Greg-ToolsSections |
RSS /
Securite InformatiqueIndex (hide) 1. Sources
2. Bruce ScnheierIt's all about the captions: ...doctored photographs are the least of our worries. If you want to trick someone with a photograph, there are lots of easy ways to do it. You don't need Photoshop. You don't need sophisticated digital photo-manipulation. You don't need a computer. All you need to do is change the caption. In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of "full disclosure," asking whether researchers should be permitted to disclose details of a fare-card vulnerability that allows people to ride the subway for free. The "Oyster card" used on the London Tube was at issue in the Dutch case, and a similar fare card used on the Boston "T" was the center of the U.S. case. The Dutch court got it right, and the American court, in Boston, got it wrong from the start -- despite facing an open-and-shut case of First Amendment prior restraint. The U.S. court has since seen the error of its ways -- but the damage is done. The MIT security researchers who were prepared to discuss their Boston findings at the DefCon security conference were prevented from giving their talk. The ethics of full disclosure are intimately familiar to those of us in the computer-security field. Before full disclosure became the norm, researchers would quietly disclose vulnerabilities to the vendors -- who would routinely ignore them. Sometimes vendors would even threaten researchers with legal action if they disclosed the vulnerabilities. Later on, researchers started disclosing the existence of a vulnerability but not the details. Vendors responded by denying the security holes' existence, or calling them just theoretical. It wasn't until full disclosure became the norm that vendors began consistently fixing vulnerabilities quickly. Now that vendors routinely patch vulnerabilities, researchers generally give them advance notice to allow them to patch their systems before the vulnerability is published. But even with this "responsible disclosure" protocol, it's the threat of disclosure that motivates them to patch their systems. Full disclosure is the mechanism (.pdf) by which computer security improves. Outside of computer security, secrecy is much more the norm. Some security communities, like locksmiths, behave much like medieval guilds, divulging the secrets of their profession only to those within it. These communities hate open research, and have responded with surprising vitriol to researchers who have found serious vulnerabilities in bicycle locks, combination safes (.pdf), master-key systems and many other security devices. Researchers have received a similar reaction from other communities more used to secrecy than openness. Researchers -- sometimes young students -- who discovered and published flaws in copyright-protection schemes, voting-machine security and now wireless access cards have all suffered recriminations and sometimes lawsuits for not keeping the vulnerabilities secret. When Christopher Soghoian created a website allowing people to print fake airline boarding passes, he got several unpleasant visits from the FBI. This preference for secrecy comes from confusing a vulnerability with information about that vulnerability. Using secrecy as a security measure is fundamentally fragile. It assumes that the bad guys don't do their own security research. It assumes that no one else will find the same vulnerability. It assumes that information won't leak out even if the research results are suppressed. These assumptions are all incorrect. The problem isn't the researchers; it's the products themselves. Companies will only design security as good as what their customers know to ask for. Full disclosure helps customers evaluate the security of the products they buy, and educates them in how to ask for better security. The Dutch court got it exactly right when it wrote: "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings." In a world of forced secrecy, vendors make inflated claims about their products, vulnerabilities don't get fixed, and customers are no wiser. Security research is stifled, and security technology doesn't improve. The only beneficiaries are the bad guys. If you'll forgive the analogy, the ethics of full disclosure parallel the ethics of not paying kidnapping ransoms. We all know why we don't pay kidnappers: It encourages more kidnappings. Yet in every kidnapping case, there's someone -- a spouse, a parent, an employer -- with a good reason why, in this one case, we should make an exception. The reason we want researchers to publish vulnerabilities is because that's how security improves. But in every case there's someone -- the Massachusetts Bay Transit Authority, the locksmiths, an election machine manufacturer -- who argues that, in this one case, we should make an exception. We shouldn't. The benefits of responsibly publishing attacks greatly outweigh the potential harm. Disclosure encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers. It's how we learn about security, and how we improve future security. This essay previously