Keep Window Healthy

Today we are posting ways to keep your window safe and free from errors . Tips . Keep at least 10 GB of free space in your c: drive. Clear junk files on a regular .....

Windowns Heathy

Wanna be hacker....?

In the beginning we all asked ourselves a few questions... Where do I start? Where do I go to learn? What do I need to Hack?...

hackers

Downloading trick for Ebooks..

This is Abhishek nehra. I just observe that in colleges (special in engineering colleges) there is a big problems on books as many of guys have to buy a book of the cost they do not want to.But there is a solution and that is ......

Free

Linux Step by Step ...

Now a days Linux became a main stream operating system. Many users are now start using it. But as we know it's like a platform build for advance users so we face a little difficulty in using it. ......

Linux

Remote File Inclusion ...

Remote file inclusion is basically a one of the most common vulnerability found in web application. This type of vulnerability allows the Hacker or attacker to add a remote file on the web server. If the attacker gets successful in performing.....

Omnis dolor repellendus

Spread your rat...

At Any Thought of a virus who can help you? Not even one? ok!! I will tell you about one , some may know it in advance but......

rat

Playing games without graphics or low graphics..

Many of us has a desire of playing PC games at high-quality. But some of us can’t fulfill our desire because of the non-availability of Graphics card or we can’t afford. Today, maximum pc games demand graphic card

Harum quidem rerum
  • Reiciendis voluptatibus maiores
  • Asumenda omnis dolor
  • Voluptates repudiandae sint
  • Necessitatibus saepe eveniet
  • Omnis dolor repellendus
  • Pomnis voluptas assumenda
  • Harum quidem rerum
Showing posts with label Update. Show all posts
Showing posts with label Update. Show all posts

Wednesday, March 2, 2011

More than 50 Android apps found infected with rootkit malware

Google acts to remove apps after developer finds 'DroidDream' malware can take over phone and send personal details to remote server (updated)
More than 50 applications on Google's Android Market have been discovered to be infected with malware called "DroidDream" which can compromise personal data by taking over the user's device,
and have been "suspended" from the store.
Google removed the apps from the Market immediately on being alerted, but it is not clear whether it has removed them from devices to which they have been downloaded. As many as 200,000 Android devices could have been infected.
The revelation comes from Android Police, a news site on Google's operating system, which calls it "the mother of all Android malware", noting that its examination had found that it "steals nearly everything it can: product ID, model, partner (provider?), language, country, and userID. But that's all child's play; the true pièce de résistance is that it has the ability to download more code. In other words, there's no way to know what the app does after it's installed, and the possibilities are nearly endless."
Lookout, a security company, which in a blogpost lists the 50-plus apps discovered to be infected. (The list is also below, via Lookout.)
Smartphones running Google's Android software have become enormously popular and are reckoned to be close to taking over worldwide as the fastest-selling smartphone platform, ahead of Finland's Nokia. Its growth has been fuelled by the fact that the software is free to license, and for developers there is no charge or checks to putting apps on the Market – unlike Apple's iPhone App Store, which checks every app against a suite of tests for suitability before allowing it on its store.
That has led the Market to grow rapidly, but also makes situations like the latest one – which is not the first case of malware found on the Market – harder to avoid.
The malware was first discovered by a Reddit user, Lompolo, who spotted that the developer of one of the malware apps had also posted pirated versions of legit apps, using the developer name "Myournet". But two other developers' products have also been found to include DroidReam.
Lompolo noted that "Myournet" had "taken 21 popular free apps from the Market, injected root exploit [code] into them and republished". More worryingly, those had seen between 50,000 and 200,000 downloads altogether in just four days.
DroidDream contains code which can "root" – take complete control of – a user's decice, and send detailed information such as the phone's IMEI (International Mobile Equipment Identity) and IMSI (International Mobile Subscriber Identity) numbers and send them to remote servers. But as Android Police's team found, the code can go much further in rooting through a phone.
Update: details of how the root code works are here. Note that this is a "privilege escalation" attack - once the app starts it uses the fact that it has user privileges to jump out of its sandbox and root the phone.
It's a rather brutal reminder of the fact that Android's openness is both a strength and, at times like this, a weakness – though Google's rapid action, in which it pulled the apps from the Android Market within just five minutes of being alerted, is encouraging.
It now looks likely that security companies will begin to compete to offer antivirus and anti-malware products for Android devices – which, given its rapid growth, could prove a fertile area for them with PC sales flat.
If you have downloaded any of the apps below, you should contact your phone company.
Full list of infected applications published by "Myournet": • Falling Down • Super Guitar Solo • Super History Eraser • Photo Editor • Super Ringtone Maker • Super Sex Positions • Hot Sexy Videos • Chess • 下坠滚球_Falldown • Hilton Sex Sound • Screaming Sexy Japanese Girls • Falling Ball Dodge • Scientific Calculator • Dice Roller • 躲避弹球 • Advanced Currency Converter • App Uninstaller • 几何战机_PewPew • Funny Paint • Spider Man • 蜘蛛侠
Full list of infected applications published by "Kingmall2010″: • Bowling Time • Advanced Barcode Scanner • Supre Bluetooth Transfer • Task Killer Pro • Music Box • Sexy Girls: Japanese • Sexy Legs • Advanced File Manager • Magic Strobe Light • 致命绝色美腿 • 墨水坦克Panzer Panic • 裸奔先生Mr. Runner • 软件强力卸载 • Advanced App to SD • Super Stopwatch & Timer • Advanced Compass Leveler • Best password safe • 掷骰子 • 多彩绘画
Full list of infected apps under the developer name "we20090202″: • • Finger Race • Piano • Bubble Shoot • Advanced Sound Manager • Magic Hypnotic Spiral • Funny Face • Color Blindness Test • Tie a Tie • Quick Notes • Basketball Shot Now • Quick Delete Contacts • Omok Five in a Row • Super Sexy Ringtones • 大家来找茬 • 桌上曲棍球 • 投篮高手
Posted by Unknown 0 comments

