<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>MSMVPS.COM</title><link>http://msmvps.com/blogs/</link><description>The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Tighter security coming in Firefox 4 - (Including silent updates?)</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/tighter-security-coming-in-firefox-4.aspx</link><pubDate>Sat, 31 Jul 2010 19:35:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775108</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;A new JavaScript engine, HTML5, tabs on top, and a new add-on framework are not the only improvements that users can expect in Firefox 4. At Black Hat on Wednesday, a trio of security representatives from Mozilla detailed how the company plans to push the browser to be more secure for users while nudging developers toward safer coding practices. &lt;/p&gt;    &lt;p&gt;One of the biggest fixes that&amp;#39;s been implemented in the Firefox 4 beta (Windows | Mac | Linux) repairs a hole that affects all browsers, a decade-old vulnerability that was mentioned in the documentation for CSS2. The exploit is a CSS sniffing history attack, where malicious code can gain access to your browser history by manipulating link appearance and style. What made the bug so difficult to repair is that the simplest solution, to prevent all link style manipulation, would be like throwing the baby out with the bathwater, said Firefox&amp;#39;s director of development, Jonathan Nightingale. Changing an already-visited link&amp;#39;s colors is one the most-used features of the Web, and it would be catastrophic to prevent that. &lt;/p&gt;    &lt;p&gt;Mozilla&amp;#39;s David Baron figured out how to solve the problem with a three-pronged approach that focuses on the user instead of the Web site. His solution limits what aspect of links can be tweaked to color, then &amp;quot;lies&amp;quot; through JavaScript so that although the page queries the link and reports back what it would look like if it was unvisited, the one that Mozilla&amp;#39;s engine draws is the correct one, whether it&amp;#39;s been visited or not. This solution also limits the amount of computation that the rendering engine needs to do, said Nightingale, which allows the focus to remain on the content and reduces the overall &amp;quot;heavy lifting&amp;quot; required to render it properly. &amp;quot;By limiting the link, there&amp;#39;s fewer options for [link exploits that look like] dancing bananas.&amp;quot; &lt;/p&gt;    &lt;p&gt;Nightingale added that Wednesday&amp;#39;s release of Safari 5.0.1 has incorporated the fix. &lt;/p&gt;    &lt;p&gt;Another type of bug addressed in the Firefox 4 beta is an XSS primary scripting exploit.&amp;#160; [...] &lt;/p&gt;    &lt;p&gt;Other changes in Firefox 4 promise to be less technical. Firefox&amp;#39;s approach to browser updates is changing, and sounds like in some cases it will more closely resemble Google Chrome&amp;#39;s automatic updates. &amp;quot;There are updates that we want you to know about, and that you&amp;#39;ll have a choice to install or not, but there&amp;#39;s also updates that we just want to get our security patches out,&amp;quot; said Nightingale. Those silent updates will be rolled out first to Windows users because Windows experience the most security risks, he said, but Mac and Linux users will eventually see them, too. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;CNET &lt;a href="http://download.cnet.com/8301-2007_4-20012280-12.html"&gt;Download&lt;/a&gt; Blog&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775108" width="1" height="1"&gt;</description></item><item><title>Tool will test for phone bugs - Airprobe</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/tool-will-test-for-phone-bugs-airprobe.aspx</link><pubDate>Sat, 31 Jul 2010 19:06:31 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775107</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;A researcher released software at the Black Hat conference on Thursday designed to let people test whether their calls on mobile phones can be eavesdropped on. &lt;/p&gt;    &lt;p&gt;The public availability of the software, dubbed Airprobe, means that anyone with the right hardware can snoop on other peoples&amp;#39; calls, unless the target telecommunications provider has deployed a patch that was standardized about two years ago by the GSMA, the trade association representing GSM (Global System for Mobile Communications) providers, including AT&amp;amp;T and T-Mobile in the United States. &lt;/p&gt;    &lt;p&gt;For more on this story, read &lt;a href="http://news.cnet.com/8301-27080_3-20012144-245.html"&gt;Can your calls be intercepted? This tool can tell&lt;/a&gt; on CNET News. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.zdnet.com/news/tool-will-test-for-phone-bugs/451528"&gt;ZDNet&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775107" width="1" height="1"&gt;</description></item><item><title>AirTight defends Wi-Fi WPA2 'vulnerability' claim</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/airtight-defends-wi-fi-wpa2-vulnerability-claim.aspx</link><pubDate>Sat, 31 Jul 2010 19:01:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775106</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;A &amp;quot;publicity stunt?&amp;quot; Major threat? Or easily contained? &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Executives at AirTight are defending their description of a little-known &amp;quot;vulnerability&amp;quot; in the 802.11 standard in the face of criticism following their demonstration of a Wi-Fi exploit at the Black Hat security conference. One WLAN vendor called the claim a &amp;quot;publicity stunt.&amp;quot; &lt;/p&gt;    &lt;p&gt;Others are saying the attack, which can only be mounted by an internal authorized WLAN user, is so limited in scope that it would be easier for an attacker to just use the unattended computer in a neighbor&amp;#39;s cubicle or even bribe a fellow employee to access data. &lt;/p&gt;    &lt;p&gt;&amp;quot;What those limitations really mean is that &amp;#39;YES&amp;#39; there are much easier ways to get the data,&amp;quot; says Jennifer Jabbusch, chief information security officer, Carolina Advanced Digital, a Cary, N.C. IT services company. &amp;quot;In a scenario like this, that data is most likely (more than 99.9% likely) to be [already] unencrypted on the wire. In addition to that, the close physical proximity [required] would mean an attacker could also just as easily walk over to the victim&amp;#39;s machine and load a tool to collect data while they&amp;#39;re at lunch or getting a soda in the break room. The wireless attack is &amp;#39;going around your butt to get to your elbow,&amp;#39; as we say in the South.&amp;quot; &lt;/p&gt;    &lt;p&gt;She analyzed the AirTight exploit previously in her &lt;a href="http://securityuncorked.com/2010/07/smoke-and-mirrors-the-upcoming-defcon-wpa2-crack/"&gt;SecurityUncorked blog&lt;/a&gt;.&amp;#160; &lt;/p&gt;    &lt;p&gt;WLAN vendor Aruba Networks issued its own &lt;a href="http://airheads.arubanetworks.com/article/aruba-analysis-hole-196-wpa2-attack"&gt;analysis&lt;/a&gt;, by Robbie Gill of the company&amp;#39;s engineering department, which concluded, &amp;quot;The attack scenario described by AirTight is well known and old news – it was, in short, a publicity stunt.&amp;quot; &lt;/p&gt;    &lt;p&gt;Yesterday&amp;#39;s detailed demonstration at Black Hat Arsenal, a demo area associated with the Black Hat info security conference, confirmed nearly all of the details that Jabbusch and others had been expecting. [See: &amp;quot;&lt;a href="https://www.networkworld.com/news/2010/072810-wif--wpa2-vulnerability-faq.html"&gt;Wi-Fi WPA2 vulnerability FAQ&lt;/a&gt;&amp;quot;.] It did little to convince observers that the exploit constituted a serious threat to enterprise wireless LAN security. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.networkworld.com/news/2010/073010-airtight-wpa2-vulnerability.html"&gt;NetworkWorld&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775106" width="1" height="1"&gt;</description></item><item><title>Dell Tech Swipes Nude Photos of Gullible Customer</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/dell-tech-swipes-nude-photos-of-gullible-customer.aspx</link><pubDate>Sat, 31 Jul 2010 18:32:45 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775104</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Dell is apparently eager to compete with Best Buy and Walmart for the title of most despised retailer in the country. A few months back, a tech support rep got in trouble for turning on a woman&amp;#39;s webcam without her permission. Then, last month, the company got nabbed knowingly shipping faulty PCs. And, just this week, the Texas-based manufacturer was caught shipping motherboards infected with malware. Now, a woman from California is alleging that a support &lt;a href="http://abclocal.go.com/kgo/story?section=news/state&amp;amp;id=7581408"&gt;technician for Dell stole nude photos&lt;/a&gt; of her from her PC and posted them online, and then charged $800 worth of computer gear to her credit card for another woman in Tennessee. &lt;/p&gt;    &lt;p&gt;This is not a cut-and-dry case of a misbehaving tech rep, though. This drama has actually been going on for almost a year, and only now is Tara Fitzgerald coming forward with her accusations. Try and follow the sequence of events, and make sense of Fitzgerald&amp;#39;s often questionable judgment. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.switched.com/2010/07/31/dell-tech-swipes-nude-photos-of-gullible-customer/"&gt;Switched&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Did Dell tech support display woman&amp;#39;s naked pics?&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Fitzgerald wanted to send some pictures of herself to her boyfriend, but she couldn&amp;#39;t find them on her Dell computer. &lt;/p&gt;    &lt;p&gt;Her urgent need to find these pictures drove her, quite naturally, to call Dell tech support. Her call was answered, she said, by a gentleman in Mumbai, India, named Riyaz Shaikh. &lt;/p&gt;    &lt;p&gt;Shaikh, who, by the time you finish this tale, might not turn out to be a gentleman, after all, offered to remotely access her computer so that he could find the pictures for her. Fitzgerald said she watched him as he located her snapshots. &lt;/p&gt;    &lt;p&gt;It was another fine day in the helpful history of tech support. However, this success was ruined somewhat, when Fitzgerald allegedly received an e-mail from an unidentified source telling her that her pictures were now freely available for anyone to see on the Web. They were on a site called &amp;quot;bitchtara.&amp;quot; [...] &lt;/p&gt;    &lt;p&gt;News10 contacted Dell, it &lt;a href="http://www.news10.net/news/local/story.aspx?storyid=88496"&gt;received the following reply&lt;/a&gt;: &amp;quot;We investigated the issue, which involved a technical representative at one of Dell&amp;#39;s vendors. We contacted the vendor about the allegation and can confirm that the representative no longer handles Dell calls. We&amp;#39;ve been in contact with Ms. Fitzgerald regarding this issue and continue to investigate her claims to best assist in a resolution.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://news.cnet.com/8301-17852_3-20012250-71.html"&gt;CNET&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775104" width="1" height="1"&gt;</description></item><item><title>Sites Feed Personal Details To New Tracking Industry</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/sites-feed-personal-details-to-new-tracking-industry.aspx</link><pubDate>Sat, 31 Jul 2010 18:27:30 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775100</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;The largest U.S. websites are installing new and intrusive consumer-tracking technologies on the computers of people visiting their sites—in some cases, more than 100 tracking tools at a time—a Wall Street Journal investigation has found.&lt;/p&gt;    &lt;p&gt;The tracking files represent the leading edge of a lightly regulated, emerging industry of data-gatherers who are in effect establishing a new business model for the Internet: one based on intensive surveillance of people to sell data about, and predictions of, their interests and activities, in real time. &lt;/p&gt;    &lt;p&gt;The Journal&amp;#39;s study shows the extent to which Web users are in effect exchanging personal data for the broad access to information and services that is a defining feature of the Internet. &lt;/p&gt;    &lt;p&gt;In an effort to quantify the reach and sophistication of the tracking industry, the Journal examined the 50 most popular websites in the U.S. to measure the quantity and capabilities of the &amp;quot;cookies,&amp;quot; &amp;quot;beacons&amp;quot; and other trackers installed on a visitor&amp;#39;s computer by each site. Together, the 50 sites account for roughly 40% of U.S. page-views.&lt;/p&gt;    &lt;p&gt;The 50 sites installed a total of 3,180 tracking files on a test computer used to conduct the study. Only one site, the encyclopedia Wikipedia.org, installed none. Twelve sites, including IAC/InterActive Corp.&amp;#39;s Dictionary.com, Comcast Corp.&amp;#39;s Comcast.net and Microsoft Corp.&amp;#39;s MSN.com, installed more than 100 tracking tools apiece in the course of the Journal&amp;#39;s test. &lt;/p&gt;    &lt;p&gt;The Journal also surveyed its own site, WSJ.com, which doesn&amp;#39;t rank among the top 50 by visitors. WSJ.com installed 60 tracking files, slightly below the 64 average for the top 50 sites.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://online.wsj.com/article/SB10001424052748703977004575393173432219064.html"&gt;The Wall Street Journal&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If you use IE, enable &amp;quot;&lt;a href="http://www.brighthub.com/computing/smb-security/articles/35547.aspx"&gt;InPrivate Filtering&lt;/a&gt;&amp;quot; &lt;/p&gt;  &lt;p&gt;Use Hosts file to block ads.&amp;#160; Use &lt;a href="http://adblockplus.org/"&gt;Adblock Plus&lt;/a&gt; for FF or use &lt;a href="http://adblockie.codeplex.com/"&gt;AdBlock IE&lt;/a&gt; for IE&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775100" width="1" height="1"&gt;</description></item><item><title>Texas Imperial Software DefCon 18 challenge</title><link>http://msmvps.com/blogs/alunj/archive/2010/07/31/1775095.aspx</link><pubDate>Sat, 31 Jul 2010 16:23:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775095</guid><dc:creator>Alun Jones</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/alunj.metablogapi/4150.MVPMugShot2_5F00_0CD6C41B.jpg"&gt;&lt;img height="104" width="82" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/alunj.metablogapi/5633.MVPMugShot2_5F00_thumb_5F00_0472EEC4.jpg" align="left" alt="MVP Mug Shot 2" border="0" title="MVP Mug Shot 2" class="wlDisabledImage" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt;&lt;/a&gt;I rarely write about my business on the blog here, and perhaps I should do so some more.&lt;/p&gt;
&lt;p&gt;I mentioned in the &lt;a href="http://msmvps.com/blogs/alunj/archive/2010/07/31/1775061.aspx"&gt;post earlier today&lt;/a&gt; of how I&amp;rsquo;d &amp;ldquo;hacked&amp;rdquo; my badge (&amp;ldquo;hacked&amp;rdquo; in the sense of &amp;ldquo;that&amp;rsquo;s not programming, that&amp;rsquo;s typing&amp;rdquo;) to display the Texas Imperial Software and WFTPD logos, and the &lt;a href="http://www.wftpd.com"&gt;wftpd.com&lt;/a&gt; domain hosting our web site.&lt;/p&gt;
&lt;p&gt;Also, that I&amp;rsquo;ll be wearing my bright orange Texas Imperial Software t-shirt.&lt;/p&gt;
&lt;p&gt;So, here&amp;rsquo;s the competition:&lt;/p&gt;
&lt;p&gt;Take a photo of the Texas Imperial Software logo either from my shirt or my badge, post it to your blog (or other web-site), along with a description of where you saw me, and a link to Texas Imperial Software&amp;rsquo;s web site, &lt;a href="http://www.wftpd.com"&gt;http://www.wftpd.com&lt;/a&gt;, send me an email with a link to your site, and when I get back to the office, I&amp;rsquo;ll email you a free copy of WFTPD Pro &amp;ndash; and as long as your page stays there for six months, you&amp;rsquo;ll get free updates the same as the rest of our customers.&lt;/p&gt;
&lt;p&gt;What can you do with the free copy of WFTPD Pro? You can host your own secured FTP server, using the FTP over TLS protocol defined in &lt;a href="http://www.rfc-editor.org/rfc/rfc4217.txt"&gt;RFC 4217&lt;/a&gt;, and also known as FTPS. Of course, what I&amp;rsquo;m guessing you&amp;rsquo;re going to do is hack on it &amp;ndash; and that&amp;rsquo;s OK, providing that you notify me by email &lt;span style="text-decoration:underline;"&gt;before(*)&lt;/span&gt; publishing your results. If you turn that hacking into a paper for a con, give me the opportunity to support your presentation, whether that&amp;rsquo;s with rebuttal, fixes, or mere apologies (sorry, can&amp;rsquo;t afford money).&lt;/p&gt;
&lt;p&gt;The closest thing I have to a catch for this is that it has to be your own unique photo &amp;ndash; I&amp;rsquo;ll be comparing all submissions for similarity, and the best way to avoid duplicates is to have someone else take the photo for you, and put yourself in the picture. And don&amp;rsquo;t forget, &lt;strong&gt;&lt;span style="text-decoration:underline;"&gt;I don&amp;rsquo;t read your blog&lt;/span&gt;&lt;/strong&gt;, so you have to email me a link to it.&lt;/p&gt;
&lt;p&gt;Thanks for participating,&lt;/p&gt;
&lt;p&gt;Alun. &lt;br /&gt;~~~~&lt;/p&gt;
&lt;p&gt;(*) I&amp;rsquo;d prefer the Google-recommended sixty days to fix stuff, but if you&amp;rsquo;re the kind of hacker who believes all vendors need public spanking, then by all means post immediately after emailing me. After all, it&amp;rsquo;s not like you couldn&amp;rsquo;t do that with the trial version anyway. But if you do that, I&amp;rsquo;ll be all grumpy about it, and won&amp;rsquo;t buy you a drink next time I see you.
&lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:3c5fc79f-28bc-43cb-93d4-c9791de79ebe" style="padding-bottom:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;float:none;padding-top:0px;"&gt;Technorati Tags: &lt;a rel="tag" href="http://technorati.com/tags/defcon"&gt;defcon&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/defcon+18"&gt;defcon 18&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/ftp"&gt;ftp&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/wftpd"&gt;wftpd&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/free"&gt;free&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/ftps"&gt;ftps&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/Texas+Imperial+Software"&gt;Texas Imperial Software&lt;/a&gt;&lt;/div&gt;
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775095" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/alunj/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/FTP/default.aspx">FTP</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/Miscellany+-+not+security/default.aspx">Miscellany - not security</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/What+my+wife+knows/default.aspx">What my wife knows</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/Alun_2700_s+code/default.aspx">Alun's code</category></item><item><title>Sauvez le musée Français de la photographie à Bievres</title><link>http://msmvps.com/blogs/mtoo/archive/2010/07/31/sauvez-le-mus-233-e-fran-231-ais-de-la-photographie-224-bievres.aspx</link><pubDate>Sat, 31 Jul 2010 15:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1773209</guid><dc:creator>Mtoo</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/mtoo.metablogapi/7851.image_5F00_07C3637A.png"&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" class="wlDisabledImage" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/mtoo.metablogapi/0488.image_5F00_thumb_5F00_7A10A771.png" width="240" height="128" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Le Musée Français de la Photographie a vu le jour à Bièvres (91) en 1964&lt;/strong&gt;, grâce à l&amp;#39;ingénieur français &lt;strong&gt;Jean Fage&lt;/strong&gt; et à son fils &lt;strong&gt;André Fage&lt;/strong&gt;, dans le but de présenter au public une collection d&amp;#39;appareils photo, d&amp;#39;accessoires et d&amp;#39;images, patiemment constituée depuis le début des années 50. &lt;strong&gt;La même année, Jean Fage crée l&amp;#39;Association du Musée Français de la Photographie&lt;/strong&gt;, une association Loi de 1901 dont l&amp;#39;objet est de fédérer l&amp;#39;action de nombreux passionnés de l&amp;#39;image, sensibles à la dimension historique de la photographie.&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/mtoo.metablogapi/7532.image_5F00_29EB4933.png"&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" class="wlDisabledImage" title="image" border="0" alt="image" align="right" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/mtoo.metablogapi/8831.image_5F00_thumb_5F00_18971FF6.png" width="256" height="336" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Sous l&amp;#39;impulsion de Jean Fage, l&amp;#39;association a accéléré le développement de la collection, qu&amp;#39;il s&amp;#39;agisse de matériels photographiques ou d&amp;#39;images, notamment grâce à l&amp;#39;apport de collections privées individuelles, dont les propriétaires ou les héritiers ont souhaité se joindre au mouvement engagé par les deux fondateurs du Musée. En 1983, une commission d&amp;#39;experts internationaux, mandatée pour formuler un avis sur la &lt;strong&gt;collection du Musée Français de la Photographie&lt;/strong&gt;, a considéré que l&amp;#39;ensemble d&amp;#39;appareils photographiques qui lui a été montré &lt;strong&gt;constitue par sa qualité et sa quantité l&amp;#39;une des plus importantes collections publiques connues dans le monde&lt;/strong&gt;. La commission a également remarqué que cette collection est particulièrement représentative des dernières décennies du XIXe siècle et du XXe tout entier. Enfin, elle a souligné que l&amp;#39;ensemble constitué par les appareils français représente à lui seul une collection unique au monde. &lt;/p&gt;  &lt;p&gt;Toutefois, ce patrimoine de grande valeur reste en grande partie méconnu. Car les locaux actuels du Musée Français de la Photographie, situés à Bièvres, en région parisienne, ne peuvent exposer qu&amp;#39;environ 10% de l&amp;#39;ensemble de la collection. La majeure partie de cet héritage unique reste donc encore aujourd&amp;#39;hui à l&amp;#39;écart des yeux du public. Les membres de l&amp;#39;Association du Musée Français de la Photographie, qui prolongent aujourd&amp;#39;hui l&amp;#39;action de Jean et André Fage, consacrent donc leur énergie à faire prendre conscience au public, comme aux autorités compétentes, de l&amp;#39;immense trésor historique que représente la collection. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Le souhait de l&amp;#39;Association est de donner enfin à la collection Fage l&amp;#39;écrin qu&amp;#39;elle mérite, conformément à la volonté exprimée par Jean Fage. Aujourd&amp;#39;hui, toutefois, des projets en cours se voient remis en question, faisant planer un doute pour l&amp;#39;avenir. La construction d&amp;#39;un musée suffisamment vaste, localisé sur la commune de Bièvres, carrefour historique de la photographie, apparaît pourtant aujourd&amp;#39;hui comme le seul moyen légitime de faire vivre la collection initiée par Jean et André Fage, témoin indispensable de l&amp;#39;Histoire de la photographie, comme de celle du XIXe et du XXe siècle, dont elle est le reflet indissociable.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Pour aider le musée à rester à Bievres, signez la pétition ici : &lt;a title="http://www.visuelab.com/asso-photo-bievres.fr/petitionreader.pdf" href="http://www.visuelab.com/asso-photo-bievres.fr/petitionreader.pdf"&gt;http://www.visuelab.com/asso-photo-bievres.fr/petitionreader.pdf&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;br /&gt;  &lt;p&gt;Le site de l’association du musée est ici : &lt;a title="http://www.visuelab.com/asso-photo-bievres.fr/" href="http://www.visuelab.com/asso-photo-bievres.fr/"&gt;http://www.visuelab.com/asso-photo-bievres.fr/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Le site Facebook ici : &lt;a title="http://www.facebook.com/pages/Association-du-Musee-Francais-de-la-Photographie/104827469548363?v=info" href="http://www.facebook.com/pages/Association-du-Musee-Francais-de-la-Photographie/104827469548363?v=info"&gt;http://www.facebook.com/pages/Association-du-Musee-Francais-de-la-Photographie/104827469548363?v=info&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Laurent Gébeau&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1773209" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/mtoo/archive/tags/photo/default.aspx">photo</category><category domain="http://msmvps.com/blogs/mtoo/archive/tags/pentax/default.aspx">pentax</category></item><item><title>I’m at DefCon–what’s on your badge?</title><link>http://msmvps.com/blogs/alunj/archive/2010/07/31/1775061.aspx</link><pubDate>Sat, 31 Jul 2010 12:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775061</guid><dc:creator>Alun Jones</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;I&amp;rsquo;ve been at DefCon 18&amp;nbsp;for some of Friday &amp;ndash; and as with Black Hat, it&amp;rsquo;s my first time.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve decoded the bar code on the badge, but have no idea what it means (is it the name of Vera&amp;rsquo;s brother?), and I&amp;rsquo;ve got a fair idea what the Japanese text is encouraging us to do.&lt;/p&gt;
&lt;p&gt;And, just to demonstrate that I can follow simple instructions, you&amp;rsquo;ll notice that my badge doesn&amp;rsquo;t look like your badge:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/alunj.metablogapi/7380.P1010057_5F00_058B89C4.jpg"&gt;&lt;img height="484" width="644" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/alunj.metablogapi/2480.P1010057_5F00_thumb_5F00_0A21947E.jpg" alt="P1010057" border="0" title="P1010057" class="wlDisabledImage" style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I should add that this isn&amp;rsquo;t anything particularly clever that I&amp;rsquo;ve done here, I haven&amp;rsquo;t solved any riddles or puzzled my way through anything, just managed to read some relatively simple (but somewhat code-ish) instructions. I hope to see many of you with similarly customised badges. &lt;/p&gt;
