Diberdayakan oleh Blogger.

Popular Posts Today

Spanish police say DDoS suspect used a van as a mobile office

Written By Unknown on Senin, 29 April 2013 | 16.00

The man suspected of participating in a large DDoS attack on an antispam organization that caused intermittent Internet hiccups drove around Spain in a van he used as a mobile office, Spain's Interior Ministry said Sunday.

The van was equipped with "various antennas" that were used to scan frequencies, the ministry said in a news release. On Thursday, Spanish police arrested a 35-year-old Dutch man in Barcelona suspected of conducting cyberattacks against Spamhaus, a nonprofit group that develops widely used lists of networks identified as sending spam.

Spanish police published a video of a sparse residence they raided. Images showed the room was strewn with wires and computer equipment, including routers, a Mac Mini computer, laptops, an antennae and a single cot with the book "Quicksilver" by Neal Stephenson on it. Also shown were several rubber stamps, two of which were emblazoned "NATO secret" and "NATO unclassified."

The man has been identified by an official close to the investigation as Sven Kamphuis, who has denied involvement. Dutch authorities only identified the suspect by the initials "S.K." for privacy reasons. Kamphuis has said he believes the attacks originated with members of Stophaus, a group aiming to shutdown Spamhaus for its antispam work.

The DDoS attack was estimated to peak at more than 300Gbps, making it one of the largest attacks on record, but computer security experts disagreed somewhat over its broader effect on the Internet. The attack caused problems for some European Internet exchanges nodes, or places where ISPs link to transfer traffic to one another.

The Interior Ministry, which did not name the suspect, said they seized two laptops and documents from the residence. At the time of his arrest, the man, from Alkmaar, Netherlands, claimed to be the minister of telecommunications and foreign affairs of the Republic of CyberBunker, Spanish police said.

CyberBunker.com is a hosting provider based in a former military facility in the Netherlands. It specializes in so-called "bulletproof" hosting, or one that resists law enforcement efforts to remove certain content from the Internet. It claims it has no involvement in spam and does not allow SMTP traffic, the protocol used to send email.

Kamphuis runs a network provider called CB3ROB, which provided services for CyberBunker. CB3ROB had been blacklisted by Spamhaus for activity related to spamming botnets and extortion scams.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

Google to discontinue Meebo social toolbar in favor of Google+

Google plans to shut down in June the Meebo Bar for receiving and sharing personalized content from websites in favor of Google+ tools for interaction between websites and users.

The Internet giant acquired Meebo in June last year. Besides offering a toolbar that offered personalized content as well as displayed advertisements, with connections to Twitter and other social networks, Meebo, set up in 2005, also offered an instant messaging application.

In July last year, Google decided to shelve Google Talk Chatback which allowed websites to embed a widget to engage with their visitors. "It's now outdated, so we're turning off Chatback and encouraging websites to use the Meebo bar," Google said in a post announcing the discontinuation or merger of over 30 of its products.

It is now the turn of Meebo to be retired. It will be discontinued on June 6, as the team working on Meebo has decided to focus its resources on initiatives like the recently launched Google+ Sign-In, which includes interactive posts and over-the-air app installs from publisher websites, and Google+ plug-ins such as the +1 recommendation button, the Meebo team said on the Meebo website.

The Meebo Bar was launched "to bring community, engagement, and revenue to publisher sites," and this will continue to be the focus of the team, it added.

Website publishers have been informed that after June 6, the Meebo Bar will stop loading on their sites. The inactive Meebo code is recommended to be removed from the site as a general code housekeeping task. The creation of new Meebo Bars has been disabled. Meebo Bar Dashboard and analytics will be available until June 30, though websites will not be able to change toolbar configurations after June 6.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com


16.00 | 0 komentar | Read More

McAfee spots Adobe Reader PDF-tracking flaw

McAfee said it has found a vulnerability in Adobe Systems' Reader program that reveals when and where a PDF document is opened.

The issue is not a serious problem and does not allow for remote code execution, wrote McAfee's Haifei Li in a blog post. But McAfee does consider it a security problem and has notified Adobe. It affects every version of Adobe Reader, including the latest version, 11.0.2, Li wrote.

McAfee recently detected some "unusual" PDF samples, Li wrote. McAfee withheld some key details of the vulnerability, but did generally describe it.

The issue occurs when someone launches a link to another file path, which calls on a JavaScript API (application programming interface). Reader warns a user when they are going to call on a resource from another place, such as a link on the Internet.