Sunday, February 27, 2011

Awesome + Resourceful Web Portals


 
Check out the following Microsoft Web portals that caters to need of almost everyone. The Portal name is followed by a brief description.
1. Website Spark : It’s for small IT enterprises. Microsoft provides them the tools needed for Designing and development for FREE!.
There is no upfront cost for first 3 years. Terms and conditions do apply, but they seem to be obvious For eg : You need to deploy a website before 6 months, renew your subscription after few months, etc. Above all, it is for all budding webmasters!
2. Biz Spark : To me, bizspark.com is extension of websitespark.com. Fundamentally it is for Tech startup’s that need support and visibility. This one is meant for all techno-preneurs!
3. Dream Spark : FREE software’s ( like Visual Studio professional! ) for students. If you need a key you can write to me at paras@parasdoshi.in.
4. Microsoft Student to Business : To bridge the gap between Industry requirements and Student’s knowledge. The website has list of Job and Internship openings of various tech firms. it’s for all those who dream to be corporate czars!.
Posted by Unknown 0 comments

Wednesday, February 23, 2011

WordPress 3.0 – “Thelonius” Advantages


Todays second post I want to share with my users is advantages of new wordpress it is wordpress 3.0 . So lets check it. WordPress 3.0, the long-awaited major version update to the world’s most popular blogging platform. The software, codenamed “Thelonius” now running your millions of websites.
The last major version, WordPress 2.9 was downloaded more than ten million times, a measure of the software’s popularity.so with the latest version 3.0 wordpress is now ready as the best  Content Management System (CMS) that is available to support personal, business, academic, and corporate Web sites as well as blogs.As this is a major release there are new features including a brand new Default WordPress Theme called TwentyTen, the ability to Customize Post Types and an excellent new Menu Manager.
wordpress3 thumb 300x168 Wordpress 3.0   Thelonius Advantages
First we just look at the features through this video
So let’s have a look at WordPress 3.0 features or advantages.
1) MU or Multi-User option :

Multi-User option is one of the best features of WordPress 3.0 that will allow you to manage multiple blogs with different permissions  from a single admin panel. Alright, admit it  we all have at least a couple of blogs to work with, right? So MU is a very good  feature.

2) Post Types Customization :

Till WordPress 2.9, WordPress has always enabled you to publish two types of content within a blog. These we recognize as blog Posts and Pages. Now in WordPress 3.0 you are able to define your own extra content types and also give them their own attributes. So now users can create any kind of content they want

3) New “Twenty Ten” the Ultimate New Theme of WordPress 3.0 :

WordPress 3.0 having a new default design theme called Twenty ten. you can see the live demo of this design on official WordPress website. As you understand according to the new name of default theme every year WordPress got a new default theme in wordpress 3.0.
wordpress 3.0 thelonious twenty ten screenshot 300x212 Wordpress 3.0   Thelonius Advantages
4) New Custom Menu Management Feature :

Probably for users the most useful feature released with WordPress 3.0 is the brand new menu management system that has been included with the new version.New Custom Menu Management feature is also available in wordpress it  allows in creation of custom menus combining posts, pages, categories, tags, and links for use in theme menus or widgets.Menu management should be the most popular new function of WordPress3.0. It allows you to completely control the site’s navigation menu. Through easy drag and drop interface, users can freely create various combination of links: internal links, external links, categories, etc. And you can embed these custom menu themes anywhere and treat them as widgets.
WordPress3 menus 600x369 300x184 Wordpress 3.0   Thelonius Advantages

5) Multi-Site WordPress :

In addition a new Multi-Site feature has been incorporated due to the merging of WordPress with WPMU, so that you can now build several WordPress blogs with the same software installation. So now you can manage several different websites each with a different domain or subdomains all from within a single installation of WordPress. This facility is not enabled by default as it will not be required by most users.

6) Custom Background and Image support system :

This option will help you create new theme for your blog in a matter of minutes.

7) Specific author templates :

Now it is possible in WordPress 3.0  to use the specific author templates. So, you can easily mark your own post or entry with your signature.

8) Canonical Plugins:
Canonical plugins  available in WordPress 3.0. This means that from the moment it is launched you will be able to easily use your favorite plugins without being afraid that new release of WordPress will kill them
Posted by Unknown 0 comments

Saturday, February 12, 2011

Top 10 most awaited technology


In the aftermath of CES 2010, our appetites are whetted for some serious gadgetry. While a lot of great electronics were debuted there and will be out this year, there’s a wide world of prototypes and other products that simply won’t be. Seeing the bounty of the present only makes us even more excited when we think about the future. Read on for our roundup of the top 10 items we wish were coming out in 2010.