&lt;p&gt;In recognition of the graphics I have on my badge, I&amp;rsquo;ll be wearing my &lt;a href="http://www.wftpd.com" title="Texas Imperial Software - wftpd.com"&gt;Texas Imperial Software&lt;/a&gt; shirt on Saturday, too.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s an even tighter close-up:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/alunj.metablogapi/3566.P1010058_5F00_01BDBF27.jpg"&gt;&lt;img height="484" width="644" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/alunj.metablogapi/5633.P1010058_5F00_thumb_5F00_6DC42C90.jpg" alt="P1010058" border="0" title="P1010058" class="wlDisabledImage" style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775061" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/alunj/archive/tags/Miscellany+-+not+security/default.aspx">Miscellany - not security</category></item><item><title>Know thy customer</title><link>http://msmvps.com/blogs/shareblog/archive/2010/07/31/know-thy-customer.aspx</link><pubDate>Sat, 31 Jul 2010 11:42:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775082</guid><dc:creator>gary</dc:creator><slash:comments>0</slash:comments><description>I was reading an excellent article by David S. Platt called &amp;quot; Using WPF for Good and Not Evil &amp;quot; in which he takes a sample application written to show off Windows Presentation Foundation (WPF) and tells what he feels are the good and bad points of the program. One thing that I read that really resonated with me was &amp;quot;Platt&amp;rsquo;s First, Last, and Only Law of User Experience Design states, &amp;ldquo;KNOW THY USER, FOR HE IS NOT THEE.&amp;rdquo; &amp;quot; He wrote this about software developers...(&lt;a href="http://msmvps.com/blogs/shareblog/archive/2010/07/31/know-thy-customer.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775082" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shareblog/archive/tags/Misc/default.aspx">Misc</category></item><item><title>Business ISP Star UK Finds Workers Use Office Internet for Personal Stuff</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/business-isp-star-uk-finds-workers-use-office-internet-for-personal-stuff.aspx</link><pubDate>Sat, 31 Jul 2010 09:42:26 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775070</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;The latest independent survey of 1,000 workers from business ISP Star UK has found that 72% of British workers spend their lunch hour online and performing activities like shopping, banking, catching up with the latest sport or chatting to their friends on email or Facebook. &lt;/p&gt;    &lt;p&gt;The research was conducted after Star noticed that the network bandwidth usage for business Internet traffic in their data centres was consistently peaking between 12:00 – 14:00hrs, which is normally when British workers should be enjoying their lunch breaks. &lt;/p&gt;    &lt;p&gt;The most popular lunchtime habits for 63% of people are checking their personal email accounts, engaging in online shopping and banking (62%), and 31% catch up with friends on social networking sites like Facebook – unsurprisingly this trend was higher ( 40%) for younger workers between the ages of 16 to 34 years. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.ispreview.co.uk/story/2010/07/31/business-isp-star-uk-finds-workers-use-office-internet-for-personal-stuff.html"&gt;ISPReview&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775070" width="1" height="1"&gt;</description></item><item><title>Farmville Will Get You in Trouble with IT Police</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/farmville-will-get-you-in-trouble-with-it-police.aspx</link><pubDate>Sat, 31 Jul 2010 09:39:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775069</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Farmville is arguably the biggest social game the world has seen. Well, maybe that&amp;#39;s a bit much, but it is a popular game. It so popular in fact, that many people will play it at work. However, doing so might get you into trouble with the IT police. &lt;/p&gt;    &lt;p&gt;According to a security report by Cisco, employees are breaking company policies by playing social networking games, and, by doing so, could be opening up networks to outside attacks. &lt;/p&gt;    &lt;p&gt;Cisco&amp;#39;s 2010 Midyear Report found that 7-percent of those who admitted to using Facebook at work also fessed up to spending an average of 68 minutes each day playing &amp;#39;FarmVille.&amp;#39; &lt;/p&gt;    &lt;p&gt;FarmVille isn&amp;#39;t the only game Facebookers play, as they are also sucked up into playing &amp;#39;Mafia Wars&amp;#39; (5-percent for 52 minutes each day) and &amp;#39;Cafe World&amp;#39; (4-percent for 36 minutes each day). &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://technorati.com/blogging/article/farmville-will-get-you-in-trouble/"&gt;Technorati&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775069" width="1" height="1"&gt;</description></item><item><title>Guard Dog Inc. Partners With Javacool Software LLC, Creators of Popular ‘SpywareBlaster’ Program</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/guard-dog-inc-partners-with-javacool-software-llc-creators-of-popular-spywareblaster-program.aspx</link><pubDate>Sat, 31 Jul 2010 09:37:30 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775068</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Guard Dog, Inc. today announces a significant advance in its mission to protect consumers with a truly complete level of security against threats of identity theft through a recent partnership with Javacool Software LLC (JCS). In keeping with the company’s commitment to provide the best protection and solutions against online identity theft threats JCS’s popular software, SpywareBlaster, will be provided to all Guard Dog members to help protect them online. &lt;/p&gt;    &lt;p&gt;“It has always been our primary objective to provide both current and future members of our identity theft protection service with the most comprehensive protection,” states Guard Dog Inc. Chief Executive Officer James Watson. “This partnership is one of many clear strategic moves towards Guard Dog achieving that objective. This is a never-ending process of building layers of protection and it is critical to include online partners in that process. SpywareBlaster is a proven anti-spyware, anti-malware system and when combined with Guard Dog’s unique, full-featured pro-active approach; the combination provides serious protection against identity theft.” &lt;/p&gt;    &lt;p&gt;There are many key features that make SpywareBlaster a perfect fit for the Guard Dog product line. SpywareBlaster works alongside any existing security software on a PC to help provide a strong “layered defense” against spyware, malware and other threats. It also prevents the installation of ActiveX-based spyware and other dangerous programs, blocks spying and tracking via cookies, and restricts the actions of potentially unwanted Web sites. Unlike many other security tools, the performance-friendly SpywareBlaster software does not remain running in the background to slow down your PC. &lt;/p&gt;    &lt;p&gt;“We are extremely pleased to announce our cooperative agreement with Guard Dog ID,” said a Javacool company spokesperson. “Over the years we have been approached by numerous companies that wanted to enter into a partnership program. The only one that was clearly in the best interests of our customers and our SpywareBlaster product was Guard Dog. We have been in talks with Guard Dog over the last three months and have a good understanding of their product and how SpywareBlaster fits into the equation. We are very excited to be a part of it.” &lt;/p&gt;    &lt;p&gt;With more than 60 million free downloads since the company’s launch in 2002, having this agreement with Javacool furthers the distance between Guard Dog ID and its competitors. The company now truly offers a full suite of comprehensive identity theft protection, including key protection against online threats. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.earthtimes.org/articles/press/creators-popular-lsquospywareblasterrsquo-program,1405693.html"&gt;EarthTimes&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775068" width="1" height="1"&gt;</description></item><item><title>FTC Issues Final Rule to Protect Consumers in Credit Card Debt</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/ftc-issues-final-rule-to-protect-consumers-in-credit-card-debt.aspx</link><pubDate>Sat, 31 Jul 2010 09:35:04 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775067</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Amendments to Telemarketing Sales Rule Prohibiting Debt Relief Companies From Collecting Advance Fees Will Take Effect in October 2010 &lt;/p&gt;    &lt;p&gt;Starting on October 27, 2010, for-profit companies that sell debt relief services over the telephone may no longer charge a fee before they settle or reduce a customer’s credit card or other unsecured debt. &lt;/p&gt;    &lt;p&gt;“At the FTC we strive every day to make sure America’s middle class families get straight deals for their dollars,” Chairman Jon Leibowitz said. “This rule will stop companies who offer consumers false promises of reducing credit card debts by half or more in exchange for large, up-front fees. Too many of these companies pick the last dollar out of consumers’ pockets – and far from leaving them better off, push them deeper into debt, even bankruptcy.” &lt;/p&gt;    &lt;p&gt;Three other Telemarketing Sales Rule provisions to take effect on September 27, 2010, will: &lt;/p&gt;    &lt;p&gt;require debt relief companies to make specific disclosures to consumers;     &lt;br /&gt;prohibit them from making misrepresentations; an       &lt;br /&gt;extend the Telemarketing Sales Rule to cover calls consumers make to these firms in response to debt relief advertising. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.ftc.gov/opa/2010/07/tsr.shtm"&gt;FTC&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775067" width="1" height="1"&gt;</description></item><item><title>FTC's List of Corporate Privacy Abusers Shows Advertisers Can't Be Trusted With Data Security</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/ftc-s-list-of-corporate-privacy-abusers-shows-advertisers-can-t-be-trusted-with-data-security.aspx</link><pubDate>Sat, 31 Jul 2010 09:32:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775066</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;The &lt;a href="http://www.ftc.gov/opa/2010/07/privacytest.shtm"&gt;FTC yesterday published a list of companies&lt;/a&gt; that used unfair, deceptive, false or misleading claims about consumer privacy that caused “substantial consumer injury,” and the names on it will surprise you. Sure, many of the companies are mortgage scammers and spam phishers. But lots of them are household and blue-chip brands such as Twitter, TJ Maxx (TJX), Microsoft (MSFT) and Dave &amp;amp; Busters. &lt;/p&gt;    &lt;p&gt;The list proves that advertisers cannot be trusted to regulate themselves when it comes to tracking and targeting consumers on the web or on mobile devices. There are currently few rules controlling how advertisers can use personal information gathered from consumers electronically, and if self regulation worked the FTC would not have brought action against these companies for privacy abuses (&lt;a href="http://www.ftc.gov/os/testimony/100727consumerprivacy.pdf"&gt;see pages 7 and 8&lt;/a&gt;): &lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;Twitter&lt;/li&gt;      &lt;li&gt;Dave &amp;amp; Buster’s&lt;/li&gt;      &lt;li&gt;LifeLock&lt;/li&gt;      &lt;li&gt;ValueClick&lt;/li&gt;      &lt;li&gt;CVS Caremark&lt;/li&gt;      &lt;li&gt;The TJX Cos. (TJ Maxx)&lt;/li&gt;      &lt;li&gt;Reed Elsevier&lt;/li&gt;      &lt;li&gt;DSW&lt;/li&gt;      &lt;li&gt;BJ’s Wholesale Club, Inc.&lt;/li&gt;      &lt;li&gt;Nationwide Mortgage Group&lt;/li&gt;      &lt;li&gt;Petco Animal Supplies&lt;/li&gt;      &lt;li&gt;Guess?&lt;/li&gt;      &lt;li&gt;Microsoft Corp.&lt;/li&gt;      &lt;li&gt;Lexis Nexis &lt;/li&gt;   &lt;/ul&gt;    &lt;p&gt;In addition, the FTC has brought: &lt;/p&gt;    &lt;p&gt;… 15 actions charging website operators with collecting information from children without parents’ consent, as well as 15 spyware cases and dozens of actions challenging illegal spam, … &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.bnet.com/blog/advertising/ftcs-list-of-corporate-privacy-abusers-shows-advertisers-cant-be-trusted-with-data-security/7643"&gt;BNET&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775066" width="1" height="1"&gt;</description></item><item><title>Android dev rejects rogue app claims, still highlights risks</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/android-dev-rejects-rogue-app-claims-still-highlights-risks.aspx</link><pubDate>Sat, 31 Jul 2010 09:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775065</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Mobile app developer Jackeey Wu defended himself against claims of producing Android spyware apps today while also underscoring some of the risks of Google&amp;#39;s mobile OS. He noted that some of the permissions his Wallpapers allegedly requested, such as for the web browser history and SMS message records, aren&amp;#39;t in the actual app. As requesting private information automatically flags the app in Android Market before the install, it&amp;#39;s virtually impossible to collect such information in secret, Wu said. &lt;/p&gt;    &lt;p&gt;What few permissions Wu needs, such as basic phone access, are to help make features such as favorites work properly as a user changes devices. There&amp;#39;s no connection to user data, he said. &lt;/p&gt;    &lt;p&gt;Lookout, the research team that had first made the accusations, has since scaled back its claims and in an update said there wasn&amp;#39;t any evidence of rogue behavior. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.electronista.com/articles/10/07/30/android.app.maker.says.spyware.claim.false/"&gt;Electronista&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775065" width="1" height="1"&gt;</description></item><item><title>Commtouch to Acquire the Antivirus Division of Authentium‎</title><link>http://msmvps.com/blogs/donna/archive/2010/07/31/commtouch-to-acquire-the-antivirus-division-of-authentium.aspx</link><pubDate>Sat, 31 Jul 2010 09:24:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775064</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Commtouch today announced that it has signed a definitive Asset Purchase Agreement to acquire the assets, products, licenses, and operations of the Command antivirus division of Authentium, Inc., a Florida-based company. &lt;/p&gt;    &lt;p&gt;Command antivirus -- which also includes technology to protect against spyware, Trojan downloaders, and other threats -- is strongly synergetic with the rest of Commtouch&amp;#39;s product portfolio. With the addition of antivirus technology as a new, third product line, Commtouch will be offering a comprehensive set of solutions for inbound and outbound messaging and Web security to its customers, which are networking and security vendors and service providers. &lt;/p&gt;    &lt;p&gt;The Command antivirus division currently provides its technology to a notable number of leading service providers and vendors, including Google, McAfee, and Microsoft. Certified by Checkmark, West Coast Labs, and a winner of multiple Virus Bulletin awards, Authentium&amp;#39;s Command antivirus technology boasts a small footprint and a highly efficient event-processing system. &lt;/p&gt;    &lt;p&gt;Commtouch is expected to pay $4.6 million in cash and an additional &amp;quot;earnout&amp;quot; contingent upon the achievement of certain revenue milestones through December 31, 2011, which may bring the total amount to approximately $8 million. &lt;/p&gt;    &lt;p&gt;The acquisition is expected to be accretive starting the first quarter post-closing, and should contribute positively to Commtouch&amp;#39;s non-GAAP top and bottom line in 2011. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://pr-usa.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=446378&amp;amp;Itemid=28"&gt;PR-USA.net&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775064" width="1" height="1"&gt;</description></item><item><title>[MS Security Bulletins] "Out-of-Band" Release - 2nd August 2010</title><link>http://msmvps.com/blogs/chobbs/archive/2010/07/31/ms-security-bulletins-quot-out-of-band-quot-release-2nd-august-2010.aspx</link><pubDate>Sat, 31 Jul 2010 08:37:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775072</guid><dc:creator>Cliff Hobbs at myITforum.com</dc:creator><slash:comments>0</slash:comments><description>Looks like Microsoft are going to do an &amp;quot; out-of-band &amp;quot; for the following patch on Monday: This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on August 2, 2010. The full version of the Read More......(&lt;a href="http://msmvps.com/blogs/chobbs/archive/2010/07/31/ms-security-bulletins-quot-out-of-band-quot-release-2nd-august-2010.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775072" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/chobbs/archive/tags/General/default.aspx">General</category><category domain="http://msmvps.com/blogs/chobbs/archive/tags/MS+Security+Bulletins/default.aspx">MS Security Bulletins</category></item><item><title>Black Hat Amazon code question part 2</title><link>http://msmvps.com/blogs/alunj/archive/2010/07/31/1775060.aspx</link><pubDate>Sat, 31 Jul 2010 08:21:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775060</guid><dc:creator>Alun Jones</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Thanks for the comments so far on the first day’s code question at Black Hat.&lt;/p&gt;  &lt;p&gt;I’ll leave it a little while before posting the comments and answers, because it’ll give you a chance to think it through for yourself if you haven’t already done so.&lt;/p&gt;  &lt;p&gt;Meanwhile, here’s the code example for day 2. What’s wrong with it?&lt;/p&gt;  &lt;pre class="csharpcode"&gt;wchar_t *fillString(
    wchar_t content, unsigned &lt;span class="kwrd"&gt;int&lt;/span&gt; repeat)
{
    wchar_t *buffer;
    size_t size;
    &lt;span class="kwrd"&gt;if&lt;/span&gt; (repeat &amp;gt; 0x7fffffffe)
        &lt;span class="kwrd"&gt;return&lt;/span&gt; 0;
    size = ( repeat + 1 ) * &lt;span class="kwrd"&gt;sizeof&lt;/span&gt; content;
    buffer = (wchar_t *) malloc ( size );
    &lt;span class="kwrd"&gt;if&lt;/span&gt; ( buffer == 0 )
        &lt;span class="kwrd"&gt;return&lt;/span&gt; 0;
    wmemset(buffer, content, repeat);
    buffer[ repeat ] = 0;
    &lt;span class="kwrd"&gt;return&lt;/span&gt; buffer;
}&lt;/pre&gt;
The language is C++, and as with the previous example, assume that everything that is &lt;u&gt;not&lt;/u&gt; given above is perfect. 

