Last week extravaganza Technology Association Annual Wireless, CTIA in Las Vegas, home of the top manufacturers of gadgets shared their latest and best products in the mobility.
While the child has recently anointed poster for Open Mobile Devices, Google Android, was virtually nowhere to be found on the show, the event will feature wall exhibition of more than 1,200 companies wall. And here and there, you can find pockets of two devices, you run applications or open source or Linux open-vendor environments Souce courting developers. We might also consider some of the highlights:
Palm ago
Palm Pre-party software creates a lot of buzz and a lot of excitement with their legacy emulator. Some of the included software is not yet proven Fandango movie ticket and app, SprintTV and Google Maps. Pandora Internet Radio "is a blessing to every music lover. A fast launcher is located in each front of the screen to reveal the young players without interrupting the current task. Another, Nascar, took a strong season as a NASCAR videos, alloy wheels, profiles and rankings, and much more.
Perhaps the most interesting for owners of older Palm software running cost is webOS OS Garnet in emulation software. It runs as a separate application and allows drag and drop installation / usage. Palm provides a key for a simple upgrade to the latest pre snazzier.
The Pre Palm announced earlier this year at CES, the characteristics of a Linux-based webOS, 3.1-inch multi-touch screen of 320 × 480 pixel resolution and a QWERTY keyboard. It is equipped with Wi-Fi, Bluetooth, GPS, 8 GB and a 3-megapixel camera.
Wistron Pursebook
Wistron presented their proof of concept Pursebook running the Qualcomm Snapdragon processor. This cute little netbook is running a customized version of Linux with fat ThunderSoft software for office tasks, communication and web-indulgence.
Yes, this paragraph is not the words "Pursebook" Snapdragon "and" Thundersoft. "You're welcome.
Observer status of the keyboard is the first generation instead chiclet-style keyboard used in some models of the current netbook, but overall the unit was easy to use. Others said it has enough energy, enough graphics are very nice, and 8 hours battery life. Prices should start at 299 USD and should be available this year.
NVIDIA Tegra
NVIDIA on the hand, all show-in-one Tegra chip for mobile devices. Tegra, an ARM-based components that are 1080p video output and capable of showing up to 1680 x 1050th It will also be able to IDE drives.
NVIDIA has equipped an HP Mini 1000 cases with a computer-on-a-chip system, used to demonstrate the potential of the Tegra. Its prototype with Windows CE, but NVIDIA also has its own interface, which has been described as something between Android and Mac OS X appearance. Tegra can also support Windows Mobile and Android, and while there was no mention of Linux in particular, a spokeswoman said Tegra technology is very flexible and can easily be used with other platforms. NVIDIA hopes to bring the new chipset market sometime this year at a reasonable price to $ 99 machines.
Nokia E71x
Another small smartphone that has created some interest was the AT & T exclusive Nokia E71x. Like the Nokia E71 is the E71x a very light weight of just 4.5 grams and comes with a 320 x 240 QVGA display, full QWERTY keyboard, 8GB of storage and broadband 3G connectivity, Wi-Fi, Bluetooth, GPS and a 3.2-megapixel camera. Mark Louison, President, Nokia Inc., said: "The Frugal E71x a multimedia computer for a lot of people are employed, the Internet-on-the-go capabilities in the palm of the hand like."
This thin Nokia comes with an upgrade to Symbian S60 Feature Pack 2 (which apps a "mobile flaunt option in all applications has) and some services from AT & T AT & T Music, AT & T Mail and AT & T Navigator . He even has support for Quickoffice. The best is probably the new reduced price of $ 100 after rebate. Should be AT & T Nokia E71x be available in the coming weeks.
Samsung Mondi
Samsung Telecommunications has to compete the first mobile Internet device, this year presented with the netbook form factor. The main features include WiMAX, Wi-Fi and Bluetooth. Its touch screen is 4.3 inches with a QWERTY keyboard and optical mouse. It comes with 4 GB of storage, a 3-megapixel camera, TV out and HDMI.
