9/30/2007

Japan to develop next next-generation network

Filed under: — Aviran Mordo

A research group will be set up in Japan to develop optical technology that will replace the Internet Protocol as the global standard in communications, a report said Sunday.

The group will be established in November by the government-affiliated National Institute of Information and Communications Technology and private companies, the leading business daily Nikkei said.

It will aim to develop and commercialise in around 2015 a network that can transfer data at 10 gigabits per second, 10 times faster than the next-generation network due to be launched in Japan this year, the report said.

The group will be joined by such companies as Nippon Telegraph and Telephone Corp., Fujitsu Ltd., KDDI Corp., Hitachi Ltd., Toshiba Corp. and NEC Corp.

It will spend some 30 billion yen (260 million dollars) on the research project over the next five years, the report said.

Similar projects are already been under way in the United States and Europe.

The optical network would allow as many as 100 billion devices to access it simultaneously and still enjoy extremely fast data-transfer speeds, the report said.

9/29/2007

Google Buys Mobile Social Network Zingku

Filed under: — Aviran Mordo

Google Inc. has acquired a mobile social networking start-up called Zingku Inc., the search company’s latest move to provide more services through mobile phones.

Zingku aims to make it easier for people to share photos, send invitations or conduct polls among friends via mobile phone. It also provides a way for businesses to send “mobile flyers” to customers advertising products and services.

Zingku was started in 2005 and the service has been in testing with a limited number of users in the U.S. New account sign-ups have been frozen following Google’s acquisition, according to Zingku’s Web site. Existing accounts will be transferred to Google unless they are cancelled by Oct. 4.

Text Messaging Warns St. John’s Students of Gunman

Filed under: — Aviran Mordo

Another lone gunman approached another campus full of students on Sept. 26, but this time there was no tragedy similar to the shootings at Virginia Tech University in April that killed 32 people and wounded many more.

Just 16 minutes after Omesh Hiraman, 22, walked on to the campus of St. John’s University, in Queens, New York, with a loaded rifle, students, faculty and staff received e-mail and text messages alerting them to the danger.

Campus police and an NYPD police cadet spotted Hiraman, wearing a hooded sweatshirt and a Halloween mask, almost immediately. Hiraman, a St. John’s student, was quickly arrested without a single shot being fired. But rumors spread that a second gunman was loose on the campus.

“From public safety. Male was found on campus with a rifle. Please stay in your buildings until further notice. He is in custody, but please wait until the all-clear,” Thomas Lawrence, St. John’s vice president for public safety, sent in a text message.

University officials said only 2,100 out of 20,000 students were signed up for the alert system. Lawrence’s text message, and two more that followed, were widely forwarded around the campus. By the end of the day, subscribers to the service had jumped to more than 6,500 students.

“I commend the administration of St. John’s University for effectively activating an innovative text-messaging system when a dangerous situation unfolded on campus,” New York Governor Eliot Spitzer said in a statement. “The alert system notified students and staff of impending danger in a timely and effective manner.”

Microsoft extends Windows XP’s stay

Filed under: — Aviran Mordo

Bowing to pressure from customers and computer makers, Microsoft plans to keep Windows XP around a little longer.

Large PC manufacturers were slated to have to stop selling XP after January 31. However, they have successfully lobbied Microsoft to allow them to continue selling PCs with all flavors of Windows XP preloaded until June 30, a further five months. Microsoft also plans to keep XP on retail shelves longer and will allow computer makers in emerging markets to build machines with Windows XP Starter Edition until June 2010.

The move indicates the continued demand for the older operating system, some nine months after Windows Vista hit store shelves.

Software update disables hacked iPhones

Filed under: — Aviran Mordo

Apple Inc. has issued a software update that creates problems for iPhones modified to work with a cellular carrier other than AT&T Inc. and disables at least some unofficial programs installed on other iPhone handsets.

Apple warned earlier this week that the iPhone update — which adds access to the iTunes Wi-Fi Music Store and fixes some security flaws — could permanently disable phones running programs that untether phones from its exclusive partner’s network.

Several gadget enthusiast Web sites, including Gizmodo and Engadget, as well as online postings from hacker communities reported that, depending on which unlocking program was used, certain modified phones no longer worked after they installed Thursday’s software update. In some cases, the phones worked, but only with the original SIM card that ties the phone to AT&T.

Some sites also reported uncondoned third-party applications on the iPhones became disabled after the update.

Hollywood studios go after two piracy sites

Filed under: — Aviran Mordo

The Motion Picture Assn. of America has filed suit against two Web sites that it claims are allowing Internet users to view pirated films, many of which are still in theaters.

The lawsuit, filed Wednesday on behalf of the major studios, seeks to shutter cinematube.net (http://cinematube.net) and ssupload.com (http://ssupload.com) from further infringing on the copyrights of the MPAA members.

The sites feature links to hundreds of titles, including such recent releases as “Resident Evil: Extinction,” “The Brave One” and “Good Luck Chuck.”

9/27/2007

AOL IM Security Hole Unplugged?

Filed under: — Aviran Mordo

A day after users of AOL’s instant messaging service were advised to upgrade to address a vulnerability uncovered by Core Security Technologies, well-known security researcher Aviv Raff reports that he has found a way to defeat the patch.