&lt;p&gt;In case it is important, this was tested on an x86 system, although the flaw will also show up in x64. We were repeatedly asked that question.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775060" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/alunj/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/Programmer+Hubris/default.aspx">Programmer Hubris</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/Alun_2700_s+code/default.aspx">Alun's code</category></item><item><title>ALERT: Out of band security update to be released on August 2</title><link>http://msmvps.com/blogs/spywaresucks/archive/2010/07/31/1775049.aspx</link><pubDate>Sat, 31 Jul 2010 03:19:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775049</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Details here:   &lt;br /&gt;&lt;a title="http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx" target="_blank"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;“&lt;em&gt;This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on August 2, 2010. The bulletin addresses a security vulnerability in all supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2, &lt;strong&gt;&lt;u&gt;that is currently being exploited in malware attacks&lt;/u&gt;&lt;/strong&gt;.”&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Please install this patch as soon as you can once it is released.&lt;/p&gt;  &lt;p&gt;If you used the workaround to mitigate the vulnerability (that is, if your shortcuts look like this &lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4061.image_5F00_189A64BF.png" width="255" height="26" /&gt; or this &lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0576.image_5F00_1E779909.png" width="70" height="85" /&gt; , then you will need to undo that workaround before installing the security update.&lt;/p&gt;  &lt;p&gt;Microsoft released a “fixit” to automatically apply, or remove, the workaround that broke *.LNK files – you can find the “fixit” here:   &lt;br /&gt;&lt;a title="http://support.microsoft.com/kb/2286198" href="http://support.microsoft.com/kb/2286198" target="_blank"&gt;http://support.microsoft.com/kb/2286198&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775049" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category></item><item><title>System Center Configuration Manager en Windows 2008 R2</title><link>http://msmvps.com/blogs/leandroamore/archive/2010/07/30/system-center-configuration-manager-en-windows-2008-r2.aspx</link><pubDate>Sat, 31 Jul 2010 03:05:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775050</guid><dc:creator>Leandro Amore</dc:creator><slash:comments>0</slash:comments><description>A partir de SP2 esta soportada la instalación de SCCM en Windows 2008 R2. Pero tiene algunos problemas con el WebDav. Como sabrán, la versión de IIS en Windows 2008 es 7.0 y no incluye WebDav, sino que hay que bajarlo como un complemento adicional. En Read More......(&lt;a href="http://msmvps.com/blogs/leandroamore/archive/2010/07/30/system-center-configuration-manager-en-windows-2008-r2.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775050" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/leandroamore/archive/tags/SCCM/default.aspx">SCCM</category></item><item><title>New Tool Allows Websites To Keep Serving Pages After Infection</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/new-tool-allows-websites-to-keep-serving-pages-after-infection.aspx</link><pubDate>Fri, 30 Jul 2010 20:20:35 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775034</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;When Web pages are infected with malicious code, the current security practice is to block the entire page and warn users not to go there. But what if the infected page is on a legitimate site that needs that page up in order to do business? &lt;/p&gt;    &lt;p&gt;In a presentation here Wednesday, a Black Hat speaker proposed a new technology that strips out malware from infected Web pages, effectively allowing sites to continue to serve Web content even after a page has been infected. &lt;/p&gt;    &lt;p&gt;The new &amp;quot;mod_antimalware&amp;quot; Web server module, which is outlined in a &lt;a href="http://info.dasient.com/mod-anti-malware.html"&gt;white paper&lt;/a&gt; at Black Hat, is designed to recognize malware by its behavior on a website, says Neil Daswani, CTO of upstart security vendor Dasient and co-author of the paper. &lt;/p&gt;    &lt;p&gt;&amp;quot;When a PC gets infected with malware, you don&amp;#39;t tell the user to stop using it,&amp;quot; Daswani says. &amp;quot;But that&amp;#39;s basically what happens to Web pages that get infected -- the whole page is blocked, and your site may even be blacklisted, all because one element on one page is infected.&amp;quot; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Mod_antimalware&lt;/strong&gt; monitors Websites for malicious behavior, such as redirecting users to other sites or attempting to download Trojan horses, Daswani explains. It then identifies the code that instigated the malicious behavior and strips it off the page, allowing the rest of the Web content to continue being served safely. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.darkreading.com/smb-security/security/app-security/showArticle.jhtml?articleID=226400030"&gt;DarkReading&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775034" width="1" height="1"&gt;</description></item><item><title>Government rules out upgrading from Internet Explorer 6</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/government-rules-out-upgrading-from-internet-explorer-6.aspx</link><pubDate>Fri, 30 Jul 2010 20:14:32 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775033</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Government to persevere with browser despite high-profile vulnerabilities and advice from France and Germany &lt;/p&gt;    &lt;p&gt;The government has ruled out scrapping the use of Internet Explorer 6 on department computers, saying it will persevere with the bullet-riddled browser despite its high-profile vulnerabilities. &lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.hmg.gov.uk/epetition-responses/petition-view.aspx?epref=ie6upgrade"&gt;Responding&lt;/a&gt; to an &lt;a href="http://petitions.number10.gov.uk/ie6upgrade/"&gt;online petition&lt;/a&gt; with more than 6,000 signatures urging government departments to upgrade away from IE6, the government said such a move would be &amp;quot;a very large operation&amp;quot; potentially at &amp;quot;significant potential cost to the taxpayer&amp;quot;. &lt;/p&gt;    &lt;p&gt;&amp;quot;It is therefore more cost-effective in many cases to continue to use IE6 and rely on other measures, such as firewalls and malware-scanning software, to further protect public sector internet users,&amp;quot; reads the statement. &lt;/p&gt;    &lt;p&gt;The petition, set up by Dan Frydman, director of Inigo Media, launched the day after Google &lt;a href="http://googleenterprise.blogspot.com/2010/01/modern-browsers-for-modern-applications.html"&gt;announced it would be phasing out support&lt;/a&gt; for the Microsoft browser after the company&amp;#39;s corporate network was broken into by Chinese hackers using a vulnerability in IE6. The (pre-election) cabinet office signalled its intention to stick with IE6 in January this year, despite governments in both France and Germany advising people to stop using it. &lt;/p&gt;    &lt;p&gt;Frydman responded to today&amp;#39;s government decision on &lt;a href="http://danfrydman.com/the-ie6-petition-uk-government-and-developers/"&gt;his blog&lt;/a&gt;, expressing disappointment that the possibility of an upgrade across any department was ruled out so off-handedly. &amp;quot;What I was looking for was a recommendation to upgrade away from IE6,&amp;quot; he says. &amp;quot;A recommendation isn&amp;#39;t hard, it&amp;#39;s cheap and easy and isn&amp;#39;t an admission of guilt. It puts the onus on the government departments to modernise, to innovate and to take care of [on] their own. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.guardian.co.uk/technology/pda/2010/jul/30/internet-explorer-6-uk-government"&gt;Guardian.co.uk&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Well, you are putting your organization or department at RISK.