appeared on Wired.com. EDITED TO ADD (8/26): Matt Blaze has a good essay on the topic. Interesting: the solution to one problem causes another. "The rigorous studies clearly show red-light cameras don't work," said lead author Barbara Langland-Orban, professor and chair of health policy and management at the USF College of Public Health. "Instead, they increase crashes and injuries as drivers attempt to abruptly stop at camera intersections." And, of course, the agenda of the government is to increase revenue due to fines: A 2001 paper by the Office of the Majority Leader of the U.S. House of Representatives reported that red-light cameras are "a hidden tax levied on motorists." The report came to the same conclusions that all of the other valid studies have, that red-light cameras are associated with increased crashes and that the timings at yellow lights are often set too short to increase tickets for red-light running. That's right, the state actually tampers with the yellow light settings to make them shorter, and more likely to turn red as you're driving through them. Starting September 27th: a 36-foot-long, 330-lb female and a 20-foot-long, 100-lb male. [+ desc]
3. Secunia
A vulnerability has been reported in HP Enterprise Discovery, which can be exploited by malicious users to gain escalated privileges. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Lostmon has discovered two vulnerabilities in the PopnupBlog module for Xoops, which can be exploited by malicious people to conduct cross-site scripting attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A security issue has been discovered in DriveCrypt Plus Pack, which can be exploited by malicious, local users to disclose sensitive information. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Corwin has discovered some vulnerabilities in K-Rate Premium, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people and users to conduct script insertion and SQL injection attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Some vulnerabilities have been reported in IBM Lotus Quickr, which can be exploited by malicious people to conduct cross-site scripting attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A vulnerability with an unknown impact has been reported in IBM DB2. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Seth Fogie has reported some vulnerabilities in KM Scanner File Utility, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A vulnerability with an unknown impact has been reported in Sharity. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Lidloses_Auge has reported a vulnerability in webEdition CMS, which can be exploited by malicious people to conduct SQL injection attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service). Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Bug Researchers Group has reported a vulnerability in Smart Survey, which can be exploited by malicious people to conduct cross-site scripting attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A security issue has been reported in BitlBee, which can be exploited by malicious people to bypass certain security restrictions and hijack accounts. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Red Hat has issued an update for ipsec-tools. This fixes two vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service). Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Debian has issued an update for tiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Hussin X has reported a vulnerability in Million Pixel Ad Script (Million Pixel Script), which can be exploited by malicious people to conduct SQL injection attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS (Denial of Service), and potentially gain escalated privileges, and by malicious people to cause a DoS. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Kacak has reported a vulnerability in Kolifa.net Download Script, which can be exploited by malicious people to conduct SQL injection attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Emory University has reported some vulnerabilities in AWStats Totals, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A security issue has been reported in Samba, which can be exploited by malicious, local users to bypass certain security restrictions. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
~!Dok_tOR!~ has discovered some vulnerabilities in MiaCMS, which can be exploited by malicious people to conduct SQL injection attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A vulnerability has been reported in OpenVMS, which can be exploited by malicious, local users to gain escalated privileges. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
InATeam has discovered a vulnerability in BtitTracker (BTI-Tracker) and xbtit, which can be exploited by malicious people to conduct SQL injection attacks. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Digital Security Research Group have reported two vulnerabilities in Pluck, which can be exploited by malicious people to disclose sensitive information. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.
