Sunday, 30 December 2012

Microsoft confirms zero-day bug in IE6, IE7 and IE8

Computerworld - Microsoft on Saturday confirmed that Internet Explorer (IE) 6, 7 and 8 contain an unpatched bug -- or "zero-day" vulnerability -- that is being used by attackers to hijack victims' Windows computers.

The company is "working around the clock" on a patch, its engineers said. They have also released a preliminary workaround that will protect affected IE customers until the update is ready.

In a security advisory issued Dec. 29, Microsoft acknowledged that attacks are taking place. "Microsoft is aware of targeted attacks that attempt to exploit this vulnerability through Internet Explorer 8," the alert stated.

Newer versions of IE, including 2011's IE9 and this year's IE10, are not affected, Microsoft said. It urged those able to upgrade to do so.

According to multiple security firms, the vulnerability was used by hackers to exploit Windows PCs whose owners visited the website of the Council on Foreign Relations (CFR), a non-partisan foreign policy think tank with offices in New York and Washington, D.C.

On Friday, FireEye corroborated earlier reports that the CFR website had been compromised by attackers and was hosting exploit code as early as Dec. 21. As of mid-day Wednesday, Dec. 26, the site was still conducting "drive-by" attacks against people running IE8, said Darien Kindlund, senior staff scientist at FireEye, in a Friday blog.

Kindlund added that the malware hidden on the CFR website used Adobe Flash Player "to generate a heap spray attack" against IE8. It wasn't clear whether Flash also contained a zero-day bug, or whether the attackers leveraged an already-known and previously patched vulnerability that had not been fixed on the victims' PCs.

On Saturday, Jaime Blasco, the labs manager at AlienVault, weighed in on the IE zero-day as well, noting that the exploit was able to circumvent Microsoft's anti-exploit technologies, DEP (data execution prevention) and ASLR (address space layout randomization), and successfully compromise Windows XP and Windows 7 PCs running IE8. He identified the IE bug as a likely "use-after-free" vulnerability, a type of memory management flaw.

AlienVault, said Blasco, had begun looking into the "watering hole" attacks stemming from the CFR website at the beginning of the week, and had alerted the Microsoft Security Response Center (MSRC) that it suspected IE harbored a zero-day vulnerability.

In a watering hole campaign, hackers identify their intended targets, even to the individual level, then scout out which websites they frequently visit. Attackers next compromise one or more of those sites, plant malware on them, and like a lion waits at a watering hole for unwary wildebeests, wait for unsuspecting users to surf there.

The CFR did not immediately reply to a request for comment on its site's current status.

Social IT Operations ManagementThe next big breakthrough in IT management is here. Learn how you can reduce change risk, speed incident resolution, and improve visibility across your environment with Social IT Operations Management.

Read now.


View the original article here

Drones, phones and other 2012 privacy threats

Computerworld - Verizon's attempt -- unsuccessful so far -- to secure a patent for a so-called 'snooping technology,' which in this case would let television advertisers target individual viewers based on what they're doing or saying in front of their sets, capped another challenging year for privacy advocates.

The Verizon technology, which includes a sensor/camera housed in a set-top box, would determine the activities of individual viewers -- eating, playing, cuddling, laughing, singing, fighting or gesturing -- and then trigger personal advertisements based on the activities.

Overall, the technology would serve targeted ads based on what the user is doing, who the user is, his or her surroundings, and any other suitable personal information, according to Verizon.

The U.S. Patent Office delivered a "non-final" rejection of Verizon's application in November.

But analysts say that because engineers are already working on such technology, it's a cinch that some kind of similar technology will be included in TV set-top boxes in the not too distant future.

Here, in no particular order, are other developments in 2012 that could have a major long-term impact on privacy:

The Federal Aviation Administration Modernization and Reform Act of 2012, signed into law by President Barack Obama in February, was immediately slammed by rights groups, privacy advocates and lawmakers who contended that the law poses a major threat to the privacy of law-abiding citizens.

The bill, still largely unnoticed by the general public, opens up American airspace to commercial unmanned aerial vehicles (UAVs), better known as drones. Over the next few years, the FAA is expected to license the use of as many as 30,000 drones by border patrol agents, government agencies, state and local law enforcement agencies as well as businesses.

The powerful drone lobby has done much to highlight the benefits of drones in tracking fugitive criminals, managing traffic, monitoring crops, conducting land management activities, news reporting and filmmaking.

Numerous agencies, including the Department of Homeland Security, NASA, the FBI. the border patrol, and local police departments have secured licenses to operate drones in U.S. airspace.

Rights advocates argue that the law includes no meaningful guidelines for protecting privacy rights.

The advocates warn that drones equipped with facial recognition cameras, license plate scanners, thermal imaging cameras, open WiFi sniffers, and other sensors could be used for general public safety surveillance.

