What is Akismet? It is a plug-in for wordpress for controlling spammers on comments. Without Akismet, you might have problem managing your valuable posts. Because 87% of wordpress comments are known to be spams and you would not want any of spams on your wordpress blog. Where I can get it? It is actually built-in your wordpress 2.0.xx or later. You just login as an admin, go to plugins, activate the Akismet.. As I have stated how to add google analytics in your wordpress post, you should have wordpress account created when you decided to start making money on blogging. :) Once you have your account created on www.wordpress.com, you have to activate via email to validate, as soon as you are validated, you will receive an email including the API key that is required for Akismet plug-in. Alternatively, you can login to wordpress.com and go to your profile and view the API key. Under plug-in configuration of Akismet, all you have to do is enter API key and you are good to go. It is that easy. :) What else besides wordpress? Don't feel disappointed that I am only talking about wordpress, you may also use Akismet in many other applications. So, if you have any other applications mentioned below, you may also want to integrate and administer Akismet.
Monday, September 22, 2008
Adding Akismet plug-in in wordpress
Thursday, September 18, 2008
Hackers claim to break into Palin's Yahoo Mail account
A group of hackers that hit the Church of Scientology's site earlier this year have apparently cracked the Yahoo Mail account belonging to Gov. Sarah Palin, the Republican nominee for vice president, according to documents and screenshots posted on the Web.
A security expert called the practice of using private e-mail accounts "incredibly dangerous" for public officials such as Palin.
The group, which calls itself "Anonymous," announced that it had gained access to Palin's Yahoo account in a message last night to, a site that regularly posts confidential documents. Among the files that WikiLeaks had posted for download were five screenshots from gov.palin@yahoo.com, an address book and two digital photos of Palin's family.
One of the account's screenshots shows a short exchange in July between Palin and Lt. Gov. Sean Parnell, who is running against Democrat Ethan Berkowitz for Alaska's lone congressional seat. In her reply, Palin called Anchorage-based conservative radio host Dan Fagan "inconsistent and purposefully misleading" in his comments about Parnell.
Another screenshot displays the text of a message to Palin from Amy McCorkell, whom Palin appointed to the Governor's Advisory Board on Alcoholism and Drug Abuse in October 2007. According to a press release issued by Palin's office at the time, McCorkell was previously a private legal investigator, an office worker and a fitness instructor and, like Palin, lives in Wasilla, Alaska.
In the message dated Sunday, McCorkell said: "I am reading the paper and have thoughts and prayers going your way ... don't let the negative press wear you down! Pray for me as well. I need strength to 1. keep employment, 2. not have to choose. Lately I just pray may God's will be done."
The day before, The New York Times had published a story critical of Palin's hiring practices as governor. The story did not mention McCorkell but said that Palin had appointed at least five former high school classmates to state positions since she took office.
Palin has come under criticism for using private e-mail accounts to conduct state business, with some alleging that she and others in her administration have used them to skirt message-retention and public records laws. The Bush administration has been accused of doing the same thing.
"Using private accounts for government or business use is incredibly dangerous," said Adam O'Donnell, director of emerging technologies at message security vendor Cloudmark Inc. "There's a reason why you have an official account. It's so that you can apply proper security management to the account."
Earlier this year, the Anonymous group launched several attacks against the Web site of the Church of Scientology, claiming that it wanted to "save people from Scientology by reversing the brainwashing."
The Republican National Committee and the McCain-Palin campaign had no immediate comment.
source: Gregg Keizer












Brad Pitt tops list of Internet malware lures
Movie star Brad Pitt has shovedParis Hilton off the top of a list neither wanted to be on. A fan entering Pitt's name in a search engine now has a startling one in five chance of finding a malware-hosting site instead, says security products companyMcAfee Inc.
Pitt is on top of the fake Web site malware league, just ahead of a collection of pop and film stars that reads (in descending order) Beyonce, Justin Timberlake, Heidi Montag, Mariah Carey, Jessica Alba, Lindsay Lohan, Cameron Diaz, George Clooney and Angelina Jolie.
Hilton no longer even makes the fake Web site top 10, but can perhaps take some solace from her continued popularity with spammers.
If you've never heard of some of these people, then it's a fair bet that you are not the intended target of a technique that for some years has been one of the most common ways to infect a PC. But still it persists, driven by an apparently insatiable appetite among some Internet users for computer screensavers, wallpaper and ringtones that feature their favorite stars, at whatever risk to themselves.
"Cybercriminals employ numerous methods, yet one of the simplest but most effective ways is to trick consumers into infecting themselves by capitalizing on Americans' interest in celebrity gossip," said McAfee spokesman Jeff Green. "Tapping into current events, pop culture or commonly browsed sites is an easy way to achieve this."