Digital Security Research Group have discovered some vulnerabilities in ezContents, which can be exploited by malicious people to disclose sensitive information. Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required. [+ desc][+ titles]
4. focus NewsOnline intruders hit Red Hat, Fedora Project Researchers race to zero in record time Gov't charges alleged TJX credit-card thieves >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Poisoned DNS servers pop up as ISPs patch Denial, hype cloud report of Best Western breach Search hacker exposes Olympic age scandal >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Opera update nixes critical flaws States seek workarounds for e-voting systems TJX employee fired for exposing shoddy security >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Thoughts of a Teenage Bot Master Radio Free Europe hit by DDoS attack Flash vuln fells Vista >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Nigeria enlists Microsoft to fight spam scammers Cross-Site Scripting Worm Hits MySpace Another data security bill in the works >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 FTC sues company over spyware WiMax: Just Another Security Challenge? Blocking Traffic by Country on Production Networks >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Integrating More Intelligence into Your IDS, Part 2 Integrating More Intelligence into Your IDS, Part 1 Get Off My Cloud >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 An Astonishing Collaboration Bad-Code Blues Firing Up Browser Security >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 News, Infocus, Columns, Vulnerabilities, Bugtraq ... [+ desc][+ titles]
5. focus vulnerabilities Opera Web Browser 9.51 Multiple Security Vulnerabilities Avaya SES Authentication Bypass Vulnerability and Information Disclosure Weakness GE Fanuc Proficy Information Portal HTTP Basic Authentication Information Disclosure Vulnerability Papoo 'suchanzahl' Parameter SQL Injection Vulnerability [security bulletin] HPSBMA02363 SSRT080106 rev.1 - HP Enterprise Discovery Running on Windows, Remote Authorized User, Gain Extended Privileges [ MDVSA-2008:180-1 ] libxml2 PacSec 2008 CFP (Deadline Sept. 1, Conference Nov. 12/13) and BA-Con 2008 Speakers (Sept .30/ Oct. 1) White Wolf Labs #080826-1: Kyocera Mita Scanner File Utility (Multiple) News, Infocus, Columns, Vulnerabilities, Bugtraq ... [+ desc]
6. US-CERT National Cyber Alert SystemVulnerability Summary for the Week of August 18, 2008 Cybersecurity for Electronic Devices Vulnerability Summary for the Week of August 11, 2008 Microsoft Updates for Multiple Vulnerabilities Microsoft Updates for Multiple Vulnerabilities Vulnerability Summary for the Week of August 4, 2008 Understanding Internationalized Domain Names Vulnerability Summary for the Week of July 28, 2008 Vulnerability Summary for the Week of July 21, 2008 Understanding Bluetooth Technology [+ desc]
7. Apple Hot NewsWhile he knew that iPhone generated a significant amount of Internet traffic to popular websites, even Peter Burrows (businessweek.com) was surprised when he perused the analysis Engadget recently posted. With iPhone ringing up nearly 80% of the traffic to engadget.com and iPod touch holding on to 16%, that meant that all other mobile devices combined accounted for the remaining 4%.
Road warriors take note. With iSpend installed on your iPhone, you can track expenses like never before. Easily enter expenses into iPhone as you incur them; quickly assign categories to separate lodging from travel from dining expenses. iSpend lets you generate reports and email comma-separated files for import into Numbers or Excel. iSpend travels well, too, letting you set the default currency for each expense log. The Print dialog offers numerous options (e.g., black and white/color, letter/legal, single or double-sided) for controlling how your documents print. If you find yourself returning to the same set of options frequently, you can save your custom print settings as a preset and save yourself some time the next time you print a similar document. Find out how by watching the most recent Quick Tip of the Week.
?House hunting? Forget the listing agents and classified ads. Now you can find homes for sale with a few taps on a smartphone,? reports Prashant Gopal (businessweek.com). Those taps can launch the Trulia Real Estate Search, ?one of the Web?s most visited home listing sites? and a recent App Store addition, StreetEasy Real Estate, Home Finder, or FrontDoor.com, which Gopal says, will be on the App Store market soon.
?I?m still impressed,? writes Mark Kellner (washingtontimes.com). He finds iPhone 3G ?a powerful little device, capable of doing a heck of a lot of things, and it does this in a small, sleek package that?s easy to operate.? Particularly impressed by the App Store, which he calls ?quite smart,? he notes that the ?ability to load third-party applications?makes the iPhone more like a miniature computer than just a phone.?
Whether you like watching them or creating your own, you?ll find a wealth of fascinating material about documentaries on iTunes U. Especially from the Center for Documentary Studies at Duke University. There you can hear poets, photographers, and filmmakers speak about creating documentaries, and you can listen to audio documentaries recorded by Duke University students. Think you have what it takes to be selected as one of the top emerging photographers of the year? If so, you have only one day left to submit your work for consideration in American Photo?s 2008 Emerging Photographers project. All you need is ten outstanding images, Aperture 2, and the free Portfolio Review export plug-in that you?ll find ? along with complete details ? on American Photo?s website.
»
[+] Seen the latest TV ads?We think you?ll really enjoy Off the Air, Pizza Box, Throne, and Calming Teas, the four latest TV ads now playing on the Get a Mac site. While you?re visiting, you may also want to watch the long version of Sad Song. It?s a classic. Maybe your friends would like to see them, too.