If the external resource does not exist, the warning dialog does not appear, but the API returns some TCP traffic, Li wrote. By manipulating a second parameter with a special value, the API's behavior changes to reveal information. That could include information such as the location of a document on a system "by calling the JavaScript 'this.path' value," Li wrote.

"Malicious senders could exploit this vulnerability to collect sensitive information such as IP address, Internet service provider or even the victim's computing routine," Li wrote. "In addition, our analysis suggests that more information could be collected by calling various PDF JavaScript APIs."

Li suggests the problem could be used for reconnaissance by attackers.

"Some people might leverage this issue just out of curiosity to know who has opened their PDF documents, but others won't stop there," Li wrote. "An APT [advanced persistent threat] attack usually consists of several sophisticated steps. The first step is often collecting information from the victim; this issue opens the door."

McAfee suggests that Adobe Reader users disable JavaScript until a patch is released. Adobe officials could not be immediately reached for comment.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

CISPA legislation appears doomed in U.S. Senate

Written By Unknown on Sabtu, 27 April 2013 | 16.00

Skip the navigation

Computerworld
  • White Papers
  • Webcasts
  • Newsletters
  • Solution Centers

    • BlackBerry: Build up your BlackBerry® 10 knowledge
    • BMC Control-M Workload Automation
    • View all Solution Centers
  • Events
  • Magazine

    • Latest Issue
    • Magazine Index
    • Subscribe
    • Subscriber Services
  • Twitter
  • Facebook
  • Google+
  • LinkedIn
  • RSS
  • Topics
    • Applications
    • Cloud Computing
    • Consumerization of IT
    • Data Center
    • Data Storage
    • Government/Industries
    • Hardware
    • Internet
    • Management
    • Mobile/Wireless
    • Networking
    • Operating Systems
    • Security
    • All Topics
  • News
  • In Depth
  • Reviews
  • Blogs
    • Featured Blogs
    • IT Blogwatch
    • Jonny Evans
    • JR Raphael
    • Michael Horowitz
    • Preston Gralla
    • Richi Jennings
    • Robert L. Mitchell
    • Shark Tank
    • All Bloggers
  • Opinion
  • Shark Tank
  • IT Jobs
  • More

    • Enterprise IT
    • Hot Topics
    • IDGE CEO Interviews
    • Insider Articles
    • QuickPoll Center
    • Slideshows
    • Video
  • IT Verticals

    • Financial IT
    • Government IT
    • Healthcare IT
Security
  • Application Security|
  • Cybercrime and Hacking|
  • Cyberwarfare|
  • Data Security|
  • Encryption|
  • Endpoint Security
  • Malware and Vulnerabilities|
  • Mobile Security
  • Privacy|

16.00 | 0 komentar | Read More

LivingSocial gets hacked, 50 million users told to reset passwords

More than 50 million users of the daily deals site LivingSocial are being asked to reset their passwords after hackers attacked the company's servers and potentially made off with personal data.

The cyberattack "resulted in authorized access to some customer data on our servers," including names, email addresses, dates of birth and encrypted passwords, LivingSocial CEO Tim O'Shaughnessy said in an email to employees and in a separate email being sent to customers.

The database that stores customer credit card information was not affected, nor was the database that stores merchants' financial and banking information, the Washington, D.C.-based company said.

Although decoding users' passwords "would be difficult," the site says it is taking "every precaution" by expiring its users' passwords and asking them to create a new one. Emails are being sent this afternoon to the more than 50 million users whose data may have been compromised, a LivingSocial spokesman said.

LivingSocial says it has 70 million members worldwide. Customers in Korea, Thailand, Indonesia and the Philippines aren't being contacted because the company uses different computer systems in those countries, it said.

The group behind the attack has not been identified. "We are actively working with law enforcement to investigate this issue," LivingSocial said on its website.

The hack may have resulted in users' accounts on other sites being compromised. "We also encourage you, for your own personal data security, to consider changing password(s) on any other sites on which you use the same or similar password(s)," O'Shaughnessy said.

hackers

"We need to do the right thing for our customers who place their trust in us," O'Shaughnessy said in the employee email, adding, "We'll all need to work incredibly hard over the coming days and weeks to validate that faith and trust."

The hack follows a slew of attacks on Twitter, Facebook, Microsoft and other companies. LivingSocial said it is "redoubling" its efforts to prevent future breaches.