The Mondi with Opera 9.5 for Internet access. The device should have not been announced this summer are available, although the price ranges.
Speaking of opera, they were on site and the transfer of your current browser Opera Mobile 9.7. Opera comes with turbo, which uses a compression algorithm to surf faster, and enjoy support for Ajax and Flash sites such as Facebook and YouTube.com. Best of all, it passes the Acid 3 test.
Motorola Evoke QA6
One of the most anticipated most was the Motorola Evoke QA6 are fully exposed, it is as "a social unit disposed charged" because of its full HTML browser, messaging and IM-style. It has a touch screen 2.8-inch touch-screen QWERTY keyboard, 2-megapixel camera and AGPS.
The Motorola OS is a customized version of Linux with the widget interface cumbersome. It comes with mobile widgets for MySpace, YouTube, Follow Me Quick Weather Picasa and Google, RSS Reader, Mobile, and USA Today. In addition, the QA4 the first phone that virtualization can run on multiple operating systems. This is done with the help of micro-hypervisor kernel Open Kernel Labs, is based on two integrated applications concurrently running operating systems. That means you can to a variant of Linux, if they so wish.
The Motorola Evoke QA4 should be available this year, but announced no pricing information.
Mozilla Fennec
Finally, Mozilla was on hand to demonstrate its new mobile browser, codenamed Fennec. The final version of Fennec, now simply as Firefox, numerous performance improvements like TraceMonkey JavaScript engine contains, in order to increase the speed of the rendering page. Plug-in support was also added to enable video playback on popular websites. Other features include download, password, and add-ons manager, Integrated web search and pop-up blocker.
The minimalist interface is designed to enter the height of the border, as we travel around the web through their imaginative use of technologies such as Smart Bookmarks Bar Integration and history, "tabbed browsing" is used, and miniatures. The second major objective of Firefox Mobile is on the interaction of the user tools to minimize the screen to devote the entire space of the display of Web content. User Tools to disappear on the page, but returning to the widescreen display. Firefox is now available for Maemo (the Nokia N810), Mac OS X, Windows and Linux. Other Maemo platforms, Windows Mobile and Symbian versions will follow shortly.
25 September 2009
Looking for more Linux and open source apps in your life
Posted by abe at 10:37 PM 0 comments
Labels:
15 September 2009
Samba Multiple Unspecified Buffer Overflow Vulnerabilities
Description:
The Samba team disclosed that, prior to v2.2.8a, there exist multiple buffer overflow vulnerabilities. No other information is available.
References:
- BID: http://www.securityfocus.com/bid/7295
- CVE: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2003-0196
- MANDRAKE: http://www.mandriva.com/security/advisories?name=MDKSA-2003:044
- OVAL: http://oval.mitre.org/oval/definitions/data/OVAL564.html
- URL: http://marc.theaimsgroup.com/?l=bugtraq&m=104973186901597&w=2
- URL: http://marc.theaimsgroup.com/?l=bugtraq&m=104974612519064&w=2
- URL: http://www.debian.org/security/2003/dsa-280
- URL: http://www.redhat.com/support/errata/RHSA-2003-137.html
Upgrade to Samba v2.2.8a
Download and apply the upgrade from: http://hostopia.samba.org/samba/ftp/stable/samba-2.2.8a.tar.gz
Information on these pages is summary information extracted from the NeXpose Vulnerabilty Assessment system. Full details are provided within the NeXpose product for licensed users.
Posted by abe at 6:14 PM 0 comments
Labels:
Microsoft Security Bulletins for June 2009
Contrary to speculations in the security community, last month's single security bulletin appears to have been an aberration rather than a sign that the patch burden for Microsoft products is diminishing. The 10 bulletins released in June are more in line with the historical number of monthly vulnerabilities. Six of them describe vulnerabilities affecting core Windows components, one affecting Internet Explorer and three affecting Microsoft Office.