You may depend on Preview to read and annotate PDFs. But did you know that you can use Preview to crop, rotate, and resize photos? Using tools available in Preview, you can also adjust exposure, saturation, and sharpness. Or make Auto Levels adjustments. Preview even lets you remove backgrounds. To find out how to make easy photo edits in Preview, watch the latest Quick Tip of the Week.
?The latest rankings from the American Customer Satisfaction Index (ACSI) show that Apple has dramatically outpaced its rival computer makers in the hearts of U.S. consumers,? reports Asher Hawkins (forbes.com). The ACSI survey ?ranks Apple at 85? out of 100, ?11 points above the computer-maker industry average.? In fact, ?Apple?s rating is also an all-time high for the computer industry.?
Pro photographer Ben Horton may depend on his unique vision to capture compelling images, but he relies on his Macs and Aperture 2 to process, perfect and present his photos to the world. ?The whole app feels right,? he says. ?It?s easy to maneuver and all the editing tools are in one place. I don?t like to spend a lot of time figuring out how to use a program, and with Aperture, I don?t have to.?
Do you crossword? Then you?re gonna love 2 Across. Eliza Block?s stellar crossword puzzle game for iPhone and iPod touch lets you download puzzles from a variety of sources ? including the Times, Washington Post, and The Onion ? and solve them on the go. 2 Across gets rave reviews from puzzle fans, and Block has even made a new Lite Edition available for the thriftiest puzzlers. How better to celebrate the 85th anniversary of the legendary Warner Brothers Studio than by watching some of the great films they?ve produced over the years? And that?s just what we?re doing at iTunes, making it easy for you to find such box-office hits as Matrix Reloaded, Goodfellas, Risky Business, Blade Runner, and eighty-one other classic Warner Brothers films, many newly restored for the occasion. ?When you?re starting a small company,? explains Lane Becker, ?every minute and every dollar counts.? That?s why he and co-founders Thor and Amy Muller chose an all-Apple infrastructure for Get Satisfaction, the startup they launched to bring peer-to-peer customer assistance to corporate customer service.
On August 27, you can meet actor, comedian, and writer Steve Coogan as he visits the Apple Retail Store, SoHo to discuss his new movie, Hamlet 2. The hilarious (and irreverent) comedy ? the comedy smash of the 2008 Sundance Film Festival ? arrives in theaters on August 22. In addition to Coogan, the movie stars Catherine Keener, Amy Poehler, David Arquette, and Elisabeth Shue. Enjoy the Hamlet 2 trailer. Part crime drama, part political intrigue, the Bank Job nabbed critical acclaim when it stole into theaters this year. Now available for both purchase ($14.99) and rental ($3.99), the film tells the story of a successful 1971 bank heist that scored not only millions of pounds in cash and jewelry but also incriminating evidence implicating members of the royal family in murder, corruption, and a sex scandal.
Wouldn?t it be great if you could enjoy up-to-the-minute sports coverage no matter where you go. Now you can. With SportsTap for iPhone and iPod touch. The free sports application ? billed as ?the ultimate mobile sports portal? ? offers box scores and detailed stats on the NFL, MLB, NBA, NHL, NCAA, LPGA, and even local sports teams. ?Issues are the last things a kid needs at college and Macs have fewer issues with viruses, malware, and icky stuff like that,? explains Bob LeVitus (chron.com). He recently sent his own daughter off to college with ? what else? ? her own Mac, and to help fellow parents make the right choice for their undergrads, LeVitus lists the twelve reasons ?why your student should take a Mac to college.? Not too long ago, Jim Dalrymple (macworld.com)) announced that his long-desired goal of recording his own Blues album on his Mac had run into a bit of a musical snag. He ran out of mic preamps for recording. Not to worry, readers came to the rescue, and in his latest Creative Note, Dalrymple describes the solutions that got his project back on track. WIth Disk Utility in Mac OS X Leopard, you can write to some types of optical media multiple times ? not just once. Doing so allows you to fill up those discs with more data and make them an even more economical storage destination. To find out how, watch the most recent Quick Tip of the Week.
