Via InformationWeek -
Two groups committed to the business adoption of Linux are merging to streamline operations and represent Linux versus its challengers with one voice.
The Open Source Development Labs in Beaverton, Ore., will combine with the Free Standards Group in San Francisco to form The Linux Foundation. The two six-year old groups shared overlapping memberships of corporate sponsors and overlapping goals, said Jim Zemlin, executive director of the new foundation.
"We will be a vendor neutral organization capable of responding to competitors' attacks and FUD," said Zemlin in an interview Friday 19 Jan. He is the former executive director of the Free Standards Group.
The merger still needs to be ratified by the members of the two groups, which is expected to be completed in early February.
While the foundation will continue the activities of both groups, the merger also represents some continued paring down and refocusing of goals. First and foremost, said Zemlin, will be the continued independent employment of Linus Torvalds and other Linux kernel maintainers.
"We will provide a safe haven for key developers," Zemlin said, citing Linux package maintainer Stephen Hemminger as well as Torvalds. Andrew Morton, sometimes referred to as Torvalds' righthand man as a kernel maintainer, left a job sponsored by the Open Source Development Labs in August to continue his Linux work at Google.
Torvalds, Hemminger and other kernel developers were previously supported by OSDL. In December the group announced that it was cutting nine of 28 staff members and turning operations over to its Chief Financial Officer Mike Temple. At the time, OSDL CEO Stuart Cohen resigned to pursue other opportunities.
Both groups depended on corporate sponsors for their annual budgets.
Key backers of The Linux Foundation include HP, IBM, Intel, Novell and Oracle. The group will have 70 vendor sponsors in all. Other members include Fujitsu, Hitachi and NEC.
Zemlin said the foundation will continue to supply the Linux Standard Base, an agreed upon set of system functionality that is supported by major Linux distributions. Keeping the Linux core functionality following a standard allows developers to produce applications that will run with different versions of Linux without modifications. The foundation will also provide the Linux Developer Network, which provides information and specifications on the services and interfaces that work with Linux.
The foundation will manage the Linux trademark and provide legal services, including the Open Source As Prior Art project to defend against patent challenges and the Patent Commons, where companies may contribute their patents to be used in defense of Linux.
"Microsoft spends a lot of money protecting its Windows platform. We're going to do the same thing," Zemlin said.
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Monday, January 22, 2007
Belfast Police Covered Up Crimes of Informants
Via seattlepi -
BELFAST, Northern Ireland -- Police intelligence officers covered up at least 10 killings and other crimes committed by Protestant outlaws who were on the payroll as informants, an investigation found Monday.
Following a 3-year probe, Police Ombudsman Nuala O'Loan concluded that former officers in the Special Branch paid informants in the outlawed Ulster Volunteer Force who were permitted to pursue killings, bombings, drug dealing and extortion.
Her report called for police to reopen dozens of cases from the 1990s and investigate ex-officers involved in cover-ups of their informants' crimes.
The commander of the predominantly Protestant police force, Chief Constable Hugh Orde, said he accepted O'Loan's conclusions and recommendations in full. In the report, both he and O'Loan noted that the police force's intelligence-gathering arm had been overhauled since 2003.
Britain's secretary of state for Northern Ireland, Peter Hain, said the report illuminated "a very dark corner of behavior by a limited number of Special Branch officers in the 1990s." He said both UVF veterans and former police officers should stand trial.
BELFAST, Northern Ireland -- Police intelligence officers covered up at least 10 killings and other crimes committed by Protestant outlaws who were on the payroll as informants, an investigation found Monday.
Following a 3-year probe, Police Ombudsman Nuala O'Loan concluded that former officers in the Special Branch paid informants in the outlawed Ulster Volunteer Force who were permitted to pursue killings, bombings, drug dealing and extortion.
Her report called for police to reopen dozens of cases from the 1990s and investigate ex-officers involved in cover-ups of their informants' crimes.
The commander of the predominantly Protestant police force, Chief Constable Hugh Orde, said he accepted O'Loan's conclusions and recommendations in full. In the report, both he and O'Loan noted that the police force's intelligence-gathering arm had been overhauled since 2003.
Britain's secretary of state for Northern Ireland, Peter Hain, said the report illuminated "a very dark corner of behavior by a limited number of Special Branch officers in the 1990s." He said both UVF veterans and former police officers should stand trial.
Sunday, January 21, 2007
Phishers Steal Over One Million Dollars from Swedish Bank
Via ZDNet UK -
Swedish bank Nordea has told ZDNet UK that it has been stung for between seven and eight million Swedish krona — up to £580,000 — in what security company McAfee is describing as the "biggest ever" online bank heist.
Over the last 15 months, Nordea customers have been targeted by emails containing a tailormade Trojan, said the bank.
Nordea believes that 250 customers have been affected by the fraud, after falling victim to phishing emails containing the Trojan. According to McAfee, Swedish police believe Russian organised criminals are behind the attacks. Currently, 121 people are suspected of being involved.
The attack started by a tailormade Trojan sent in the name of the bank to some of its clients, according to McAfee. The sender encouraged clients to download a "spam fighting" application. Users who downloaded the attached file, called raking.zip or raking.exe, were infected by the Trojan, which some security companies call haxdoor.ki.
