Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

December 08, 2010

Updates Fail After Fresh Install Of XP

Graphic which hints to Microsoft Windows Image via WikipediaBy The Computer Doctor

So the situation arose where after installing XP Pro on a virtual machine I can't get any updates after installing Service Pack 3. The disc I have comes with SP2 already loaded and the first update that I ran was SP3. Now I see 56 updates waiting and whenever I try to get them I get update failed for each item.

The Problem: Back in 2007 the Windows Update Agent was silently being upgraded which was creating a lot of complaints. As a result the new Windows Update Agent is not included in SP3. So in essence Microsoft goes from sneaky to bonehead in one move.

The Solution(s): My solution was to just install the new WUA from the following file.

http://download.windowsupdate.com/WindowsUpdate/redist/standalone/7.0.6000.381/WindowsUpdateAgent30-x86.exe


Another user on the internet suggested to use the AURESET tool that you can read about and get the download for at this site.

http://aumha.net/viewtopic.php?f=62&t=33560

If you want to see the Microsoft solution, look at the end of the article as it is lengthy and the above two methods are preferred by the user community.


Hopefully this helps as the use of Windows XP will probably still be around for as long as the updates are available.




**** Microsoft Solution ****

Solution: re-registered the .dll files for updates

action: stop the BITS, .ASPnet, cryptographic services

action: rename the software distribution folders, catroot2 folders

action: start the BITS,AUTOMATIC UPDATES ,CRYPTOGRAPHIC SERVICES

action: register the following update files

cd /d %SystemRoot%\system32
Regsvr32 wups2.dll /s
Regsvr32 licdll.dll /s
Regsvr32 regwizc.dll /s
regsvr32 msxml.dll /s
regsvr32 msxml2.dll /s
regsvr32 msxml3.dll /s
regsvr32 comcat.dll /s
regsvr32 shdoc401.dll /s
regsvr32 shdoc401.dll /i /s
regsvr32 asctrls.ocx /s
regsvr32 oleaut32.dll /s
regsvr32 shdocvw.dll /I /s
regsvr32 shdocvw.dll /s
regsvr32 browseui.dll /s
regsvr32 browseui.dll /I /s
regsvr32 msrating.dll /s
regsvr32 mlang.dll /s
regsvr32 hlink.dll /s
regsvr32 mshtmled.dll /s
regsvr32 urlmon.dll /s
regsvr32 plugin.ocx /s
regsvr32 sendmail.dll /s
regsvr32 scrobj.dll /s
regsvr32 mmefxe.ocx /s
regsvr32 corpol.dll /s
regsvr32 jscript.dll /s
regsvr32 msxml.dll /s
regsvr32 imgutil.dll /s
regsvr32 thumbvw.dll /s
regsvr32 cryptext.dll /s
regsvr32 rsabase.dll /s
regsvr32 inseng.dll /s
regsvr32 iesetup.dll /i /s
regsvr32 cryptdlg.dll /s
regsvr32 actxprxy.dll /s
regsvr32 dispex.dll /s
regsvr32 occache.dll /s
regsvr32 occache.dll /i /s
regsvr32 iepeers.dll /s
regsvr32 urlmon.dll /i /s
regsvr32 cdfview.dll /s
regsvr32 webcheck.dll /s
regsvr32 mobsync.dll /s
regsvr32 pngfilt.dll /s
regsvr32 licmgr10.dll /s
regsvr32 icmfilter.dll /s
regsvr32 hhctrl.ocx /s
regsvr32 inetcfg.dll /s
regsvr32 tdc.ocx /s
regsvr32 MSR2C.DLL /s
regsvr32 msident.dll /s
regsvr32 msieftp.dll /s
regsvr32 xmsconf.ocx /s
regsvr32 ils.dll /s
regsvr32 msoeacct.dll /s
regsvr32 inetcomm.dll /s
regsvr32 msdxm.ocx /s
regsvr32 dxmasf.dll /s
regsvr32 l3codecx.ax /s
regsvr32 acelpdec.ax /s
regsvr32 mpg4ds32.ax /s
regsvr32 voxmsdec.ax /s
regsvr32 danim.dll /s
regsvr32 Daxctle.ocx /s
regsvr32 lmrt.dll /s
regsvr32 datime.dll /s
regsvr32 dxtrans.dll /s
regsvr32 dxtmsft.dll /s
regsvr32 WEBPOST.DLL /s
regsvr32 WPWIZDLL.DLL /s
regsvr32 POSTWPP.DLL /s
regsvr32 CRSWPP.DLL /s
regsvr32 FTPWPP.DLL /s
regsvr32 FPWPP.DLL /s
regsvr32 WUAPI.DLL /s
regsvr32 WUAUENG.DLL /s
regsvr32 ATL.DLL /s
regsvr32 WUCLTUI.DLL /s
regsvr32 WUPS.DLL /s
regsvr32 WUWEB.DLL /s
regsvr32 wshom.ocx /s
regsvr32 wshext.dll /s
regsvr32 vbscript.dll /s
regsvr32 scrrun.dll mstinit.exe /setup /s
regsvr32 msnsspc.dll /SspcCreateSspiReg /s
regsvr32 msapsspc.dll /SspcCreateSspiReg /s
exit
Enhanced by Zemanta

December 07, 2010

Federal Cloud Conversions Heat Up Google-Microsoft Competition

By John K. Higgins
E-Commerce Times


The GSA's award of a $6.7 million email contract to Google has raised hackles in Redmond. "Microsoft offers some pretty robust programs and maybe there was a trade-off in price in opting for something less robust for a lower cost. However, Google has been working to make its cloud offerings pretty robust too," noted IDC analyst Shawn McCarthy. "If this works at GSA, it will show it can work elsewhere."