It is notable that four of the ten security bulletins address publicly disclosed vulnerabilities: one in Internet Explorer, one in RPC, two in the Windows kernel and one in IIS. Microsoft's response time for last month's zero-day IIS vulnerability was faster than expected, but the DirectShow QuickTime parser vulnerability that became public on May 28 remains unpatched.
Tas Giakouminakis from Rapid7 said that "We've seen the patch window for Microsoft vulnerabilities shrink to the point where vulnerabilities are being exploited on the day the patches are released or even prior to that."
The active directory vulnerability (MS09-018) had the potential to be devastating for enterprise environments because it affects domain controllers, but fortunately it is ranked critical only for Windows 2000 systems. On Windows Server 2003 the vulnerability leads only to a denial of service.
Of more concern are the print spooler vulnerabilities in MS09-022. One of these is a critical remote code execution on Windows 2000, while the other two allow authenticated users to elevate their privileges on all versions of Windows.
Tas Giakouminakis from Rapid7 said that "The large number of vulnerabilities to be patched in June shows that attackers are not slowing down and the opportunities for them to infiltrate customer networks are increasing. The never-ending stream of Microsoft security bulletins highlights the need for proper patch cycle management and intrusion detection policies in all enterprises."
Posted by abe at 6:13 PM 0 comments
Labels:
Samba TRANS2_OPEN Buffer Overflow
Description:
There exists a buffer overflow vulnerability in certain versions of Samba that can be exploited if a remote attacker sends an overly long file name to the TRANS2_OPEN call. Successful exploitation yields root privileges.
References:
- BID: http://www.securityfocus.com/bid/7294
- CERT-VN: http://www.kb.cert.org/vuls/id/267873
- CONECTIVA: http://distro.conectiva.com/atualizacoes/?id=a&anuncio=CLA-2003:624
- CVE: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2003-0201
- MANDRAKE: http://www.mandriva.com/security/advisories?name=MDKSA-2003:044
- OVAL: http://oval.mitre.org/oval/definitions/data/OVAL2163.html
- OVAL: http://oval.mitre.org/oval/definitions/data/OVAL567.html
- REDHAT: http://rhn.redhat.com/errata/RHSA-2003-137.html
- SGI: ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P
- SUSE: http://www.novell.com/linux/security/advisories.html
- URL: http://marc.theaimsgroup.com/?l=bugtraq&m=104972664226781&w=2
- URL: http://marc.theaimsgroup.com/?l=bugtraq&m=104974612519064&w=2
- URL: http://marc.theaimsgroup.com/?l=bugtraq&m=104981682014565&w=2
- URL: http://marc.theaimsgroup.com/?l=bugtraq&m=104994564212488&w=2
- URL: http://www.debian.org/security/2003/dsa-280
- URL: http://www.digitaldefense.net/labs/advisories/DDI-1013.txt
Upgrade to Samba v2.2.8a
Download and apply the upgrade from: http://hostopia.samba.org/samba/ftp/stable/samba-2.2.8a.tar.gz
Information on these pages is summary information extracted from the NeXpose Vulnerabilty Assessment system. Full details are provided within the NeXpose product for licensed users.
Posted by abe at 5:43 PM 0 comments
Labels:
Microsoft PowerPoint Vulnerabilities
This week's Patch Tuesday is focused on PowerPoint vulnerabilities. Since PowerPoint files are frequently exchanged across organizational boundaries and are not blocked by most email gateways, this vector has been used extensively for targeted attacks in the past. At this point all customers should we well aware that attackers have been able to apply highly effective targeted fuzzing to the PowerPoint and other Microsoft Office file formats. Rapid7 expects that we’ll see more vulnerabilities in those products in the future.
Microsoft Office vulnerabilities present a unique threat to organizations because they provide a way for attackers to easily breech the perimeter firewall to gain access to internal systems through email and to spread throughout the enterprise using network shares, internal email or collaboration systems like Microsoft SharePoint and Lotus Notes. A single email with a malicious PowerPoint attachment could be enough to compromise the desktops of enough critical personnel to cripple even a large enterprise.