Haxdoor typically installs keyloggers to record keystrokes, and hides itself using a rootkit. The payload of the .ki variant of the Trojan was activated when users attempted to log in to the Nordea online banking site. According to the bank, users were redirected to a false home page, where they entered important log-in information, including log-in numbers.
After the users entered the information an error message appeared, informed them that the site was experiencing technical difficulties. Criminals then used the harvested customer details on the real Nordea website to take money from customer accounts.
According to McAfee, Swedish police have established that the log-in information was sent to servers in the US, and then to Russia. Police believe the heist to be the work of organised criminals.
Nordea spokesman for Sweden, Boo Ehlin, said that most of the home users affected had not been running antivirus on their computers. The bank has borne the brunt of the attacks, and has refunded all the affected customers.
------------------------------------------------------
580 000 British pounds = 1.14521 million U.S. dollars
Swedish bank Nordea has told ZDNet UK that it has been stung for between seven and eight million Swedish krona — up to £580,000 — in what security company McAfee is describing as the "biggest ever" online bank heist.
Over the last 15 months, Nordea customers have been targeted by emails containing a tailormade Trojan, said the bank.
Nordea believes that 250 customers have been affected by the fraud, after falling victim to phishing emails containing the Trojan. According to McAfee, Swedish police believe Russian organised criminals are behind the attacks. Currently, 121 people are suspected of being involved.
The attack started by a tailormade Trojan sent in the name of the bank to some of its clients, according to McAfee. The sender encouraged clients to download a "spam fighting" application. Users who downloaded the attached file, called raking.zip or raking.exe, were infected by the Trojan, which some security companies call haxdoor.ki.
Haxdoor typically installs keyloggers to record keystrokes, and hides itself using a rootkit. The payload of the .ki variant of the Trojan was activated when users attempted to log in to the Nordea online banking site. According to the bank, users were redirected to a false home page, where they entered important log-in information, including log-in numbers.
After the users entered the information an error message appeared, informed them that the site was experiencing technical difficulties. Criminals then used the harvested customer details on the real Nordea website to take money from customer accounts.
According to McAfee, Swedish police have established that the log-in information was sent to servers in the US, and then to Russia. Police believe the heist to be the work of organised criminals.
Nordea spokesman for Sweden, Boo Ehlin, said that most of the home users affected had not been running antivirus on their computers. The bank has borne the brunt of the attacks, and has refunded all the affected customers.
------------------------------------------------------
580 000 British pounds = 1.14521 million U.S. dollars
Teen Steals GPS Devices - Gets Tracked & Arrested
Via Yahoo News -
LINDENHURST, N.Y. - Three thieves who allegedly stole 14 global positioning system devices didn't get away with their crime for long. The devices led police right to their home.
Town officials said the thieves didn't even know what they had: they thought the GPS devices were cell phones, which they planned to sell.
According to Suffolk County police, the GPS devices were stolen Monday night from the Town of Babylon Public Works garage in Lindenhurst. The town immediately tapped its GPS system, and it showed that one of the devices was inside a house. Police said that when they arrived there, Kurt Husfeldt, 46, had the device in his hands.
Husfeldt was charged with criminal possession of stolen property. His 13-year-old son also was arrested on grand larceny charges.
Town officials said the boy committed the burglary with Steven Mangiapanella, 20, also of Lindenhurst. He was charged with grand larceny.
Babylon installed 300 GPS devices in snow plows, dump trucks, street sweepers and other vehicles last January.
LINDENHURST, N.Y. - Three thieves who allegedly stole 14 global positioning system devices didn't get away with their crime for long. The devices led police right to their home.
Town officials said the thieves didn't even know what they had: they thought the GPS devices were cell phones, which they planned to sell.
According to Suffolk County police, the GPS devices were stolen Monday night from the Town of Babylon Public Works garage in Lindenhurst. The town immediately tapped its GPS system, and it showed that one of the devices was inside a house. Police said that when they arrived there, Kurt Husfeldt, 46, had the device in his hands.
Husfeldt was charged with criminal possession of stolen property. His 13-year-old son also was arrested on grand larceny charges.
Town officials said the boy committed the burglary with Steven Mangiapanella, 20, also of Lindenhurst. He was charged with grand larceny.
Babylon installed 300 GPS devices in snow plows, dump trucks, street sweepers and other vehicles last January.
Vepr: First Ukrainian SUV
Check out the rest of the pics over at pravda.ru

First Ukrainian SUV, named VEPR (Warthog), designed and assembled by the engineers of Kremenchug Autotransport Enterprise.
First Ukrainian SUV, named VEPR (Warthog), designed and assembled by the engineers of Kremenchug Autotransport Enterprise.
Cheating Hardware Based RAM Forensics
Via theinvisiblethings -
We all know that any software-based system compromise detector can always be cheated if malware runs at the same privilege level as the detector (usually both run in kernel mode). This is what I call Implementation Specific Attacks (ISA). Because of that, mankind has tried to find some better, more reliable ways for analyzing systems, which would not be subject to interference from malware…And we all know what we’ve come up with as a solution – hardware based devices for obtaining the image of volatile memory (RAM), usually in the form of a PCI card.