Reading the latest statistics, it's hard to avoid the conclusion that malware writers think that the celebrity-obsessed are as recklessly naive as they are star-struck. Most malware-infection techniques have shown some evolution over the past two years, but the fake Web site ploy just goes on and on.
In fact, a deeper problem is the way users interact with search engines, as was pointed out by McAfee itself only a year ago. McAfee's motives for publicizing the issue may not be entirely neutral; at least one search engine,Yahoo, recently began using McAfee's SiteAdvisor tool to filter the Web sites it returns in search boxes.
And for those users who visit only Web sites they know are legitimate, there is also bad news. The biggest hack trend of the last year has been compromising perfectly legitimate Web sites to serve malware -- witness this week's large attack on the Web site of BusinessWeek magazine.
For Internet users, there is no easy escape, only the awareness of the growing number of pitfalls.
source: John E. Dunn
Wednesday, September 17, 2008
SELinux in RHEL 5: More enhanced, more security
Security Enhanced Linux (SELinux), an open source project sponsored by the National Security Agency to help implement mandatory access controls (MAC), was first introduced in Red Hat's distribution with Red Hat Enterprise Linux 4 (RHEL 4). In our review of RHEL 4 and SELinux in 2005, we were excited about the possibilities and the GUI interface that came with SELinux, but we were cautious about the software package's ability to capture the market. Despite the user-friendly GUI, SELinux was difficult to configure and hard to understand. The documentation wasn't much help either. Most administrators were just turning off SELinux.
Red Hat clearly understood that some changes were necessary. They were either intimidated by its complexity or feared the possible damage that a poorly configured system could do to their applications. On RHEL 4, there was no easy way to determine why, if an application stopped working, whether or not the problem was due to SELinux.
Red Hat hopes to change this with several new features and enhancements in RHEL 5. New monitoring tools, multilevel security integration, policy modules and utilities will provide RHEL 5 users the added security of SELinux with less difficulty.
SELinux Troubleshooter
One of these enhancements is the new SELinux Troubleshooter. Written in Python, setroubleshoot is a tool that watches the audit log files for access vector cache (AVC) messages and sends reports when things go bump in the night. The daemon continuously watches audit logs for errors and then translates them into laymen's terms for you. SELinux denials were one of the most common problems that administrators reported, which is why most decided to deactivate SELinux. Another daemon, setroubleshootd, receives connections which examine the data and alerts listeners. This tool maintains its own log file, under /var/log/setroubleshoot, and includes the use of the sealert command. This is a GUI desktop notification function, which contacts setroubleshootd, the local server daemon, and essentially registers itself as an alert listener.
To begin, start the browser:
# sealtert –b
This system is made up of three components, including the alert feature, setroublesoot and the audit subsystem. The audit subsystem reports the actual AVC messages. When the kernel sends a message that SELinux denies authorization for something, it creates this AVC message. Each message is tagged into a denial event, which setroubleshoot can assemble into complete events. The tool merges all these independent messages into single denial events.
New domains, policy modules
The extent that SELinux monitors the operations of services in RHEL 5 has significantly increased since the last version. In RHEL 4, only 15 services had domains defined, while in RHEL 5 more than 200 target services are governed by the SELinux system. It is recommended that every program shipped by Red Hat and started on boot should have a domain defined. The benefit here is that it is much less likely for processes governed under SELinux running on RHEL5 to be compromised, increasing the comfort of security administrators. Another benefit is the introduction of policy modules, which make the process of modifying SELinux policies much easier. In RHEL 4, one had to go through many steps (downloading source, editing code, using make) to rebuild the policy tools. With policy modules, these setups are not necessary. The audit2allow utility gives you the ability now to generate policy modules (allow rules) directly from audit.log messages. One can also configure these polices using the system-config-selinux utility. This much improved GUI lets you modify the policy you need changed from a set of pre-defined parameters. Also, it is very easy to change system policies. You no longer need to edit configuration files, you only need to check or uncheck boxes. This is available out of the box and is fully integrated with RHEL5.