&amp;#160; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775033" width="1" height="1"&gt;</description></item><item><title>Free Android apps scrape personal data, send it to China</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/free-android-apps-scrape-personal-data-send-it-to-china.aspx</link><pubDate>Fri, 30 Jul 2010 20:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775032</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Millions have downloaded &amp;#39;suspicious&amp;#39; wallpaper apps, says mobile security firm &lt;/p&gt;    &lt;p&gt;Between one and four million users of Android phones have downloaded wallpaper apps that swipe personal data from the phone and transmit it to a Chinese-owned server, a mobile security firm said today. &lt;/p&gt;    &lt;p&gt;According to San Francisco-based Lookout, a large number of free wallpaper apps in the Android Market scrape the phone number; the user-specific subscriber identifier, also know as the IMSI (International Mobile Subscriber Identity); the phone&amp;#39;s SIM card&amp;#39;s serial number; and the currently-entered voicemail number from the phone. &lt;/p&gt;    &lt;p&gt;That information is then transmitted to a server that Internet records show is registered to a resident of Shenzhen, a city in China&amp;#39;s Guangdong province, just north of Hong Kong. &lt;/p&gt;    &lt;p&gt;Over 80 wallpaper apps created by a pair of developers -- &amp;quot;callmejack&amp;quot; and &amp;quot;IceskYsl@1sters!&amp;quot; -- include code that accesses users&amp;#39; personal data, said Kevin Mahaffey, chief technology officer and a co-founder of Lookout. &lt;/p&gt;    &lt;p&gt;&amp;quot;All that is sent to a Chinese server in clear text,&amp;quot; said Mahaffey in an interview prior to Black Hat, where he and CEO John Hering presented findings of what the company called the &amp;quot;App Genome Project,&amp;quot; an attempt to analyze the code of some 300,000 applications available in the Android Market and Apple&amp;#39;s iPhone App Store. &lt;/p&gt;    &lt;p&gt;In a Friday entry on Lookout&amp;#39;s &lt;a href="http://blog.mylookout.com/2010/07/mobile-application-analysis-blackhat/"&gt;blog&lt;/a&gt;, Mahaffrey published pieces of the data-scraping code found in the wallpaper apps, as well as an example of the HTML request made to the Chinese server by those programs.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.computerworld.com/s/article/9179894/Free_Android_apps_scrape_personal_data_send_it_to_China?taxonomyId=75"&gt;ComputerWorld&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775032" width="1" height="1"&gt;</description></item><item><title>Is Twitter Less Secure Than E-mail?</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/is-twitter-less-secure-than-e-mail.aspx</link><pubDate>Fri, 30 Jul 2010 20:02:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775031</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Barracuda Networks is out this week with new research attempting to quantify how much malicious activity occurs on Twitter. Barracuda defines the Twitter &amp;quot;crime rate&amp;quot; as the percentage of accounts created per month that are eventually suspended by the company. &lt;/p&gt;    &lt;p&gt;Barracuda presented its research here at the BSides event, down the Strip from the Black Hat security conference. &lt;/p&gt;    &lt;p&gt;In total, Barracuda looked at more than 25 million accounts and found that the crime rate for the first half of 2010 is only 1.67 percent. Barracuda saw the crime rate on Twitter fluctuate from month to month, peaking in October 2009 when the rate checked in at 12 percent. &lt;/p&gt;    &lt;p&gt;David Maynor, a research scientist at Barracuda Networks, told InternetNews.com that Twitter has not published a rigid set of guidelines specifying why accounts are deleted, though spammers and phishers are likely candidates for deletion. &lt;/p&gt;    &lt;p&gt;While some Twitter accounts may have been set up by those with malicious intent, others may have been compromised by third-party applications, a situation Twitter is trying to address by moving to the OAuth. Maynor said that OAuth can be helpful, but won&amp;#39;t necessarily make much of a difference to the Twitter crime rate. &lt;/p&gt;    &lt;p&gt;&amp;quot;OAuth is the first step toward building a more secure infrastructure,&amp;quot; Maynor said. [...] &lt;/p&gt;    &lt;p&gt;Compared to other forms of online communications, Twitter&amp;#39;s crime rate ranks somewhere in the middle. &lt;/p&gt;    &lt;p&gt;&amp;quot;The crime rate on Twitter is more than it is on Facebook but less than it is on e-mail,&amp;quot; Judge said. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://itmanagement.earthweb.com/features/article.php/3896071/Is-Twitter-Less-Secure-Than-E-mail.htm"&gt;InternetNews&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775031" width="1" height="1"&gt;</description></item><item><title>Google tops comparative review of malicious search results</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/google-tops-comparative-review-of-malicious-search-results.aspx</link><pubDate>Fri, 30 Jul 2010 19:58:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775030</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;According to a newly released &lt;a href="http://www.barracudalabs.com/wordpress/index.php/2010/07/28/barracuda-labs-2010-midyear-security-report/"&gt;report by Barracuda Labs&lt;/a&gt;, based on a two-month study reviewing more than 25,000 trending topics and 5.5 million search results, Google remains the most popular search engine used by malicious attackers, relying on poisoned keywords. &lt;/p&gt;    &lt;p&gt;The company, which also sampled Yahoo Search, Bing, and Twitter, contributes Google’s leading position to the fact that Google remains the market share leader in online search, and consequently the most targeted search engine. &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Key highlights of the study: &lt;/strong&gt;&lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;Overall, Google takes the crown for malware distribution – turning up more than twice the amount of malware as Bing, Twitter and Yahoo! combined when searches on popular trending topics were performed. Google presents at 69 percent; Yahoo! at 18 percent; Bing at 12 percent; and Twitter at one percent.&lt;/li&gt;      &lt;li&gt;The average amount of time for a trending topic to appear on one of the major search engines after appearing on Twitter varies tremendously: 1.2 days for Google, 4.3 days for Bing, and 4.8 days for Yahoo! &lt;/li&gt;      &lt;li&gt;Over half of the malware found was between the hours of 4:00 a.m. and 10:00 a.m. GMT. The top 10 terms used by malware distributors include the name of a NFL player, three actresses, a Playboy Playmate and a college student who faked his way into Harvard. &lt;/li&gt;   &lt;/ul&gt;    &lt;p&gt;Interestingly, based on the data gathered, the most popular topic of choice for cybercriminals were spyware related searches, followed by entertainment news, with hosting sites, P2P and proxies related searches showing a significant growth. What’s worth highlighting while interpreting the data, is that it’s only valid for a specific period of time. How come? [...]