Seeding of Microsoft Vista SP2 for developers next week

October 25, 2008 by loolia556

A small group of Microsoft Technology Adoption Program customers will receive hands SP2, Vista, the next week, but it’s time for the general public has not yet been determined.

Tech adopted customers to get other service pack for Windows Vista on October 29, Mike Nash, Corporate Vice President of Windows Product Management, wrote Friday in a blog entry.

“The final date for Windows Vista SP2, is based on quality,” Nash wrote. “We will follow customers, and feedback from the beta program before the deadline for the release.”

Vista SP2 contains “previously released patches are concentrated in certain reliability, performance and compatibility issues”, according to Nash.

Microsoft has issued a “utility model,” so SP2 will be packaged in a release includes a Windows Vista client and Windows Server 2008.

“This would also reduce the spread and testing complexity of our customers,” Nash wrote.

In addition, SP2 also adds: Windows Search 4.0, Bluetooth 2.1 Feature Pack, the ability to store information on the Blu-Ray media directly to Windows, Windows Connect Now Wi-Fi configurations, and the ability to have exFAT file system to support UTC timestamps, which makes the right to file synchronization in different time zones.

Despite these improvements, Nash requires the most Vista users will be able to hang tight and formal SP2’s release. “Although we recommend SP2 when it ships, your best bet today is Windows Vista SP1,” he said.

Microsoft released SP1 in March. It includes compatibility, security and improved performance, but almost no features or interface changes that the end-user communication.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

Oprah jumps into the Ebook reader niche – Amazon.com

October 25, 2008 by loolia556

People talk-show host Oprah Winfrey on Friday accepted ignite Amazon.com is a blessing that will probably give the e-book reader a powerful force against its main competitor, the Sony Reader.

In a publication on its website, Winfrey revealed that it had become ignite his “new favorite gadget” afternoon on his television talk show. Earlier speculation that the celebrity does nod for the device was triggered by a 24-second video ad on the site in the Amazon. The announcement said Winfrey would discuss on his show a gadget that has “life change for me” and “the wave of the future.” The announcement directly above a promotion to ignite.

During his presentation, Winfrey, who was joined by Amazon’s founder and CEO Jeff Bezos said that while the light is expensive at $ 359, she saw as an investment environment. “I know it is expensive in these times, but it is not trivial, because it pays off,” she said, according to its website. “Books are much cheaper, and you save paper.” All books are $ 9.99 or less at Amazon.

The ignite books on Oprah The Story of Edgar Sawtell from David Wróblewski, the audacity to hope of Barack Obama, Ageless: The Naked Truth About Bioidentical Hormones by Suzanne Somers, The Alchemist by Paulo Coelho, The Forever War by Dexter Filkin, and crack the loss of fat Code: Was your metabolism and the conquest of the plateau of Food Wendy sing.

Approval of the media magnate is the gold ring coveted by many consumer-product companies. Winfrey proved her star power of the popularity of her book club, which has catapulted many a writer for The New York Times best seller list. When Obama Winfrey supported the president, a study from the University of Maryland economist Craig Garth Waite and Tim Moore showed that Winfrey nod would add 1 million votes in the Democratic nominee.

Winfrey approval of the light may lead to more than just increasing sales. It can go a long way to move ignite the integration of a market niche.

Amazon ignite and Sony Reader, which is about the size of a reduction in paperback, is capable of storing thousands of books, magazines, newspapers or any other electronic documents. The devices use the same display technology from E Ink, which shows the text to read even in direct sunlight.

A major difference is in how the books can be purchased for the devices. Sony (NYSE: SNE), requires that purchased content on a computer and transmitted to the reader via a cable connection. The ignite, however, ships with a new network connection that allows users to buy and download books on Amazon. The wireless connection is available at no additional cost. The light costs about $ 40 less than the reader.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

What can we expect in iPhone 2.2?

October 25, 2008 by loolia556

Apple has recently begun to extend to developers of the second beta version 2.2 of its software for the iPhone and iPod touch, and it becomes increasingly clear what will be included in the update. (The first beta version includes a slightly different version of the Safari browser.) Currently, it seems that the most important new features focused on maps, which is built for the iPhone by Google.