You can also use the semanage utility to configure elements of these polices without any recompilation of policy sources. The semodule command is another useful one. For example, this command lists out the policies:
[root ((Content component not found.)) _29_137_21 selinux]# semodule -l amavis 1.1.0 ccs 1.0.0 clamav 1.1.0 dcc 1.1.0 evolution 1.1.0 iscsid 1.0.0 mozilla 1.1.0 mplayer 1.1.0 nagios 1.1.0 oddjob 1.0.1 pcscd 1.0.0 pyzor 1.1.0 razor 1.1.0 ricci 1.0.0 smartmon 1.1.0
Multi-level security integration
Another important enhancement is the multi-level security (MLS) integration into RHEL5. This model allows RHEL5 to get EAL4+ LSLPP certifications, which means that RHEL5 is now considered a trusted OS and can be sold to Government agencies which require the tightest security polices. MLS allows users to label files with categories. To turn the system into a trusted system in RHEL 5, install the policy (using the selinux-policy-mls utility) and make changes to the selinux config files to reference MLS. Prior to MLS, there was Type enforcement (TE), which is the primary mechanism and role based access control (RBAC). I'm still not thrilled about the fact that Red Hat still does not have a special SELinux guide for RHEL5. If Red Hat is really going to make SELinux an important part of its distribution, it needs to provide strong documentation so users do not have to fumble through the web looking for pieces of information. While there have been major improvements and tighter integration between RHEL5 and SELinux, Red Hat still has a way to go before it is user friendly enough for most IT departments. Better documentation will help in their efforts. The small chapter in the RHEL deployment guide (Chapter 43, Security and SELinux) isn't enough.
Deploying SELinux
Let's look at the Z parameter. Many utilities such as ps, lsof and netstat are optimized for SELinux, using the Z parameter.
[root ((Content component not found.)) _29_137_21 selinux]# ps -aeZ | more LABEL PID TTY TIME CMD system_u:system_r:init_t 1 ? 00:00:01 init system_u:system_r:kernel_t 2 ? 00:00:00 migration/0 system_u:system_r:kernel_t 3 ? 00:00:00 ksoftirqd/0 system_u:system_r:kernel_t 4 ? 00:00:00 watchdog/0 system_u:system_r:kernel_t 5 ? 00:00:00 migration/1 system_u:system_r:kernel_t 6 ? 00:00:00 ksoftirqd/1
Where SELinux is not installed, this is what you will see:
[root ((Content component not found.)) _29_137_21 selinux]# netstat -Z SELinux is not enabled on this machine.
We can also run the sestatus and genforce commands for further information on the status of SELinux on our system.
[root ((Content component not found.)) [root ((Content component not found.)) _29_137_21 selinux]# sestatus SELinux status: disabled [root ((Content component not found.)) _29_137_21 selinux]#72_29_137_21 selinux]# [root ((Content component not found.)) _29_137_21 selinux]# getenforce Disabled [root ((Content component not found.)) _29_137_21 selinux]#
How can we turn on SELinux when it is disabled? The simplest way is to edit the selinux config file and change the SELINUX parameter, which can take three values: enforcing, permissive and disabled. In our case, we made it permissive. This is the option where alerts will be sent, though polices will not yet be strictly enforced. I recommend this as a good first step towards SELinux deployment.
# This file controls the state of SELinux on the system. # SELINUX= can take one of these three values: # enforcing - SELinux security policy is enforced. # permissive - SELinux prints warnings instead of enforcing. # disabled - SELinux is fully disabled. SELINUX=permissive # SELINUXTYPE= type of policy in use. Possible values are: # targeted - Only targeted network daemons are protected. # strict - Full SELinux protection. SELINUXTYPE=targeted
After editing this file you must reboot your system in order for the change to take effect. Let's look at the status now, after the reboot.
[root ((Content component not found.)) _29_137_21 ~]# sestatus SELinux status: enabled SELinuxfs mount: /selinux Current mode: permissive Mode from config file: permissive Policy version: 21 Policy from config file: targeted
Perhaps the best new utility available is the system-config-selinux utility. Almost everything can be displayed or configured from here. If you are using X, make sure that you turn on x11 forwarding on your ssh client.
************************************************************* [root ((Content component not found.)) _29_137_21 ~]# system-config-selinux /usr/share/system-config-selinux/system-config-selinux.py:68: Warning: IA__g_object_get_valist: object class `GnomeProgram' has no property named `default-icon' xml = gtk.glade.XML ("/usr/share/system-config-selinux/system-config-selinux.glade", domain=PROGNAME)
SELinux and RHEL5 are a better marriage than SELinux and RHEL 4 ever were. The utilities are more focused, more user-friendly and more powerful. Setting up policies and administering the systems are easy and MLS, allowing this Linux distribution to be certified as a trusted system, is icing on the cake. Red Hat should publish more detailed documentation on SELinux and RHEL5: until that happens, I fear that administrators will continue to shun SELinux.
About the author: Ken Milberg is a systems consultant with two decades of experience working with Unix and Linux systems.
VMware upgrades Mac virtual machine software
VMware Inc. today shipped Fusion 2.0, a major update for its virtualization software that lets Intel-based Macs run Windows, Linux and other operating systems. The upgrade is free to current Fusion users.
After a four-month stretch in beta, Fusion 2.0 is ready for prime time, said Pat Lee, a VMware group manager. "We want our customers to see that Windows really is better on a Mac," Lee said in a statement.
