Wednesday, May 9, 2007
Early morning thoughts
Keep away from people
who try to belittle your ambitions.
Small people always do that,
but the really great make you feel
that you, too, can become great.
- Mark Twain
Friday, May 4, 2007
Creative Soundcards - rant
Creative may never see another dollar from me again. I own(ed) an Audigy Sound card.
From the beginning my experience with that card was mixed. Hardware acceleration was awesome, when the card didn't crash. And it wasn't only me . . . but it took more than a year after I bought the card before Creative finally released a driver update that fixed the random crash. X-Fi owners faced similar, if not worse, problems.
Now comes Vista. Which was released in usable (from a Developers point of view at least) Beta form darn near a year before it's release to all major hardware venders/manufacturers. Creative totally dropped the ball, they did not have Vista drivers available at release. Today they still don't - unless you have one of their X-Fi cards.
To be sure, it's not all Creative's fault. Microsoft pulled the rug out from under them with a totally new way to address sound card DSP chips. But Creative had a year to get ready.
So now the final nail in the coffin: Creative just announced that they have begun working on a Audigy series Vista driver. And hidden in the announcement is this key phase: " . . . hope to offer this product as a low-cost upgrade." So - is that a typo? An accident from someone that failed to get the right proof-reading from marketing?
Here is the complete announcement as it appeared originally:
"When we released the first beta of ALchemy for X-Fi, we hoped customers would appreciate our efforts. Within only a few months, the response from users and the press has been overwhelmingly positive. Many of our customers have asked if we could adapt ALchemy to Audigy series sound cards. The X-Fi and Audigy series sound cards are built on different hardware architectures, and therefore require separate development efforts. However, based on the requests to date, we are pleased to announce that we have begun development of an implementation of ALchemy for Audigy series sound cards, and hope to offer this product as a low-cost upgrade to interested Audigy owners later this year."
From the beginning my experience with that card was mixed. Hardware acceleration was awesome, when the card didn't crash. And it wasn't only me . . . but it took more than a year after I bought the card before Creative finally released a driver update that fixed the random crash. X-Fi owners faced similar, if not worse, problems.
Now comes Vista. Which was released in usable (from a Developers point of view at least) Beta form darn near a year before it's release to all major hardware venders/manufacturers. Creative totally dropped the ball, they did not have Vista drivers available at release. Today they still don't - unless you have one of their X-Fi cards.
To be sure, it's not all Creative's fault. Microsoft pulled the rug out from under them with a totally new way to address sound card DSP chips. But Creative had a year to get ready.
So now the final nail in the coffin: Creative just announced that they have begun working on a Audigy series Vista driver. And hidden in the announcement is this key phase: " . . . hope to offer this product as a low-cost upgrade." So - is that a typo? An accident from someone that failed to get the right proof-reading from marketing?
Here is the complete announcement as it appeared originally:
"When we released the first beta of ALchemy for X-Fi, we hoped customers would appreciate our efforts. Within only a few months, the response from users and the press has been overwhelmingly positive. Many of our customers have asked if we could adapt ALchemy to Audigy series sound cards. The X-Fi and Audigy series sound cards are built on different hardware architectures, and therefore require separate development efforts. However, based on the requests to date, we are pleased to announce that we have begun development of an implementation of ALchemy for Audigy series sound cards, and hope to offer this product as a low-cost upgrade to interested Audigy owners later this year."
The Trojan that might get even the paranoid user's CC number
Symantec has the skinny on a new Trojan that is just now beginning to make the rounds in the wild. It's not yet widespread, but be prepared just in case you run into it.
"Recently we came across an interesting Trojan sample, detected by Symantec as Trojan.Kardphisher. The Trojan is not very technical - it's really just another classic social-engineering attack. What makes it interesting is that the author has obviously taken great pains to make it appear legitimate."
The Trojan presents screens on boot up that state you need to re-activate Windows. The twist is that during the process it asks the user for their CC information.
