Your security, networking, programming, and application news source.
Google

Friday, May 30, 2008

TCP Reset Injection Detection Utility

  An interesting source, <NNSquad> (Network Neutrality Squad), has released an open source tool (licensed under <LGPL>) to detect TCP reset (RST) packets that may have been injected into a TCP connection by a party other than the endpoints.
  The <NNSquad Network Measurement Agent (NNMA)> tool's available downloads are beta and include a Windows 2000/XP/Vista installer binary and <VC++ 6.0> Windows source code.
  TCP reset injection has been discovered being controversially used by internet service providers, such as <Comcast>, to disrupt torrent and P2P file sharing.

Thursday, May 29, 2008

Firefox 3 Preparing for World Record Attempt

Download Day
  The official release of Firefox 3 maybe be the most anticipated software releases of the year. Firefox 3 shows many promising improvements, most notably major memory usage cutbacks and performance improvements. <Early memory comparisons> have shown impressive numbers. Many other changes and improvements are already locked in since the first <release candidate> was released. A quick run down of feature comparisons can be found <here>.

  <The Mozilla Blog> has announced an attempt to break a world record for most software downloads in 24 hours. The release date for Firefox 3 isn't set yet, but is expected some time in June. Mozilla has a <Download Day Headquarters> site where you can monitor for the release date, read more, and even pledge to download on the release date.

Sunday, May 11, 2008

BSD fixes 25 year old bug

The flaw for reading MS-DOS directories in all BSDs (including Mac OS X) tracked back to 1983 was recently fixed. SAMBA uses a special workaround in order to function properly on BSD systems. OpenBSD developers received an email from an OpenBSD user which led to unraveling the bug.

Source with quotes from <Marshall Kirk McKusick>, the original developer of the *dir() library:

<OS News - The 25 year Old BSD Bug> (May 10, 2008)

Monday, April 28, 2008

Automated SQL Injection Mass Attack Hits IIS Websites

“Exploits of a Mom” by <xkcd>

  An automated attack against Microsoft’s IIS servers has hit some 500,000 websites. Websites affected include the United Nations, UK Government sites and the U.S. Department of Homeland Security.

  These attacks targeted Microsoft IIS servers which allow generic SQL commands that don’t require specific table-level arguments. The attack targets IIS servers which run ASP allowing them to pollute database servers in a generic way that doesn't require prior knowledge of the database's table and field structure.

  The attacking script injects malicious JavaScript code into every text field of the database. The JavaScript then loads an external script that can compromise a user’s PC. So far there have been no details about who is behind the attacks.

<Wired Blog - Massive Attack: Half A Million Microsoft-Powered Sites Hit With SQL Injection> (4/28/2008)
<Hackademix - Mass Attack FAQ> (4/26/2008)

Saturday, April 26, 2008

When Logo Design Goes Wrong

  The Office of Government Commerce, an office of the treasury in the United Kingdom, is commonly known as OGC. An investment of £14,000 was put into a logo design, which resulted in a nice formal image of the OGC acronym.



According to insiders, within seconds of unveiling employees spotted the problem with this proud logo. This despite it already being etched in mouse pads and pens. If you turn it on it's side, you should notice the problem.



<A hallarious animated version (gif) was posted here>

<The UK Telegraph - OGC unveils new logo to red faces> (4/25/2008)