As far as the PC architecture is concerned, probably the first two papers in this area are those about Tribble and CoPilot. As an alternative to expensive dedicated PCI cards, one can also use a FireWire bus, as it has been described by Maximillian Dornseif at el., and later by Adam Boileau.
The point is: once we get the memory image, we can analyze it for signs of compromises on a trusted machine or we can have the PCI device to do some checks itself (like e.g. CoPilot does).
The whole idea behind hardware based RAM acquisition is that the process of reading the memory is using Direct Memory Access (DMA) to read the physical memory. DMA, as the name suggests, does not involve CPU in the process of accessing memory. So, it seems to be a very reliable way for reading the physical memory…But it is not! At least in some cases...
Next month, at Black Hat DC, I will be demonstrating how to cheat hardware based memory acquisition on AMD based systems. In other words, I will be showing that the image obtained using DMA, can be made different from the real contents of the physical memory as seen by the CPU. Even though the attack is AMD-specific, it does not rely on virtualization extensions. Also, the attack does not require system reboot. Nor does it require soldering ;)
I have tested my proof-of-concept code against a FireWire-based method of memory acquisition, using tools from Adam Boileau’s presentation.
We all know that any software-based system compromise detector can always be cheated if malware runs at the same privilege level as the detector (usually both run in kernel mode). This is what I call Implementation Specific Attacks (ISA). Because of that, mankind has tried to find some better, more reliable ways for analyzing systems, which would not be subject to interference from malware…And we all know what we’ve come up with as a solution – hardware based devices for obtaining the image of volatile memory (RAM), usually in the form of a PCI card.
As far as the PC architecture is concerned, probably the first two papers in this area are those about Tribble and CoPilot. As an alternative to expensive dedicated PCI cards, one can also use a FireWire bus, as it has been described by Maximillian Dornseif at el., and later by Adam Boileau.
The point is: once we get the memory image, we can analyze it for signs of compromises on a trusted machine or we can have the PCI device to do some checks itself (like e.g. CoPilot does).
The whole idea behind hardware based RAM acquisition is that the process of reading the memory is using Direct Memory Access (DMA) to read the physical memory. DMA, as the name suggests, does not involve CPU in the process of accessing memory. So, it seems to be a very reliable way for reading the physical memory…But it is not! At least in some cases...
Next month, at Black Hat DC, I will be demonstrating how to cheat hardware based memory acquisition on AMD based systems. In other words, I will be showing that the image obtained using DMA, can be made different from the real contents of the physical memory as seen by the CPU. Even though the attack is AMD-specific, it does not rely on virtualization extensions. Also, the attack does not require system reboot. Nor does it require soldering ;)
I have tested my proof-of-concept code against a FireWire-based method of memory acquisition, using tools from Adam Boileau’s presentation.
2007 CES Wootable Awards
Via Woot.com Blog -
No mere mortal could see more than a fraction of the vast 2007 Consumer Electronics Show, so we don't pretend that this is a definitive list. But here are our choices for the 2007 CES Wootable Awards, with an assist from a few loyal Wooter correspondents.
--------------------------------------
Please visit the link at the top for all the great pics...funny stuff indeed.
No mere mortal could see more than a fraction of the vast 2007 Consumer Electronics Show, so we don't pretend that this is a definitive list. But here are our choices for the 2007 CES Wootable Awards, with an assist from a few loyal Wooter correspondents.
--------------------------------------
Please visit the link at the top for all the great pics...funny stuff indeed.
Pharming - The Hard to Detect Threat
Via Ha.ckers.org -
Am I going to have to eat my words? I was thumbing through some AV reports over the last few days and one report stuck out at me. Granted, I don’t follow each worm (not enough hours in the day for all the things I’d like to explore) but I was surprised to see a worm that had to do with Pharming. For those of you who are unfamiliar with the term, unlike phishing, pharming takes a more proactive approach by forcing people’s DNS entries to point to a different/malicious server. Frankly, I thought it was mostly the stuff of science fiction since no one could point to a single example of any instance of pharming greater than 100 people (a single ISP that got it’s DNS compromised). Granted, the trojan doesn’t mention pharming but that is the obvious next step if it isn’t already doing it (rather than just trying to get some click-through traffic on some websites).
Trojan.Flush.K also known as Trojan.Dnschanger modifies DNS entries on your Windows box and attempts to forward you to a malicious website. The obvious synergies with phishing attacks make this particular one stand out at me. Symantec rated this one very low (probably to do both with the lack of virulence and the ease of cleaning the system), but it’s interesting to note how potentially dangerous this could be if it were more widespread and written with more malice.
----------------------------------------
Your general public has no hope if detecting this treat. This is even a hard detection for security professionals. When is the last time you looked at your HOSTS file? Or checked for a static DNS server in your IP settings?
Exactly.