[+ desc][+ titles]
8. Oracle Technology NetworkScores of hands-on labs and deep-dive sessions about Oracle Fusion
Development, JEE (including BEA content), Rich Internet Applications,
Embedded Technology, Database, and SOA await you. Runs concurrently with
Oracle OpenWorld; explore and register! Get an introduction to developing Java EE Web applications, using Oracle Workshop for WebLogic. In this new installment to the "Mastering SOA" series, learn best practices for rich interface development in an SOA, based on the experiences of Collect America. Download the first fully Oracle-compliant, feature-bearing release of WebLogic Server. Web 2.0, Spring, Web services, world-record performance, lightweight install - it's all here A quick introduction to the most powerful?as well as confusing?aspects of this ubiquitous command. Learn the necessary steps for using the same codebase under Oracle's two flagship development environments, Oracle JDeveloper and Oracle Workshop for WebLogic. Get guidelines and pointers for building efficient drivers for accessing the Oracle Database using key technologies such as OCI. BEA-related products in the Oracle Fusion Middleware Family are now available for download under the OTN Developer License. Documentation, Discussion Forums, and other resources are also available. OTN is adding an "Architect" focus to the community, with new centers covering expanded SOA (including governance), Extreme Transaction Processing, Virtualization (Oracle VM + JRockit VM), and Enterprise 2.0. Get an overview of the architecture, design, and configuration of Oracle (formerly BEA AquaLogic) Service Buses that are federated via a messaging Store-and-Forward system. [+ desc]
9. Latest Security NewsAugust 19, 2008 Evan Schuman, Editor of StorefrontBacktalk.com As retail and healthcare executives around the globe struggle to adhere to a wide range of data security ... Cisco conducted an Internet TV roundtable with PCI experts and executives from the retail and healthcare industries on July 30. They discussed the evolution of security threats, real-world business challenges, PCI's role and the approach to managing compliance. Following are the highlights of that roundtable: Highlights / Key Facts: Data-security-related attacks on the healthcare industry have increased 85 percent between January 2007 - January 2008 (source: ... SAN JOSE, Calif., July 30, 2008 - Expanding on the success of its Payment Card Industry (PCI) for Retail Solution, Cisco today introduced its first validated architecture to address PCI compliance in healthcare settings. Specifically, the PCI Data Security Standard is providing healthcare organizations with a prescriptive model for how to safeguard patient financial transaction data and other personally identifiable information that is captured and processed within a healthcare facility or ... July 29, 2008 What: On July 30, 2008, Cisco and two senior information/security executives from the retail and healthcare industries will host a live, interactive Internet TV broadcast to discuss an urgent data security compliance requirement impacting both key markets - the recently enacted Payment Card Industry (PCI) standards and the protection of confidential consumer/patient information. The data security roundtable discussion will ... Vancouver, Canada, June 26, 2008 - Today, five leading information technology (IT) vendors announced the creation of the Industry Consortium for Advancement of Security on the Internet (ICASI), a nonprofit organization that will enhance global IT security by proactively driving excellence and innovation in security response. Founded by Cisco, International Business Machines, Intel Corporation, Juniper Networks, and Microsoft Corp., ICASI provides a unique forum for global companies committed ... [+ desc]
10. MSDN: Security11. Brian Johnson on SecurityToday we posted a page with information about the PDC 2005 Security Symposium (Friday, September 16th at the PDC). This is a great opportunity to hear some of the top security people from Microsoft discuss security issues. Here's the link to the page:
I'll update that page with addional resources as they come available. For now, be sure to review the page and read the SDL Document as prep for the symposium. If you're not going to the PDC, stay tuned and I'll try to get as much information about these topics as I can added to the page. Good story in eWeek about some of the Microsoft efforts around Katrina.
Microsoft Brings .NET to Katrina Relief EffortThe calls for help inside Microsoft went out and were answered incredibly quickly. Robert Scoble has more on similar efforts here. The Microsoft Disaster Relief Page was updated tonight with a statement about Hurricane Katrina.
