3/24/2009

Obama Sides With RIAA, Supports $150,000 Fine per Music Track

Filed under: — Aviran Mordo

The Obama administration for the first time is weighing in on a Recording Industry Association of America file sharing lawsuit and is supporting hefty awards of as much as $150,000 per purloined music track.

The government said the damages range of $750 to $150,000 per violation of the Copyright Act was warranted.

Researchers Demo BIOS Attack That Survives Disk Wipes

Filed under: — Aviran Mordo

A pair of Argentinian researchers have found a way to perform a BIOS level malware attack capable of surviving even a hard-disk wipe. Alfredo Ortega and Anibal Sacco from Core Security Technologies — used the stage at last week’s CanSecWest conference to demonstrate methods (PDF) for infecting the BIOS with persistent code that will survive reboots and re-flashing attempts.

The technique includes patching the BIOS with a small bit of code that gave them complete control of the machine. The demo ran smoothly on a Windows machine, a PC running OpenBSD and another running VMware Player

Microsoft Launches Free Web Software Eco-System

Filed under: — Aviran Mordo

Microsoft, inspired perhaps by the ease of selecting and installing iPhone apps, has taken a similar approach to gather back market share of its IIS web server in a predominantly Apache/PHP market.

10 open source CMS, gallery, wiki, and blog tools were chosen to populate the eco-system, dubbed Web App Gallery. Developers must agree to principles and can now submit their PHP or .NET application for inclusion. Once an application is in the gallery, Windows users use Microsoft Web Platform Installer, released in a keynote at MIX this week, which inspects the the local system, and installs and configures dependencies like the IIS webserver, PHP, URL re-writers, and file permissions.

Screenshots show this to be quite easy for the typical computer user. This could provide some real competition for WAMP and Linux shell install processes

Botnet Worm Targets DSL Modems and Routers

Filed under: — Aviran Mordo

The people who bring you the DroneBL DNS Blacklist services, while investigating an ongoing DDoS incident, have discovered a botnet composed of exploited DSL modems and routers.

OpenWRT/DD-WRT devices all appear to be vulnerable. What makes this worm impressive is the sophisticated nature of the bot, and the potential damage it can do not only to an unknowing end user, but to small businesses using non-commercial Internet connections, and to the unknowing public taking advantage of free Wi-Fi services.

The botnet is believed to have infected 100,000 hosts.” A followup to the article notes that the bot’s IRC control channel now claims that it has been shut down, though the ongoing DDoS attack on DroneBL suggests otherwise.

Powered by WordPress