Pages

Saturday, January 23, 2010

Twitter disables ‘widget’ function

Twitter has temporarily disabled one of the features on its website after a security researcher warned of a programming flaw that left the login credentials of its users vulnerable to hackers.

Twitter co-founder Biz Stone said in an email that the company had temporarily cut off access to a feature that lets users display Twitter updates on their websites by using Flash technology.
“Our team has disabled the Flash widget while we look into the problem,” Stone said.
Mike Bailey, a senior security analyst with Foreground Security of Orlando, Florida, said that the problem exploits a widely known vulnerability in Adobe Systems Inc’s Flash programming language.
Adobe has told programmers how to address the vulnerability, which was first discovered in 2006, Bailey added, but noted the operators of many websites have failed to respond to those warnings.
The microblogging site’s huge popularity has made it a prime target for hackers looking to spread malicious software to Twitter’s millions of users.
“As simple as the attack is, I’ve been finding them all over the place,” Bailey said.
Officials with Adobe declined to comment.
A hacker last month briefly hijacked the Twitter site and redirected it to one that claimed to represent a group calling itself the Iranian Cyber Army. That high-profile attack — by a perpetrator who stole credentials to the account that Twitter uses to route its traffic — did not compromise credentials of any Twitter users.
Bailey said his analysis of the Twitter site showed that it could have been vulnerable to attacks for more than a year, but that it was impossible to know whether hackers had actually exploited the Adobe flaw.
He is scheduled to discuss his research on the Twitter flaw at the Black Hat DC security research conference in Washington, which begins on Feb. 2.

Motorola seeks to ban BlackBerry

The patents relate to some early-stage innovations developed by Motorola in key areas such as Wi-Fi access, application management

Motorola Inc is seeking to ban imports of Research In Motion Ltd's BlackBerry smartphones into the US that it claims infringe its patents.
Motorola, the largest US mobile-phone maker, said it filed a complaint with the US International Trade Commission, citing unfair trade practices and infringement of five patents.
The patents relate to some early-stage innovations developed by Motorola in key areas such as Wi-Fi access, application management, user interface and power management, that are now being used by RIM, Motorola said in a statement. The technology allows better connectivity at a lower cost, the company claims.

Litigation
"We've not been able to convince RIM over two years in litigation elsewhere to reach a reasonable settlement so we've taken it to the ITC to stop its infringement," Jonathan Meyer, Motorola's senior vice president of intellectual property law, said in an interview.
He said the two companies had a licence agreement in place from 2003 to 2007 and haven't been able to reach terms since then. Motorola and RIM have been suing each other in recent years.

Thursday, January 14, 2010

Surge in e-crimes in Dubai

Sixty-two per cent of phishing in the UAE last year targeted local banks
Surge in e-crimes in DubaiSixty-two per cent of phishing in the UAE last year targeted local banks
By Sharmila Dhal, Senior Reporter Published

Dubai Most cyber attacks in the UAE last year targeted banks and were perpetrated by electronic criminals from outside the country, a government report has revealed, adding that the number of hacking and defacement incidents quadrupled in 2009 from 2008.
It added that of all the electronic breaches during 2009, "phishing" comprised the main offence - 62 per cent of which targeted local banks, followed by UAE branches of international banks and other institutions at 19 per cent each.


Emergency plan
The report was presented by Mohammad Geyath, Executive Director, Technology Development Affairs, Telecom Regulatory Authority (TRA), at the Crises and Emergency Management Conference in Abu Dhabi which concluded on Wednesday. The report was put together by the Computer Emergency Response Team (CERT), a consultative body that advises TRA. The total number of cyber-related offences recorded by CERT was 51 in 2009, up from 47 in 2008, while incidents of phishing and defacement had increased to 26 in 2009, from six in 2008.
Meanwhile, the TRA announced at the conference an Emergency Plan for the country's telecom sector. Making the announcement Mohammad Nasser Al Ganem, Director-General of TRA, said the plan has been developed in co-operation with the National Crisis and Emergency Management Authority (NCEMA) and in consultation with key stake-holders, telecom operators and service providers.
Designed to protect critical infrastructure for communications, the plan encompasses various stages to deal with crises which cover all aspects of security and protection on the one hand and the preservation of a sustainable network during emergencies on the other.
Earlier, Richard Clarke, former security adviser to the US government, said of all the future risks that the world faces today, the threat of a cyber war could not be wished away, just as the potential crises arising out of climate change and pandemic diseases.

Global issue
He said nations need to ask themselves what national functions depend on cyberspace and conduct an analysis of the risks such utilities as power, water, banking, airports and oil supplies face.
He said countries should spend time to put audits and back-up systems in place to meet any contingency.
"Somewhere on the curve of low probability and high consequence, we should be prepared to spend time on these matters," he said, pointing to cyber wars in some parts of the world like Estonia and Georgia.