The screenshots in question look very much like the original Windows Activation screens, same theme, color, logos, etc. Even the "engrish" which is generally a dead giveaway is fairly polished. Worse, if you refuse to cooperate the Trojan shuts down your system immediately - a tactic that is also used by Microsoft when Windows Genuine Advantage thinks you stole their system. The next time you power-up, you are again given the fake option to re-activate your Windows installation - complete with the request for your CC info.
Arm yourselves and your computer-challenged family members with this simple reminder:
The real activation process from Microsoft will NOT ask for your Credit Card. Nor will their support staff.
I'm half expecting the next step from Trojan authors using this tactic to include an 800 number purporting to be for Microsoft Support but that will connect you to some mafia-run phone center. There they would -- in theory -- collect even more personal information with which they could steal your entire identity.
Wednesday, May 2, 2007
New phishing attack method - dial * 72
This simply amazes me. It's not the method (see below) but the fact that people actually fall for this. I guess I should not be surprised -- even after multiple warnings people still open junk email with attachments from unknown senders -- which exposes them to keylogging trojans or worse.
SecureWorks posted the details, partially copied below: (I changed the phone number.)
"The victim receives an email from the phisher telling them that their bank needs to verify their phone number immediately. If they do not confirm their phone number their account will be suspended. The instructions are as follows:
Step 1- Go to your phone and Dial *72
Step 2- Dial 7075551212 (XYZ Bank Secure Line)
Step 3- Your phone is confirmed.
You will receive a call from us in 1 h for final verification!
If you have confirmed your phone, you can continue the update process:
By calling these phone numbers, the bank customer is actually forwarding their calls to the phisher's number. The calls will continue to be forwarded until the victim notices they are not getting any calls.
After the victim confirms their phone number, they are asked to update their personal info, social security number, bank account number, credit card number, etc.
If the bank customer cooperates, then the phisher has all of the banking and personal information needed to begin making fraudulent transactions on the victim's bank account. If the customer's bank calls them to query an odd transaction during the period that their calls are being forwarded, the phisher will receive the calls and confirm that the fraudulent transaction is legitimate."
Tuesday, May 1, 2007
Critical exploitable bugs in Trillian and WinAmp
Two separate bugs, both being exploited.
Trillian has released an update to fix things up. Get it here:
http://www.ceruleanstudios.com/downloads/
No fix for WinAmp yet, best advice is don't open untrusted MP4 files. MP3's are safe.
More info about these bugs at
Trillian: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=522
WinAmp: http://secunia.com/advisories/25089/
Trillian has released an update to fix things up. Get it here:
http://www.ceruleanstudios.com/downloads/
No fix for WinAmp yet, best advice is don't open untrusted MP4 files. MP3's are safe.
More info about these bugs at
Trillian: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=522
WinAmp: http://secunia.com/advisories/25089/
Sunday, April 29, 2007
Don't break that Compact Fluorescent Light Bulb!
More grumbling about CFL's after my last mini-rant.
"Bridges had the misfortune of breaking a CFL during installation in her daughter's bedroom: It dropped and shattered on the carpeted floor.
[ . . . ]
The DEP sent a specialist to Bridges' house to test for mercury contamination. The specialist found mercury levels in the bedroom in excess of six times the state's "safe" level for mercury contamination of 300 billionths of a gram per cubic meter. The DEP specialist recommended that Bridges call an environmental cleanup firm, which reportedly gave her a "low-ball" estimate of US$2,000 to clean up the room."
Wednesday, April 25, 2007
Congress wants to pass a Spyware law that you don't want.
Spy Act Only Protects Vendors and Their DRM
"Last week a subcommittee of the House Committee on Energy and Commerce approved H.R. 964, the Spy Act.
[ . . . ]
If the Spy Act become law, hardware, software, and network vendors will be granted carte blanche to use spyware themselves to police their customers' use of their products and services. Incredibly broad exceptions will probably allow even the worst of the adware outfits to operate with legal cover. State attempts to deal with the spyware problem will be pre-empted and enforcement left up almost entirely to the FTC."