The U.S. government's drive to adopt cloud technology has generated a huge opportunity for vendors -- and has sparked fierce competition for the business.

In the latest go round, Unisys (NYSE: UIS), in partnership with Google (Nasdaq: GOOG), emerged victorious with a contract to provide a cloud-based email system for the General Services Administration. However, it didn't take long for competitor Microsoft (Nasdaq: MSFT) to downplay Google's GSA offering while promoting what it contends are the superior features of the Microsoft entry.

GSA awarded the five-year, US$6.7-million contract to the Unisys-Google partnership for email and collaboration tools that will reduce inefficiencies and lower costs by 50 percent, the agency said. With the contract award, GSA became the first federal entity to move its email system to a cloud-based platform on an agency-wide basis. Almost 17,000 GSA users in the U.S. and abroad will be migrated to the Unisys-Google platform.


Cloud Presents Opportunities

The GSA procurement is part of a government-wide effort to utilize lightweight technologies such as cloud computing and shared services to limit the need for expensive, redundant infrastructure, the agency said.

"GSA's email award is in step with the administration's 'cloud first' strategy and demonstrates that agile, secure, reliable and cost-effective cloud options exist to rapidly improve agency operations," said Dave McClure, GSA associate administrator of the Office of Citizen Services and Innovative Technologies.

For Google, the contract represents a major marketing coup in cracking the federal market.

"GSA is leading the way in embracing the federal Cloud first policy under which agencies should opt for hosted applications when secure, reliable, cost-effective options are available. We are thrilled that GSA has chosen to move to the Cloud with Google and we look forward to expanding our productive partnership with the agency," said Mike Bradshaw, director of Google's federal enterprise team, in a Google blog post.

Microsoft, understandably, was less than thrilled by the GSA's selection of Unisys-Google, but a top executive tried to convey a sporting tone.

"Industry competition drives innovation and is good for government agencies," said Curt Kolcun, Microsoft's vice president of U.S. public sector business. "We are disappointed in the GSA's internal email decision."

It appeared Microsoft was puzzled as to why GSA selected Google, in light of what Microsoft felt were the attractive features of its own offering.

"Our business productivity online suite (BPOS) federal proposal was a conscious decision to provide GSA with U.S.-only data center support, where data is maintained in the U.S. and is administered by U.S. citizens with background checks," Kolcun told the E-Commerce Times.

"This offering meets the most stringent requirements of governments, and we are working with several agencies who see this as essential. We are gratified that so many federal, state and local governments have chosen Microsoft to meet their business needs," Kolcun said.


Microsoft Sees Google Flaws

Another Microsoft executive was more pointed in his comments, expressing consternation over GSA's procurement rationale.

"We will continue to serve GSA's productivity needs through the familiar experience of Microsoft Office and we look forward to understanding more about GSA's selection criteria, especially around security and architecture," said Thomas Rizzo, senior director of Microsoft Online, in a corporate blog posting.

"There's no doubt that businesses are talking to Google, and hearing their pitch, but despite all the talk, Google can't avoid the fact that often times they cannot meet basic requirements. For instance, in California, the state determined that Google couldn't meet many of its requirements for functionality and security. Rather than address deficiencies in their product by developing a more robust set of productivity tools, Google cried foul instead of addressing these basic needs," Rizzo said.

"Constraints such as inadequate product support, failure to provide a roadmap, poor interoperability with other line of business applications and limited functionality are all reasons why public sector organizations such the state of Minnesota and New York City have said 'no thanks' to what Google is offering," he added.

As matter of policy, GSA was circumspect in explaining its decision.

"The government cannot disclose details of competitive proposals or the pre-decisional information used in the Best Value determination," GSA spokesperson Steve Hoffman told the E-Commerce Times.

"However, Unisys provided the Best Value solution for the GSA objectives as stated in the request for quotation," he added.

Those objectives: 1) modernization of the email system; 2) provision of an effective collaborative working environment; 3) reduction of the government's in-house system maintenance burden by providing related business, technical and management functions; and 4) application of appropriate security and privacy safeguards.


Google's Partnership Strategy

GSA awarded the contract to Unisys under its Alliant government-wide acquisition contract. The Alliant program was designed to facilitate IT procurement with the creation of a roster of qualified vendors who are basically approved to later compete for federal contracts. The mechanism saves individual federal agencies from setting up their own qualification procedures.

GSA approved 59 vendors for email services, including heavyweights such as Microsoft, Unisys, Verizon and AT&T (NYSE: T). However, Google was not among them, and as a result had to partner with an Alliant contractor to qualify for the work.

"Google's federal enterprise often works with partners, including Unisys, to deliver our technology," David Mihalchik, business development executive at Google, told the E-Commerce Times.

"Google has been working its way into the federal space for a while, and this partnership is actually the primary means for many companies to compete these days," explained Deniece Peterson, industry analyst with INPUT.

"Because the trend is now to consolidate smaller contracts into bigger contracts with broader scope, as well as for agencies to create their own vehicles, companies that don't win a spot on the original contract sometimes only have access to a particular agency by partnering with a company on the vehicle," she told the E-Commerce Times.

"Since Google doesn't yet have the federal presence of Unisys, it makes sense for them to partner with a recognized Alliant entity in order to gain entry. This partnership seems to be the most viable way for Google to make inroads into the federal space right now," added Peterson.