Telecom Emergency Plan Announced
Meanwhile the TRA has announced an Emergency Plan for the country's telecom sector.
Making the announcement at the concluding day of the Crises and Emergency Management Conference in Abu Dhabi on Wednesday, Mohammad Nasser Al Ganem, Director-General of TRA, said the plan has been developed in co-operation with the National Crisis and Emergency Management Authority (NCEMA) and in consultation with key stake-holders, telecom operators and service providers.
Designed to protect critical infrastructure for communications, the plan encompasses various stages to deal with crises which cover all aspects of security and protection on the one hand and the preservation of a sustainable network during emergencies on the other.
The stages covered include prevention, preparedness, response and recovery.
Earlier, Richard Clarke, former security adviser to the United States government, said of all the future risks that the world faces today, the threat of a cyber war could not be wished away, just as the potential crises arising out of climate change and pandemic diseases.
He said nations need to ask themselves what national functions depend on cyberspace and conduct an analysis of the risks such utilities as power, water, banking, airports and oil supplies face.
He said countries should spend time to put audits and back-up systems in place to meet any contingency. "Somewhere on the curve of low probability and high consequence, we should be prepared to spend time on these matters," he said, pointing to cyber wars that had proven to be a reality in some parts of the world like Estonia and Georgia.


Wednesday, October 28, 2009

Microsoft Office 2010 Beta 2 Leaks, Public Beta Expected in November













After Microsoft announced yesterday that Visual Studio 2010 Beta 2 will be sent to testers this week, more exciting news comes from the Office 2010 section. Microsoft has announced that an Office 2010 public beta will be available sometime in November.
Office 2010 has be noted as a “hybridization” of applications. It’s available on your PC, in a web browser *Office Web Apps”, and in Windows Mobile as Office Mobile. Currently, only the
Office Web Apps are available; but to a select group.
According to the Wzor website, Office 2010 build 14.0.4514.1009 will be the build Microsoft will officially release as Beta 2 to attendees of the Tech-Ed Conference in Berlin, November 6, 2009.
Among things, this build features a new installation procedure, which requires you to enter a unique installation product key. Bad news for pirates.






Saturday, October 17, 2009

D-Roll






Modern gadgets apart from being stylish are getting smaller day-by-day. And the latest creation to catch our eye is the ‘next gen laptop design’ by Hao Hua. Dubbed “D-roll” or “digital roll,” the new device works like a regular laptop, but rolls up to be a side bag or even a backpack for easy transportation. Designed like an artist’s tube, the D-roll Laptop features a roll up OLED screen and a slide out keyboard, together with a mouse and a detachable webcam that can be worn on your wrist when not attached to the system. The mouse and web camera can also be used as the end caps for the laptop case, while the straps double as ports to plug in your USB devices.






Thursday, October 15, 2009

Delete Files in C:\Windows\Installer

I was shocked when found out free space in my C drive is only 94MB left. At first I thought it was because of a virus attack so I did run virus scan on my computer but got negative result. So I run disk space analyzer and here is the result.

As you can see, 7GB space has been occupied by Installer folder in my C drive. But is it safe to remove all those files from my system?
The answer is Yes! But in the future, you might having trouble when want to remove installed programs completely. This is because, C:\Windows\Installer contains a copy of changed system info when you install a program using the Windows installer. With this file, your system can restore back to its original condition when you remove the program using the Add/Remove Programs.
But in my situation, I don’t care with the problem or trouble or anything because what I want is the free space in my C drive. So what I did was,


1. I downloaded and installed Windows Installer CleanUp Utility.


2. Go to Start > Run and type,Add Image


“C:\Program Files\Windows Installer Clean Up\msizap.exe”


3. Click Ok.
Then I wait until Windows Installer CleanUp Utility finished doing its job. And here is the result,



I have 4GB of free space available in my C drive. Yay!

Warning! The command that I give here might corrupt your system and requires to reinstall or repair.

Monday, October 12, 2009

Microsoft’s U.K. Domain was Hacked!

Looks like the official Microsoft U.K. Domain was attacked and defaced by a hacker identified as rEmOtEr. Microsoft confirmed that the hack has been successful.

rEmOtEr altered a webpage in the Microsoft.co.uk domain with two images and multiple references to the kingdom of Saudi Arabia. The U.K. branch of the Redmond company managed to fix the problem, and the functionality of the website is back to normal parameters. The webpagehacked dealt with Microsoft events and can be found here. In the adjacent image you can see how the hacker defaced the page, courtesy of Zone-H.

Roger Halbheer, chief security advisor for Microsoft in Europe, the Middle East and Africa admitted that the hack was successful and revealed that the whole event was unfortunate. According to Microsoft, no sensitive information was compromised in the attack. This is a clear indication that the hack was done for show, rather than to actually cause any harm. Another argument that supports such a scenario is the fact that rEmOtEr took time to document the hack in two separate video fragments. You will be able to watch for yourselves the live hacking via the two “remoter_vs_microsoft.avi” files.
The hack was possible mainly because of the fact that the database was allowed to return error messages explained Halbheer, as cited by InfoWorld. The attack was possible through a technique referred to as SQL injection. This fact is also confirmed by the hacker in the two videos that were made available. Via Structured Query Language injection rEmOtEr was able to gain access to the database. In the video fragments you will be able to see how easy the hacker obtains both usernames and passwords for the database. Working his way from error message to error message, rEmOtEr finally could switch from SQL queries with an unexpected form to direct instructions to the database.

Asbestos Cancer Asbestos Cancer