Your security, networking, programming, and application news source.
Google

Tuesday, November 11, 2008

[Link] Windows 7 is , You Guessed it, Vista Rebranded

Kernel process profiling shows it looks like a Vista; performance testing shows is walks like a Vista; claims of being a high performing Linux-laptop-killer falling flat on it's face, make it sound like a just another disappointing Vista.

InfoWorld 5 pages (Nov 10, 2008)

<InfoWorld - Test Center benchmarks: Windows 7 unmasked>

Thursday, November 6, 2008

Adobe Reader Exploite Using Java Script

ADOBE READER 8

  Core Security Technologies reported a critical vulnerability to Adobe about it's Adobe Reader. Adobe has already released an update to address the vulnerability in version 8.1.2. The vulnerability was found in Foxit Reader (CVE-2008-1104) and later successfully tried in Adobe Reader. Adobe Reader and Foxit Reader both have different security approaches that lead people to think Adobe Reader wouldn't be affected.

Foxit Reader 2.3 build 2825 security bulletin from Secunia Research details the following:

"The vulnerability is caused due to a boundary error when parsing
format strings containing a floating point specifier in the
"util.printf()" JavaScript function. This can be exploited to cause a
stack-based buffer overflow via a specially crafted PDF file."
(Secunia Research, May 20, 2008)

Help Net Security's coverage of the Adobe Reader vulnerability added that the util.printf() function "converts the argument it receives to a String, using only the first 16 digits of the argument and padding the rest with a fixed value of “0” (0x30). By passing an overly long and properly formatted command to the function, it is possible to overwrite the program’s memory and control its execution flow."(Help Net Security)

Help Net Security - Critical vulnerability in Adobe Reader (Nov 4, 2008)
<http://www.net-security.org/secworld.php?id=6715>

Security Focus - Secunia Research: Foxit Reader "util.printf()" Buffer Overflow.
(May 20 2008)
<http://www.securityfocus.com/archive/1/archive/1/492289/100/0/threaded>

Wednesday, November 5, 2008

[Link] Windows 3.x Still Dying


Microsoft ended support for Windows 3.x at the end of 2001, but 3.x continued on as an embedded operating system. Windows 3.x continued to power cash registers, ticket systems, and even in-flight entertainment systems.

"On 1 November Microsoft stopped issuing
licences [for Windows3.x]"
(Ward)


BBC News (Mark Ward) (Nov 5, 2008)

<BBC News - The end of an era - Windows 3.x>

Will iPwn for Food

Will iPwn for Food


  Forbes reports on <(blog)Piergiorgio Zambrini>, 38 year old Italian systems engineer who created the first popular iPhone carrier break application named <Ziphone>. Zambrini is reported to be "revealing a bug that can crash the iPhone and, he says, other devices including iPods and Apple computers."(Buley)

  Zambrini is holding the details for Apple. Forbes reported this bug to be in the audio portion of Apple's video format, that able to crash Apple iPod and latest generation iPhone. Forbes says this bug is in a shared library used in most Apple operating systems(i.e., Mac) and has confirmed this claim on iPhones.

  Zambrini goes on in the interview with Forbes about wanting a job in the Apple security department and wanting to talk to Steve Jobs. Yeah, it got weird, but apparently Zambrini made a nice chunk off Ziphone already.

Forbes.com (Taylor Buley), Crashing The iPhone
[Feed]<http://www.forbes.com/technology/2008/11/03/apple-iphone-bug-tech-security-cz_tb_1103iphone.html?feed=rss_popstories> (Nov 3, 2008)

Sunday, November 2, 2008

[Release] OpenBSD 4.4 Released


OpenBSD

Free, Functional & Secure

"Only two remote holes in the default install, in more than 10 years!"



OpenBSD 4.4 released Nov 1, 2008:

<(Wiki)OpenBSD>

<OpenBSD 4.4 Release Details>

<OpenBSD Download Page>