Am I going to have to eat my words? I was thumbing through some AV reports over the last few days and one report stuck out at me. Granted, I don’t follow each worm (not enough hours in the day for all the things I’d like to explore) but I was surprised to see a worm that had to do with Pharming. For those of you who are unfamiliar with the term, unlike phishing, pharming takes a more proactive approach by forcing people’s DNS entries to point to a different/malicious server. Frankly, I thought it was mostly the stuff of science fiction since no one could point to a single example of any instance of pharming greater than 100 people (a single ISP that got it’s DNS compromised). Granted, the trojan doesn’t mention pharming but that is the obvious next step if it isn’t already doing it (rather than just trying to get some click-through traffic on some websites).
Trojan.Flush.K also known as Trojan.Dnschanger modifies DNS entries on your Windows box and attempts to forward you to a malicious website. The obvious synergies with phishing attacks make this particular one stand out at me. Symantec rated this one very low (probably to do both with the lack of virulence and the ease of cleaning the system), but it’s interesting to note how potentially dangerous this could be if it were more widespread and written with more malice.
----------------------------------------
Your general public has no hope if detecting this treat. This is even a hard detection for security professionals. When is the last time you looked at your HOSTS file? Or checked for a static DNS server in your IP settings?
Exactly.
Porting Scanning Clients via IFRAME
Via Ha.ckers.org -
A recent thread on sla.ckers.org discussing a vulnerability in neopets actually got me thinking. Spikeman posted that you could detect once the page had completed loading in an iframe using an onload event handler. More timing attacks anyone? Well that’s not all. In Firefox it actually has a peculiar behavior. In IE (as it should) the onload event handler works all the time, because the page has finished loading. In Firefox it doesn’t fire if the browser encounters an error. An error could be something as simple as the server is not up (I have not tested with other server errors).
This proof of concept shows the difference (try in IE and Firefox to see the difference). You can see that in Firefox a series of iframes can be chained together to do port scanning (including Intranet port scanning). This is obviously a known issue when talking about JavaScript includes, but this is the first time I’ve heard of anyone discussing using an iframe for this purpose. Yet another way to do cross domain leakage (and cross firewall leakage at that). Thanks to Spikeman for alerting me to the onload event handler in iframes.
A recent thread on sla.ckers.org discussing a vulnerability in neopets actually got me thinking. Spikeman posted that you could detect once the page had completed loading in an iframe using an onload event handler. More timing attacks anyone? Well that’s not all. In Firefox it actually has a peculiar behavior. In IE (as it should) the onload event handler works all the time, because the page has finished loading. In Firefox it doesn’t fire if the browser encounters an error. An error could be something as simple as the server is not up (I have not tested with other server errors).
This proof of concept shows the difference (try in IE and Firefox to see the difference). You can see that in Firefox a series of iframes can be chained together to do port scanning (including Intranet port scanning). This is obviously a known issue when talking about JavaScript includes, but this is the first time I’ve heard of anyone discussing using an iframe for this purpose. Yet another way to do cross domain leakage (and cross firewall leakage at that). Thanks to Spikeman for alerting me to the onload event handler in iframes.
Conceptualizing a Cyborg
Via biologynews.net -
Investigators at the University of Pennsylvania School of Medicine describe the basis for developing a biological interface that could link a patient's nervous system to a thought-driven artificial limb. Their conceptual framework - which brings together years of spinal-cord injury research - is published in the January issue of Neurosurgery.
"We're at a junction now of developing a new approach for a brain-machine interface," says senior author Douglas H. Smith, MD, Professor of Neurosurgery and Director of the Center for Brain Injury and Repair at Penn. "The nervous system will certainly rebel if you place hard or sharp electrodes into it to record signals. However, the nervous system can be tricked to accept an interface letting it do what it likes - assimilating new nerve cells into its own network".
-----------------------------------------
As Cut Chemist will tell ya, "the robots are coming..."
Investigators at the University of Pennsylvania School of Medicine describe the basis for developing a biological interface that could link a patient's nervous system to a thought-driven artificial limb. Their conceptual framework - which brings together years of spinal-cord injury research - is published in the January issue of Neurosurgery.
"We're at a junction now of developing a new approach for a brain-machine interface," says senior author Douglas H. Smith, MD, Professor of Neurosurgery and Director of the Center for Brain Injury and Repair at Penn. "The nervous system will certainly rebel if you place hard or sharp electrodes into it to record signals. However, the nervous system can be tricked to accept an interface letting it do what it likes - assimilating new nerve cells into its own network".
-----------------------------------------
As Cut Chemist will tell ya, "the robots are coming..."
Biometric ATMs Coming to Rural India
Via engadget.com -
Considering all the ATM hacking that's been going on of late, it's not all that surprising to see those "uber-secure" fingerprint readers hitting mini-banks in Japan and Columbia, and now a pilot program is getting set to install 15 biometric ATMs at "village kiosks in five districts across southern India."
The fingerprint-reading machines are expected to serve around 100,000 workers, primarily farmers and other laborers, who will finally be able to withdraw funds directly from a machine rather than suffering through the corrupt hand-me-down process that often steals money away from already poor workers.
AGS Infotech, who is supplying the first batch of systems for the trial, is interested in seeing if the system actually works out, as many villagers have trouble interacting with any type of computing interface, and because many villages have their own dialects, making a UI that can communicate to everyone is difficult.
Of course, there are individuals who suggest that these systems will only incite crime, as thieves look to new methods (read: hacking a thumb or two) to extract funds, but proponents of the system say that this is no different than armed criminals forcing someone to give up their PIN number at gunpoint.
