Hack contest sponsor confirms IE8 bug in final code

Saturday, March 28, 2009 at 8:40 AM
The final version of Microsoft Corp.'s Internet Explorer 8 (IE8) does contain the vulnerability used to hack a preview of the browser at last week's Pwn2Own, the contest's sponsor confirmed today.

But the exploit used by the computer science student to break the release candidate of IE8 -- and walk away with a Sony laptop and $5,000 in cash -- won't work on the final version of IE8 as long as it's running in Windows Vista Service Pack 1 or Windows 7, said Terri Forslof, manager of security response at 3Com Corp.'s TippingPoint unit.

Questions had arisen about the exploitability of IE8 almost immediately after the Pwn2Own hack because Nils, the German student who gave only his first name, hacked IE8 Release Candidate 1 (RC1), while Microsoft released the final code less than 24 hours later.

Today, Forslof put the chatter to rest by confirming that IE8's RTW, or "release to Web" portions, were immune from Nils' hack. "His exploit did, in fact, employ the technique found by Sotirov and Dowd," said Forslof, referring to work by Alex Sotirov and Mark Dowd, two researchers who announced last summer that they were able to bypass two of Vista's biggest security defenses, ASLR (address space layout randomization) and DEP (data execution prevention).

Microsoft made changes to IE8 between RC1 and the final code that blocked Dowd's and Sotirov's circumvention technique, thereby making Nils' exploit moot -- but only in some situations, said Forslof today.

"Nils' exploit is only broken when IE8 is running in Windows Vista SP1 or Windows 7," she said. "The vulnerability is absolutely there, so for IE8 on Windows XP, which lacks ASLR and DEP, it can be exploited using commonly known techniques."

Also at risk, said Forslof, are users running IE8 on the browser's Intranet security zone, no matter what operating system is on the machine. "If an organization is compromised, the flaw could still be exploited from the internal network on machines running Windows Vista and IE8," she said.

Forslof declined to confirm whether the bug also exists in older versions of IE, such as IE7. "We're not going to comment on that because we're still confirming the vulnerability on the previous versions ourselves," she said. "So we'll let Microsoft handle that [announcement]."

But Forslof suspects that IE7 is vulnerable. "My guess would be yes," she said. "A lot of times, researchers look at the current software, in this case IE7, find a bug, then they test on the beta of the next. If they find it there [in IE8], they wait and see whether it's fixed in the final."

Microsoft has said little about the IE8 vulnerability, although during an online Q&A on Wednesday, the browser team noted that Nils' exploit wouldn't work on the RTW edition. "We can say that the attack as demonstrated in Pwn2Own at CanSecWest will not succeed on the RTW build released on March 19 because of changes that can block the ASLR+DEP .Net bypass demonstrated by Dowd and Sotirov," said Kymberlee Price, a program manager for IE8 security.

Mozilla Corp., whose Firefox browser was also hacked by Nils last week, plans to patch that flaw, as well as another that just went public, next week. However, Microsoft has not spelled out a timetable for an IE fix.