Version 2.0 adds multimonitor support and mirrored folders, as well as support for DirectX 9.0 Shader Model 2, which is crucial for 3-D game-playing under Windows XP. Users can now also take and manage multiple "snapshots," VMware's term for saved versions of a virtual machine (VM) -- originally, only a single snapshot could exist at any one time -- and back up existing VMs automatically with a new auto-snapshot tool.
Other changes to the virtualization software include improvements to Unity, the Mac-Windows integration that puts Windows applications in Mac-style windows. Fusion 2.0 also comes with a free 12-month subscription to McAfee Inc.'s VirusScan Plus antivirus software in any VM running Windows.
The upgrade can be downloaded and installed free of charge by owners of Fusion 1.x; the price for first-time buyers is $79.99 for a single license, $349.99 for five seats and $699.99 for 10. Currently, Fusion 2.0 is available only by electronic distribution from the company's site and several third-party online stores, including those operated by Apple Inc., Amazon.com and Best Buy.
Fusion is one of the several virtualization programs available for the Macintosh. In the commercial arena, it goes head to head with Parallels Inc.'s flagshipParallels Desktop for Mac. Another option is Sun Microsystems Inc.'s open-source VirtualBox, which can be downloaded at no charge.
source: Gregg Keizer
Tuesday, September 16, 2008
Hackers hit Large Hadron Collider Web site
Hackers defaced one of the Web sites of the Large Hadron Collider (LHC) earlier this week, but the controversial science project's network suffered no permanent damage, a spokesman for CERN maintained today.
The attack took place Monday, two days before the massive collider ran its first operational test, said James Gillies, a spokesman for theEuropean Organization for Nuclear Research, or CERN, which operates the LHC.
A group going by the name Greek Security Team, or GST, claimed responsibility for the defacement of one of the LHC sites, cmsmon.cern.ch, according to a report earlier Friday in U.K. newspaperThe Telegraph.
Hackers ended the long message that temporarily replaced the CERN site with the line: "We are 2600 - dont [sic] mess with us," the newspaper said.
It was a defacement, and that's all it was, said Gillies today. "It was benign, but it reminds us that we need to be vigilant," he said. "And no harm was done to the experiment or its computer network." No additional files, malicious or otherwise, had been injected into the project's computers, he said.
CERN brought the site back up but has blocked public access. Instead, only CERN users can reach the revived site.
The hackers targeted a site for the Compact Muon Solenoid (CMS), one of the major experiments being run at the LHC. Built around a huge solenoid magnet that generates a magnetic field 100,000 times more powerful than Earth's own, the CMS detector is designed to search for the Higgs boson particle and others that could make up the elusive dark matter scientists theorize comprises the bulk of the universe's matter.
The CMS detector is a rival of the ATLAS experiment, a second LHC sensor that uses radically different technologies and designs for its magnetic detector. CMS is located in France, while ATLAS is in Switzerland; the LHC sprawls across the Franco-Swiss border near Geneva.
Prior to Wednesday's test, some people had claimed that switching on the LHC would create a black hole that would destroy the earth. CERN responded last week with a report that dismissed the fears as "unfounded." Scientists associated with the project have also receiveddeath threats.
Site defacements are not unusual. Zone-H.org, a group that collects evidence of site attacks, logs hundreds each day. But attacks against internationally known domains are relatively rare. In June, for example, a Turkish hacker group broke into the site for the Phoenix Mars Lander, at the time a new NASA arrival on the Red Planet.
Android Winners
Late last year, Google Inc. announced that it would give $10 million in prizes to software development companies with plans for the most innovative and useful applications for its open-source mobile Android platform.
Roughly nine months later, Google has announced the winners. The applications it has selected help users do everything from calling the nearest taxicab or comparing sale prices at different stores to calculating their carbon footprints. Here are the winners:
Cab4me
Using Android's Google Maps application, cab4me lets a user call a cab to her location with a single click. By using GPS capabilities to locate not only the user's current location, but also the location of the nearest cab company, the application can initiate a call to the cab company with a mere click on the map. The application was developed by Konrad Huebner and Henning Boerger.
Locale
Ever get embarrassed at a company meeting when your cell phone unexpectedly goes off? With Locale, you can make sure your device knows to switch to vibrate mode the minute you step into your office. With Android's GPS capabilities, Locale adjusts your phone's settings to wherever you are. Thus, your phone will forward calls to different numbers based on whether you're at work or home, or it will send out a status message on Twitter letting people know where you're located. This application was developed by Carter Jernigan, Clare Bayley, Jasper Lin and Christina Wright, with additional contributions from Jennifer Shu.
PicSay
Essentially a drop-and-drag picture editor for your mobile phone, PicSay lets users spruce up their pictures with color correction, highlighting, word bubbles and distortion effects. It also can be used to create event invitations or holiday greeting cards that can be sent out to friends, family and associates. This application was developed by Eric Wijngaard.