Nevertheless, the trial is slated to start soon, and there's quite a few outsiders watching intently to gauge its eventual success or failure, as analysts predict that "over 100,000 ATMs" could be necessary to handle India's booming economy in the next few years.
-----------------------------
Lets just hope they changed the default master password on those ATMs.
Considering all the ATM hacking that's been going on of late, it's not all that surprising to see those "uber-secure" fingerprint readers hitting mini-banks in Japan and Columbia, and now a pilot program is getting set to install 15 biometric ATMs at "village kiosks in five districts across southern India."
The fingerprint-reading machines are expected to serve around 100,000 workers, primarily farmers and other laborers, who will finally be able to withdraw funds directly from a machine rather than suffering through the corrupt hand-me-down process that often steals money away from already poor workers.
AGS Infotech, who is supplying the first batch of systems for the trial, is interested in seeing if the system actually works out, as many villagers have trouble interacting with any type of computing interface, and because many villages have their own dialects, making a UI that can communicate to everyone is difficult.
Of course, there are individuals who suggest that these systems will only incite crime, as thieves look to new methods (read: hacking a thumb or two) to extract funds, but proponents of the system say that this is no different than armed criminals forcing someone to give up their PIN number at gunpoint.
Nevertheless, the trial is slated to start soon, and there's quite a few outsiders watching intently to gauge its eventual success or failure, as analysts predict that "over 100,000 ATMs" could be necessary to handle India's booming economy in the next few years.
-----------------------------
Lets just hope they changed the default master password on those ATMs.
Attack on AACS in Blue-Ray
Via engadget.com -
It's still early on to tell whether this is actually true, but HD DVD cracker muslix64 is back, and with the help of another anti-DRM cracker, Janvitos, claims to have also broken the Blu-ray's implementation of AACS. Although their protection does not yet account for BD+ copy-protection, they claim to have been able to implement the same key-grabbing known-plaintext attack as muslix64 used to crack HD DVD in order to successfully to crack Blu-ray without even using a disc or drive (apparently they just used a raw encrypted data file and nothing more). Unfortunately they haven't yet posted code for us to test this out, so we'll have to take their word for it for the time being.
It's still early on to tell whether this is actually true, but HD DVD cracker muslix64 is back, and with the help of another anti-DRM cracker, Janvitos, claims to have also broken the Blu-ray's implementation of AACS. Although their protection does not yet account for BD+ copy-protection, they claim to have been able to implement the same key-grabbing known-plaintext attack as muslix64 used to crack HD DVD in order to successfully to crack Blu-ray without even using a disc or drive (apparently they just used a raw encrypted data file and nothing more). Unfortunately they haven't yet posted code for us to test this out, so we'll have to take their word for it for the time being.
The Science of Tear Film
Via biologynews.net -
It's no secret why we shed tears. But exactly what our tears are made of has remained a mystery to scientists.
A new study sheds some light on the complex design of tears. What we think of as tears, scientists call tear film, which is made up of three distinct, microscopic layers. The middle, watery layer – what we normally think of as tears when we cry – is sandwiched between a layer of mucus and an outer layer of fatty, oily substances collectively called meibum.
It's in this outer layer that researchers describe, for the first time, a new class of lipids – a type of fat – that make up part of the film. They also identified one of these lipids, oleamide, which had not been known to be a part of tears before.
With each blink, meibum spreads over the surface of the eye. It keeps the watery middle layer in place, ensuring that our eyes stay moist.
It's no secret why we shed tears. But exactly what our tears are made of has remained a mystery to scientists.
A new study sheds some light on the complex design of tears. What we think of as tears, scientists call tear film, which is made up of three distinct, microscopic layers. The middle, watery layer – what we normally think of as tears when we cry – is sandwiched between a layer of mucus and an outer layer of fatty, oily substances collectively called meibum.
It's in this outer layer that researchers describe, for the first time, a new class of lipids – a type of fat – that make up part of the film. They also identified one of these lipids, oleamide, which had not been known to be a part of tears before.
With each blink, meibum spreads over the surface of the eye. It keeps the watery middle layer in place, ensuring that our eyes stay moist.
Iran Considers Request for Direct Talks
Via irna.ir (Official Iran News Agency) -
Iran would consider Washington's official request for negotiations on regional issues, said a senior Iranian official Sunday.
Foreign Ministry spokesman Mohammad-Ali Hosseini made the remark while speaking to domestic and foreign reporters.
Asked about Iran's nuclear case, he said "No change has occurred in Iran's nuclear stance. The issue of suspension of enrichment is not acceptable because it has no legal and rational basis."
Pointing to the US President George Bush's new strategy on Iraq and the US attack on Iran's consulate general in the Iraqi city of Erbil on January 11, he added, "The US intends to make broad scale arrests at different levels and in various regions of Iraq in the future.
"The new approach will escalate tension in Iraq and the region," said the spokesman.
In reply to a question whether Iran was following up the release of Iranian diplomats through direct or indirect contacts with the US, he said, "Iran is pursuing the case via the Iraqi officials. There is no need to hold direct talks with the Americans."