With the update, users will be able to obtain the directions of public transport for its products. It is not just the bus, subway and train lines, but also walking directions, too. The card will also feature Street View, the area that allows you to virtually walk the streets with real images displayed. This was added to other versions of Google Maps for Mobile recently, and is included in the Google mobile platform Android.

The blog iPhoneYap.com could get a lot of photos of the new features (below), which also apparently a way to send your current location to friends. Although this May’s interesting, and can generate alarms for several location-based Apps here (as Kite Bright, loopt and Whrrl to name a few), it seems these data will be sent by e-mail – which seems rather pointless because May you be well past a place where the person reading the e-mail. Now if only the iPhone has a message that can operate in the background …

You can probably count on a number of other new features and fixes before Apple officially launched the 2.2 update. The 2.1 update in the first part of September, so many questions that users have with the device.

Although noted for future updates to the iPhone is a study that AT & T recently sent to customers asking them to assess the level of interest in new services for the device. This list probably has nothing to do with Apple, Apple Insider says (more likely that AT & T to use), it contains some nice features that people have indicated they want on the device:

* Copy and paste feature. A third option was presented briefly, but Apple killed with a software update.
* MMS (picture messaging). It is still quite strange that a device can not do.
* Flash and Java support, it is also, the two are constant rumors of new features.
* IChat (instant messaging). Although there are many third party solutions instant messaging there, nobody can even run in the background. It is hoped that Apple does (as I mentioned above).
* In tones. Not even me started on how lame it is.
* GPS pending. This is another characteristic that is always rumors and future, probably at some point.
* The video recording. The current iPhone camera is activated only for taking pictures, but as we have seen in the iPhone hacked to run programs not in the store app, video is possible. It is certainly interesting to note that the streaming video QIK has apparently found a way to get video recording feature, which works with non-hacked iPhone. Both Digg founder Kevin Rose and blogger Robert Scoble saw this practice, but the application is not yet available in the App Store, and we do not know when it will be (although Rose expects soon).

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

MS08-067 and the SDL

October 24, 2008 by loolia556

Hi, Michael here.

No doubt you are aware of the out-of-band security bulletin issued by the Microsoft Security Response Center today, and that all the problems of security, this is a vulnerability we can learn and if necessary can use to future versions of the Security Development Lifecycle (SDL).

Before I go to in certain details, it is important to understand that the SDL is a multi-pronged security to reduce the systemic weaknesses. In theory, if one aspect of the SDL is not to prevent or catch a bug, then every other aspect should avoid detection or error. The SDL also mandates the use of security-defense, because we know very well that the SDL process will never catch any safety deficiencies. As we have said many times, the goal of the SDL is “to reduce vulnerability and mitigate the consequences of what was missed.”

In this article I would like to SDL code required for analysis, code review, fuzzing and the compiler and operating systems defense and how it is delivered.
Code analysis and examination

I would like to begin by analyzing the code to understand why we do not find this error by manual code review or through our static analysis tools. The code in question is relatively complex to canonicalize street names, such as strips of “..” Such signs and to the simplest possible directory name. Bug is a stack-based buffer overflow in a loop; find buffer overflows in grinding, particularly complex loops that are difficult to detect with a high degree of probability, but many false positives. At a later stage, I will publish more of the source code for the function.

Loop function within walking on a string to determine whether a character in the path May on a short, short, short, slash or backslash and the next, the canonical algorithms.

The irony of the bug, which also requires a limited function call:

_tcscpy_s (previous Last slash, pBufferEnd – Last slash past, ptr 2);

This feature is a macro that expands to wcscpy_s (dest, len, source), technically, the error is not included in the invitation to wcscpy_s, but it is on the way of reasoning is calculated. As I already mentioned, all three arguments are very dynamic and constantly updated, while in ()-loop. There are a lot of pointer arithmetic in this cycle. Without going into all the details of the attack category, a special kind, and after the while () loop has gone through a few times, the pointer, earlier last slash, May will be clobbered.