1. Light Blue Optics Light Touch


The Light Touch is an amazing prototype that essentially frees your computer from your monitor completely, transforming any flat surface into an interactive touchscreen. It accomplishes this feat by means of Holographic Laser Projector (HLP) technology, which projects your display onto pretty much anything. The touchscreen has a very reliable reputation and with 10.1” and WVGA resolution it has enough real estate for you to work on your virtual keyboard and still see what’s above it. Honorable mention also goes to the B-membrane (http://www.yankodesign.com/2008/06/23/laptopdesktop-hybrid/), a concept design by Won-Seok Lee, which isn’t even a prototype (and maybe never will be) but definitely earns style points within the same genre. See more here

2. Samsung’s 14” transparent OLED notebook


At CES Samsung displayed a 14” notebook featuring an OLED display that was 40% transparent. It just looks cool, and I want one – don’t you? This is the largest transparent display and with the industry average currently at 25% transparency, this is the biggest and best model there is right now. Beyond the cool factor (if you need to go beyond it) how useful it is for laptops is debatable, but we’re sure you’ll think of something as soon as you have one. Certainly, the applications across the board for this tech is exciting. Honorable mention goes to another concept we saw a while back for a VAIO which was purely holographic (http://www.yankodesign.com/2007/09/18/futuristic-vaio-zoom/), and simply transparent glass when off – we love concepts that both make us think and get us excited at the possibilities. See more here

3. Alioscopy Glasses-Free 3D TV


This one also piqued our interest from CES, and if this were coming out in 2010 our excitement for 3D TV would be exponentially higher than it currently stands. Alioscopy has was seems like a pretty usable prototype for 3D TV that doesn’t require the use of sometimes bulky, always ugly 3D glasses. Imagine if viewing 3D at home (or even in theaters) didn’t feel like a goofy trip back to the 1980s (http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/2009/8/19/1250693481388/3d-glasses-001.jpg), and instead were exactly as simple as turning on your TV and switching to the 3D version of your favorite channel? For the sake of anyone who likes watching 3D TV, this tech can’t come out soon enough. See more here

4. Inventables Foldable DVD player


This DVD player concept from Inventables with an origami style foldable screen seems to have made its rounds way back in 2006 with no update. But we wish this had existed. In fact, if you upgrade this puppy to a Blu-ray player, this becomes an extremely relevant machine. Imagine having a full HD 10” display that is actually pocketable? Say goodbye to watching video on the go on your smartphones. The exciting thing is that even though this concept appears to be dropped, advancements in flexible display technology means something like this could genuinely appear any day… more on that below. See more here

5. 2011 Chevy Volt


Ok, so we’re cheating a little bit with this one, since despite the 2011 tag the Volt will begin production in November 2010. But suffice it to say we can’t wait for this to hit the mainstream. The Volt will be the first fully plug-in mainstream car, capable of traveling 40 miles entirely on emission-free electricity. If you want to go beyond that, it uses gasoline to create electric charge, bringing the total distance on a full tank up to hundreds of miles. Cost is expected to be in the general consumer range for cars, plus there is a $7500 tax credit available for electric vehicle purchases, meaning this could be something that really has a mass impact on the car industry and changes the way we think about driving. Plus it looks pretty sweet – Chevy didn’t forget the style points. See more here

6. LG’s 19” E-Ink Newspaper


E-Readers came out hot and heavy at CES this year, but for the moment they all use inflexible glass to display their e-ink goodness to your eyes. LG recently showed off a .3mm thin, 130 grams light, 19” prototype of flexible e-paper designed to emulate the A3 size of a standard newspaper. The possibilities with flexible e-paper are endless, and we love this application of it. If there was a market-ready product like this out today, newspapers, magazines, and consumers would be lining up, and we’d be right there with them. See more here

7. The Brain-Twitter Interface


The field of brain scanning has come a long way, and we may have crossed a new line with the invention of this mind reading Twitter prototype. To use it, the Twitterer straps a relatively painless looking apparatus onto their head and, staring at a grid of letters, thinks of the one they want. Based on a series of flashes and your measured reactions, the device figures out the letter you want and inputs it into your Twitter account. Current speeds top out at 8 characters a minute but imagine if the detection algorithm could be sped up! Instant applications for the paralyzed abound but just as exciting is the potential that lies in this tech which could eventually make it universally used. It might not be that far off, and the sooner tech like this moves past the prototype stage the sooner it will come. See more here

8. MSI dual screen e-reader/netbook


MSI debuted this device at CES, and it’s pretty marvelous. Featuring twin linked 10” LCD touchscreen displays and running Windows/Intel inside, it has a number of uses. With a virtual keyboard it can be a netbook, without it perhaps a two paged e-Reader, or else 1 page of text and pretty much anything else you want on the other side. You can even use the whole thing as a single display if you want to (albeit with a hinge in the middle). MSI claims they might have this out by Q4 of this year, but given how much we’ve heard (http://www.laptopical.com/samsung-reaffirms-oled-commitment--promises-laptop-by-q3-2010-35575.html) of other (http://www.laptopical.com/sony-showcases-new-oled-concept-32839.html) concepts that have never quite come to light, we won’t let this seemingly working prototype get our hopes up too high for a 2010 release. See more here