The Center for Democracy and Technology earlier this year noted that static surveillance technology like closed circuit television cameras cannot track individuals beyond their fields of vision. But drones, the group contended, can peek into backyards and be used -- without a warrant -- to track individuals pervasively.

Social IT Operations ManagementThe next big breakthrough in IT management is here. Learn how you can reduce change risk, speed incident resolution, and improve visibility across your environment with Social IT Operations Management.

Read now.


View the original article here

Velocity Solo X2 review: Teach an old PC new SATA 6-gbps tricks

PC World - If your PC lacks a SATA 6-gigabits-per-second interface, you can't get top performance out of any of the latest consumer-grade solid-state drives. Such drives bump up against the 6-gbps limit of that bus, while the older second-generation SATA interface maxes out at just 3 gbps. Apricorn's Velocity x2 should remove that roadblock for you.

My main system sports a circa-2009 Intel D58SO motherboard. It has a great feature set, but it predates third-generation, 6-gbps SATA. The only way to upgrade such a beast is via a PCIe adapter card with a SATA 6-gbps interface, of which the market has plenty to choose from. I tried installing one of those a couple of years ago, but it gave me blue screens. SSDs at that time weren't nearly as fast as they are today, so I saw no real reason to upgrade. But with SSD performance now topping 600 MBps, it's time.

Lo and behold, Apricorn contacted me about its Velocity Solo PCIe cards. These will not only add SATA 6-gbps capability to any system with an available PCIe slot, but they'll also serve as a caddy for a single SSD. Apricorn sent two cards for me to evaluate: the $50 Velocity x1 and the $99 Velocity x2. I tried both, and recommend one.

A Kingston HyperX 3K drive attached to my motherboard's second-generation SATA interface, which is capable of delivering maximum performance of only 3 gbps, read data at 227 MBps and wrote data at 236 MBps while running the synthetic benchmark CrystalDiskMark 3. Surprisingly enough, a much faster OCZ Vertex 4 SSD mounted on the Velocity x1 delivered slower performance: It read at only 203.3 MBps and wrote at 196.5 MBps.

When I paired the Vertex 4 with Apricorn's Velocity Solo x2 card, however, the SSD's numbers jumped to 348.1 MBps reading and 323.2 MBps writing--a substantial improvement beyond what is possible with the second-generation SATA interface. Attaching the Kingston HyperX 3K to the Velocity Solo x2, meanwhile, improved its numbers to 322.1 MBps reading and 239.6 MBps writing. That considerably faster read performance made my system feel much more responsive.

The reason for the two cards' performance disparity is that the x1 uses only a single PCIe 2.0 lane, while the x2 employs two lanes (and must be installed in at least a PCIe 2.0 x2 slot as a result). Since each PCIe 2.0 lane is capable of transferring data at 500 megabytes per second (or 3.9 gigabits per second) in each direction, two PCIe lanes are necessary to satisfy the requirements of the SATA 6-gbps interface. Both Velocity Solo cards are outfitted with a standard female SATA connector for attaching a second drive, and both cards are bundled with Apricorn's EZ Gig software for cloning your existing hard drive to your new SSD.

I can't recommend the Velocity Solo x1, as the SSDs I mounted to it performed more slowly than they did when connected to my motherboard's second-generation SATA interface. The Velocity Solo x2, on the other hand, delivered a dramatic improvement, both during testing and subjectively. My only real qualm is the x2's $99 price tag, which is steep compared with the cost of some SATA 6-gbps interface cards (such as the Syba HyperDuo) that don't have the handy mounting caddy. The lowest street price we could find as of December 18, 2012, was $95.

Note: Don't miss our SSD roundup, where you'll find a detailed explanation of how SSDs work, plus links to reviews of seven new models as of December 18, 2012.

Reprinted with permission from PCWorld.com. Story copyright 2012 PC World Communications. All rights reserved.

View the original article here

Researchers find malware targeting Java HTTP servers

IDG News Service - Security researchers from antivirus vendor Trend Micro have uncovered a piece of backdoor-type malware that infects Java-based HTTP servers and allows attackers to execute malicious commands on the underlying systems.

The threat, known as BKDR_JAVAWAR.JG, comes in the form of a JavaServer Page (JSP), a type of Web page that can only be deployed and served from a specialized Web server with a Java servlet container, such as Apache Tomcat.

Once this page is deployed, the attacker can access it remotely and can use its functions to browse, upload, edit, delete, download or copy files from the infected system using a Web console interface. This is similar to the functionality provided by PHP-based backdoors, commonly known as PHP Web shells.

"Aside from gaining access to sensitive information, an attacker gains control of the infected system thru the backdoor and can carry out more malicious commands onto the vulnerable server," Trend Micro researchers said Thursday in a blog post.

This JSP backdoor can be installed by other malware already running on the system that hosts the Java-based HTTP server and Java servlet container or can be downloaded when browsing to malicious websites from such a system.