Sunday, April 22, 2007
Microsoft Office Compatibility Pack released
If you use Microsoft Office products (Word, Excel or PowerPoint) version 2000, 2002 (aka XP) or 2003 and would like to be compatible with the new file formats for the 2007 versions of those applications, Microsoft released a 'free' new compatibility pack that will enable you to view, edit and save your files to those new formats. This is pretty nice, as you will no longer have to tell co-workers/co-students/co-anybody using Office 2007 to save stuff in the old formats so you can use them.
Before you run off to install it, there are some caveats. You MUST upgrade your version of Office (or standalone Word, Excel or PowerPoint) to the very latest service packs available.
If you need direct links to the various required Service Packs:
Office 2000: SP3 - http://www.microsoft.com/downloads/details.aspx?FamilyID=5c011c70-47d0-4306-9fa4-8e92d36332fe&DisplayLang=en
Office 2002 (XP): SP3 - http://www.microsoft.com/downloads/details.aspx?FamilyID=85af7bfd-6f69-4289-8bd1-eb966bcdfb5e&DisplayLang=en
Office 2003: SP2 - http://www.microsoft.com/downloads/details.aspx?FamilyID=57e27a97-2db6-4654-9db6-ec7d5b4dd867&DisplayLang=en
Those Service Packs work for all full versions of Office, as well as the standalone versions of the three main applications included.
In turn you must also get the most recent critical fixes published as of April 10, 2007 using the Office or Microsoft Update site.
Once you have finished all the updates needed, go and install the Compatibility Pack from http://www.microsoft.com/downloads/details.aspx?familyid=941b3470-3ae9-4aee-8f43-c6bb74cd1466&displaylang=en&tm
Before you run off to install it, there are some caveats. You MUST upgrade your version of Office (or standalone Word, Excel or PowerPoint) to the very latest service packs available.
If you need direct links to the various required Service Packs:
Office 2000: SP3 - http://www.microsoft.com/downloads/details.aspx?FamilyID=5c011c70-47d0-4306-9fa4-8e92d36332fe&DisplayLang=en
Office 2002 (XP): SP3 - http://www.microsoft.com/downloads/details.aspx?FamilyID=85af7bfd-6f69-4289-8bd1-eb966bcdfb5e&DisplayLang=en
Office 2003: SP2 - http://www.microsoft.com/downloads/details.aspx?FamilyID=57e27a97-2db6-4654-9db6-ec7d5b4dd867&DisplayLang=en
Those Service Packs work for all full versions of Office, as well as the standalone versions of the three main applications included.
In turn you must also get the most recent critical fixes published as of April 10, 2007 using the Office or Microsoft Update site.
Once you have finished all the updates needed, go and install the Compatibility Pack from http://www.microsoft.com/downloads/details.aspx?familyid=941b3470-3ae9-4aee-8f43-c6bb74cd1466&displaylang=en&tm
Friday, April 20, 2007
Global warming???
Thursday, April 19, 2007
The new frontier for hackers: your router
http://www.infoworld.com/article/07/04/19/HNroutercellattackrisk_1.html
"Jack's null pointer exploit is effective on the Arm and xScale processors that are widely used in embedded devices, but it does not work on Intel architecture processors used by PCs.
In his demonstration, Jack plans to show how his attack could be used to make changes to the firmware of a router so that it injects malicious code into any executable files downloaded from the Internet. This technique could be used to turn legitimate software updates -- Microsoft's monthly software patches, for example -- into an avenue of attack."
So what routers use these processors? Almost all of the home firewall/router boxes made by D-Link, Netgear, Linksys and other brands. Most modern PDA's and Pocket PC's also use one of these processors.
Nothing like this is in the wild -- yet. But now that the concept is out, you can be sure it will be used sometime in the future. I will be tracking this closely. Best case scenario is that simple firmware upgrades to your router can close off the attack vector. Worst case scenario is that millions of home routers will need to be replaced.
Scary stuff . . . :-/
Subscribe to:
Posts (Atom)