"This is a real beachhead for Google, but I couldn't say why they prevailed over Microsoft," commented Shawn McCarthy, director of research at IDC Government Insights.

"Every contract is different. It could have been a price thing but I'm not privy to that either," he told the E-Commerce Times.

"Microsoft offers some pretty robust programs and maybe there was a trade-off in price in opting for something less robust for a lower cost. However, Google has been working to make its cloud offerings pretty robust too," McCarthy observed.

"I would advise GSA to be cautious on this installation and look at Google's email contract with the city of Los Angeles because of some of the early implementation issues that came up there," McCarthy added.

Google's Los Angeles project has both positive and negative aspects, McCarthy noted in a blog post. The benefit is a potential $13 million in savings over five years. The negative includes some initial problems with security and archiving functions.

There will definitely be an impact on cloud computing as a result of the contract, owing to GSA's high visibility.

"I wouldn't say this shows a federal commitment to the cloud, but it shows a commitment to explore the cloud," McCarthy said. "You need a few powerful case studies for demonstration -- but if this works at GSA, it will show it can work elsewhere."

The GSA contract was announced December 1, just about a month after Google took the U.S. Interior Department to court for its failure to fully consider its technology when the department awarded an email services contract to Microsoft.

Enhanced by Zemanta

November 11, 2010

Validating Windows With WGA Behind The Proxy

By The Computer Doctor

Windows Genuine AdvantageImage via WikipediaSo it's behind the proxy time again people and the Doctor has found the key. I'm working with a virtual XP machine and needed to update to SP3 and everyone knows that WGA is the intrusive plague that Microsoft adds to try and ruin the pirates secret sauce.

What does that have to do with the Doctor since he would never ever ever ever ever ever (continue to add ever until it sounds remotely believable) condone piracy? Well my legitimate copy is behind a proxy server.

Problem: Said proxy server does not allow WGA to authenticate to it's home server. WGA also does not allow any settings to add proxy authentication.

Solution: Follow the yellow brick road... which isn't actually yellow... or made of bricks... or even remotely resembles a road.

Prepping Your Box

Step 1: Reboot troubled machine.

Step 2: Hit cancel on the WGA installation box when it pops up.

WGA Manual ActiveX Installation

Step 3: Click the Start button, then Click Run

Step 4: Type: iexplore http://go.microsoft.com/fwlink/?LinkID=39204 then Click OK
You will be prompted to download “LegitCheckControl.cab”

Step 5: Choose Open

Once this completes, a window will open showing two files. “LegitCheckControl.dll” and “LegitCheckControl.inf” Leave this window open for now.

Step 6: Click the Start button, then Click Run

Step 7: Type: system32, then Click OK

(If you are running Windows XP, you may need to click Show Files to allow access to this system directory.)

Step 8: Drag the “LegitCheckControl.dll” file from the window that was open into the “system32” directory folder. If you are prompted to overwrite a file, choose Yes, to overwrite any existing file. (If you are running Vista, you may be prompted to provide administrator permission to complete the action. If so, Press Continue, and allow it.)

Step 9: Click the Start button, then Click Run

Step 10: Type “regsvr32 LegitCheckControl.dll”, and then click ‘OK’.

You should see a dialog saying “DllRegisterServer in LegitCheckControl.dll succeeded.”

Step 11: restart the computer

Step 12: Cancel the WGA once again

Step 13: Go to the following website http://www.microsoft.com/genuine

Step 14: Locate the “Validate Windows” button. Double click on the button and follow the guidance.

Final WGA Installation

Step 15: Reboot the computer once again

Step 16: Do not cancel the WGA installation, but go ahead and run it (continue or next)


Yay! We have conquered the Microsoft insanity machine once again... and did not use one hack or crack.
Enhanced by Zemanta

September 27, 2010

Stuxnet, Is Israel To Blame?

Editorial By The Computer Doctor

In this Bloomberg video showcasing the Stuxnet Malware I find a few statements to be very hilarious even though the gravity of the situation calls for less levity than I am able to muster.

In this video, the security expert (male talking hair doo) tries to portray a picture that some government, probably Israel and probably not the U.S., has released the Stuxnet Malware program to target a Nuclear target in Iran.

Please see my editorial after the video...


1:10 "... using stolen certificates..."
Certificates was supposed to be one of the few ways of stopping hackers from gaining access to networks.

1:43 "what are the chances that the U.S. created it?"
Nice softball toss to a former government security adviser.

2:00 "in my judgment it's a very remote possibility"
In The Computer Doctors judgment this is a very real possibility. On July 8th the U.S. announced the “Perfect Citizen” program to help defend industrial networks. Anna Chapman deported to Russia for a spy-swap, from which we got a bunch of ugly fat guys back. With this "Perfect Citizen" program enabled to be some super secret program that will protect important industrial targets from programs just like Stuxnet. How convenient. On the other hand... any program that claims to protect Microsoft Windows is speculative at best.

2:31 "Is Iran really running it's nuclear power, it's nuclear plant on Windows software?"
It's blatantly obvious to female talking hair doo that this is an incredulously bad idea. I agree news chick. Most U.S. military installations only use Windows in a sandbox inside Linux.

2:53 "... it also seems an increasing concern because I don't know... I've used Windows and I know other people have and it's not stable even without a virus sometimes."
You're exactly correct sweetie. Why would you leave the operation of any important industrial process to the fragile stability of Microsoft Windows? Where is the cry for a better solution?