Microsoft Response to Hurricane KatrinaThis page has links to many different relief agencies, so this is a good place to start if you're considering a contribution. Windows Server 2003 R2 RC 0 is available for download. You can get more information here:
Windows Server 2003 R2 Release Candidate 0This page contains links to information about new features, a reviewer's guide, a FAQ, and a product overview. There's additional infomation available on the TechNet Windows Server 2003 R2 Beta Roadmap page. This is the introduction from the Product Overview page: Windows Server 2003 R2 is an update release of the award-winning Windows Server 2003 operating system. Built on Windows Server 2003 with Service Pack 1 (SP1), Windows Server 2003 R2 takes advantage of the stability and security of a proven code base while extending connectivity and control into new areas. Windows Server 2003 R2 offers all the benefits of Windows Server 2003 SP1 while greatly improving branch office server solutions, identity and access management, storage setup and management, and application development inside and outside your organization's traditional boundaries. Windows Server 2003 R2 is easy to integrate into an existing Windows Server 2003 environment as it has the same application compatibility, manageability, and serviceability as the existing servers with SP1. The IE team has published a new whitepaper describing IE 6 security. Get it here:
Understanding Security in Microsoft Internet Explorer 6 in Windows XP SP2This paper isn't targeted at developers, but it gives a good overview of the security features in the browser. DevDiv VP Somasegar has posted information about the Visual Studio 2005 launch. Check it out here:
Visual Studio 2005 updateThere's a lot more information in the post, so be sure to read it all. I've blogged before about the Visio Connector for MBSA. Well, I ran into Sanjay Puri a while back and he let me know that this tool has been updated for MBSA 2.0. Here's a link to the download and the details:
Visio Connector for Microsoft Baseline Security Analyzer (MBSA)This article on TechNet has a picture to take a look at and more details about the tool. As I mentioned before, this tool is a great way to visualize potential security deficiencies your network. Stepto posted information today around the Win32/Zotob.A worm. Here's a link to his post:
Guidance pages and information on Worm:Win32/Zotob.AHere's a direct link to Microsoft's incident page for the worm: What You Should Know About ZotobAs always, the bottom line with this type of thing is to make sure that you're fully patched, you're using a firewall, and that your antivirus signatures are up-to-date. Also be sure to subscribe to the MSRC blog for the latest information; it's a great resource. In my ongoing effort to link to every SDK in the world, here's the WinFX Beta 1 SDK for your coding pleasure.
Microsoft® WinFX ? Software Development Kit for Microsoft® Pre-Release Windows Operating System Code-Named "Longhorn", Beta 1 Web SetupHere is a direct link to the ISO, if you prefer to install from a disc. (Thanks to Norm Diamond for pointing out that I was linking to an earier version.) After a flurry of hard work by people from all over Microsoft, we propped the Windows Vista Developer Center today. Get the details here:
Microsoft Windows Vista Developer CenterCheck out the site from a design perspective, even if you're not doing Windows Vista development yet. Duncan Mackenzie and Laurie Moloney get a ton of credit for pulling this together. Good stuff. Get the details here:
Windows OneCare Live Home »
[+] Can you Spot the Bug?Microsoft Product Manager for Developer Security Rick Samona, with the help of Foundstone, has created a new feature for the Security Developer Center called Spot the Bug. The way this works is that Rick will post a new bug in his blog every so often and you can take a shot at guessing the bug in the comments for the entry. When Rick posts a new bug, he'll answer the question on the current bug and mark the bug squashed. We've rebuilt the home page on the Security Developer Center to feature the latest unanswered bug and link to the squashed bugs. This is a total experiment, and it could fail miserably, but it seems cool right now. :) You might notice that I took the Security Bulletins list off the home page and replaced it with a link to the Security Bulletin Search page. Let me know if you were relying on that feature or not and I'll bring it back if there's a popular demand. Thanks to Erica Wiechers for helping us get this posted. Kim Komando has nice little writeup of the Microsoft Shared Computer Toolkit for Windows XP in USA Today. Check it out:
Microsoft tool secures shared computers If you missed Tech-Ed in Orlando, many of the sessions are now available online. Check out the site here:
Tech-Ed 2005 Webcast SeriesI watched Mark Russinovich's (Winternals, Sysinternals) Understanding and Fighting Malware: Viruses, Spyware and Rootkits talk the other day. Good stuff. You can hear the crowd respond in the background, which always seems to make these more interesting. I wasn't aware that the Patterns and Practices group was doing a regular weekly webcast. You can get the details here:
Patterns and Practices Live [+ desc][+ titles]
12. rootpromptHas anyone else noticed how the newer versions of VIM attempt to be smart? Yeah, they think that just because yo |