According to Trend Micro's technical notes, the malware targets systems running Windows 2000, Windows Server 2003, Windows XP, Windows Vista and Windows 7.

"Another possible attack scenario is when an attacker checks for websites powered by Apache Tomcat then attempts to access the Tomcat Web Application Manager," the Trend Micro researchers said. "Using a password cracking tool, cybercriminals are able to login and gain manager/administrative rights allowing the deployment of Web application archive (WAR) files packaged with the backdoor to the server."

In order to protect their servers from such threats, administrators should use strong passwords that cannot be easily cracked by using brute force tools, should deploy all security updates available for their systems and software and should avoid visiting unknown and untrusted websites, the Trend Micro researchers said.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Apple drops bid to add Samsung Galaxy S III Mini to patent lawsuit

IDG News Service - Apple has dropped its patent-infringement accusations against the Galaxy S III Mini, a mid-market Android smartphone that Samsung Electronics says it is not selling in the U.S.

In a filing in the U.S. District Court for Northern California on Friday, Apple said it would withdraw its request to include the Galaxy S III Mini in a patent infringement case against Samsung that is set for trial in 2014. On Nov. 23, Apple had asked to add the Mini and five other recently released Samsung products to its complaint, which originally was filed in February. The case is one of many in an ongoing set of disputes between the two companies in several countries.

When Apple asked to add the Mini to its case, the phone was expected to be released in the U.S. soon. Samsung subsequently filed an opposition to that request in which the South Korean company said it was not selling the Mini in the U.S.

In its filing on Friday, Apple said the Mini apparently was available for sale in the country, because its attorneys had bought multiple Minis from Amazon.com's U.S. online store and successfully had them shipped to addresses in the U.S. The company also said it appeared the device was still on sale at Amazon on Wednesday.

However, Apple wrote that because Samsung had represented it wasn't "making, using, selling, offering to sell or importing the Galaxy S III Mini in the United States," it would drop the patent allegations against the Mini.

Apple's move may rely on Samsung staying true to its statement. Apple withdrew its allegations "without prejudice," reserving the right to make the accusations again "if the factual circumstances change."

Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

FCC eases licensing for in-flight Internet gear on aircraft

IDG News Service - The FCC is making it easier to launch in-flight Internet services on planes in the U.S. by setting up a standard approval process for onboard systems that use satellites.

Since 2001, the Federal Communications Commission has approved some satellite based Internet systems for airplanes, called Earth Stations Aboard Aircraft (ESAA), on an ad-hoc basis. On Friday, the agency said it had formalized ESAA as a licensed application, which should cut in half the time required to get services approved, according to the FCC.

In-flight Internet access is typically delivered via Wi-Fi in an airplane's cabin, but that access requires a wireless link outside the plane to the larger Internet. Some services make that link via special 3G cellular towers on the ground, while others exchange their data over satellites. Row44, a provider of satellite-based in-flight Wi-Fi, names Southwest Airlines and Allegiant Air as customers on its website.

Under the new rules, all it will take for airlines to implement onboard ESAA systems is to test the technology, establish that it meets FCC standards and doesn't interfere with any aircraft systems, and get Federal Aviation Administration approval, the FCC said. The result should be quicker deployments and more competition among in-flight Internet systems, according to the agency.

Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Saturday, 29 December 2012

Toshiba developing Lytro-like phone camera with over 30,000 mini-lenses

IDG News Service - Toshiba is developing a tiny digital camera module similar to the Lytro camera, which shoots tens of thousands of individual photos and then allows the user to pick the point of focus.

The new camera will have from 30,000 to 50,000 tiny lenses, yet still be small enough to fit in modern smartphones and tablets. The company aims to have a product ready for sale by March of 2014.

The concept is similar to that behind a much-hyped camera launched by California-based Lytro earlier this year. Lytro calls its technology "light field capture," and photos taken by the device can be adjusted for focus and perspective after they are taken.

"Lytro doesn't make semiconductors, so the camera module is a product that Toshiba is probably better-suited to make," said Toshiba spokesman Atsushi Ido.

Ido said the concept behind the camera module is similar to the compound eyes found in many insects. He said much of the processing involved in taking and combining the individual images with the new camera would likely be handled by the module's hardware.

Toshiba is among the world's largest manufacturers of CMOS image sensors, where it competes with rivals including Sony, Samsung and OmniVision. Toshiba is better known for its massive NAND flash operations, where it cranks out memory chips for hard drives and memory cards.

In January, Lytro executive Charles Chi told PCWorld that his company was focused on branded cameras aimed at consumers, and any entry into the smartphone market would probably involve a tie-up with an established player.

Earlier this week, Toshiba announced it is readying a 20-megapixel CMOS image chip aimed at the digital camera market, where it hopes to challenge the dominance of Sony. The new chip will also be able to shoot 30 frames per second at full resolution, or 60 frames at 1080P. Toshiba said it will ship samples of the new CMOS sensor next month, with mass production to begin in August.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here