3:07 "Well... (insert crickets chirping) that is the nature of the modern economy and our technology. We rely heavily on these IT systems"
That's F'N Wonderful You Microsoft Fan-Boy, Talking Head, Moronic, Idiot. "well I guess Microsoft is the only thing that separates us from modern man from the cave man" "I guess we'll just bend over and kiss our technological butts goodbye now" This reminds me of the end of the Wizard of Oz where the Giant Head tells Dorthy not to pay any attention to the little man behind the curtain.

3:24 "that's why it's so important to stay up to date with your software patches that come along"
Hooray for Microsoft. Their patches always fix the problems... unless they totally miss the problem and the zero day, and could cause more problems than they fix. Although I agree that installing patches is vitally important, if Microsoft patches fixed their software we wouldn't need antivirus software, antispyware, Intrusion Prevention Systems, Firewalls, Proxies, VPN's, Certificates, et al ad infinitum.


People, do not rely on our government or any other government to have it's citizens best interest at heart. If you don't think that the U.S. in conjunction with Israel is not taking a gigantic gamble with the technological backbone of the world you are mistaken. On the other hand it is too late for Joe Six-Pack to do anything. We have voted in these out of control governments for over four generations now. How else do we expect them to act?
Enhanced by Zemanta

September 23, 2010

Microsoft Missed 2009 Published Article on Stuxnet-Type Attack

by Paul Roberts

A security flaw affecting Microsoft's Windows operating system that was exploited by the Stuxnet worm was publicly disclosed more than a year before the worm appeared, according to a researcher at Symantec Corp.

On September 17, Symantec researcher Liam O Murchu noted on that company's Connect blog that a security publication in April, 2009 had described the same flaw in the Windows Print Spooler Service function that Stuxnet used. Microsoft disclosed and patched the hole in its September security update on September 14, saying it learned of the vulnerability from researchers at Kaspersky Lab.

O Murchu was one of a handful of security researchers who discovered the Print Spooler Service hole as part of a forensic analysis of Stuxnet. The vulnerability, which was believed at the time to be previously undisclosed, affects most versions of Windows, could allow remote code to be run on vulnerable systems. Microsoft issued a security update, MS10-061, closing the hole and commending researchers at Kaspersky Lab and Symantec for relaying information about the vulnerability.

However, it now appears that information about the flaw was in the public domain for more than a year before Stuxnet first appeared, buried in the pages of Hakin9, a respected bimonthly magazine published out of Warsaw, Poland. An article by security researcher Carsten Köhler describes how shared network printer functionality on Windows can be used to elevate the local user's privileges or to gain command line access to network print servers. The article details both privilege escalation attacks and attack code for carrying out remote code excecution on a vulnerable Windows system.

O Morchu said that Microsoft has confirmed that the vulnerability described by Carsten Köhler is the same as the hole that was patched by MS10-061. Microsoft did not immediately respond to requests for comment, but a company spokesman also acknowledged, in a published report, that details of the hole were discussed in a security publication in April, 2009, but said that the company was not made aware of the issue at the time.

The Print Spooler Service hole was just one of four Windows security flaws that were believed to be unknown at the time Stuxnet was identified in the wild. Three other flaws have yet to be patched by Microsoft, which promises fixes in the coming months.

The sophistication of the worm and its ability to compromise industrial control systems by Siemens Inc. has led to speculation that Stuxnet was the work of state-sponsored hackers and may have had a specific target in mind. In recent days, attention has turned to Iran and the country's controversial Bushehr nuclear reactor. Iran had the highest rate of Stuxnet infections in the world, and some speculate that the worm started as a targeted attack against Bushehr or related facilities, but then jumped the fence to India and other countries.

Attention now shifts to the researcher in question, Carsten Köhler, who is described as a former Ernst & Young employee who now "works as an information systems security expert for a European institution." Researchers typically relay their findings to Microsoft's Security Response Center in advance of, or at the time they decide to go public. After a dust up with Google, the company recently revised its policy of "responsible disclosure" to advocate "coordinated vulnerability disclosure," encouraging researchers to give the company an opportunity to patch security holes before details of them are made public.
Enhanced by Zemanta

September 22, 2010

Is Stuxnet the 'best' malware ever?

'Groundbreaking' worm points to a state-backed effort, say experts

By Gregg Keizer

Computerworld - The Stuxnet worm is a "groundbreaking" piece of malware so devious in its use of unpatched vulnerabilities, so sophisticated in its multipronged approach, that the security researchers who tore it apart believe it may be the work of state-backed professionals.

"It's amazing, really, the resources that went into this worm," said Liam O Murchu, manager of operations with Symantec's security response team.

"I'd call it groundbreaking," said Roel Schouwenberg, a senior antivirus researcher at Kaspersky Lab. In comparison, other notable attacks, like the one dubbed Aurora that hacked Google's network and those of dozens of other major companies, were child's play.

O Murchu and Schouwenberg should know: They work for the two security companies that discovered that Stuxnet exploited not just one zero-day Windows bug but four -- an unprecedented number for a single piece of malware.

Stuxnet, which was first reported in mid-June by VirusBlokAda, a little-known security firm based in Belarus, gained notoriety a month later when Microsoft confirmed that the worm was actively targeting Windows PCs that managed large-scale industrial-control systems in manufacturing and utility firms.

Those control systems are often referred to using the acronym SCADA, for "supervisory control and data acquisition." They run everything from power plants and factory machinery to oil pipelines and military installations.

At the time it was first publicly identified in June, researchers believed that Stuxnet -- whose roots were later traced as far back as June 2009 -- exploited just one unpatched, or "zero-day," vulnerability in Windows and spread through infected USB flash drives.

Iran was hardest hit by Stuxnet, according to Symantec researchers, who said in July that nearly 60% of all infected PCs were located in that country.