9. Sony 24.5” 3D OLED TV


Ever since Sony came out with a working 11” OLED TV 2 years ago, people have been clamoring for a successor. A larger OLED TV model would be a perfect match with the boom of 3D movies this year to get the most out of the home experience. OLED presents a thinness and picture clarity unmatched by any sort of LCD/LED mashup, and Sony’s 24.5” 3D capable OLED TV prototype was a sight to behold at CES 2010. Unfortunately OLED just isn’t ready yet – even their 11” model costs $2,500, so who could afford one that’s twice as large and 3D capable? Pricing issues aside, we still can’t wait for the day when OLED TVs finally hit the mainstream. See more here

10. E-Rope


Our last choice for a prototype we’d love to see is less a fantastical one and more of a functional one. The E-Rope concept was designed by Chul Min Kang and Sung Hun Lim a few years ago, and it presents an elegant, attractive, and efficient way to handle your power strip needs. It is modular, so you add plugs as you go, making it never larger than it needs to be and since it can rotate, you can even snake around corners. Turning the socket section 90 degrees will cut off the current too, eliminating the power drain caused by leaving items plugged in that we’re all guilty of. This just makes sense – it’s what power strips should be, and we can’t help but hope it’ll happen someday. See more here
Posted by Unknown 1 comments

Facebook Downfall in near future!!!!!!! What are the reasons??

Facebook was once a website limited to Ivy league students whom CEO Mark Zuckerberg hacked for the thrill of collecting private data. Now it is a massive website habited by users from all parts of the world, from your grandma to your third grade teacher and back again.

Some predicted the downfall of Facebook a couple years ago. Some are predicting that it will happen any moment now. Others foresee the end in the distant future. Whether it comes fast or slow, Facebook will fade when the next best thing comes along. The question is: what will be the cause of Facebook’s demise? Below are the things we foresee being the force that drives users away.

Broadcast By Default, Hunt for the Off Switch

A fairly universal understanding of life is that things should be opt IN, not opt OUT. For example, credit cards. You opt in when you get one. Imagine if banks could decide that, since you have a checking account with them, they’ll automatically enroll you for credit cards, without publishing any sort of notice on your account when you log in, and if you don’t want it, hey, you can simple opt out.
That wouldn’t fly so well, would it?
Facebook doesn’t seem to understand this little nugget of wisdom. The way they seem to see it, you’re on their website—they can do with you what they wish. Never mind the entire fiasco over who owns photos placed on the website. Now Facebook is actively giving your information away by default, and you have to opt OUT of it.
If that weren’t bad enough, the ability to opt out isn’t as easy as you’d think. A banner across the top of the screen saying something like “WE’RE GIVING YOUR INFORMATION AWAY, CLICK HERE TO STOP THE MADNESS" would be nice. Instead you have to hunt through three different sections, into the subsections of those sections, to find the little radio button you click to keep your online life private.
That is not cool. In a world where home values can be looked up online, where probable salary numbers are just a click away, where your home can be zoomed in on via a web browser, where your cellphone can be beamed coupons based on your habits, where web advertisements target you in ways that are just a wee too familiar, how many users are going to happily maintain an account on a website that is actively trading pieces of their online lives to the highest bidder?
Not many.

Rogue Applications

You have to authorize an application. This is a good security feature, in that it prevents applications you don’t even know exist from plastering your wall with crap. The problem, in this case, is the people. Some people don’t use a lot of common sense, much like when it comes to sending away banking information to phishers or opening an attachment on an email from someone they don’t know.
Individuals with less than proper intent recognize this security loophole—we’ll call it the Human Authorized Annoyance Loophole—and create malicious applications that look appealing. Uninformed or clueless users access and authorize these applications, which then post odd, disgusting, vulgar, or otherwise eyebrow-raising things on their friend’s walls from under the user’s name. In some cases, these rogue applications even toss in the targeted friend’s name.
Hey Jane Doe, check out this video I just saw! It’s the most hilarious thing I’ve ever seen!
And if they (the victim) click on this video which, as far as they can tell, is from a trusted friend, their account then becomes infected with this rogue application. The result is the spread of this application like a virus.
If you’ve any decently sized Facebook friends list, you’ve no doubt experienced at least one friend who has an account become so crippled by these annoying applications that you can’t help but hide them, maybe even unfriend them. If these applications become so populous that wading through the junk on your Facebook page every morning makes you feel like you’re stuck in a Hotmail inbox, what is the point of having an account?