In my opinion hand examine this issue and success in this error would be a much skill and luck. So what about tools? It is very difficult to make an algorithm to analyze C or C code for these kinds of mistakes. The possible variable states is growing very fast. It is still difficult, such algorithms and scope to non-trivial code base. This is even more complicated, because the function of an entirely different argument, it is not that the argument is a value of 1, 2 or 3! Our current tools do not catch this error.

OK, now I’m really on a part with the next section.

In the past year or so, I noticed that the security vulnerability in Microsoft, but most noticeably in Windows have been wrong in a class I call “onesey – twosies” in other words, individual errors. It is a good side and bad side to this. First the good news, I think we May have removed a large number of low-hanging vulnerability of many of our products, especially the newer code. The bad news is that we continue to have security problems, because you can not train a developer to hunt unique wrong, and the creation of tools to search for such errors is also difficult to do without an incredible amount of False Positive. With all this said, I will add details about the individual errors to our internal training, I think it is important that people realize that even with great tools and experienced security engineers, there are still bugs that are difficult to find.
Fuzz Testing

Let me blunt, we do not catch Fuzz testing, and they should have. So we return to our fuzzing algorithms and libraries to update on this issue. For what it is worth, we are constantly updating our fuzz testing heuristics and rules so that this error is not unique.
Defense

If you want all the details of the defense, and how they play in Windows Vista and Windows Server 2008, I urge you to read the sword in the team-depth analysis, once it is posted.

A major focus of the SDL is to define and to require the defense, because we have no illusions about the search or prevent any security problems by trying to run the code right the whole time, because nobody can do it. None. See my comment above about individual fault!

Let’s take a look at each SDL requirements and how they cut in the light of this vulnerability.
-GS

The GS-is not so simple. Many run before a cookie, and the attacker can overflow because the flooding starts with an offset in the stack buffer, instead of the stack buffer itself. Thus, the attacker can overwrite the other frames of the call stack, similar functions to return before a cookie check is done. It is a long way to say that-GS was not to prevent this kind of scenario.
ASLR and NX

The code, in order to fully with SDL, and in connection with the / DYNAMIC BASE, and / NXCOMPAT on Windows Vista and Windows Server 2008. There is a great defense, if used together, and reduce the risk of a successful attack significantly. Stack is also a randomized deterministic attack even more unlikely.
Service restart policy

By default, the services concerned are marked at the start only twice after a crash on Windows Vista and Windows Server 2008, which means that the attacker only has two attempts to attack the right side. Before Windows Vista, the attacker has unlimited attempts since the service started an indefinite period.
Authentication

Thanks to the mandatory integrity control (MIC) settings (which comes with the kind permission of UAC) in the network endpoint, which cause the vulnerable code requires authentication under Windows Vista and Windows Server 2008 enabled by default. Before Windows Vista, the end is always anonymous, so that everyone can attack it, as long as the attacker can pass through the firewall. This is an excellent example of SDL emphasis on attack surface reduction, which requires authentication: the number of attackers with access to entry are dramatically reduced.
Firewall

We activated the firewall in Windows XP SP2 and later, this was a direct teachings of the Blaster worm. By default, ports 139 and 445 is not open to the Internet in Windows XP SP2, Windows Vista and Windows Server 2008.
Abstract

The $ 64,000 question we ask ourselves if we have a bulletin is “SDL has not?” and the answer in this case is the categorical “No!” No, because as I said earlier goal of SDL is “reduce vulnerability and to mitigate the consequences of what you missed.” Windows Vista and Windows Server 2008 customers by the defense in the operating system has developed that in one part of SDL. The development team built, that the related section together and in connection with the settings in the Windows Vista ISV Security and Writing Secure Code for Windows Vista, so that their service is through the operating system.

The team is not blind holes through the firewall unnecessarily, in accordance with the SDL.

The team reduced their attack surface, in accordance with the SDL, which authenticated connections instead of anonymous connections by default.

We know that the SDL mission-GS has very strict HEURISTICS so some features are not protected by a stack cookie, but in this case, there is no buffer on the stack, so there will be no cake. We know this. There are currently no plans to be put in a short time.

Fuzzing missed, we will update our HEURISTICS Fuzz testing, but we are constantly updating our fuzzing HEURISTICS anyway.

In short, based on what we know now, Windows Vista and Windows Server 2008 customers are protected because the SDL defense missions in the operating system, and because the development team followed to the letter of SDL to use this defense.