Earth Hour 2009 Movie

at 8:25 AM


Earth Hour - Tips to save energy

at 6:25 AM

EARTH HOUR - Tips to save energy

  • When you go away for more than a day switch off the main power switch.
  • Use candles instead of your incandescent lights for dinner.
  • Configure your computer to “energy saving” mode in which it will automatically change to the state of low consumption.
  • Switching off the screen can save even more than just letting the screen saver run.
  • Turning your computer off at night instead of leaving it on will save on average 25% of its annual energy bill.
  • A television in standby mode can use up to as much as half the electricity as when it is switched on.
  • Make sure that your refrigerator door is tightly fit.
  • Don’t put warm or hot food straight into the freezer.
  • The toaster is more energy efficient than the grill for toasting bread.
  • When using a percolator to make tea or coffee, boil only the amount of water required.
  • Install patio covers, awnings and solar window screens to shade your home from the sun.
  • Replace air conditioner filters.
  • Turn off appliances, lights andequipment when not in use.
  • Do not use the remote to switch off your appliances, since they will still be consuming electricity on stand by.
  • Use solar powered lights for your garden.
  • Keep the refrigerator away from direct sunlight or the oven.
  • Fill your electric jug with only the amount of water you need to boil.
  • Using a warm machine wash setting in your washing machine rather than a hot wash will cut consumption by half.
  • Look for an energy rating when shopping for appliances.
  • Only heat or cool the rooms you are using
  • Use a ceiling fan whenever you can.
  • Don’t leave the water running while brushing your teeth.
  • At home, separate cans, bottles, plastic, and newspaper and take it to a recycling center.
  • When you go grocery shopping, take a permanent carrying bag instead of using their plastic bags.
  • Use rechargeable batteries instead of regular throw away batteries as much as you can.
  • Keep your fridge and freezer closed as much as possible.
  • Don’t locate your fridge and freezer in direct sunlight or next to the stove or dishwasher.
  • Don’t use your dryer, if you can help it.
  • Check the seal on your refrigerator door.
  • Drive slow, the faster you drive the more fuel you consume.
  • If your intended destination is not too far away, consider walking than driving your car.

  • Use a sponge instead of a paper towel around the kitchen.

  • Encourage recycling, buy recycled products and support your local recycling agency.

  • Don’t buy single-use, throw-away products such as plastic utensils, razors and paper plates.

  • Don’t throw but recycle your old phones.

  • Use containers again - buy food, drinks and toiletries in returnable containers and ask local shops to stock them.

  • Repair your old electronic gadgets instead of constantly shopping for new ones.

  • Rearrange your plumbing so that rainwater or wastewater from your shower and tub is used to flush your toilet.

  • Refrain from purchasing overpackaged products.

  • Educate your children on the importance of climate change.

McAfee names world’s most dangerous web domains: .

Tuesday, March 17, 2009 at 6:16 AM

Asian internet neighborhoods dominated McAfee’s list of the “most dangerous” on the web with HongKong’s “.hk” and China’s “.cn” domains, and the Philippines’ “.ph” topping the list.

In its second annual McAfee “Mapping the Mal Web” report, the security technology firm McAfee found that 19.2% of all Web sites ending in the “.hk” domain pose a security threat1 to Web users. China (.cn) is second this year with over 11%.

Romania (.ro) and Russia (.ru) are still in the top five most dangerous domains.

The report also noted that the Philippines (.ph) experienced a 270% increase in overall riskiness, from being ranked 19 last year to No. 4 this year.

How to tell, what to do if computer is infected

Monday, March 16, 2009 at 7:24 AM
Computer-virus infections don't cause your machine to crash anymore.

Nowadays, the criminals behind the infections usually want your computer operating in top form so you don't know something's wrong. That way, they can log your keystrokes and steal any passwords or credit-card numbers you enter at Web sites, or they can link your infected computer with others to send out spam.

Here are some signs your computer is infected, tapped to serve as part of "botnet" armies run by criminals:

• You experience new, prolonged slowdowns. This can be a sign that a malicious program is running in the background.

• You continually get pop-up ads that you can't make go away. This is a sure sign you have "adware," and possibly more, on your machine.

• You're being directed to sites you didn't intend to visit, or your search results are coming back funky. This is another sign that hackers have gotten to your machine.

So what do you do?

• Having anti-virus software here is hugely helpful. For one, it can identify known malicious programs and disable them. If the virus that has infected your machine isn't detected, many anti-virus vendors offer a service in which they can remotely take over your computer and delete the malware for a fee.

• Some anti-virus vendors also offer free, online virus-scanning services.

• You may have to reinstall your operating system if your computer is still experiencing problems. It's a good idea even if you believe you've cleaned up the mess because malware can still be hidden on your machine. You will need to back up your files before you do this.

How do I know what information has been taken?

• It's very hard to tell what's been taken. Not every infection steals your data. Some just serve unwanted ads. Others poison your search result or steer you to Web sites you don't want to see. Others log your every keystroke. The anti-virus vendors have extensive databases about what the known infections do and don't do. Comparing the results from your virus scans to those entries will give you a good idea about what criminals may have snatched up.