The Paradigm of ‘Friendship’

The thing about real life and friendship in the real world is that it has tiers. There is the tier of friends with whom you are closer to than family. There is the tier of friends that you see regularly, and who may be pleasant to be around, but for a variety of reasons, you just don’t keep them this || close. Then there’s family, which is scattered amongst different tiers. There are coworkers and bosses who rest on a different plane with their own tiers. Etc. Etc. Plainly spoken, some people are kept distant and out of the loop more than others. This is order amongst what would otherwise be chaos.
On Facebook, it doesn’t work like that. You’re friends, or you’re not friends. If you’re friends in real life with someone you can tolerate only in certain places for certain durations, you might find them unbearable online, where they can post to anything you say, where they can poke you and post things on your wall for everyone to see.
You can avoid friending these individuals…and then make them incredibly angry, or hurt, or whatever that particular friend feels like being.
Why did you friend so and so, but not me?
Oh, I’m not good enough for your Facebook account?
I commented, and you never replied. You must hate me!
So you can either friend them online and come to hate them in real life, or not friend them and have them hate you in real life. Options, options. Facebook turns friendship into an orchestrated dance of politics. In the real world:
Mother doesn’t have to know about your dating life.
Grandma doesn’t have to hear your bad language in the real world.
You can avoid Annoying Friend #1, #3, and #27 in real life.
You can carefully dictate who your boyfriend/girlfriend gets to meet during each phase of your relationship in real life.
But on Facebook, everybody’s mashed together.

Professional Life

As companies take to the Internet for evaluating current and prospective employees, the reality of needing to maintain online privacy is more imperative than ever. People have been fired from their jobs and suspended from their schools for things posted on Facebook. The need for private things to remain private clashes with Zuckerberg’s idea for Facebook, which is to be “Open”. Though they have implemented privacy features across the accounts, they are either difficult to find (ala, the first section of this article), or they fail.
Facebook chat was recently down for a period of a couple hours after it was discovered that private chats could be viewed in real-time by friends. How about when Facebook implemented a privacy upgrade that left Zuckerberg’s private photos visible to anyone who wanted to see them? These security breaches and unforeseen oopsies and unaccounted for changes may not be bothersome to some individuals, but for others, it could be a career-breaker. If Facebook continually proves that it is a liability due to its near-constant security holes and breaches and hiccups, can it truly expect uses to stick around and share their lives online while potentially putting their jobs on the line?

Conclusion

When the effort to maintain outweighs the benefits of the object being maintained, the object is no longer desirable. When your computer, car, or home has a small problem, you fix it. When that computer starts failing and the neighbors start breaking in at midnight and the car dies at every stop light, it is better to get rid of it/them and start over with something new. Can Facebook continue to thrive while users start to feel the burden of maintaining their account?
Posted by Unknown 0 comments

Google again on Top


Nielsen has released the Search Statistics for March. No surprises… at least no big ones.
The biggest surprise is that Google remained stagnate at 58.7% when compared to the same statistics from February. But if you look at the same period last year, Google’s numbers go way up with an increase of 25.5%.

Yahoo! Search gained a bit from last month but saw a 4.5% decrease from last year. The third place still remains (and will probably remain) with MSN/Windows Live with a share of 12% (up 0.8% from last month).
From Nielsen-Online:


What strikes me in these numbers is, for example, the 130.5% yearly growth of AT&T Worldnet Search. It seems that users are trying to find alternatives to the big ones.
What do you make of the numbers? Everything as expected? Is your favorite search engine on the top 3?
Posted by Unknown 0 comments

Future of Social Networking Sites


As you may have noticed, this website has not been updated in a while. This is because all 3 of the writers are busy on some projects — These are Stix and iSociale. Jimmy and Colum have done much work on the iSociale project, but after the Stix project gets going and done, I will be helping out with iSociale by combining the design aspects with the backend system. But here I would like to
write about the Stix social networking application that will be soon released to the public. Here you will find some previews and our goals as a web startup team.

At the very beginning, I was encountered by Todd Oh (long story) from SpotEngine to develop a micro-blogging system. Through a long time of planning, Todd and I have turned a micro-blogging idea into a social networking application. We have also recruited Colum McGaley to help with the design of Stix because of the tremendous work load I have had recently. Here is the staff listing on the SpotEngine website: Stix Staff
The sweet part about this is, we got a nice and short domain name. www.stix.me. Easy to type in on mobile devices and web browsers.
So here is the main idea of Stix — A Facebook-like application that includes geotagged media. This includes blogging, photos, and video. Of course we do not have the server power that Twitter or Facebook have, but we would like to build the next generation of social networking. We have 3 servers to run Stix on, and this still will not be sufficient if we get many users to use Stix. This would mean we would have to acquire more servers later on if Stix gets popular.
Geotagged media would allow you to view where your friends collect media on a map. There will also be “real-time” viewing features as well as advanced filters for viewing (such as photos only, or only from a certain location). Users will be able to see what other users are doing and where they are. Media collected is put in the “Library” in “Books” where other users can view.
Stix Library Book
Stix Library Book
Our main focus is to keep it as simple as possible and still provide great features within the application. It is similiar to Twitter’s status update system, only with an added field to updates — which is just the location. Read more on the SpotEngine website here. The next thumbnail is a preview of our homepage.

