
Important |
Remote Code Execution |
| MS06-046 |
922616 |
Vulnerability in HTML Help Could Allow Remote Code Execution |
Critical |
Remote Code Execution |
| MS06-047 |
921645 |
Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution [Office & VBA] |
Critical |
Remote Code Execution |
| MS06-048 |
922968 |
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution [PowerPoint] |
Critical |
Remote Code Execution |
| MS06-049 |
920958 |
Vulnerability in Windows Kernel Could Result in Elevation of Privilege [Win2K] |
Important |
Elevation of Privilege |
| MS06-050 |
920670 |
Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution |
Important |
Remote Code Execution |
| MS06-051 |
917422 |
Vulnerability in Windows Kernel Could Result in Remote Code Execution |
Critical |
Remote Code Execution |
| |
920103 |
Update for InfoPath 2003 |
|
non-security |
| |
890830 |
Malicious Software Removal Tool (MSRT) |
|
monthly update |
| |
920907 |
Outlook 2003 Junk E-Mail Filter Update |
|
monthly update |
In our environment:
i.) MS06-44 and MS06-49 only apply to Win2K, and as such are less important in our environment
as we should have no W2K in production; where we have W2K it should be deployed.
ii.) MS06-45 and MS06-50 are classed as IMPORTANT, these should be deployed anyway.
iii.) The remaining patches are CRITICAL and should be depolyed in our environment as they
affect software included in our SOE
Posted by DCR 2006-08-09
 Technorati Tags:
patch_tuesday
 Del.icio.us Tags:
patch_tuesday
 Flickr Tags:
patch_tuesday
 Wikipedia:
patch_tuesday
2006-08-08
Mayon volcano.
(TOPIC::google earth)
Volcanic eruption:
Philippines residents face an imminent eruption of the rumbling
Mayon volcano.
The volcano is found in the province of Albay in the
Bicol Region.
Legazpi City
is the top tourist destination in Bicol as it lies 15 kilometers
southeast of Mayon Volcano, one of the Philippines' most famous volcano.
Mayon in GoogleEarth
Want to locate it quickly? Try MayonVolcano.kml
Posted by DCR 2006-08-08
 Technorati Tags:
Mayon
 Del.icio.us Tags:
Mayon
 Flickr Tags:
MayonVolcano
 Wikipedia:
Mayon_Volcano
2006-08-08
Jedi time?
(TOPIC::census)
Today is the day that the Jedi come out and play.
Supposedly 10,000 people are required to claim that their religion is "Jedi"
on the Australian national census to be held tonight for "Jedi"
to be recognised as an official religion in Australia;
(How Ron L. Hubbard is that?).
It didn't work in 2001, so I doubt it will work this time around ...
maybe the force is stronger with this one?
ABS recognises that people have a wide range of belief systems [1]
If your belief system is "Jedi" then answer as such on the census form. But if you
would normally answer Anglican or Jewish or Buddhist or something else to the question
"what is your religion?" and for the census you answer "Jedi" then this may impact on
social services provision if enough people do the same.
Luke, feel the power ...
Oh, and by the way the Census can be completed
online :)
The five years have come and gone and once again the Australian Bureau of Statistics (ABS)
is asking us all for information about where we live, who we live with, how much we earn
and what, if any, our religious beliefs are.
In 2001, an email campaign successfully encouraged 70,509 Australians to report their
religion as Jedi, the powerful religious force attributed to Luke Skywalker in the Star Wars movies. [3]
Feel the power of the Dark Side!
Bloody Sith!
The Dark Side all right -- couldn't access eCensus with Firefox v1.5.0.6 and had to use IE.
Not happy Jan!
Posted by DCR 2006-08-08
2006-08-04
Vista - a view from the trenches
(TOPIC::vista)
...
Is Windows Vista ready? [1]
No. God, no. Today's Windows Vista builds are a study in frustration, and trust me,
I use the darn thing day in and day out, and I've seen what happens when you subject
yourself to it wholeheartedly. I think I've mentioned the phrase "I could hear the screams"
on the SuperSite before. My wife said that to me one day, and she was referring to the sound
of me barking some primeval curse at my desktop PC as it succumbed to Vista's stupid slowdowns,
crashes, and hang ups for the umpteenth time. She, more than anyone, knows the frustration
I've experienced because of Windows Vista. But even she doesn't know the details.
They would bore her, frankly. She's normal like that.
-- Paul Thurrott
Posted by DCR 2006-08-04
2006-08-04
Patch Tuesday, a Heads Up.
(TOPIC::security)
A *heads up* for this months Patch Tuesday offerings from Microsoft;
Microsoft Security Bulletin Advance Notification [1]
Updated: August 3, 2006
...
On 8 August 2006 Microsoft is planning to release:
Security Updates
• Ten Microsoft Security Bulletins affecting Microsoft Windows.
The highest Maximum Severity rating for these is Critical.