Softrace
This application actually lets you set up real, live races with your friends and track their progress in real time while the race is going on. Whether the racers are on foot, bicycles or skis, Softrace uses Google Maps' location application programming interface to track each user's progress, and it can store statistics of the race on Android's SQLite database. This application was developed by Staffan Kjellberg and Thomas Kjellberg.
TuneWiki
An open-source music-based social network, TuneWiki lets users share what they're listening to with one another. They can also use Google Maps to find what users around the world are listening to. TuneWiki also plays audio and video for songs while scrolling synchronized lyrics as they play. The application creates a virtual library of songs that connects to the Internet and suggests similar-sounding songs or artists. This application was developed by TuneWiki, with additional help from Rani Cohen, Chad Kouse, Zach Jobbs, Jared Fleener and Amnon Sarig.
Wertago
Billing itself as "the mobile application nightlifers have been waiting for," Wertago is a social networking application that lets users coordinate social events with their friends, rate current hot spots and create personalized social networking profiles for users to share their favorite locations. Like many other Android applications, Wertago uses Google Maps' API to map out clubs, restaurants and theaters. This application was developed by Kelvin Cheung, Teresa Ko, Peter Ree, Robert Sarvis and Douglas Yeung.
Life360
This is a neighborhood-centric social networking application that keeps users up to date with their families and local communities. Life360 users can send or receive neighborhood emergency alerts. Whether you're holding a backyard barbecue or looking for help to find a lost pet, Life360 gives you quick access to your neighbors and your family. This application was developed by Chris Hulls Dilpreet Singh, Luis Carvalho, Phuong Nguyen and Steve Potell.
GoCart
The goal of GoCart is to help shoppers gather as much information as they need to make smart, informed decisions. Using GPS and Android's built-in camera to scan bar codes, the application will search both the Web and local stores to compare prices of any product. The application also lets users read other users' reviews of products and can set up price alerts whenever prices go down. This application was designed by Rylan Barnes, with contributions from Noah Labhart and ZXing Developers.
Ecorio
An application destined to warm Al Gore's heart, Ecorio uses Android's GPS capabilities to track a user's carbon footprint while driving. It also gives suggestions for carpooling and public transportation, and it lets users invest in carbon-reduction projects and purchase carbon credits over their phones. This application was developed by Jeff Kao, Gary Pong, Robert Lam and Taneem Talukdar, with additional contributions from Jason Wong
Compare Everywhere
This application is very similar to GoCart because it uses Android's built-in camera to scan bar codes and compare prices for products at different retail outlets. It also lets customers rate products and create shopping lists like those on Amazon.com. This application was created by Jeffrey Sharkey.
Friday, September 12, 2008
San Francisco hunts for mystery device on city network
With costs related to an alleged rogue network administrator's hijacking of the city's network now estimated at $1 million, San Francisco officials say they are searching for a mysterious networking device hidden somewhere on the network.
The device, referred to as a "terminal server" in court documents, appears to be a router that was installed to provide remote access to the city's Fiber WAN network, which connects municipal computer and telecommunication systems throughout the city. City officials haven't been able to log into the device, however, because they do not have the username and password. In fact, the city's Department of Telecommunications and Information Services (DTIS) isn't even certain where the device is located, according to court filings.
The router was discovered Aug. 28. When investigators attempted to log into the device, they were greeted with what appears to be a router log-in prompt and a warning message saying: "This system is the personal property of Terry S. Childs," according to a screenshot of the prompt filed by the prosecution.
The disclosure is the latest turn in a bizarre story that has made headlines in San Francisco for the past two months. Childs, a network administrator at DTIS, was arrested July 12 on charges of network tampering after he refused to provide his superiors with administrative access to the city of San Francisco's network, which he had managed for the past five years.
Initially, Childs refused to hand over administrative passwords to the city's routers, which had been configured to wipe out all configuration information if they were reset.
After a dramatic jailhouse meeting with San Francisco's mayor one week after his arrest, Childs handed over the data.DTIS Chief Administrative Officer Ron Vinson said Wednesday that the city now expects to spend more than $1 million to clean up the mess. To date, DTIS has paid out $182,000 to Ciscocontractors and $15,000 in overtime costs, he said in an e-mail interview.
The city has also set aside a further $800,000 to address the problem. Vinson did not specify what the additional money was expected to cover, but if the city has to hire network consultants to remap, reconfigure and lock down its network, that amount would not be an unreasonable estimate. The city has also retained a security consulting firm called Secure DNA to conduct a vulnerability assessment of its network.