We believe that a defense in depth approach is crucial to protecting enterprises from these attacks. The Microsoft Office Isolated Conversion Environment (MOICE), combined with system protections such as Data Execution Prevention (DEP) reduce the risk of successful exploitation. Outbound firewalls, limited user accounts and network segmentation are also highly recommended best practices.
The MS09-017 security bulletin released today includes a fix for 14 new vulnerabilities. It is interesting that most of them were reported to Microsoft by researchers working through the iDefense and TippingPoint vulnerability acquisition programs, rather than researchers working directly with the vendor. We believe that this is another example of the increased value of vulnerabilities and the amount of effort required to find them. The large number of vulnerabilities in PowerPoint is not that surprising, considering the immense attack surface and poor code quality of the legacy file format parsers in Microsoft Office. Unfortunately for most organizations there are few alternatives to exchanging Microsoft Office with untrusted parties over email. Even PDF, which for years has been considered more secure than the Office file formats, has proven to be riddled with vulnerabilities that attackers are actively exploiting.
The only good news is that so far we have seen very few vulnerabilities in the new XML based file formats introduced in Office 2007, which means that the measures Microsoft has taken in recent years to increase code quality and security are bearing fruit. Organizations that can afford to make a complete break with the legacy products and file formats will have a better security posture than those still supporting them.
At least one of the vulnerabilities fixed in this bulletin was a public zero day vulnerability described in the 969136 security advisory from Microsoft (dated April 2, 2009). This vulnerability was discovered in the wild and has been used in limited targeted attacks, but widespread exploitation is not currently being observed. It is however likely that this vulnerability would become known to a larger number of attackers in the days after the Microsoft patch is released. Customers who are at risk of targeted attacks are advised to apply this patch promptly, but in most organizations the update can be applied within the regular patch lifecycle.
These new vulnerabilities fit a common pattern many organizations fail to recognize. For example, Adobe has been the hot target lately due to well-publicized Reader vulnerabilities that hackers have exploited, both in limited targeted attacks and in mass exploitation for building botnets. As administrators continue to be on the lookout for new issues and rush to patch Adobe flaws, hackers will now revert back to "old" attacks vectors that are not receiving as much attention, like PowerPoint and other Office vulnerabilities. The false sense of security around "old" threats is put to use all the time by hackers, and this see saw approach keeps them one step ahead of organizations.
Posted by abe at 5:42 PM 0 comments
Labels:
Samba Share Restriction Bypass
Description:
- BID: http://www.securityfocus.com/bid/11281
- CVE: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2004-0815
- DEBIAN: http://www.debian.org/security/DSA-/DSA-600-1
- MANDRAKE: http://www.mandriva.com/security/advisories?name=MDKSA-2004:104
- OSVDB: http://www.osvdb.org/displayvuln.php?osvdb_id=10464
- REDHAT: http://rhn.redhat.com/errata/RHSA-2004-498.html
- SUN: http://sunsolve.sun.com/search/document.do?assetkey=1-22-101584-1
- SUN: http://sunsolve.sun.com/search/document.do?assetkey=1-22-57664-1
- SUSE: http://www.novell.com/linux/security/advisories.html
- URL: http://distro.conectiva.com.br/atualizacoes/?id=a
- URL: http://marc.theaimsgroup.com/?l=bugtraq
- URL: http://us4.samba.org/samba/news/#security_2.2.12
- URL: http://www.idefense.com/application/poi/display?id=146
- URL: http://www.securityfocus.com/archive/1/377618
- URL: http://www.trustix.org/errata/2004/0051/
- URL: https://bugzilla.fedora.us/show_bug.cgi?id=2102
- XF: http://xforce.iss.net/xforce/xfdb/17556
Solution:
- Upgrade to Samba v2.2.12
Download and apply the upgrade from: http://hostopia.samba.org/samba/ftp/stable/samba-2.2.12.tar.gz - Upgrade to Samba 3.0.7
Download and apply the upgrade from: http://us4.samba.org/samba/ftp/stable/samba-3.0.7.tar.gz
Information on these pages is summary information extracted from the NeXpose Vulnerabilty Assessment system. Full details are provided within the NeXpose product for licensed users.