These updates will be detectable using the Microsoft Baseline Security Analyzer
and the Enterprise Scan Tool. Some of these updates will require a restart.
• Two Microsoft Security Bulletins affecting Microsoft Office.
The highest Maximum Severity rating for these is Critical. These updates will be
detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.
Microsoft Windows Malicious Software Removal Tool
• Microsoft will release an updated version of the Microsoft Windows Malicious
Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services
and the Download Center.
Note that this tool will NOT be distributed using Software Update Services (SUS).
Non-security High Priority updates on MU, WU, WSUS and SUS
• Microsoft will not release any NON-SECURITY High-Priority Updates for Windows on
Windows Update (WU) and Software Update Services (SUS).
• Microsoft will release two NON-SECURITY High-Priority Updates on Microsoft Update
(MU) and Windows Server Update Services (WSUS).
...
Posted by DCR 2006-08-04
2006-08-03
SECURITY: A few issues today
(TOPIC::security,wlan,firefox)
i.) Intel WLAN Vulnerabilities
Intel Centrino Vulnerabilities [1]
...
Below are the summaries of the affected platforms
Intel® Centrino Wireless Driver Malformed Frame Remote Code Execution
* Intel® PRO/Wireless 2200BG Network Connection
* Intel® PRO/Wireless 2915ABG Network Connection
Intel® PROSet/Wireless Software Local Information Disclosure
* Intel® PRO/Wireless 2100 Network Connection
* Intel® PRO/Wireless 2200BG Network Connection
* Intel® PRO/Wireless 2915ABG Network Connection
* Intel® PRO/Wireless 3945ABG Network Connection
Intel® Centrino Wireless Driver Malformed Frame Privilege Escalation
* Intel® PRO/Wireless 2100 Network Connection
The details of which drivers are listed on the pages and we recommend you look there.
...
The 2915ABG chipset is used in the DELL latitude D810 laptop (our SOE model) and by default
our Driver Version is 9.0.0.61. (** NOTE: the HP NC8000 uses an HP W500 and is not affected)
Currently an update is NOT available via Windows Update for the D810.
The DELL Support website has
Intel (R) PRO/Wireless 2200BG Network Connection, (R) PRO/Wireless 2915ABG Network Connection, (R) PRO/Wireless Network Connection, v.10.1.1.3 (TIC 113763), A12 Release Date: 5/17/2006
The Intel site says that affected versions are All prior to 10.5 with drvr 9.0.4.16, so this DELL version
will not help
This leaves us with no OEM driver and the need to go with the generic Intel release;
"Intel(R)PROSetWirelessSoftwareVer10.5.0.0.exe"
After an install anb some testing the "Intel(R)PROSetWirelessSoftwareVer10.5.0.0.exe"
appears to be a good installation and works well on the D810.
Recommendation:
In our environment, due to the nature of MUWIRLESS and the untrusted locations that our laptop fleet
can venture into, it is my recommendation to install the generic Intel 10.5.0.0 software.
ii.) Mac wireless issues
Hijacking a Macbook in 60 Seconds or Less [5]
...
While those device driver flaws are particular to the Macbook -- and presently not publicly disclosed
-- Maynor said the two have found at least two similar flaws in device drivers for wireless cards either
designed for or embedded in machines running the Windows OS. Still, the presenters said they ultimately
decided to run the demo against a Mac due to what Maynor called the
"Mac user base aura of smugness on security."
...
But according to Maynor and Ellch, this attack can be carried out whether or not a vulnerable targeted
laptop connects with a local wireless network. It is, they said, enough for a vulnerable machine to have
its wireless card active for such an attack to be successful. That's a trivial demand, given that most
wireless devices embedded in laptops these days are switched on by default and are configured to
continuously seek out available wireless networks.
...
Recommendation:
In our environment we should;
1.) Turn off the wireless card, and bluetooth,
2.) Watch for patches.
iii.) FireFox update
Firefox 1.5.0.6 is a stability update that is part of our ongoing program to provide a safe Internet experience
for our customers. We recommend that all users upgrade to this latest version.
- Fixed an issue with playing Windows Media content (mms://)
Release Date: August 2, 2006 [4]
Recommendation:
In our environment we should be running Firefox 1.5.x with autoupdate enabled.
Our fleet should update themselves, laptops should be checked during standard patching.
Posted by DCR 2006-08-03
2006-08-02
A Quick Guide to desktop Videoconf : Part II
(TOPIC::videoconf,)
More toys ... SightSpeed 5.0 (Build 5016). There are clients for Windows and Mac.
There are two plan options; a free 'Basic Service' plan, and a monthly premium 'Pro Service'
plan that comes in at US$4.95/month or US$49.95/year.
For my testing I have gone with the free 'Basic Service' account
New SightSpeed Features Challenge Skype and Slingbox [2]
...