From Yahoo.com

Human knowledge belong to the world

Wednesday, March 11, 2009 at 7:20 AM
I just watch A film titled ‘Antitrust(also titled also titled Conspiracy.com[4] and Startup)’, Which was release on 2001. It is a story which promotes open source of knowledge (software).
Here is the Plot

Working with his three friends at their new software development company "Skullbocks", Milo Hoffman (Phillippe) is contacted by CEO Gary Winston (Robbins) of NURV (Never Underestimate Radical Vision) for a programming position few would refuse: a fat paycheck, an almost-unrestrained working environment, and extensive creative control over his work. Accepting Winston's offer, Hoffman and his girlfriend, Alice Poulson (Forlani), move to their new home.

The environment of NURV seems as advertised: a friendly, family-oriented company that places great value on individual creativity. NERF footballs fly around the office, the atmosphere is relaxed, and Winston personally shows Milo to his workstation and introduces him to his co-workers. Despite development of the flagship product ("Synapse", a worldwide media distribution network) being well on schedule, Hoffman soon becomes suspicious of the excellent source code Winston personally provides to him, seemingly when needed most, while refusing to divulge the code's origin.

After his best friend, Teddy Chin (Tso), is murdered, Hoffman's world is turned upside down when he uncovers that NURV is stealing the code they need from programmers around the world—including Chin—and then killing them to cover their tracks. Hoffman learns that not only does NURV employ an extensive surveillance system to observe and steal code, they have their fingers in both the United States Department of Justice and most of the mainstream media. Even his girlfriend is a plant, an ex-con hired by the company to manipulate him.

While searching through a secret NURV database containing surveillance dossiers on employees, he finds that the company has information of a very personal nature about a friend and co-worker, Lisa Calighan (Cook). When he reveals to her that the company has this information, she agrees to help him expose NURV's crimes to the world. Coordinating with one of Hoffman's friends (Dushku) from his old startup, they plan to use a local cable access station to hijack Synapse and broadcast their charges against NURV to the world. However, Calighan turns out to be a double agent, foils Hoffman's plan, and turns him over to Winston.

His paranoia paying off, Hoffman had already confronted his "girlfriend", Poulson, and convinced her to side with him against Winston and NURV. When it became clear that Hoffman had not succeeded, a backup plan was put into motion by Poulson, the third member of Skullbocks (Runyan), and the incorruptible internal security firm hired by NURV. While Hoffman is mocked by Winston, the second team successfully usurps one of NURV's own work centers and transmits the incriminating evidence as well as the Synapse code.

Parting ways with the redeemed Poulson, Hoffman re-joins Skullbocks in the garage where it all started, and while the media beats a path to their driveway, Winston and his entourage are publicly arrested for their crimes.

________________________________________________________________

We can find ample amount of open-source knowledge treasures of various kinds, including computer software and various other knowledge and information sources on internet. Many of us have been immensely benefited from these open-source treasures. One of the great features of such extremely precious knowledge sources is they provide users with interactive forums and they are open for questions, answers and for more clarifications.




DOTA or GIRLFRIEND

Monday, February 2, 2009 at 6:24 AM
DOTA or GIRLFRIEND
si DOTA isa lang sa mundo,
GF napakarami niyan.
si GF iiwan ka din niyan,
si DOTA hindi.
si GF nagagalit pagnagdodota ka,
si DOTA hindi nagagalita pag nagGF ka.
si DOTA P20 lang masaya na,
si GF baka P200 hindi pa masaya.
pagnakakakita ka ng ibang Hero hndi nagagalit si DOTA,
pero pagnakakakita ka ng ibang babae nagagalit si GF.
si GF pag iniwan mo mahirap na balikan,
si DOTA pag iniwan mo, handa ka parin tanggapin.
Ano mas gusto mo DOTA o GF?
mag-isip ka na....
GIRLFRIEND: Bakit ang DOTA ba maroromansa ka?
REPOST
mabsa ng mga adik sa dota
DOTA VS. GF

This is from Bulletin From Friendster.com


Trash Chronicles | Powered by Blogger | Entries (RSS) | Comments (RSS) | Designed by MB Web Design | XML Coded By Cahayabiru.com