His finding, subsequently confirmed by AOL in an e-mail he received, is the latest twist in the case of a vulnerability reported to AOL by Core Security in August but publicized among security aficionados two weeks ago, before either company was ready to disclose the issue.

The flaw in question affects AIM 6.1, 6.2 beta, AIM Pro and AIM Lite. All of the vulnerable AIM clients include support for enhanced message types that allow people to use HTML to customize text messages with specific font formats or colors. To render this HTML content, the vulnerable AIM clients use an embedded Internet Explorer server control, Core Security officials said.

Since these clients do not properly sanitize potentially malicious content before it is rendered, an attacker could deliver malicious HTML code in a IM message to directly exploit IE bugs without user interaction or to target security configuration weaknesses in IE.

Adobe gifts internal file permissions to unwashed masses

Filed under: — Aviran Mordo

A scripting error in Adobe’s website gave outsiders broad access to internal files on the company’s webserver that could prove valuable to malicious hackers trying to penetrate its security.

The error, which appeared to reside in a faulty CGI script, allowed people outside Adobe to read and download files entering specially crafted URLs into their favorite browser. An Adobe spokesman said company engineers have plugged the leak, but couldn’t say when or how long the error had exposed site internals.
Click here to find out more!

The flaw, known as a directory traversal, has serious implications for the security of Adobe’s site because it effectively gave web surfers the same permissions to read files afforded Adobe’s web application. Online discussions, including this one from Reddit contained numerous posts claiming the private key Adobe uses to authenticate itself during Secure Socket Layer sessions was exposed. The interception of the key could make it easier for malicious hackers to spoof trusted portions of Adobe’s site.

New tools help hack into iPhone

Filed under: — Aviran Mordo

iPhone hackers have some new tools now, thanks to HD Moore, one of the developers of the Metasploit hacking software.

On Tuesday, Moore announced that he was supporting the iPhone within his Metasploit framework and released software that would allow hackers to run “shellcode” command prompts on Apple’s mobile device.

By integrating the iPhone into Metasploit, it will now be a little easier for hackers to gain access to someone else’s iPhone, but they will also need a few other tools to succeed. First, they will need to create working exploit code, which takes advantage of bugs in Apple’s software, to trick the device into running the shellcode. They will also need to create more sophisticated “payload” applications that can do things like remotely connect with the hacker. “It’s a first step,” Moore said of his hack.

With iPhone prices dropping and noticeable improvements in the quality of iPhone hacking tools, Apple’s phone has become a more interesting target of late, Moore said.

Court Affirms Vonage Infringed 2 Verizon Patents

Filed under: — Aviran Mordo

A U.S. appeals court on Wednesday upheld a verdict that Vonage Holdings Corp. infringed two patents held by Verizon Communications Inc and also reaffirmed an order barring Vonage from using the Internet phone call technologies involved.

The U.S. Court of Appeals for the Federal Circuit affirmed an injunction issued by a lower court judge earlier this year with regard to two of three Verizon patents, while reversing the judge’s interpretation of a third patent in the case.

The appeals court sent the case back to the district court for further proceedings on the third patent and a new calculation of damages and royalties awarded to Verizon.

The decision was a further blow to Vonage, coming a day after a U.S. jury found it had infringed patents owned by Sprint Nextel Corp.

Vonage shares were halted soon after trading began Wednesday on the New York Stock Exchange after falling 26 cents, or 20 percent, to $1.04. At that price they have fallen 94 percent from the company’s initial public offering at $17 per share in May 2006.

A Vonage spokeswoman confirmed the court upheld two of the three verdicts in the Verizon case but declined to comment further, saying the company was still preparing a statement.

Internet sheds light on communist secret police archives

Filed under: — Aviran Mordo

Nearly two decades after the fall of communism, Europe’s former Moscow-dominated states are using the Internet to make public the files of the security services that helped keep their regimes in power.

In the latest step, the body in charge of Poland’s communist-era secret police files began Tuesday posting documents related to top officials, including the President Lech Kaczynski and his identical twin Prime Minister Jaroslaw Kaczynski.

The material on the special site of National Remembrance Institute (IPN) was hardly shocking, and simply confirmed that both Kaczynskis were spied on and harassed by the Sluzba Bezpieczenstwa police because of their anti-communist activities in the 1970s and 1980s.

But the possibility of peeking into the SB archives — which cover people who were spies, victims, or both — was such a draw for Poles that users swamped the IPN’s site.

Microsoft Touts New ‘Media Extenders’

Filed under: — Aviran Mordo

Microsoft Corp. and its hardware partners are trying to bridge the divide between home computers and TV sets this holiday season with the release of several “media extenders.”

These TV set-top boxes will connect wirelessly to computers running the Home Premium or Ultimate flavors of Windows Vista and enable users to use their TV sets to watch movies, TV shows and Internet video that is stored on their computers.

Microsoft planned to announce the prices and more details about the extenders Thursday at the DigitalLife trade show in New York.

The cheapest extender, from Cisco Systems Inc.’s Linksys division, will cost $300. Linksys will have another model with a built-in DVD player for $350, a price matched by D-Link’s model, which lacks a DVD player but includes a USB port for viewing photos and other content stored on flash drives or hard drives.

Another extender is from Niveus and is aimed at home theater enthusiasts. No price was announced yet, but Microsoft product planner Hakan Olsson said it would be substantially higher than the other models.