SightSpeed has developed a new, proprietary video codec for person-to-person video calling that offers
30 frames per second video streaming with almost no latency. You'll need a broadband connection that's
capable of 128Kbps download speeds in order to get those numbers, but that's fairly standard in urban
areas these days. Ryan Singel from Wired News has tested the service, and he says that the clarity is
fantastic. Other initial reports, like this review of the beta from PC Mag, claim that SightSpeed's
video service is the best in the industry. Better than Yahoo, AOL, Skype, and iChat.
...
![[SightSpeed]](./images/2006-08-02_SightSpeedScreen2.jpg)
Fishtank test
And another review for Windows Live Messenger;
Windows Live Messenger Review [5]
...
If you haven't been paying attention to Windows Live Messenger, listen up. It's not just for the
kiddies anymore. Yes, the new version allows you to perform text chats with your contacts, and
you can trigger annoying Winks and Nudges, though such things could get you killed in certain
neighborhoods. And yes, you can share files using a new peer-to-peer feature called Sharing Folders,
which the grandmothers over at the RIAA will no doubt have a field day with. Windows Live Messenger
is exactly what you'd expect from an IM application. It's also a lot more. If you're interested in
the basics, check out my preview. This time around, we're going to look at some new stuff, and I'll
explain why I think it is that Windows Live Messenger could soon become the center of the way I
communicate with the people I most care about at work and home. ...
--Paul Thurrott
Posted by DCR 2006-08-02
Update by DCR 2006-08-04
2006-08-02
This weeks links
(TOPIC::links)
OSS Watch Survey 2006
During February and March 2006, OSS Watch conducted a survey2 of UK Higher Education (HE)
and Further Education (FE) institutions, looking at their attitudes and policies towards open
source software (OSS). This was in many ways a repeat of a similar exercise that OSS Watch
performed in October 2003.
...
Although only 25% of institutions mention OSS in an institutional policy, in practice 77% of
institutions consider OSS when procuring software.
...
OSS Watch Survey 2006: Executive Summary [OSS Watch]
AUC Interactive Podcasting Presentation
AUC offers free Podcasting Workshops for University Staff.
The Apple University Consortium will be presenting two Interactive Podcasting Presentations in
Melbourne (16th August) and Sydney (9th August) for University staff.
The content of the workshops is being specifically developed by Steve Doyle, our Professional
Development Manager for Higher Education, to address issues pertaining to Podcasting in Universities. ...
AUC Interactive Podcasting Presentation : August 2006 [Apple Australia]
McAfee flaw discovered
San Francisco — Consumer versions of McAfee Inc.'s leading software for securing PCs is
susceptible to a flaw that can expose passwords and other sensitive information stored on
personal computers, researchers said Monday.
The vulnerability affects many of McAfee's most popular consumer products, including its
Internet Security Suite, SpamKiller, Privacy Service and Virus Scan Plus titles, said Marc Maifrett,
chief hacking officer at eEye Digital Security Inc., a competing maker of security products.
i.) McAfee flaw discovered [globeandmail.com]
ii.) Heads Up: new flaw in McAfee [SANS]
Posted by DCR 2006-08-02
Update by DCR 2006-08-04
2006-08-01
(TOPIC::politics, middle-east)
Analysis: Bush Mideast Stance May Flop [1]
...
Mehdi Noorbaksh, associate professor of international affairs
at Harrisburg University of Science and Technology, said the
United States miscalculated on two grounds in its stance on
the Israel-Hezbollah violence.
"Buying time for the Israelis" allowed violence against Lebanese
citizens to rise and turned the tide of world opinion against both
Israel and the United States, he said. At the same time, the U.S.
position helped fan support across the Arab world for Hezbollah.
...
The Google Maps Mania Blog directs us to a KML file that geographically documents
events that have taken place in the past week on both sides of the Israel - Lebanon border.
Google Map of Israel Lebanon Conflict (using KML) [2]
Viewed in GoogleEarth
Interesting work by Kathryn Cramer using GoogleEarth and Photoshop to
Speculate on where Israel will attack on the ground [3]
"Israeli Forces Push Through Lebanon Border" (from Lebanon looking towards Israel) [4]
Bush links fighting to war on terror [5]
...
Rice's maneuvering highlights the deepening crisis in which she now finds herself -
by far the biggest in her tenure as America's top diplomat. By refusing to call for an
immediate cease-fire, even in the face of the Qana bombing, Rice was teetering on the edge
of a public relations disaster, particularly in the Arab world.
...
Mazen Kerbaj is a Beirut blogger who is posting illustrations and live improv as bombs drop;
mazen kerbaj's blog (Blogger)
mazen kerbaj's photos (flikr)
Rice turns up the heat on Israel [6]
...
Leading US neoconservative commentator Bill Kristol reflected the view of many in the
Administration, when he said that Israel and the US had underestimated Hezbollah's strength
and that both Israel and the US looked likely to be the losers in this conflict and
Hezbollah and Iran the winners.
...
Posted by DCR 2006-08-01
|