In response to a question on the date of a scheduled visit to Tehran of France's special envoy, he said, "The sides have not reached a final agreement on the date and level of the visit."
On recent remarks by the International Atomic Energy Agency (IAEA) chief Mohamed ElBaradei who has acknowledged Iran is not engaged in any undeclared nuclear activities, the spokesman expressed hope that relevant officials in European and non-European states would opt for negotiations.
He also said the Qatari foreign minister was to arrive in Tehran today (Sunday).
------------------------------------------------------
Please be aware that IRNA.IR is the official news agency of Iran, therefore their spin reference should be clear. Readers must read thru the lines...and always compare offical regional local news agencies to others in the region. This is great advise for all news, not just news from IRNA.
Iran would consider Washington's official request for negotiations on regional issues, said a senior Iranian official Sunday.
Foreign Ministry spokesman Mohammad-Ali Hosseini made the remark while speaking to domestic and foreign reporters.
Asked about Iran's nuclear case, he said "No change has occurred in Iran's nuclear stance. The issue of suspension of enrichment is not acceptable because it has no legal and rational basis."
Pointing to the US President George Bush's new strategy on Iraq and the US attack on Iran's consulate general in the Iraqi city of Erbil on January 11, he added, "The US intends to make broad scale arrests at different levels and in various regions of Iraq in the future.
"The new approach will escalate tension in Iraq and the region," said the spokesman.
In reply to a question whether Iran was following up the release of Iranian diplomats through direct or indirect contacts with the US, he said, "Iran is pursuing the case via the Iraqi officials. There is no need to hold direct talks with the Americans."
In response to a question on the date of a scheduled visit to Tehran of France's special envoy, he said, "The sides have not reached a final agreement on the date and level of the visit."
On recent remarks by the International Atomic Energy Agency (IAEA) chief Mohamed ElBaradei who has acknowledged Iran is not engaged in any undeclared nuclear activities, the spokesman expressed hope that relevant officials in European and non-European states would opt for negotiations.
He also said the Qatari foreign minister was to arrive in Tehran today (Sunday).
------------------------------------------------------
Please be aware that IRNA.IR is the official news agency of Iran, therefore their spin reference should be clear. Readers must read thru the lines...and always compare offical regional local news agencies to others in the region. This is great advise for all news, not just news from IRNA.
Iran to Conduct Missile War Games
Via intelligence-summit -
TEHRAN, Iran - Iran plans to conduct missile war games during a three-day period beginning Sunday, state-run television reported.
The war games will be carried out near Garmsar city, about 60 miles southeast of Tehran, according to the broadcast."Zalzal and Fajr-5 missiles will be test fired in the war game," the broadcast quoted an unnamed military commander, as saying. Both are considered short-range missiles.
The exercise will be the first by Iran since the U.N. Security Council imposed sanctions on December 23, which banned selling materials and technology that could be used in Iran's nuclear and missile programs and the freezing of assets of 10 Iranian companies and individuals.
Earlier in November Iran test-fired dozens of missiles — including the Shahab-3 that can reach Israel.
Iran held three large-scale military exercises last year. In its April exercises, Iran tested what it called an "ultra-horizon" missile, which is fired from helicopters and jets, and the Fajr-3 missile, which can reportedly evade radar and use multiple warheads to hit several targets simultaneously.
TEHRAN, Iran - Iran plans to conduct missile war games during a three-day period beginning Sunday, state-run television reported.
The war games will be carried out near Garmsar city, about 60 miles southeast of Tehran, according to the broadcast."Zalzal and Fajr-5 missiles will be test fired in the war game," the broadcast quoted an unnamed military commander, as saying. Both are considered short-range missiles.
The exercise will be the first by Iran since the U.N. Security Council imposed sanctions on December 23, which banned selling materials and technology that could be used in Iran's nuclear and missile programs and the freezing of assets of 10 Iranian companies and individuals.
Earlier in November Iran test-fired dozens of missiles — including the Shahab-3 that can reach Israel.
Iran held three large-scale military exercises last year. In its April exercises, Iran tested what it called an "ultra-horizon" missile, which is fired from helicopters and jets, and the Fajr-3 missile, which can reportedly evade radar and use multiple warheads to hit several targets simultaneously.
Another Myspace Phish with HTMLCrypt
Hacked accounts are used to send bulletins and leave spam comments on friend's profiles.
In this phishing example, you see a bulletin that claims to point to a Myspace video of a drunk girl at a party. Guys think "Girl Gone Wild" and they click the link.

Following the link, takes you to vidspace9.com

Which then pushes you to a AOL member page that is hosting the Myspace phishing site.

I wonder if the AOL account was hacked as well. The Phishers must know that AOL will most likely kill the site very quickly, once reported and maybe even the account......however, it might be a free limited time trial account as well.
Looking at the source of the phishing site, shows something more interesting. The phishers are using a beta version of HTMLCrypt to help protect their phishing code.

I reported this site to PIRT this morning.
In this phishing example, you see a bulletin that claims to point to a Myspace video of a drunk girl at a party. Guys think "Girl Gone Wild" and they click the link.

Following the link, takes you to vidspace9.com

Which then pushes you to a AOL member page that is hosting the Myspace phishing site.