16.00 | 0 komentar | Read More

Fedora 19 alpha offers a peek at what's coming

It's been about three months since the release of Fedora 18 "Spherical Cow," but this week afforded the first glimpse at the next version of the popular Linux distribution.

Arriving just a week behind schedule, the alpha version of Fedora 19, code-named "Schrödinger's Cat," comes packed with several new features as well as an assortment of updated packages.

It's not intended for production use, of course. Rather, the alpha software is available purely for testing purposes. Still, if you want to take it for a whirl to see what's coming in the final release due in July, it's now available as a free download. Here are some of the highlights of what you'll find.

1. Classic desktop options

Included among the desktop environments available in the Fedora 19 alpha are GNOME 3.8, KDE Plasma Workspaces 4.10, and MATE 1.6. One result is that those who prefer the classic GNOME 2-style experience will have multiple options, including both MATE and GNOME 3.8's "classic mode." Though there was speculation early this year that Cinnamon might be offered by default in Fedora 19, this alpha release offers no evidence that that will be the case.

2. Multiple niche flavors

In addition to the main Fedora 19 OS, there are also a number of what the project calls "spins" with hand-picked application sets or customizations tailored for specific interests. Examples include a Design Suite Spin, a Robotics Spin, and a Security Spin. Other available desktop environments include Xfce, Sugar on a Stick, and LXDE.

3. 3D printing support

Also evident in this alpha release is an effort to bring 3D printing tools to Fedora and make the OS a competitive choice for users of 3D printers such as RepRap without requiring that they download binary blobs or run Python code from Git. OpenSCAD, Skeinforge, SFACT, Printrun, and RepetierHost are among the new tools included for this purpose.

4. Developer tools

Last but not least, targeting developers and programming enthusiasts, Fedora 19 includes tools such as Developer's Assistant, OpenShift Origin, Node.js, Scratch, and Ruby 2.0.


16.00 | 0 komentar | Read More

US lawmakers plan sweeping review of copyright

Written By Unknown on Kamis, 25 April 2013 | 16.01

A key U.S. lawmaker has unveiled plans for a comprehensive review of the laws surrounding copyright in the United States to determine whether they are still relevant in the digital age.

Bob Goodlatte, a Virginia Republican and chairman of the House Judiciary Committee, said Wednesday that his committee will begin its review in the coming months. When the review is finished, the committee could propose revisions to the current copyright law to help it better apply to an era where almost every citizen has become a publisher.

"There is little doubt that our copyright system faces new challenges today," he said, according to a transcript of remarks delivered at the Library of Congress. "The Internet has enabled copyright owners to make available their works to consumers around the world, but has also enabled others to do so without any compensation for copyright owners."

America's copyright laws have been occasionally updated to accommodate new technologies since the first Copyright Act was passed into law in 1790. But the quick pace of technological change has meant the current law, enacted in 1976, fails to directly address copyright and how it applies to technologies that are commonplace today.

"It is my belief that a wide review of our nation's copyright laws and related enforcement mechanisms is timely," said Goodlatte. "I am announcing today that the House Judiciary Committee will hold a comprehensive series of hearings on U.S. copyright law in the months ahead. The goal of these hearings will be to determine whether the laws are still working in the digital age."

The review has been welcomed by groups representing both content creators and consumers, something easy to do when it's still unclear in which direction the review will go.

"We welcome a public conversation about modernizing the copyright laws," said Cary Sherman, chairman and CEO of the Recording Industry Association of America (RIAA), in a statement. Sherman agreed the law needs to change to keep up with digital technology, but he called for any review to be balanced between the rights of content creators and consumers.

"We share the view that our laws must be modern, streamlined and ensure that all creators are paid a fair market rate for their work," he said. "They must work more efficiently -- not only for creators, but for users and service providers as well. At the same time, a right with no recourse is no right at all. Laws like the DMCA must work for creators too, to allow digital music services to flourish."

Public Knowledge, a group that examines copyright issues from the consumer standpoint, also welcomed the review.

"We welcome the Chairman's proposal to examine how best our copyright laws can, as the Constitution requires, promote the progress of science and the useful arts," Sherwin Siy, the group's vice president of Legal Affairs, said in a statement. "As such, we hope that Congress and the Copyright Office will work to balance the interests of artists with those of their audiences and the public in general, ensuring that the ultimate goal of the law is met in promoting innovation and creativity."

Goodlatte's announcement comes a month after Maria Pallante, the current U.S. registrar of copyrights, called for a review of the current copyright act.

Speaking at Columbia Law School on March 4, Pallante outlined a number of issues that she thinks should be examined. They include what constitutes an identical copy in the digital age, the balance between enforcement and free expression, and licensing. Later in March, she delivered the same message before the House Judiciary Committee.

"There's a whole bunch of things that Ballante has proposed, and they run the gamut," said Sina Khanifar, a digital rights activist and founder of FixtheDMCA.org. "I think she is very much looking for broad reforms across the base of copyright."

Khanifar works on issues related to the Digital Millennium Copyright Act (DMCA), enacted in 1998 and the last major revision of copyright law in the United States. Several controversial sections of the DMCA have made it something of a rallying cry for those campaigning for a new copyright regime.

The controversial parts of the law include Section 1201, which makes it a crime to circumvent technological measures protecting copyrighted material.

Khanifar and others say the language is over broad for a provision that was intended to make cracking digital rights management technology a crime. The section has been cited in arguments for keeping consumers from circumventing any kind of software lock, including recently in cases over the unlocking of cellphones.

Martyn Williams covers mobile telecoms, Silicon Valley and general technology breaking news for The IDG News Service. Follow Martyn on Twitter at @martyn_williams. Martyn's e-mail address is martyn_williams@idg.com


16.01 | 0 komentar | Read More

Wireless networks may learn to live together by using energy pulses

Researchers at the University of Michigan have invented a way for different wireless networks crammed into the same space to say "excuse me" to one another.

Wi-Fi shares a frequency band with the popular Bluetooth and ZigBee systems, and all are often found in the same places together. But it's hard to prevent interference among the three technologies because they can't signal each other to coordinate the use of the spectrum. In addition, different generations of Wi-Fi sometimes fail to exchange coordination signals because they use wider or narrower radio bands. Both problems can slow down networks and break connections.

Michigan computer science professor Kang Shin and graduate student Xinyu Zhang, now an assistant professor at the University of Wisconsin, set out to tackle this problem in 2011. Last July, they invented GapSense, software that lets Wi-Fi, Bluetooth and ZigBee all send special energy pulses that can be used as traffic-control messages. GapSense is ready to implement in devices and access points if a standards body or a critical mass of vendors gets behind it, Shin said.

Wi-Fi LANs are a data lifeline for phones, tablets and PCs in countless homes, offices and public places. Bluetooth is a slower but less power-hungry protocol typically used in place of cords to connect peripherals, and ZigBee is an even lower powered system found in devices for home automation, health care and other purposes.

Each of the three wireless protocols has a mechanism for devices to coordinate the use of airtime, but they all are different from one another, Shin said.

"They can't really speak the same language and understand each other at all," Shin said.

Each also uses CSMA (carrier sense multiple access), a mechanism that instructs radios to hold off on transmissions if the airwaves are being used, but that system doesn't always prevent interference, he said.

The main problem is Wi-Fi stepping on the toes of Bluetooth and ZigBee. Sometimes this happens just because it acts faster than other networks. For example, a Wi-Fi device using CSMA may not sense any danger of a collision with another transmission even though a nearby ZigBee device is about to start transmitting. That's because ZigBee takes 16 times as long as Wi-Fi to emerge from idle mode and get the packets moving, Shin said.

Changing ZigBee's performance to help it keep up with its Wi-Fi neighbors would defeat the purpose of ZigBee, which is to transmit and receive small amounts of data with very low power consumption and long battery life, Shin said.

Wi-Fi devices can even fail to communicate among themselves on dividing up resources. Successive generations of the Wi-Fi standard have allowed for larger chunks of spectrum in order to achieve higher speeds. As a result, if an 802.11b device using just 10MHz of bandwidth tries to tell the rest of a Wi-Fi network that it has packets to send, an 802.11n device that's using 40MHz may not get that signal, Shin said. The 802.11b device then becomes a "hidden terminal," Shin said. As a result, packets from the two devices may collide.

To get all these different devices to coordinate their use of spectrum, Shin and Zhang devised a totally new communication method. GapSense uses a series of energy pulses separated by gaps. The length of the gaps between pulses can be used to distinguish different types of messages, such as instructions to back off on transmissions until the coast is clear. The signals can be sent at the start of a communication or between packets.

GapSense might noticeably improve the experience of using Wi-Fi, Bluetooth and ZigBee. Network collisions can slow down networks and even cause broken connections or dropped calls. When Shin and Zhang tested wireless networks in a simulated office environment with moderate Wi-Fi traffic, they found a 45 percent rate of collisions between ZigBee and Wi-Fi. Using GapSense slashed that collision rate to 8 percent. Their tests of the "hidden terminal" problem showed a 40 percent collision rate, and GapSense reduced that nearly to zero, according to a press release.

One other possible use of GapSense is to let Wi-Fi devices stay alert with less power drain. The way Wi-Fi works now, idle receivers typically have to listen to an access point to be prepared for incoming traffic. With GapSense, the access point can send a series of repeated pulses and gaps that a receiver can recognize while running at a very low clock rate, Shin said. Without fully emerging from idle, the receiver can determine from the repeated messages that the access point is trying to send it data. This feature could reduce energy consumption of a Wi-Fi device by 44 percent, according to Shin.

Implementing GapSense would involve updating the firmware and device drivers of both devices and Wi-Fi access points. Most manufacturers would not do this for devices already in the field, so the technology will probably have to wait for hardware products to be refreshed, according to Shin.

A patent on the technology is pending. The ideal way to proliferate the technology would be through a formal standard, but even without that, it could become widely embraced if two or more major vendors license it, Shin said.

Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com


16.01 | 0 komentar | Read More

Mt. Gox delays plan to support virtual currency litecoin

Bitcoin exchange Mt. Gox has temporarily shelved plans to support a competing currency, litecoin, the company said Thursday.Mt. Gox, which is the largest bitcoin exchange, has been battling ongoing distributed denial-of-service (DDoS) attacks that caused it to delay launching an exchange for litecoin, a lesser known virtual currency designed to improve on some of bitcoin's weaknesses.The Tokyo-based exchange said in a news release it was planning to support litecoin two weeks ago "but events derailed that plan. Right now we are focused on overall stability of the exchange and will launch LTC [litecoin] when we are ready. Otherwise we could be further complicating things."Bitcoin's price has seen dramatic swings since January, in part due to continued attacks that Mt. Gox believes are intended to manipulate its price. Attackers have conducted DDoS strikes on Layer 7, which is the application protocol layer including protocols such as HTTP, FTP and SMTP.The attacks are hard to detect and "make it difficult to distinguish malicious traffic from normal traffic," Mt. Gox said.Mt. Gox employes the services of Prolexic, a company based in Florida that runs a network of data centers designed to filter malicious traffic. Mitigating a DDoS attack takes some time, however, and Mt. Gox has experienced outages during attacks.Mt. Gox's decision to support litecoin marks increasing interest in virtual currencies. Similar to bitcoin, litecoin uses a peer-to-peer network that harnesses the computing power of the network to generate new coins, known as "mining," and to confirm that transactions are legitimate.One of bitcoin's weaknesses is that it can take upwards of three hours to confirm a transaction, although most are verified by the network within an hour. Litecoin's network provides verification of transactions in less than three minutes, according to the project's website. Litecoin mining can also be done on consumer-grade hardware, whereas bitcoin mining now requires advanced, specialized hardware to be efficient.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

ZTE agrees to Android, Chrome patent licensing from Microsoft

Written By Unknown on Rabu, 24 April 2013 | 16.01

Microsoft has inked an agreement with China's ZTE for its Android and Chrome patent licensing program.

Financial details of deal were not disclosed. But the agreement gives ZTE access to Microsoft patents covering phones, tablets, computers and other devices running Google's Android and Chrome operating systems.

ZTE joins others, including Samsung, HTC and Acer, that have also signed up with Microsoft's patent licensing program. Last week, manufacturing giant Foxconn entered into a similar agreement and is paying royalties to Microsoft for access to its patent portfolio.

Both Android and Chrome are Google-developed operating systems. But according to Microsoft, the two operating systems also use technologies patented by the company. Previously, Microsoft has filed lawsuits against Android device makers for patent infringement.

Microsoft's Android and Chrome licensing program is meant to help gadget vendors avoid further litigation with Microsoft. So far, the company has reached licensing deals with nearly all of the world's largest Android smartphone vendors and manufacturers, said Microsoft vice president Horacio Gutierrez in a company blog post.

"In fact, 80 percent of Android smartphones sold in the U.S. and a majority of those sold worldwide are covered under agreements with Microsoft," he added.

But two major holdouts still remain. Chinese company Huawei, the world's third largest smartphone vendor, along with Google and its Motorola Mobility business, have yet to sign on.


16.01 | 0 komentar | Read More
techieblogger.com Techie Blogger Techie Blogger