Posted by abe at 5:33 PM 0 comments
Labels:
Downadup Internet Worm
Posted by abe at 5:30 PM 0 comments
Labels:
Samba nmbd Mailslot Packet Denial of Service Vulnerability
Description:
References:
- BID: http://www.securityfocus.com/bid/11156
- CVE: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2004-0808
- OSVDB: http://www.osvdb.org/displayvuln.php?osvdb_id=9917
- SECUNIA: http://secunia.com/advisories/12516/
- URL: http://samba.org/samba/security/CVE-2004-0807_CVE-2004-0808.html
Upgrade to Samba 3.0.7
Information on these pages is summary information extracted from the NeXpose Vulnerabilty Assessment system. Full details are provided within the NeXpose product for licensed users.
Posted by abe at 5:27 PM 0 comments
Labels:
Microsoft rates MS09-001 as critical
MS09-001 replaces the SMB patch MS08-063 issued last October
Posted by abe at 5:25 PM 0 comments
Labels:
CIFS Minimum Password Length Policy Allows Password Brute Forcing
Description:
Solution:
- Open the Windows Control Panel.
- Select "Administrative Tools"
- To change the domain-wide lockout policy, select "Domain Security Policy" (or "Domain Controller Security Policy" if the computer is a Domain Controller). Otherwise, to change the policy for this computer only, select "Local Security Policy."
- Expand the "Account Policies" folder and select "Password Policy".
- Set the Minimum Password Length. This setting enforces a minimum length for new or changed passwords. A value of 6 or higher is recommended.
- Note that this policy does not affect existing passwords. It will only take effect when an existing user changes his password.
- Open the "Performance and Maintenance" control panel.
- Select "Administrative Tools".
- To change the domain-wide lockout policy, select "Domain Security Policy" (or "Domain Controller Security Policy" if the computer is a Domain Controller). Otherwise, to change the policy for this computer only, select "Local Security Policy."
- Expand the "Account Policies" folder and select "Password Policy".
- Set the Minimum Password Length. This setting enforces a minimum length for new or changed passwords. A value of 6 or higher is recommended.
- Note that this policy does not affect existing passwords. It will only take effect when an existing user changes his password.
- Open the "Administrative Tools" control panel.
- To change the domain-wide lockout policy, select "Domain Security Policy" (or "Domain Controller Security Policy" if the computer is a Domain Controller). Otherwise, to change the policy for this computer only, select "Local Security Policy."
- Expand the "Account Policies" folder and select "Password Policy".
- Set the Minimum Password Length. This setting enforces a minimum length for new or changed passwords. A value of 6 or higher is recommended.
- Note that this policy does not affect existing passwords. It will only take effect when an existing user changes his password.
- Click on the "Start" button from the Task Bar
- Select "Programs"
- Select "Administrative Tools"
- To change the domain-wide lockout policy, select "User Manager for Domains". Otherwise, to change the policy for this computer only, select "User Manager".
- From the "Policies" menu, select "Account..."
- Set the Minimum Password Length. This setting enforces a minimum length for new or changed passwords. A value of 6 or higher is recommended.
- Note that this policy does not affect existing passwords. It will only take effect when an existing user changes his password.
IBM OS/400
Set the minimum password length
Samba
Set the minimum password length
Information on these pages is summary information extracted from the NeXpose Vulnerabilty Assessment system. Full details are provided within the NeXpose product for licensed users.
Posted by abe at 8:36 AM 0 comments
Labels:
Higher risk of SSL attacks for those relying on MD5 signed certificates
Summary
What is this attack?
The attack works as follows:
- The attacker creates a rogue CA using vulnerabilities in MD5.
- The attacker creates a valid HTTPS certificate for the target Web site.
- The attacker uses this secure certificate to gain trusted status in mainstream browsers.
- The attacker executes any number of browser-based attacks to gain sensitive data from end-users.