Stix Home
Geographic tagging was very easy to build. The hardest part about this was building the query system to enable users to quickly find media on a map. The search concept is still being sketched up. The next thumbnail is the Flickr geographic search mode integrated into Stix (We will be designing another system). We call it “Stix Wave”.
Stix Wave
Stix Wave
Mobile device support is currently in progress and will not be released until after the API is released to the public. We currently have planned several mobile devices to build a Stix application for.
We are currently a Microsoft BizSpark member and Neowiz startup incubation #4 team.
Thanks to Todd, we have also had many people interested in our startup and we were featured on KBS Korea in a new years special.
We plan on releasing very soon, hopefully in June sometime. With this release will be the release of the API for developers to create applications to work with the Stix program.
So check out Stix and keep watching for a release. It is coming soon.
www.stix.mewww.spotengine.net
Posted by Unknown 0 comments

Microsoft Warns of Windows Script Injection Vulnerability


fixit.jpgMicrosoft tonight released a security advisory for a publicly-disclosed vulnerability in all versions of Windows. Security Advisory 2501696 describes a bug in the MHTML handler in Windows which could lead to information disclosure.
MHTML (MIME Encapsulation of Aggregate HTML) encapsulates HTML in a MIME structure.
MIME (Multipurpose Internet Mail Extensions) is a data format for encapsulating more complex binary structures in a text-only format. Windows includes a pluggable protocol handler (MHTML:) that allows applications to render MHTML structures. Internet Explorer is one of these and it can be abused to exploit the bug in the context of a web page, causing script to be executed. The user would have click a link to an MHTML:// document.
The vulnerability is similar to a cross-site scripting bug on a web page, in which HTML and script from another site is executed in the web page context. In this case, script could be executed in the client-side context.
mhtmlbug.png
Microsoft has provided a "Fix it" link to disable the MHTML protocol handler. This is a rather radical move, but it's probably the only thing Microsoft can do without an actual patch, which they will of course provide—when it's ready. They are also working with other companies to develop server-side protections to prevent attacks.
The link above to the Fix it also includes what amounts to a proof of concept for the bug which you can use to test if you are vulnerable or if mitigating measures have worked.
Posted by Unknown 0 comments

Friday, February 11, 2011

Microsoft Patches 22 Vulnerabilities in 12 Updates


Thumbnail image for WindowsUpdate.jpgMicrosoft today released 12 updates to Windows and Office fixing 22 separate vulnerabilities. One of the updates, fixing 2 of the vulnerabilities, affects Microsoft Visio. The remaining updates and vulnerabilities affect various versions of Windows.

3 of the updates contain at least one vulnerability rated "critical" on at least one platform. One in particular (MS11-007) presents the possibility of kernel mode compromise of the system.
  • MS11-003: Cumulative Security Update for Internet Explorer—4 remote code execution vulnerabilities are fixed. Two of them have been publicly disclosed, including a variation on the insecure DLL loading issue that we have been seeing fixed for months.
  • MS11-006: Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution—This update fixes a publicly-disclosed vulnerability the handling of specially crafted thumbnail images by the Windows Shell graphics processor.
  • MS11-007: Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution—A flaw in the Windows OpenType Compact Font Format (CFF) driver could allow remote code execution via specially crafted OpenType fonts. This update affects kernel mode code and is therefore more dangerous than the other two.
9 updates have maximum rating of "important":

  • MS11-004: Vulnerability in Internet Information Services (IIS) FTP Service Could Allow Remote Code Execution—A publicly-disclosed flaw in the IIS FTP service could allow remote code execution through a malicious command. The FTP service is not installed by default.
  • MS11-005: Vulnerability in Active Directory Could Allow Denial of Service—Improper validation of service principal names (SPN) could lead to collisions and subsequent DOS.
  • MS11-008: Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution—All versions of Visio are vulnerable to two remote code execution vulnerabilities exploitable through malicious data files.
  • MS11-009: Vulnerability in JScript and VBScript Scripting Engines Could Allow Information Disclosure—A memory corruption could lead the scripting engines to disclose information which could be used to abuse the system further.
  • MS11-010: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege—The CSRSS terminates processes when a user logs off. A vulnerability in this function could allow an attacker to run code which could monitor the behavior of users who logged on to the system subsequently.
  • MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege—All Windows versions are affected by a flaw in the interaction of drivers with the kernel. Another flaw affects only Windows XP.
  • MS11-012: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege—5 separate vulnerabilities.
  • MS11-013: Vulnerabilities in Kerberos Could Allow Elevation of Privilege—Two separate vulnerabilities are involved. The elevation of privilege bug had been publicly-disclosed. The other allows spoofing.
  • MS11-014: Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege—Maliciously-crafted authentication requests could cause LSASS to elevate the user's privileges.
Microsoft also released a group of updates designated as "non-security" including one which changes AutoRun behavior.
Posted by Unknown 0 comments

Oracle Fixes Java "Magic Number" Crash Bug


Java logo.jpg2.2250738585072012e-308—It's the floating point number of death.
It was revealed several months ago that when creating this number in binary form, Java crashes or, as Oracle describes it, experiences "a complete denial of service." Both client and server versions are affected.
It's a weird bug but Oracle has fixed it now.