&lt;/p&gt;    &lt;p&gt;&lt;img title="Image Credits:  Zero Day Blog" alt="Image Credits:  Zero Day Blog" src="http://i.zdnet.com/blogs/barracuda_lab_malware_search_engines_google.png" width="424" height="303" /&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.zdnet.com/blog/security/google-tops-comparative-review-of-malicious-search-results/7009"&gt;Zero Day Blog at ZDNet&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775030" width="1" height="1"&gt;</description></item><item><title>Happy bitchday from Facebook</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/happy-bitchday-from-facebook.aspx</link><pubDate>Fri, 30 Jul 2010 19:33:42 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775029</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;From Graham Cluley&amp;#39;s &lt;a href="http://www.sophos.com/blogs/gc/g/2010/07/30/happy-bitchday-facebook/"&gt;Blog&lt;/a&gt; at Sophos: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Yesterday my colleague Pablo Teijeira, who is based in our Madrid office, logged into Facebook as normal and was confronted with a rather unusual message in place of the usual reminder of whose birthday it was today: &lt;/p&gt;    &lt;p&gt;Rather than &amp;quot;Hoy es cumple de&amp;quot; (&amp;quot;Today is the birthday of&amp;quot;) the Spanish language version of Facebook was saying &amp;quot;f*ck you bitches&amp;quot;. Charming. &lt;/p&gt;    &lt;p&gt;Pablo dropped me a line, wondering if I knew if Facebook had been hacked or if there was some other sinister explanation. &lt;/p&gt;    &lt;p&gt;Well, the good news is that it wasn&amp;#39;t malware and it was more done as a prank than with malicious intent. Facebook has relied upon volunteers to translate its site, and if enough people vote for an incorrect translation it can automatically replace the legitimate wording. &lt;/p&gt;    &lt;p&gt;It&amp;#39;s all very well harnessing the power of the net to get your website translated, but maybe Facebook should put a few more checks in place before the system is abused again in future - perhaps with more malicious intentions. &lt;/p&gt;    &lt;p&gt;By the way, the Turkish translation version of Facebook was also abused in a similar way [...] &lt;/p&gt;&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775029" width="1" height="1"&gt;</description></item><item><title>Black Hat gets its video feed hacked</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/black-hat-gets-its-video-feed-hacked.aspx</link><pubDate>Fri, 30 Jul 2010 19:31:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775028</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;A security expert found a way to catch the talks at Black Hat for free, thanks to bugs in the video streaming service used by the security conference. &lt;/p&gt;    &lt;p&gt;Michael Coates, the head of Web security for Mozilla, said he discovered &lt;a href="https://www.blackhat.com/html/uplink/bh-us-10-uplink.html"&gt;several problems&lt;/a&gt; while trying to sign up for the US$395 service. As he went through the sign-up procedure, he was &amp;quot;quickly sidetracked by a few oddities in the design,&amp;quot; he wrote in a &lt;a href="http://michael-coates.blogspot.com/2010/07/irony-black-hat-video-stream-hack.html"&gt;blog post&lt;/a&gt; describing the incident. &lt;/p&gt;    &lt;p&gt;He poked around a bit more and discovered that he could register an account without providing anything more than an e-mail address, and then use that account on a test login page to access the videos for free. &lt;/p&gt;    &lt;p&gt;&amp;quot;Now, to be fair, Black Hat didn&amp;#39;t operate this video service themselves,&amp;quot; Coates wrote. &amp;quot;But its still a bit ironic that the largest hacking conference in the world has this security hole in their video streaming service.&amp;quot; &lt;/p&gt;    &lt;p&gt;Black Hat&amp;#39;s video streaming was provided by Inxpo this year. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.computerworld.com/s/article/9179879/Black_Hat_gets_its_video_feed_hacked"&gt;ComputerWorld&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775028" width="1" height="1"&gt;</description></item><item><title>QuickTime Player Allows Movie Files to Trigger Malware Download</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/quicktime-player-allows-movie-files-to-trigger-malware-download.aspx</link><pubDate>Fri, 30 Jul 2010 19:27:31 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775024</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;blockquote&gt;   &lt;p&gt;Quicktime Player (version 7.6.6) allows movie files to trigger download of files, and cybercriminals are using this to download malware from malicious websites. &lt;/p&gt;    &lt;p&gt;Trend Micro Threat Research Engineer Benson Sy encountered two .MOV files (001 Dvdrip Salt.mov, salt dvdrpi [btjunkie][xtrancex].mov) that both used the recent movie, Salt of Angelina Jolie. It looks suspicious enough because of its relatively small size compared to regular movie files. &lt;/p&gt;    &lt;p&gt;When the movie files are loaded to Quicktime player, it doesn’t show any live action scenes but leads users to download malware pretending to be either an update codec or another player installation. It is still under investigation whether the malware is using vulnerability or a known functionality to download the malware. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://blog.trendmicro.com/quicktime-player-allows-movie-files-to-trigger-malware-download/"&gt;TrendLabs Malware Blog&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775024" width="1" height="1"&gt;</description></item><item><title>Reading older aircraft MDL files (at least partly)</title><link>http://msmvps.com/blogs/arnogerretsen/archive/2010/07/30/reading-older-aircraft-mdl-files-at-least-partly.aspx</link><pubDate>Fri, 30 Jul 2010 19:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775022</guid><dc:creator>arno</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/arnogerretsen/8686.Image2010_2D00_07_2D00_30-2107.21.027.jpg"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/arnogerretsen/8686.Image2010_2D00_07_2D00_30-2107.21.027.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The screenshot above shows some success with reading the older aircraft MDL files. In this case it is a CFS2 aircraft (they use the same MDL structure as FS98 and FS2000). This models comes out quite good. Unfortunately not all models load that well. Many of them only show partly or not at all after importing. This seems to be caused by the fact that aircraft MDL files have a lot more conditional display than the scenery objects that ModelConverterX normally reads.&lt;/p&gt;
&lt;p&gt;So I will first have to think of a best way to handle these conditions, else it is not possible to read aircraft MDL files usefully. Luckily this was already on the wishlist for other objects as well. I would like to add the ability to switch variables on or off from within ModelConverterX and that you then see the object change. If that is not possible I will probably let the user set the value of all variables used before importing. But the first option would be more powerful of course.&lt;/p&gt;
&lt;p&gt;So time to do some thinking and hopefully I can implement this feature soon....&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/arnogerretsen/2818.Image2010_2D00_07_2D00_30-2108.12.600.jpg"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/arnogerretsen/2818.Image2010_2D00_07_2D00_30-2108.12.600.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775022" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/arnogerretsen/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/arnogerretsen/archive/tags/ModelConverterX/default.aspx">ModelConverterX</category><category domain="http://msmvps.com/blogs/arnogerretsen/archive/tags/FS2000/default.aspx">FS2000</category><category domain="http://msmvps.com/blogs/arnogerretsen/archive/tags/FS98/default.aspx">FS98</category><category domain="http://msmvps.com/blogs/arnogerretsen/archive/tags/CFS2/default.aspx">CFS2</category></item><item><title>Well, it is only shows how data mining works</title><link>http://msmvps.com/blogs/donna/archive/2010/07/30/well-it-is-only-shows-how-data-mining-works.aspx</link><pubDate>Fri, 30 Jul 2010 18:59:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1775021</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a href="http://www.networkworld.com/news/2010/072910-details-from-100-million-facebook.html"&gt;Details from 100 million Facebook profiles posted online&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Why it happened?&lt;/p&gt;  &lt;p&gt;1.&amp;#160; The user did not lock/secure their info? Maybe.&lt;/p&gt;  &lt;p&gt;2.&amp;#160; The user really allow sharing their info? Possible since it&amp;#39;s called sharing and they want it shared. Their choice.&lt;/p&gt;  &lt;p&gt;3.&amp;#160; They know what is FB for and they know the catch? Maybe or No.&amp;#160; You know... not every user reads privacy agreements/terms/policies.&amp;#160; &lt;/p&gt;  &lt;p&gt;What&amp;#39;s the catch? Data mining.&amp;#160; Profilers/Scammers/Thieves has easy targets.&amp;#160; Yours is theirs.&amp;#160; Theirs is theirs.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1775021" width="1" height="1"&gt;</description></item></channel></rss>