I wonder if the AOL account was hacked as well. The Phishers must know that AOL will most likely kill the site very quickly, once reported and maybe even the account......however, it might be a free limited time trial account as well.
Looking at the source of the phishing site, shows something more interesting. The phishers are using a beta version of HTMLCrypt to help protect their phishing code.

I reported this site to PIRT this morning.
Saturday, January 20, 2007
Wireless Networks Around the World Shake - Kismet 2007
On Jan 15th, Kismet-2007-01-R1 was released. Includes native Win32 capture (ONLY with CACE Airpcap, NO OTHER CARDS), nokia770/800 support, better BSD support, multiple crash fixes, more IDS features.
But on Jan 16th, several minor issues were corrected and Kismet-2007-01-R1b was released. Come and get it...
But on Jan 16th, several minor issues were corrected and Kismet-2007-01-R1b was released. Come and get it...
Opposition MPs Investigate UK School Fingerprinting
Via theregister.co.uk -
Opposition MPs have begun investigating the use of biometric scanners in UK schools and the use of funds that might otherwise be spent buying books and learning materials to buy the systems.
Foremost in written parliamentary questions tabled by Conservative and Liberal Democrat MPs was the question of fingerprint scanners being bought with e-Learning credits, which are a mechanism used by the Department for Education and Skills (DfES) to provide schools with direct funding to buy educational software.
Sarah Teather, shadow education secretary and MP for Brent East, asked the government whether it had given schools permission to use e-Learning credits to buy biometric scanners that took children's fingerprints.
"I believe that the collection of biometric data from young pupils without parental consent is illegal and must cease," she told The Register in a written statement.
Opposition MPs have begun investigating the use of biometric scanners in UK schools and the use of funds that might otherwise be spent buying books and learning materials to buy the systems.
Foremost in written parliamentary questions tabled by Conservative and Liberal Democrat MPs was the question of fingerprint scanners being bought with e-Learning credits, which are a mechanism used by the Department for Education and Skills (DfES) to provide schools with direct funding to buy educational software.
Sarah Teather, shadow education secretary and MP for Brent East, asked the government whether it had given schools permission to use e-Learning credits to buy biometric scanners that took children's fingerprints.
"I believe that the collection of biometric data from young pupils without parental consent is illegal and must cease," she told The Register in a written statement.
Friday, January 19, 2007
Dead Birds in Austin Caused By Parasites & Cold Weather
Via News8Austin.com -
Three aviary pathologists at Texas A&M blame parasites and cold weather for the deaths last week of 63 birds in Austin.
The executive director of the Texas Veterinary Medical Diagnostic Laboratory says there were no toxins or public health concerns to be worried about. The night the birds died, temperatures dropped from about 50 degrees to 40 degrees in six hours.
The birds, which were mostly grackles, had parasites in their muscles, tissues and brains.
None had food in their crops or gizzards, indicating they hadn't eaten in the previous 24 to 36 hours.
Three aviary pathologists at Texas A&M blame parasites and cold weather for the deaths last week of 63 birds in Austin.
The executive director of the Texas Veterinary Medical Diagnostic Laboratory says there were no toxins or public health concerns to be worried about. The night the birds died, temperatures dropped from about 50 degrees to 40 degrees in six hours.
The birds, which were mostly grackles, had parasites in their muscles, tissues and brains.
None had food in their crops or gizzards, indicating they hadn't eaten in the previous 24 to 36 hours.
Google Releases New Tool - Google Purge
Via theOnion (Aug 2005) -
MOUNTAIN VIEW, CA—Executives at Google, the rapidly growing online-search company that promises to "organize the world's information," announced Monday the latest step in their expansion effort: a far-reaching plan to destroy all the information it is unable to index.
"Our users want the world to be as simple, clean, and accessible as the Google home page itself," said Google CEO Eric Schmidt at a press conference held in their corporate offices. "Soon, it will be."
The new project, dubbed Google Purge, will join such popular services as Google Images, Google News, and Google Maps, which catalogs the entire surface of the Earth using high-resolution satellites.
As a part of Purge's first phase, executives will destroy all copyrighted materials that cannot be searched by Google.
"A year ago, Google offered to scan every book on the planet for its Google Print project. Now, they are promising to burn the rest," John Battelle wrote in his widely read "Searchblog." "Thanks to Google Purge, you'll never have to worry that your search has missed some obscure book, because that book will no longer exist. And the same goes for movies, art, and music."
"Book burning is just the beginning," said Google co-founder Larry Page. "This fall, we'll unveil Google Sound, which will record and index all the noise on Earth. Is your baby sleeping soundly? Does your high-school sweetheart still talk about you? Google will have the answers."
Page added: "And thanks to Google Purge, anything our global microphone network can't pick up will be silenced by noise-cancellation machines in low-Earth orbit."
As a part of Phase One operations, Google executives will permanently erase the hard drive of any computer that is not already indexed by the Google Desktop Search.
"We believe that Google Desktop Search is the best way to unlock the information hidden on your hard drive," Schmidt said. "If you haven't given it a try, now's the time. In one week, the deleting begins."