They have issued a standalone patch entitled Java SE Floating Point Updater Tool, but it's a JAR file that you have to run it manually and I had trouble getting it to work. It said it couldn't write to the temp directory. I can't imagine why not.
Oracle also announced that JRE 6 update 24 will include this fix and also be distributed with the Java SE and Java for Business Critical Patch Update - February 2011, scheduled for February 15.
What's even weirder about this bug is that it's was also in PHP and has been fixed there as well. Read the link, as it attempts to explain why this particular number is significant.
Posted by Unknown 0 comments

Set Up Google’s Two-Step Verification Now for Seriously Enhanced Security for Your Google Account

Google just launched two-step verification for all Google accounts, a system which makes your Google/Gmail account—the account possibly containing the lion's share of your private communication online—considerably more secure. In fact, we'd encourage everyone who uses Gmail (the @gmail version or your Google Apps version) as their primary email provider to start using this feature as soon as possible. Here's why, and then how.
Set Up Google's Two-Step Verification Now for Seriously Enhanced Security for Your Google Account

What's Two-Step Verification?

The only thing standing between a hacker and your Google account—and more importantly, your sensitive information—is your password. Even if you had the strongest password you could possibly randomly generate, if someone were able to discover that password, they'd be in.
Two-step verification offers a more secure way for Google to verify that you are who you say you are when you're logging into your Google account on a new web browser, through a new application, or on a new mobile device. With two-step verification, your password isn't enough by itself. As Google put it:
2-step verification requires two independent factors for authentication, much like you might see on your banking website: your password, plus a code you only use once.
Those two factors are:
  1. Your password (just like always)
  2. A single-use verification code that Google sends to your phone in one of three ways: 1) Using the Google Authenticator app available for Android, iPhone, and BlackBerry, 2) via SMS, or 3) through a voice call (meaning you could even use a landline if you didn't have a cellphone—basically the call would read off the code to you).
Both your password and the single-use verification code are required to log in on a new browser. You can then tell Google to remember your log-in for 30 days.

How to Set Up Two-Step Verification

If you're convinced that you want the added security, or you at least want to give two-step verification a try, just log into your Google account and point your browser to your Google accounts page. (Google Apps users will need to go to their domain-specific control panel to enable two-step verification. If you're not the Google Apps admin, talk to yours about it.)
Set Up Google's Two-Step Verification Now for Seriously Enhanced Security for Your Google AccountOn the right side of the page, under Personal Settings > Security, click the Using 2-step verification link (you can bookmark that link if you like).
Set Up Google's Two-Step Verification Now for Seriously Enhanced Security for Your Google AccountNow walk through Google's two-step verification setup guide. It's pretty simple: Essentially you have to add a new phone that you want to use for your two-step verification, confirm that it is indeed your phone (you do this in different ways depending on what method you're using. Using the Google Authenticator app for Android or for iPhone, for example, you verify by scanning a QR code and then testing the verification code it generates. Just follow along with the wizard for whatever method you're using.
Once you've set up your phone, you can also add a backup—a trusted number you can also access if, for example, you lose your phone—so you can still access your account. You can even print off a few backup codes to carry in your wallet or somewhere safe.

Using Two-Step Verification

The process for logging into your Google account from a new browser will now look something like this:
  1. You visit a Google sign-in page, like this one.
    Set Up Google's Two-Step Verification Now for Seriously Enhanced Security for Your Google Account
  2. You enter your username and password, like always.
  3. You're now prompted to enter a code, which is tied only to a phone number you provide. You can receive this code on your phone using one of the Google Authenticator apps available for Android, iPhone, and BlackBerry, via SMS, or through a voice call (or, I suppose, using one of your printed backup codes).
  4. You enter the code, optionally checking the box to Remember verification for this computer for 30 days, click Verify, and you're in.
It's fairly simple, but it does add a little bit of hassle to your login. Personally, I think the added security is well worth it.
The other thing you'll need to get used to involves logging into your Google account from third-party applications—like, say, a desktop email client. Since those clients don't support Google's two-step verification, you actually have to create single-use passwords first time you log into any new third-party application that needs to access your Google account. You'll only need to generate the new password for each application once—unless you decide to revoke access to that device. Here's how it works:
Set Up Google's Two-Step Verification Now for Seriously Enhanced Security for Your Google AccountPoint your browser to this page (I'd actually recommend bookmarking it, but you can also find the link on your Account settings page under Security > Authorizing applications & sites. Here you'll see all the webapps that you've allowed access to your Google account via Oauth (which uses the verification process above); below you'll see the Application-specific passwords section, which is where you generate new passwords for devices that can't support the two-step verification. To do so:
  1. Type in the name of the device or application that you want to generate a single-use password for.
  2. Click Generate password.
  3. Google will return a new 16-digit (plus four spaces) password for you to use on that device. Once you hide it, you have no way to retrieve it again (a good thing).
Unlike the two-step process for logging into your Google account on the web, you only have to enter an application-specific password once; it remains active with that single-use password indefinitely. You can, however, revoke any password/device/application from accessing your Google account at any time—which I've done for the password I generated in the screenshot above. (Hands off my Google account!) From the device configuration page, you can also clear your phone info and all printable codes, should you lose your phone or misplace a printed code.
Posted by Unknown 0 comments

Saturday, February 5, 2011

Miramar (Thunderbird 3.3) Alpha 2 now available for testing

Miramar Alpha 2, available here for download, is for testers, extension developers, and friends who are curious to follow the development of our next release of Thunderbird.