Meanwhile, Childs remains in a county jail, held on a $5 million bond. His supporters say he is a dedicated city employee who was pushed too far by incompetent management, while the county's district attorney argues that he concealed a violent criminal past when hired by the city and remains a threat to the network. Childs served prison time following a 1983 robbery conviction, a fact he concealed in his city job application forms.
In court filings, prosecutors said Childs has not provided passwords to city-owned encrypted hard drives or access to two Corsair Flash Survivor USB drives that may contain sensitive information.
In a report filed before the city disclosed the hidden router, a court-appointed expert witness for the defense wrote that DTIS could easily prevent Childs from accessing the networks. "I have seen no evidence that Mr. Childs is a 'computer hacker,' and by taking a number of simple steps, DTIS could block access by Mr. Childs to San Francisco networks," wrote Doug Tygar, a computer science professor at theUniversity of California, Berkeley.
Childs' next court appearance is set for Sept. 24. If convicted, he faces up to seven years in prison.
iTunes 8 takes down Vista with 'blue screen of death'
As soon as an iPod or iPhone is plugged into the PC, Vista crashes and shows the "blue screen of death" (BSOD), the critical error screen on a blue background that requires a reboot to recover, users said. The errors began showing up immediately after updating iTunes to Version 8.0, which Apple released Tuesday as part of its iPod refresh.
"I just installed iTunes 8 over my iTunes 7 on Vista [and] now whenever I plug in my iPod, I get a blue screen death. Three times so far. Even if it is plugged in on boot, I get a blue screen," said a user identified as "sambeckett" on the support forum about 90 minutes after Apple CEO Steve Jobs wrapped up the iPod launch.
The thread, which as of early Thursday had been viewed nearly 10,000 times and sported almost 300 messages, also quickly accumulated theories about the cause. The Vista error message, for example, fingered an Apple-provided USB driver, several users said.
"I think it's safe to say then that either Apple's USB driver shipped with iTunes 8 is broken on Vista, or it's causing a problem with some other common Vista driver," speculated a user named "Mike de Awesome."
Numerous users reported that they were able to avoid the BSOD by unplugging peripherals from their PCs' USB ports, particularly Hewlett-Packard Co. printers and scanners, and in some cases, keyboards, mice and cameras made by Logitech International SA.
Others, however, disputed that fix. "I tried another clean install last night, same BSoD problem," said "bryankaras" early Thursday morning. "I have no HP drivers, no HP printer, no Logitech drivers or peripherals."
"I disconnected all of my USB devices except for the mouse and keyboard, and also disconnected [my] Belken USB hub," echoed "CobraBob" on the same thread. "BSOD. I then disconnected the HP LaserJet parallel cable. BSOD. So my conclusion is that this issue is not solely applicable to HP printers with a USB interface. If this is a USB issue then I'm stumped because with all of my devices unplugged, including the LaserJet parallel printer, I still get the BSOD."
One message on the thread purported to come from an Apple employee, who asked users to report their findings to him via an Apple e-mail account. "Look in the Programs and Feature Control Panel. Do you have Logitech Setpoint software installed?" asked "RoyB" Tuesday afternoon. "Does the issue go away if you remove the Logitech software and reboot the computer?"
Not surprisingly, users vented.
"Funny how iTunes 7 worked flawlessly before I downloaded iTunes 8," said "GogoGadget69" Tuesday. "It couldn't be iTunes 8 could it? And by the way the entire world is getting fantastic 3G reception on the iPhone 3G. And MobileMe has always worked fantastic!!! I love how Apple owns up to problems... IT'S NOT US! IT MUST BE YOU! OR MICROSOFT! OR YOUR MOUSE! OR YOUR CHAIR!"
"This is unbelievable. Who beta tests this software? Oh wait...obviously no one," said "davestoltz" on the thread. "Microsoft would get raked over the coals if they put out this kind of garbage."
iTunes has generated BSOD errors before, most recently after Windows Vista users updated to Version 7.7 in July. A support document spelled out the problem, which was limited to 64-bit editions of the Microsoft Corp. operating system. "Attempting to connect an iPhone or iPod touch, which has been updated with the latest iPhone 2.0 software, to iTunes 7.7 on a 64-bit Microsoft Vista platform may cause the system to unexpectedly quit and display a blue error message screen," the document read.
At the time, Apple recommended that users update to Vista Service Pack 1.
This week's problem, however, was not limited to 64-bit Vista, according to the user reports.
Apple and HP officials were not available for comment.
Thursday, September 11, 2008
London Stock Exchange suffers .NET Crash
It should have been a great day on the London Stock Exchange. The U.S. government had announced on the Sunday before that it was coming to the rescue of Freddie Mac and Fannie Mae. Trading would have been extremely brisk, but then, at 9:15 AM GMT, the Exchange's software failed due to "connectivity issues."Six-hours and 45-minutes later, the London Exchange, along with the Johannesburg Stock Exchange, which uses the LSE's trading platform TradElec, were finally back up.