Chalk one for the Windows Vista and later and SDL!

As always, questions and comments are welcome.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

New windows bug??

October 24, 2008 by loolia556

Only a few hours after Microsoft information on a Windows bug, new attack code that errors arose.

It took developers of immunity Security Testing Tool, two hours to write their advantage after Microsoft released a patch for the issue Thursday morning. Software developed by the immunity is only for paying customers, which means that not everyone has access to the new attacks, but security experts assume that some version of the code begins to circulate in public very soon.
Microsoft has the unusual step of rushing an emergency patch for error Thursday, two weeks after noticed a small number of targeted attacks used that mistake.
Vulnerability has not been publicly disclosed before Thursday, but by giving its patch, Microsoft has hackers and security researchers enough information to draw up their own attack code.
The mistake lies in the Windows Server service is used to connect various network resources such as file and print over a network. By sending malicious messages to a Windows computer with Windows Server, an attacker can take control of your computer, Microsoft said.
Apparently, not so much trouble to write this kind of attack code.
“It is very useful,” says Immunity Security researcher Bas Alberts. “It is a very manageable stack overflow.”
Stack overflow error when a program allows attackers to enter a command on parts of the computer, normally at the curb and then lead to a command to run the victim’s computer.
Microsoft has spent millions of dollars to eliminate these kinds of errors from its products in recent years. And one of the architects of Microsoft’s Security Testing Program had an open assessment of the situation Thursday, saying that the company “fuzzing” test should have detected the issue earlier. “Our Fuzz testing is not catching, and they should have,” wrote Security Program Manager Michael Howard in a blog posting. “So we return to our fuzzing algorithms and libraries to update on this issue. For what it is worth, we are constantly updating our fuzz testing heuristics and rules so that this error is not unique.”
Even Microsoft has warned that these errors could be used to create a computer worm, Alberts said, it is unlikely that such a mask, if created, would get very far. That is because most networks would be blocked, this type of attack in the firewall.
“I see it as a problem for the internal network, but it is a very real and useful wrong,” he said.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

Smart phone roundups

October 24, 2008 by loolia556

What is the first Google Android phone and the 3G iPhone and other hot new phones?

There is no shortage of capacity, innovative smartphone options these days, regardless of the carrier platform or you would prefer. Devices like the BlackBerry Curve or Motorola Q9c is incomparably higher than they were as little as two years ago, so much so that some “oohs” and “ahhs” that they now May, once all but silenced.

These “blah”, of course, mean that a new generation of smartphones transshipment operation is imminent. The last six months alone have seen the touch-screened wonder, as well as 3G iPhone and the upcoming BlackBerry Storm, the introduction of Google’s Android mobile OS on T-Mobile G1, all despite a seemingly endless game of a -upmanship on the carriers and handset manufacturers alike.

To help you order in the struggles we have a blow-by-species comparison of five of the hottest new gene phones.

See how the latest crop of smartphones to hot side by side, and comparing data, prices and much more.

Featured phones in this summation:

Apple iPhone 3G (AT&T)
The iPhone 3G represents the birth of a new computing platform. It’s also one very cool phone. While it’s not perfect, it makes other options on AT&T look tired.


BlackBerry Bold 9000 (Rogers Wireless in Canada, coming soon to AT&T in the U.S.)
RIM’s next-generation BlackBerry Bold 9000 does for the boardroom what the
iPhone does for the rec room.


BlackBerry Storm 9530 (Verizon)
Could the Storm be the “iPhone for business?” RIM and Verizon fire directly at Apple with this attractive and innovative touch-screen BlackBerry.


HTC Touch Diamond (Sprint)
With its 3G support and much lower (subsidized) price, Sprint’s version of the drop-dead-gorgeous Touch Diamond makes much more sense than the unlocked version.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

I wish someone could had blown my school away too…

October 24, 2008 by loolia556

ISLAMABAD, Pakistan, Oct. 23 — At least 10 people were killed and six others injured in a suspected U.S missile strike Thursday in Pakistan’s restive tribal region, intelligence officials and an eyewitness said.