Miramar Alpha 2 is built on top of Gecko 2.0 and includes a new Troubleshooting information page, improvements to add-on notifications and attachment handling, and numerous other bug fixes. We expect to release further interim releases as we work towards the next major version of Thunderbird.
Posted by Unknown 0 comments

Linux News

Posted by Unknown 0 comments

New in Labs: Smart mute and easier ways to unmute - Gmail Tutorial

If you subscribe to a lot of mailing lists and like to keep an empty inbox, muting (or preventing a conversation from re-entering your inbox) is an essential feature. We just made a few changes that should make muting even better.

First up is “Smart Mute,” a new Gmail Labs feature that helps solve the problem of conversations that just won’t die. You know the ones I’m talking about:
those emails with 10+ people cc’d where everyone replies all, but you lost interest five emails ago. The current mute behavior doesn’t do well in these situations since the messages are addressed to you. You end up with muted messages in your inbox, and the only way to prevent these emails from coming back to your inbox has been to create a custom filter for a specific conversation.


If you enable “Smart Mute” from the Labs tab in Gmail Settings, muted conversations will only appear in your inbox if a new message in the conversation is addressed to you and no one else, or a new email in the conversation adds you to the “To” or “Cc” line. Once you enable Smart Mute, mute behavior will change across all versions of Gmail: web, mobile, Android, etc. Try it out and let us know what you think.

Since you’ll likely be muting more than ever, we also added easier ways to unmute muted conversations. Previously, the only way to unmute a conversation was to move it to your inbox -- not super intuitive and useless if the conversation was already in your inbox. Now there are two new ways to unmute a conversation. The first is through an "Unmute" option in the "More actions" menu. You’ll see this when you view or select a muted conversation.

If you’re viewing a muted conversation, you’ll see the second new way to unmute: the "Muted" label next to the subject line now behaves just like all other labels. Clicking on the "X" will remove the Muted label and unmute the conversation.


Hopefully these changes will make it easier to mute and unmute conversations.
Posted by Unknown 0 comments

Restore your contacts - Gmail Tutorial

There are many times in life when a do-over can come in handy. Perhaps you clicked “Send” on an email that was better left unsaid, or “Delete” on a contact before realizing you still needed it. Just like Gmail lets you unsend a message, you can now have a second chance with your contacts too.


We’ve added a new feature to Google Contacts that allows you to revert your contact list and undo any mistakes made up to 30 days in the past. Let’s say you accidentally deleted a bunch of contacts or wiped the contact data from your Gmail account by mistake while syncing to another device. Visit Gmail’s Contacts section, select “Restore contacts” in the “More actions” menu, and choose the time you would like to revert to.


Your contacts will be restored to exactly the same state they were in at that time — any contacts that didn’t exist then will be deleted and any that have since been added will be deleted. Don’t worry, you can always undo this change by restoring again if you didn’t get the time right.
Posted by Unknown 0 comments

Email delegation: Granting access to your Gmail account

I use two Gmail accounts: one is my personal account and the other I share with my family (we use it to subscribe to groups like my children's classroom mailing list). Checking these two different accounts used to mean I had to sign out and back in to Gmail all the time. Not anymore. Instead, I can grant my personal account access to my shared family account and view, organize and send mail on behalf of our shared account.


We've offered email delegation for Google Apps accounts for a while — it's super useful for people who want their assistants to have access to read or respond to mail on their behalf. Now this functionality is available for anyone using Gmail. To grant access to another account, click the Settings link in the top right corner of Gmail. On the "Accounts" tab, you'll see a new section where you can "Grant access to your account." For example, below we've given hikingfan@gmail.com access to the hikingfanfamily@gmail.com account.


The account you add will get a verification email with links to accept or deny access. Once the account accepts and you've refreshed your browser or logged in and out again, you'll see a small down arrow beside the email address at the top right corner of Gmail which can be used to toggle between accounts — in this case hikingfan@gmail.com and hikingfanfamily@gmail.com.


Each account will open in a different browser tab or window so you can view both accounts simultaneously, all while signed into your primary account. When you send a message from hikingfanfamily@gmail.com while signed in as hikingfan@gmail.com, it will appear as being sent by hikingfan@gmail.com on behalf of hikingfanfamily@gmail.com.


Signing out of any one of the accounts will sign you out of all the accounts you're currently viewing, and, of course, you can revoke access at any time.
Posted by Unknown 0 comments

New in Labs: Unread message icon

When you’re visiting sites other than Gmail, it’s easy to find out how many unread messages are in your inbox by glancing at the title of your Gmail tab or window. However, if you have a ton of tabs open, or if you use Chrome’s “Pin Tab” feature that hides everything except the tab’s icon, it can be tricky to figure out without switching tabs.


If you’ve ever found yourself in this situation, you may like the new Unread message icon we just added to Gmail Labs. It embeds the number of unread messages you have right into the Gmail icon itself, like this:


To turn it on, go to the Labs tab in Settings, enable this lab, and click the “Save Changes” button at the very bottom of the page. Note that it’ll only works in Chrome (version 6 and above) and Firefox (version 2 and above).
Posted by Unknown 0 comments