That was no consolation to traders. As Reuters reported, "We have the biggest takeover in the history of the known world ... and then we can't trade. It's terrible," one trader said.
So what happened? Officially, the LSE first said that, "We will be investigating this and will do everything we can to make sure this doesn't reoccur." Laterthe LSE gave the vague explanation, that "It was software-related, a coincidence, due to two processes we couldn't have foreseen," and not caused by high-volume. The spokesperson added, "We've introduced a fix and we're confident it will not happen again."
Somehow "we couldn't have foreseen" and "we're confident it will not happen again" don't fit very well together.
So what really happened? I doubt we'll ever get a detailed, nitty-gritty explanation, but I have friends in London and... Well, let me just make the following points about TradElec. First, TradElec runs on more than a 100 HP ProLiant servers in several locations in London. These servers are running Windows Server 2003.
On top of this runs the TradElec software itself. This is a custom set of C# and .NET programs, which was created by Microsoft and Accenture, the global consulting firm. Its back-end databases, believe it or not, run on Microsoft SQL Server 2000. The goal was to maintain sub-ten millisecond response times. In short, it's meant to be a real-time system.
The programmers and serious database administrators in the audience can already see where this is going. Sorry, Microsoft, .NET Framework is simply incapable of performing this kind of work, and SQL Server 2000, or any version of SQL Server really, can't possibly handle the world's number three stock exchange's transaction load on a consistent basis.
I'd been hearing from friends who trade on the LSE for ages about how slow the system could get. Now, I know why.
What I find really amazing is that the LSE's software stack hadn't blown its top earlier. Even setting aside my feelings for Linux, there's simply no way I'd recommend Server 2003, .NET and SQL Server for a job even a tenth this size. If a customer of mine insisted that they didn't want open source - more fool them - I'd recommended Sun Solaris, JEE (Java Enterprise Edition) and Oracle or IBM AIX or z/OS, WebSphere and DB2.
What I'd really prefer to see is RHEL (Red Hat Enterprise Linux), JBoss, and MySQL or Oracle or Novell's SLES (SUSE Linux Enterprise Server), JEE, and, again MySQL or Oracle for the DBMS engine. In any case, though, the real moral of this story is that if you really want HA (high availability) or HPC (high performance computing), Microsoft's products should be at the bottom of your list. Unix, mainframes, and, yes Linux, are far, far better for companies that need fast and reliable computing.
You don't have to believe me though. The New York Stock Exchange has already started to use Linux on its servers.
P-to-P network administrator sentenced to 18 months in prison
WASHINGTON -- An administrator of a peer-to-peer network focused on distributing movies has been sentenced to 18 months in prison, the U.S. Department of Justice said.
Daniel Dove, 26, formerly of Clintwood, Va., was an administrator for EliteTorrents.org, a site focused on releasing pirated movies, the DOJ said. Judge James Jones of the U.S. District Court for the Western District of Virginia fined Dove $20,000 in addition to the prison sentence, the DOJ said Tuesday.
A jury found Dove guilty of conspiracy and felony copyright infringement on June 26.
Before it closed in May 2005, EliteTorrents.org offered movies to other P-to-P users, often before the movies were in general release at theaters, the DOJ said.
Dove was an administrator of a small group of EliteTorrents members known as "uploaders," who were responsible for supplying pirated content to the group, the DOJ said. Dove recruited members who had high-speed Internet connections to become uploaders, and he operated a high-speed server, which he used to distribute pirated content, the DOJ said.
Dove's conviction is the eighth resulting from Operation D-Elite, a federal crackdown against the illegal distribution of movies, software, games and music over P-to-P networks using BitTorrentfile-sharing technology. Operation D-Elite focused on the EliteTorrents P-to-P network, which at one point had more than 125,000 members and shared 700 movies. The network also offered pirated software, video games and music to its members, the DOJ said.
source: Grant Gross
Wednesday, September 10, 2008
Google bends to Chrome privacy criticism
Reacting to criticism that its newChrome browser was essentially acting as a keylogger, potentially recording users' every keystroke, Google Inc. yesterday said it would render anonymous the data it collects from the browser within 24 hours.
A privacy expert said the change's impact couldn't be gauged without knowing exactly how Google will "anonymize" the data it records as users type in Chrome's "OmniBox," the name given to the browser's combination address bar-search bar.
Google has taken heat over the "Google Suggest" feature used within OmniBox since it launched Chrome last week. The Suggest feature automatically lists related search queries and popular Web destinations based on the text typed into the OmniBox. Suggest works by logging users' keystrokes -- not just in the OmniBox, but since late last month in Google's primary search field -- and offering the most likely sites or searches based on a blend of popularity and the search company's own algorithms.
Suggest transmits those keystrokes to Google's servers, as the feature's FAQacknowledges. "Just as E.T. needs to phone home in order to get a spaceship to pick him up, Google Suggest needs to talk to Google while you type in order to offer suggestions to you," the FAQ reads.
While all keystrokes typed into Chrome's OmniBox are sent to Google, the vast majority aren't permanently recorded, but instead are discarded as soon as suggestions are returned to the browser. About 2% of the time, however, the keystrokes are recorded, along with associated data such as the IP address of the user who entered those keystrokes.
Previously, Google said it needed that data to monitor and improve Suggest. On Monday, the company announced it would change how long it keeps the data logged from Suggest.
"Given the concerns that have been raised about Google storing this information, and its limited potential use, we decided that we will anonymize it within about 24 hours, basically, as soon as we practically can," said Urs Holzle, Google's senior vice president for operations, in an entry to the company's blog late Monday.
"All data retention is a balance between user privacy and trust on the one hand, and security and innovation on the other," argued Holzle. "In the case of Google Suggest, we decided it's possible to provide a great service while anonymizing data almost immediately."
Google Suggest, which had been in development since 2004, began rolling out to Google's search engine late last month. Before that, it was widely used by Google Toolbar, Mozilla Corp.'s Firefox and Apple Inc.'s iPhone.
The logging, transmitting and recording of keystrokes, however, returned to the forefront when Google released Chrome a week ago. What sparked the criticism over Chrome was the everything-in-one-place nature of the browser's OmniBox, said Alissa Cooper, the chief computer scientist at the Center for Democracy and Technology. Unlike other browsers, which separate the address bar -- where users type URLs -- from the search bar, Chrome combines the two.
"It's the URLs that sparked the criticism, and the change by Google," said Cooper. "Users were faced with Google retaining all of their search logs and all of the URLs they were typing."
Nor was Cooper sure that Google's new promise to anonymize the recorded data within 24 hours is enough. "That's a good step, but that doesn't mean that all those logs are rendered anonymous," she said, pointing out that Google says it anonymizes its server logs, for instance, when it only partially deletes IP addresses and cookies.
"It will really depend on the mechanism Google uses to anonymize those logs," Cooper said. "The impact this has on privacy will only become clear when we know how they render the data anonymous."
Chrome users can disable Google Suggest by right-clicking the OmniBox, then selecting "Edit search engines" and clearing the check box beside "Use a suggestion service to help complete searches and URLs typed in the address bar."
source: Gregg Keizer
Monday, September 1, 2008
Online scammers prep for Gustav, say researchers
According to television station KTAL in Shreveport, La., the office of Louisiana's Attorney General Buddy Caldwell has warned residents of Gustav phishing attacks already in progress.
On Saturday, Marcus Sachs, the director of the SANS Institute's Internet Storm Center (ISC), noted that numerous domains containing the word "gustav," "charity," "hurricane," and "relief" had been recently registered.
"On the day [Hurricane] Katrina hit New Orleans [in 2005] hundreds of donation sites appeared online, many if not most were scam sites," said Sachs in a post yesterday to the ISC research blog. "Well this time around it looks like the people who like to register domain names in anticipation of a storm's arrival have already started registering them for Gustav."
By Sunday, Sachs had listed almost 100 Gustav sites culled from the DomainTools' Web site. "Most of these sites are parked domains and many of them are for sale," he said. "They will be worth monitoring, particularly if 'donate here' messages appear."
Several of the domains, in fact, do appear to be parked, or registered but not fleshed out with content. Others, including helpgustavictims.com and helpgustavvictions.net, were for sale on eBay as of mid-day Sunday.
A few, however, led to legitimate charities. The domain gustavcharity.com, for example, redirected users to the Web site of the evangelical Christian organization "Samaritan's Purse," while contributegustav.org took users to the Baton Rouge Area Foundation's site.
Another security expert, Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, also posted a list of parked domains that may be used for scamming purposes. "Anytime we've seen a natural disaster, we've been on the lookup for domains which might be abused for fraud," said Warner Sunday on his blog. "It was only natural then that I retuned my settings at DomainTools yesterday to alert on Gustav domains."
Warner also pointed out a handful of domains that led to legitimate content.
Three years ago, before and after Hurricanes Katrina slammed into New Orleans, security researchers noted a similar run-up of domain registrations. Enough were used for phony relief scams, often by identity thieves hoping to trick consumers into divulging personal information, that the U.S. Department of Justice set up a Katrina anti-fraud task force.
More than a year later, two brothers were convicted on federal charges for running a fake Salvation Army site that solicited money, supposedly for Katrina relief efforts. The pair, Steven and Bartholomew Stephens, were sentenced to more than 100 months in prison for the scam last December.
source: Gregg Keizer