Although Google executives are keeping many details about Google Purge under wraps, some analysts speculate that the categories of information Google will eventually index or destroy include handwritten correspondence, buried fossils, and private thoughts and feelings.
The company's new directive may explain its recent acquisition of Celera Genomics, the company that mapped the human genome, and its buildup of a vast army of laser-equipped robots.
"Google finally has what it needs to catalog the DNA of every organism on Earth," said analyst Imran Kahn of J.P. Morgan Chase. "Of course, some people might not want their DNA indexed. Hence, the robot army. It's crazy, it's brilliant—typical Google."
Google's robot army is rumored to include some 4 million cybernetic search-and-destroy units, each capable of capturing and scanning up to 100 humans per day. Said co-founder Sergey Brin: "The scanning will be relatively painless. Hey, it's Google. It'll be fun to be scanned by a Googlebot. But in the event people resist, the robots are programmed to liquify the brain."
Markets responded favorably to the announcement of Google Purge, with traders bidding up Google's share price by $1.24, to $285.92, in late trading after the announcement. But some critics of the company have found cause for complaint.
"This announcement is a red flag," said Daniel Brandt, founder of Google-Watch.org. "I certainly don't want to accuse of them having bad intentions. But this campaign of destruction and genocide raises some potential privacy concerns."
Brandt also expressed reservations about the company's new motto. Until yesterday's news conference, the company's unofficial slogan had been "Don't be evil." The slogan has now been expanded to "Don't be evil, unless it's necessary for the greater good."
Co-founders Page and Brin dismiss their critics.
"A lot of companies are so worried about short-term reactions that they ignore the long view," Page said. "Not us. Our team is focused on something more than just making money. At Google, we're using technology to make dreams come true."
"Soon," Brin added, "we'll make dreams clickable, or destroy them forever."
MOUNTAIN VIEW, CA—Executives at Google, the rapidly growing online-search company that promises to "organize the world's information," announced Monday the latest step in their expansion effort: a far-reaching plan to destroy all the information it is unable to index.
"Our users want the world to be as simple, clean, and accessible as the Google home page itself," said Google CEO Eric Schmidt at a press conference held in their corporate offices. "Soon, it will be."
The new project, dubbed Google Purge, will join such popular services as Google Images, Google News, and Google Maps, which catalogs the entire surface of the Earth using high-resolution satellites.
As a part of Purge's first phase, executives will destroy all copyrighted materials that cannot be searched by Google.
"A year ago, Google offered to scan every book on the planet for its Google Print project. Now, they are promising to burn the rest," John Battelle wrote in his widely read "Searchblog." "Thanks to Google Purge, you'll never have to worry that your search has missed some obscure book, because that book will no longer exist. And the same goes for movies, art, and music."
"Book burning is just the beginning," said Google co-founder Larry Page. "This fall, we'll unveil Google Sound, which will record and index all the noise on Earth. Is your baby sleeping soundly? Does your high-school sweetheart still talk about you? Google will have the answers."
Page added: "And thanks to Google Purge, anything our global microphone network can't pick up will be silenced by noise-cancellation machines in low-Earth orbit."
As a part of Phase One operations, Google executives will permanently erase the hard drive of any computer that is not already indexed by the Google Desktop Search.
"We believe that Google Desktop Search is the best way to unlock the information hidden on your hard drive," Schmidt said. "If you haven't given it a try, now's the time. In one week, the deleting begins."
Although Google executives are keeping many details about Google Purge under wraps, some analysts speculate that the categories of information Google will eventually index or destroy include handwritten correspondence, buried fossils, and private thoughts and feelings.
The company's new directive may explain its recent acquisition of Celera Genomics, the company that mapped the human genome, and its buildup of a vast army of laser-equipped robots.
"Google finally has what it needs to catalog the DNA of every organism on Earth," said analyst Imran Kahn of J.P. Morgan Chase. "Of course, some people might not want their DNA indexed. Hence, the robot army. It's crazy, it's brilliant—typical Google."
Google's robot army is rumored to include some 4 million cybernetic search-and-destroy units, each capable of capturing and scanning up to 100 humans per day. Said co-founder Sergey Brin: "The scanning will be relatively painless. Hey, it's Google. It'll be fun to be scanned by a Googlebot. But in the event people resist, the robots are programmed to liquify the brain."
Markets responded favorably to the announcement of Google Purge, with traders bidding up Google's share price by $1.24, to $285.92, in late trading after the announcement. But some critics of the company have found cause for complaint.
"This announcement is a red flag," said Daniel Brandt, founder of Google-Watch.org. "I certainly don't want to accuse of them having bad intentions. But this campaign of destruction and genocide raises some potential privacy concerns."
Brandt also expressed reservations about the company's new motto. Until yesterday's news conference, the company's unofficial slogan had been "Don't be evil." The slogan has now been expanded to "Don't be evil, unless it's necessary for the greater good."
Co-founders Page and Brin dismiss their critics.
"A lot of companies are so worried about short-term reactions that they ignore the long view," Page said. "Not us. Our team is focused on something more than just making money. At Google, we're using technology to make dreams come true."
"Soon," Brin added, "we'll make dreams clickable, or destroy them forever."
Subscribe to:
Posts (Atom)