Protect Web applications:
- Identify any certificate or certificate chain using MD5. In particular, check for TLS/SSL server or client certificates. Rapid7 NeXpose scans for this vulnerability.
- Migrate affected certificates from MD5 to SHA-1 or SHA-2.
Posted by abe at 8:05 AM 0 comments
Labels:
Samba Print Change Denial Of Service Vulnerability
Description:
Certain versions of Samba are vulnerable to a denial of service if out-of-sequence print change notify requests are receieved. Successful exploitation crashes the Samba daemon.
References:
Solution:
- Upgrade to Samba v2.2.11
Download and apply the upgrade from: http://hostopia.samba.org/samba/ftp/stable/samba-2.2.11.tar.gz - Upgrade to Samba 3.0.7
Download and apply the upgrade from: http://us4.samba.org/samba/ftp/stable/samba-3.0.7.tar.gz
Posted by abe at 7:51 AM 0 comments
Labels:
09 September 2009
INF Update Utility - Primarily for Intel® 5, 4, 3, 900 Series Chipsets
**Note**
**Important**
Multi language: infinst911autol.exe Download
Ver:9.1.1.1019 Date:9/7/2009 Size:2735 (KB) Time @56Kbps:6.33 min
Posted by abe at 11:05 AM 0 comments
Labels:
Schroff - Power Search facility simplifies subrack selection
Posted by abe at 11:02 AM 0 comments
Labels:
Gefran - Ethernet/IPT added to compact four-channel temperature control range
Posted by abe at 10:58 AM 0 comments
Labels:
Austriamicrosystems - Optimal motion sensing solution for angle position systems
Posted by abe at 9:28 AM 0 comments
Labels:
Texas Instruments (TI) - Processors and analog technologies help simplify building management
Posted by abe at 9:24 AM 0 comments
Labels:
Farnell - Configurable power management unit integrates two Dc-DC converters
Posted by abe at 9:18 AM 0 comments
Labels:
Toshiba - Integrated constant current drivers provide responsive LED brightness
Posted by abe at 9:11 AM 0 comments
Labels:
06 September 2009
AMD Release Packs 6-Core Opteron
Posted by abe at 10:09 PM 0 comments
Labels:
Holographic Projections at Near Real-Time Speeds
The PDF is freely available and contains a number of films.
Posted by abe at 9:57 PM 0 comments
Labels:
AMD Outlined its Upcoming 12-core Server Processor
Posted by abe at 8:32 PM 0 comments
Labels:
IBM's 8-core POWER7 Crams an Amazing Amount of Hardware
Speaking of a back-end POWER7 core, each core includes a solid set of execution resources. There are 12 units in total performance, as follows:
- 2 integer units
- 2 Load in-store units
- 4 Double-precision floating-units
- 1 branch unit
- 1 record unit condition
- 1 unit vector
- 1 decimal floating-point unit
Posted by abe at 7:21 PM 0 comments
Labels:
Second Android Phone from T-Mobile
Here spiel on the T-Mobile
Equipment
But how real hardware myTouch stacking against the G1? Very good.
The iPhone
Price
Posted by abe at 6:09 PM 0 comments
Labels:
AT&T has announced that MMS
Posted by abe at 3:50 PM 0 comments
Labels:
Solar Cell for Charging iPods and iPhones
Posted by abe at 2:13 PM 0 comments
Labels:
Maybe Kernel 2.6.31 More Faster?
The arrival of Windows 7 in October, conduct a market share of desktop Linux even further.
USB 3.0 or USB-Super Speed, UPS theoritcal the maximum data rate to 4 Gbit / s.
The latest release candidate for the new Linux kernel 2.6.31-rc8 August 28.
Posted by abe at 1:47 PM 0 comments
Labels:
Notebook Lenovo gScreen G400 NVIDIA GeForce
Posted by abe at 3:29 AM 0 comments
Labels:
Ultra Lightweight Design Sony VAIO X Slim Netbook
Posted by abe at 2:21 AM 0 comments
Labels: