3/10/2010

New Internet Explorer code-execution attacks

Filed under: — Aviran Mordo

Hackers are exploiting a security bug in earlier versions of Internet Explorer that allows them to remotely execute malicious code, Microsoft warned on Tuesday.

The vulnerability in IE versions 6 and 7 allows remote attackers to gain the same access to the affected PC as the local user. The bug, which stems from an invalid pointer reference, either doesn’t exist in IE 8 or can’t be exploited in that version, providing users with yet another strong reason to upgrade to a modern browser

Adobe Reader is world’s most-exploited app

Filed under: — Aviran Mordo

Adobe’s ubiquitous Reader application has replaced Microsoft Word as the program that’s most often targeted in malware campaigns, according to figures compiled by F-Secure.

Files based on Reader were exploited in almost 49 per cent of the targeted attacks of 2009, compared with about 39 per cent that took aim at Microsoft Word. By comparison, in 2008, Acrobat was targeted in almost 29 per cent of attacks and Word was exploited by almost 35 per cent.

“Why has it changed?” F-Secure asks here. “Primarily because there has been more vulnerabilities in Adobe Acrobat/Reader than in the Microsoft Office applications.”

Google goes cycling

Filed under: — Aviran Mordo

Google is offering a cycling option for users of its map service.

If you ask Google for directions in some US cities from today you can choose “bicycling” as an option, alongside “by car”, “walking” or “by public transport”.

The company said it had been the most requested feature since the map site launched.

Cisco leapfrogs rivals with faster router

Filed under: — Aviran Mordo

Cisco Systems Inc introduced its first major new routers in six years and said they can be configured to handle Internet traffic up to 12 times faster than rival products.

Cisco, the world’s largest network equipment maker, said up to 72 of the new CRS-3 routers can be connected for capacity of 322 terabits per second (tbs). The new routers hit the market in the third quarter of this year.

At that maximum configuration, Cisco boasted the routers could in theory deliver every movie ever made in four minutes over the Internet, or connect China’s entire population of 1.3 billion people by video conference at the same time.

3/9/2010

UTF-8 Encoding In POST And GET Request On Tomcat

Filed under: — Aviran Mordo

I recently had to write a project using Tomcat that takes data from html forms and save the data to a database. I thought hey this is pretty strait forward, however while I was expecting the form data to arrive to Tomcat as a UTF-8 string I surprisingly got the request encoding is ISO-8859-1.

While you think that browsers take hints from the page or form encoding and send form data back to the server in the same encoding, web servers remain unaware of the encoding scheme. They typically assume that the request encoding is ISO-8859-1.

So, if my application expects a UTF-8 encoded string, Tomcat assumes 8859-1. The result, of course, is that text data becomes mangled.

Looking for answers I found that I can specify URIEncoding=”UTF-8″ in Tomcat’s connector settings within the server.xml file. Now you might think, hey that’s pretty strait forward, well I thought so too, until I discovered that it only works for GET requests, and Tomcat ignores this setting for POST request.

Now my project had to deal with POST data, and also store the data into a database. So I kept looking until I found a solution. In order for your Servlet to process POST data at UTF-8 you need to explicitly set the character encoding in your Servlet, and to do that all you need to do is put this line in your doPost method (or just add a filter chain and add this line in the doFilter method

request.setCharacterEncoding("UTF-8")

Another trick to get UTF-8 in Tomcat is to tell the JVM to use UTF-8 as file encoding?

-Dfile.enconding=UTF-8

I know it seems strange that Tomcat does not have a configuration setting to handle UTF-8 encoding in POST request, but I could not find one. If you know of such configuration setting you are welcome to share this information in the comments.

Google, Dish testing new TV search service

Filed under: — Aviran Mordo

Google Inc and No. 2 U.S. satellite TV operator Dish Network Corp are jointly testing a television programing search service, the Wall Street Journal reported on Monday, citing people familiar with the matter.

The paper said the service runs on TV set-top boxes which use elements of Google’s Android wireless operating system. It allows users to search content from Dish as well as websites such as YouTube, and to personalize the lineup of shows.

3/8/2010

Microsoft Demos Game Across Phone, Xbox 360 & Win 7

Filed under: — Aviran Mordo

During the keynote presentation at TechEd Middle East in Dubai, Microsoft’s Eric Rudder played the same Indiana Jones-ish game on a Windows computer, a Windows Phone 7 phone, and an Xbox 360. Gaming is about to get real ubiquitous.

Not only is the game itself playable on all three platforms, but the session is maintained when you move from device to device: if you’re playing on your Xbox and have to run out the door, you’ll be on the same level when you fire it up on your Windows Phone 7 Series phone. Basically, you’ll never have an excuse not to be gaming.

Firefox alpha dons Flash flak jacket

Filed under: — Aviran Mordo

Mozilla has pushed out a Firefox developer preview that runs Adobe Flash and other plug-ins as a separate process, hoping to prevent crashing plug-ins from crashing the browser proper.

Mozilla’s new developer preview is the second “pre-release” version of the open source outfit’s Gecko 1.9.3 rendering engine. Today’s official Firefox offering - version 3.6 - uses Gecko 1.9.2.

Google Intros Web Clipboard For Docs

Filed under: — Aviran Mordo

This week Google quietly rolled out a new feature within Google Docs. It is offering a Web-based clipboard that will let users copy-and-paste content between Google Docs. It also manages to keep Web formatting intact.

Google writes in a blog post, “This new clipboard temporarily stores items you’ve copied in the cloud, then allows you to paste them with proper formatting into other Google Docs. The new web clipboard lets you copy content between documents, spreadsheets and presentations more easily and with improved fidelity, and this is just our first step. Note that while items in your web clipboard are available across browsers and across sessions, they do expire after a month.”

3/7/2010

Real settles lawsuits, will stop selling RealDVD

Filed under: — Aviran Mordo

RealNetworks has agreed to pay US$4.5 million and permanently stop selling its RealDVD software as part of a legal settlement with six Hollywood movie studios, the company said Wednesday.

The lawsuits date back to 2008, when the movie studios accused RealNetworks of selling software that allowed people to essentially steal DVDs by making copies of them. RealNetworks argued that RealDVD was designed only to let customers make a backup copy of movies on their PC hard drive.

Google takes aim at Microsoft with acquisition | Reuters

Filed under: — Aviran Mordo

Google Inc stepped up its assault on Microsoft Corp’s productivity software business with the acquisition of a small start-up company that allows Microsoft users to edit and share their documents on the Web.

Google said on its company blog on Friday that it has acquired San Francisco-based DocVerse. Terms of the deal were not disclosed.

“With DocVerse, people can begin to experience some of the benefits of Web-based collaboration using the traditional Microsoft Word, Excel and PowerPoint desktop applications,” Google Product Manager Jonathan Rochelle said in the blog post.

Panasonic, Best Buy to tie up on 3D TV sales

Filed under: — Aviran Mordo

Panasonic Corp will tie up with the top U.S. electronics chain Best Buy Co to market and boost the sales of its 3D TVs in the United States, the Nikkei business daily reported on Sunday.

The report comes ahead of the world’s fourth-largest flat TV maker’s launch of its 3D TV in the United States this month amid rivalry with TV makers such as Samsung Electronics Co Ltd, LG Electronics Inc and Sony Corp.

Best Buy will set up special exhibition corners where its customers can view 3D videos in its 300 stores in major U.S. cities. This will expand to 1,000 stores by the end of the year, the Nikkei reported.

Powered by WordPress