The attack apparently targeted a madrassa, or religious school, operated by Taliban commander Sirajuddin Haqqani, according to a Pakistani intelligence official who spoke on the condition of anonymity. It took place in North Waziristan, an area known to be a haven for al-Qaeda and Taliban insurgents.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

Pirates putting NATO to alert

October 24, 2008 by loolia556

It seems like pirates isn’t a problem on the Internet only. Wonder a little bit what a modern pirate from Somalia lookslike but decided to satify myself with the thought of a mix between Bootstrap Bob and Bob Marley.

BRUSSELS (AP) — A NATO flotilla sailing toward the Somali coast will begin antipiracy operations within the next few days, but officials said Wednesday that the alliance was still working out the ships’ rules of engagement.

The seven NATO warships will escort cargo ships carrying United Nations food aid to Somalia and will patrol the shipping lanes off the Somali coast, where pirates have hijacked more than 25 ships this year and attacked more than 50 vessels.

“They will have the rules of engagement that they need, the operational plan that they need,” said James Appathurai, a NATO spokesman. “I would not be surprised to see all of this complete in the next two days.”

The Sept. 25 seizure of a Ukrainian cargo ship, the Faina, carrying 33 battle tanks and heavy weaponry, has focused international attention on the menace posed by pirates.

United States warships have surrounded the Faina for weeks to prevent the pirates from trying to unload the weapons, and a Russian guided missile frigate is traveling to the area.

The NATO naval group consists of destroyers from Italy and the United States; frigates from Germany, Greece, Turkey and Britain; and a German auxiliary vessel.

“There will be a number of very competent and very effective military ships to provide presence, deterrence and, where necessary and possible, to intervene to prevent acts of piracy and to escort ships,” Mr. Appathurai said.

Details of each ship’s responsibilities and the rules for how they will deal with the pirates are still being worked out.

“This is obviously a very, very complicated thing they are trying to do,” the NATO spokesman said. “There are a host of pirates, but they don’t identify themselves with eye patches and hook hands that they are pirates.”

The NATO crews are likely to find it hard to distinguish between ordinary Somali fishing boats and pirate boats, some experts said.

About 20,000 ships pass annually through the Gulf of Aden, a strategic body of water off the coasts of Somalia and Yemen. Somalia, caught up in an Islamic insurgency, has not had a functioning government since 1991 and cannot guard its coastline.

The operators of the Faina said Wednesday that they had not raised enough money to meet the pirates’ multimillion-dollar ransom demand.

Viktor Murenko, the head of Tomex Team, which operates the cargo ship, said the company had accumulated only $1 million toward the ransom.

He said the bandits were demanding $20 million.

Mr. Murenko said the Faina’s crew members had received food and water and were in satisfactory condition.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

Greenspan Partially Wrong?!

October 24, 2008 by loolia556

Ok… This is the main question for the day… “PARTIALLY” WRONG or totally wrong?

Greenspan softened his longstanding opposition to many forms of financial market regulation, acknowledging in an exchange with Waxman that he was “partially” wrong in his belief that some trading instruments, specifically credit default swaps, did not need oversight.

Waxman cited a series of public statements by Greenspan saying the market could handle regulation of derivatives without government intervention.

“My question is simple: Were you wrong?” Waxman asked.

Greenspan said he was “partially” wrong in the case of credit default swaps, complex trading instruments meant to act as insurance against default for bond buyers.

While Greenspan was once hailed as one of the most accomplished central bankers in U.S. history, the low interest rates during his final years at the Fed have been blamed for fueling the housing bubble and eventual crash that touched off the current financial crisis.

His strong advocacy for limited regulation of financial markets has also been called into question as a result of the crisis.

The former Fed chair said that a securitization system that stimulated appetite for loans made to borrowers with spotty credit histories, was at the heart of the breakdown of credit markets.

“Without the excess demand from securitizers, subprime mortgage originations — undeniably the original source of crisis — would have been far smaller and defaults, accordingly, far fewer,” he said.

By the way.. Check out cool stuff at…

Blackhatworld And on Blackhatzen

a0rta

Hello world!

October 24, 2008 by loolia556

Welcome to WordPress.com. This is your first post. Edit or delete it and start blogging!