On Aug. 2, Microsoft issued an emergency update to patch the bug that Stuxnet was then known to exploit in Windows shortcuts.

But unbeknownst to Microsoft, Stuxnet could actually use four zero-day vulnerabilities to gain access to corporate networks. Once it had access to a network, it would seek out and infect the specific machines that managed SCADA systems controlled by software from German electronics giant Siemens.

With a sample of Stuxnet in hand, researchers at both Kaspersky and Symantec went to work, digging deep into its code to learn how it ticked.

The two companies independently found attack code that targeted three more unpatched Windows bugs.

"Within a week or week and a half [of news of Stuxnet], we discovered the print spooler bug," said Schouwenberg. "Then we found one of the EoP [elevation of privilege] bugs." Microsoft researchers discovered a second EoP flaw, Schouwenberg said.

Working independently, Symantec researchers found the print spooler bug and two EoP vulnerabilities in August.

Both firms reported their findings to Microsoft, which patched the print spooler vulnerability on Tuesday and said it would address the less-dangerous EoP bugs in a future security update.

"Using four zero-days, that's really, really crazy," said Symantec's O Murchu. "We've never seen that before."

Neither has Kaspersky, said Schouwenberg.

But the Stuxnet wonders didn't stop there. The worm also exploited a Windows bug patched in 2008 with Microsoft's MS08-067 update. That bug was the same vulnerability used to devastating effect by the notorious Conficker worm in late 2008 and early 2009 to infect millions of machines.

Once within a network -- initially delivered via an infected USB device -- Stuxnet used the EoP vulnerabilities to gain administrative access to other PCs, sought out systems running the WinCC and PCS 7 SCADA management programs, hijacked them by exploiting either the print spooler or MS08-067 bugs, then tried the default Siemens passwords to commandeer the SCADA software.

They could then reprogram the so-called PLC (programmable logic control) software to give machinery new instructions.

On top of all that, the attack code seemed legitimate because the people behind Stuxnet had stolen at least two signed digital certificates.

"The organization and sophistication to execute the entire package is extremely impressive," said Schouwenberg. "Whoever is behind this was on a mission to get into whatever company or companies they were targeting."

O Murchu seconded that. "There are so many different types of execution needs that it's clear this is a team of people with varied backgrounds, from the rootkit side to the database side to writing exploits," he said.

The malware, which weighed in a nearly half a megabyte -- an astounding size, said Schouwenberg -- was written in multiple languages, including C, C++ and other object-oriented languages, O Murchu added.

"And from the SCADA side of things, which is a very specialized area, they would have needed the actual physical hardware for testing, and [they would have had to] know how the specific factory floor works," said O Murchu.

"Someone had to sit down and say, 'I want to be able to control something on the factory floor, I want it to spread quietly, I need to have several zero-days,'" O Murchu continued. "And then pull together all these resources. It was a big, big project."

One way that the attackers minimized the risk of discovery was to put a counter in the infected USB that allowed it to spread to no more than three PCs. "They wanted to try to limit the spread of this threat so that it would stay within the targeted facility." O Murchu said.

And they were clever, said Schouwenberg.

Once inside a company, Stuxnet used the MS08-067 exploit only if it knew that the target was part of a SCADA network. "There's no logging in most SCADA networks, and they have limited security and very, very slow patch cycles," Schouwenberg explained, making the long-patched MS08-067 exploit perfect for the job.

Put all that together, and the picture is "scary," said O Murchu.

So scary, so thorough was the reconnaissance, so complex the job, so sneaky the attack, that both O Murchu or Schouwenberg believe it couldn't be the work of even an advanced cybercrime gang.

"I don't think it was a private group," said O Murchu. "They weren't just after information, so a competitor is out. They wanted to reprogram the PLCs and operate the machinery in a way unintended by the real operators. That points to something more than industrial espionage."

The necessary resources, and the money to finance the attack, puts it out the realm of a private hacking team, O Murchu said.

"This threat was specifically targeting Iran," he continued. "It's unique in that it was able to control machinery in the real world."

"All the different circumstances, from the multiple zero-days to stolen certificates to its distribution, the most plausible scenario is a nation-state-backed group," said Schouwenberg, who acknowledged that some people might think he was wearing a tin foil hat when he says such things. But the fact that Iran was the No. 1 target is telling.

"This sounds like something out of a movie," Schouwenberg said. "But I would argue it's plausible, suddenly plausible, that it was nation-state-backed."

"This was a very important project to whoever was behind it," said O Murchu. "But when an oil pipeline or a power plant is involved, the stakes are very high."

And although Siemens maintains that the 14 plants it found with infected SCADA systems were not affected or damaged by Stuxnet, O Murchu and Schouwenberg weren't so sure.

Experts have disagreed about when the Stuxnet attacks began -- Kaspersky believes it was as early as July 2009, while Symantec traced attacks back to January 2010 -- but they agree that the worm went undetected for months.

"We don't know if they succeeded or not, but I imagine that they got to the targets that they wanted," said O Murchu, citing the stealthy nature and sophistication of the worm.

"The command-and-control infrastructure of Stuxnet is very, very primitive, very basic," said Schouwenberg. "I think they were convinced that they would be able to do what they wanted before they were detected."

O Murchu will present a paper on Symantec's Stuxnet work at the Virus Bulletin security conference, which is slated to kick off Sept. 29 in Vancouver, British Columbia. Researchers from Microsoft and Kaspersky will present a separate paper at the same conference.
Enhanced by Zemanta

August 19, 2010

XP Mode Screen Resolution

The Windows 7 sticker is affixed to most PCs t...Image via WikipediaBy The Computer Doctor

One of the complaints that we get when using the Windows 7 XP mode is that the print is too small to read. There are two keys to changing the screen resolution for the XP mode to make it "bigger".

First you must break the integration from the Windows 7 machine.

  • Open Virtual PC in windowed mode (normal)
  • Click on tools
  • Disable integration feature
  • Now right click on the XP screen
  • Choose properties
  • Choose settings
  • Change color quality to 32 bit
  • Finally change the resolution to something smaller like 1024 X 768
Second you must change the relational size of the Windows 7 screen to something closer to what your wanted the XP mode to be. See illustrations for clarification.

In the first illustration we have a windows size of 2480 x 1530, so the XP mode will originally have a resolution of over 2000 x 1400 which will have tiny print. If you change the resolution down to 1024 x 768 the print will not become larger, but the viewing screen will become smaller and 800 x 600 will be even smaller yet.


In the second illustration we have changed the resolution to something slightly larger than 1024 x 768 (like 1152 x 864) and now the relational size is closer to the targets.


If the icons on the Windows 7 screen are too large now, you will need to go to the desktop personalize settings and change the desktop icons down to medium or small (150% or 100%)


Enhanced by Zemanta

Windows 7 XP Mode

Image representing Windows 7 as depicted in Cr...Image via CrunchBaseBy The Computer Doctor
Video By Jonathan Mann

So many of you are still bemoaning the shortcomings of Microsoft's project Longhorn which has spawned the Windows Vista and Windows 7 series of operating systems.

Despite the compatibility mode which is supposed to make older software run properly, many times we find erroneous errors popping up in our applications or that the applications will not run at all.

Well for once I applaud a Microsoft decision with reservation of course. If you own a legitimate copy of Windows 7 Professional, Enterprise or Ultimate you can get for no additional cost the Windows XP mode. This is a virtual machine of Windows XP running on Microsoft Virtual PC platform.

My reservation of course is that if you have Windows 7 Basic or Home premium or any copy of Windows Vista you are S.O.L.

My experience with XP mode is in helping a customer who couldn't run software for her class that was required for school. Her computer specs were a 2.8 Ghz processor with 8 Gb of RAM and a 250 GB hard drive running Windows 7 Professional. We tried running in compatibility mode, changing graphics modes, cleaning the registry, and re-installing multiple times. Why shouldn't a 6 year old program designed for Windows XP Professional work on this system? Because the Windows Kernel has more forks than a public school cafeteria! So now what was she to do? Search endless garage sales for a used computer with Windows XP on it?

The answer came from one of my oldest tricks from the Linux side. If you can't beat them then join them with a virtual machine running the OS that the software you need was designed for. Microsoft finally saw the light in making a real XP environment available for these circumstances.

See the following promotional video for more information and to see what this XP mode looks like.




Enhanced by Zemanta

August 18, 2010

Shuttleworth: Oracle's Java Lawsuit 'An Extremely Unsophisticated Move'

Image representing Oracle Corporation as depic...Image via CrunchBaseJava (programming language)Image via WikipediaBy

Sean Michael Kerner



Last week's move by Oracle to sue Google over Java use in the Android open source mobile operating system, may well end up having an impact that effects far more that just Android. And that has some key stakeholders in the open source community concerned.

Mark Shuttleworth, founder of Ubuntu Linux, is among those in the community who don't see a positive outcome from Oracle's lawsuit, which was based around claims of Linux-based Android wrongfully treading on Oracle's patented Java code and copyrights.

"It's an extremely unsophisticated move by someone at Oracle to launch a patent-based lawsuit, and it's clearly going to be a significant setback for their relationship with the broader open source community, which is a significant part of many of their products," Shuttleworth told InternetNews.com.

Ubuntu is no stranger to working with Sun Microsystems -- original owner of the patents in question -- prior to Sun's acquisition by Oracle. Back in 2006, Canonical, the lead commercial sponsor of Ubuntu, first gained certification for Ubuntu Linux on Sun hardware. The effort was further expanded in 2007 with Sun Java technologies made directly available to Ubuntu Linux users.

"This will complicate the relationships Oracle has with a very important audience, which is the broader open source community," Shuttleworth said. "It will significantly undermine their efforts to establish many of their major products like Java, Solaris and Oracle Unbreakable Linux, and in due course, I'll imagine that they'll quietly wish they hadn't taken this approach."

"I certainly respect their right to take whatever approach they want to take with what they consider to be their property, but I cannot see any way in which this ultimately ends in a constructive outcome for them," he added.

Shuttleworth, like many open source advocates, is critical of software patents in general, which he said aren't a winning strategy for major software vendors.

"Big, traditional software companies have been looking for ways of protecting their franchises and many have waved patents around as a way of entrenching their margins," Shuttleworth said. "But it isn't working out that way."

That open source community leaders like Shuttleworth have long argued against software patents isn't surprising, considering the fights that flare up frequently between the open source and proprietary worlds around intellectual property. For instance, there's the looming specter of Microsoft, which in 2007 claimed that Linux infringed on hundreds of patents, and which hasn't been afraid to use that position to encourage open source users to pay for licenses. Last year, Microsoft inked a number of Linux users to licensing agreements, and sued GPS vendor TomTom over open source patent issues -- a spat that ended in a settlement and another licensing deal for Microsoft.

Last week, Eben Moglen, director-counsel and chairman at the Software Freedom Law Center (SFLC), told attendees at the LinuxCon conference that he sees patent threats against open source companies on a regular basis, and that the patent crisis facing open source is not going away anytime soon.

But Shuttleworth's view is that eventually big software companies will wake up to the reality that patents actually don't help them.

"I think that large software companies are simply going to find that patents and patent-based thinking keeps them locked in the past," Shuttleworth said. "Fundamentally, the biggest software organizations are the biggest losers from software patents-based litigation."
Enhanced by Zemanta

August 16, 2010

Microsoft’s IE turns 15

Internet Explorer Mobile LogoImage via WikipediaBy Balasubramanyam Seshan

Software giant Microsoft’s internet explorer turned 15 years on Monday. The company recently said it would launch the internet explorer 9 public beta version on September 15, 2010.

Microsoft would launch the new version at a special event in San Francisco and confirmed the browser would only function with Windows Vista and Windows 7.

In July 2010, Internet Explorer has a combined market share of 60.74 percent and Firefox is at 22.91 percent, followed by Google's Chrome with 7.16 percent, Safari with 5.09 percent, and Opera with 2.45 percent, according to the latest data from Net Applications.

The software giant launched the first version of the browser internet explorer 1 on August 16, 1995. It was a revised version of Spyglass Mosaic, which Microsoft had licensed from Spyglass Inc. The first version came with Microsoft Plus! for Windows 95 and the original equipment manufacturer release of Windows 95.

Internet explorer 2 was released for Windows 95, Windows NT 3.5, and NT 4.0 on November 22, 1995 (following a 2.0 beta in October). Internet explorer 3 was released on August 13, 1996.

Microsoft internet explorer 4, released in September 1997, deepened the level of integration between the web browser and the underlying operating system. The traditional Windows Explorer was replaced by version 4, when installed.

Internet explorer 5 was launched on March 18, 1999. Also, with the release of internet explorer 5, Microsoft released the first version of XMLHttpRequest, giving birth to Ajax. Internet explorer 6 was released on August 27, 2001, a few months before Windows XP. Internet explorer 7 was released on October 18, 2006.

“The company's Windows 7 should benefit from the corporate PC refresh cycle, which is in its early stages and the release of Windows Service Pack 1 (SP1) in the first half of calendar year 2011. The much-awaited corporate PC refresh cycle is underway and should drive Windows 7 sales for at least the next year,” said David Hilal, an analyst at FBR Capital Markets.

Internet Explorer 8 "Final" was released on March 19, 2009. On March 5, 2008, the first public beta (Beta 1) was released to the general public. The second public beta (Beta 2) was released on August 27, 2008. Internet Explorer 8 (IE8) RC1 was released on January 26, 2009.
Enhanced by Zemanta

Has Dell Dropped Ubuntu Linux?

Dell LogoImage via WikipediaBy: David Murphy

Has Dell dropped Ubuntu Linux as an operating system selection for its panoply of PCs? Yes… and no. PC Pro is reporting that one can no longer pick up consumer PCs preloaded with the popular Linux distribution, but that's only if one's trying to order online.

PC Pro goes on to quote a company spokesperson: "We've recently made an effort to simplify our offerings online, by focusing on our most popular bundles and configuration options, based on customer feedback for reduced complexity and a simple, easy purchase experience. We're also making some changes to our Ubuntu pages, and as a result, they are currently available through our phone-based sales only."

However, the same spokesperson—in an interview with PC Pro—went on to suggest that a majority of Dell's sales go toward consumer PCs laden with Microsoft's Windows operating system. Ubuntu systems tend to shop out to, "advanced users and enthusiasts," a sentiment that's reflected in Dell's own on-side material about Linux.

On the company's "Windows or Ubuntu?" page, Dell states that the former is the better choice of an OS for those that are already familiar with Windows programs or, conversely, for those completely new to the world of computing in general. Ubuntu, on the other hand, should be reserved for those that, "do not plan to use Microsoft WINDOWS," or those who are, "interested in open source programming."

The caveat, however, is that this material—as well as the lack of online Ubuntu options—seems to be limited to the European Dell hub. The standard dell.com domain still features a "Top Ten" list of facts to know for consumers interested in an Ubuntu system, as well as purchasing links to both an Ubuntu-backed Dell Mini 10n notebook and a Dell Inspiron 15n notebook.

That said, Slashdot commenter "Nimey" points to a key visual indicator that Dell's Ubuntu support, in general, might be waning.

"They don't offer any with 10.04, and two of the four models they offer still have 9.04," Nimey writes. "Doesn't seem like they're too keen on it."

According to Canonical, Ubuntu's primary commercial sponsor, the Linux distribution is currently used by more than 12 million individuals. Data taken by the site Distrowatch—which has been tracking the popularity of hundreds of Linux distributions since its inception in 2001—ranks Ubuntu as the most popular distribution based on an analysis of hits to the site's official "Ubuntu" section.
Enhanced by Zemanta

May 26, 2010

The Windows era is over

By Joe Wilcox

About five years ago, when blogging as an analyst, I asserted that computing and informational relevance had started shifting from the Windows desktop to cloud services delivered anytime, anywhere and on anything. The day of Windows' reckoning is come: 2010 will mark dramatic shifts away from Microsoft's monopoly to something else. Change is inevitable, and like IBM in the 1980s, Microsoft can't hold back its destiny during this decade. The Windows era is over.

What's surprising: New competition encroaching on Microsoft's Windows territory. Mobile device-to-cloud competition's shifting relevance bears striking similarities to the move from mainframes to PCs, and it is a long, ongoing trend. Microsoft's newer problem is sudden and unexpected: Competing operating systems moving up from smartphones to PCs or PC-like devices. Apple's iPhone OS on iPad is one example. More startling: HP's acquisition of Palm and plans to release WebOS tablets this year; and Android's push upwards to Sony TVs.

Some readers of this post will balk at such assertion. Windows is a huge, profitable monopoly coming off version 7's successful launch. Windows & Windows Live accounted for 48 percent of the five Microsoft divisions' combined operating profit during fiscal 2010 third quarter -- that's without factoring in expenses or other charges.

Windows is a cash machine. But so was the IBM mainframe monopoly before the dawn of the PC era and for many years afterwards. The DOS/Windows PC didn't destroy IBM or its mainframe monopoly, but simply diminish its computing and informational relevance. Windows is on the same track. The mobile device-to-cloud applications stack will merely displace Windows' relevance. It's inevitable.

Before the PC, computers were large and expensive. Only large corporations really could afford them. The PC extended computational and informational utility to more people, and at much lower cost. Information could be accessed in many more places, too. IBM's mainframe monopoly made the company slow moving to adaptation, even when launching its own personal computer in 1981. The company's huge ecosystem and customer base made executives cautious, with many decisions made for fear of losing customers.

Nearly three decades later, Microsoft's situation is so similar to IBM at the height of its mainframe monopoly's dominance. Microsoft's main business is reselling to the same corporate customers running the company's software, much the same as IBM 30 years ago. Many Microsoft business strategies follow a similar track: Making concessions and avoiding risks to keep existing customers coming back for more.

Sudden Changes are Long Coming

Still, it might not be obvious to many people that the Windows cash machine could run out. That's because change can be dramatic and sudden, although the causes and progression tend to be long-time coming. The Berlin Wall fell suddenly in 1989, but not without Perestroika and a warming of the Cold War preceding it. Similarly, Windows' dominance will seemingly change suddenly and, I predict, during the first half of this decade. A new era dawns.

Microsoft has long known this day would come. It's why the company fought the browser wars with Netscape. During the US antitrust case, Microsoft repeatedly asserted it faced competition, not that the US Justice Department, suing state attorneys general or presiding judge believed it. The trial ignored how much Microsoft invested on sales, marketing and its huge channel of partners. The competition Microsoft feared has come, and there is some irony to it. Last week, Google announced the Chrome Web Store, which makes reality what Microsoft feared in the late 1990s: The browser as competing applications platform to Windows.

Microsoft lumbers along, avoiding risks, clinging to Office and Windows revenues. Meanwhile, companies without Microsoft's existing monopoly-bound customers drive change, and they are willing to take risks. The mobile-to-cloud service platform is to the PC what the PC was to the mainframe: It extends computational and informational utility to more people and places -- and for lower cost. The Windows era is giving way to the anytime, anywhere, on-anything era. The most dynamic innovations are occurring outside the Windows monopoly.

Perhaps it's no coincidence that 2005, the year Microsoft originally planned to release Windows XP's successor, marks the beginning of dramatic changes affecting the company today. This month, YouTube celebrated its fifth anniversary -- of posting the first video, anyway. The service opened to the public in late 2005. In August 2005, Google bought Android, while seemingly innocuous then it is hugely problematic for Microsoft today. In 2006, Facebook opened to the public and Twitter launched. In the vacuum left by Windows, innovators, well, innovated. Most of the popular transforming cloud services in use today didn't exist before 2006. Then there is iPhone (released in June 2007) and Apple's App Store (launched in July 2008). Google followed with Android and Chrome in autumn 2008.

The numbers show how dramatically computing and informational relevance is shifting to the mobile device-to-cloud app stack and how suddenly change can come:

  • Firefox launched in late 2004; according to Net Applications, its usage share was 24.59 percent in April.
  • Internet Explorer usage share dropped from around 95 percent six years ago to 59.95 percent in April, according to Net Applications.
  • Android and iPhone OS outsell Windows Mobile on smartphones; Windows Mobile was ranked fifth in Q1 by Gartner.
  • Google claims 100,000 new Android activations per day. Apple's iPhone run rate is close but just a little behind based on first-quarter phone sales.
  • App Store has more than 200,000 applications, and the Android Marketplace more than 50,000.
  • Facebook has close to 500 million subscribers, up from 30 million in July 2007.
  • Americans watched 31.2 billion videos in March, 42 percent of them at YouTube, according to ComScore.
  • Apple's market capitalization is $227.95 billion and Microsoft's $228.47 billion. Apple's market cap was $88.68 billion on Oct. 2, 2008 and Microsoft's was $228.35 billion on Sept. 29, 2008. Mmmm, do you see a difference?

Unsurprisingly, all this competition -- and innovation -- is beyond Windows, much as the PC ecosystem was to the IBM mainframe during the 1980s.

Loyal Partners Go Rogue

Microsoft has a much bigger problem. Competition from without is to be expected. Competition from once loyal partners is something else. Nokia and Intel are partnering on MeeGo, which the companies plan to bring to mobile devices. In March I declared the end to the Wintel (Windows-Intel) hegemony when asking: "Which is eviler? Apple, Facebook and Google?" -- all Microsoft competitors. Microsoft can no longer count on Intel's loyalty, which has been in doubt since Apple shipped the first Intel-based Macs in 2006.

But matters are worse. Compaq was Microsoft's most important partner. In the 1980s, Compaq popularized the IBM PC clone, which allowed Microsoft to broadly license DOS and later Windows. HP assumed the loyal partner role after acquiring Compaq, particularly for servers. Now, because of the Palm acquisition, HP is a turncoat.

Microsoft CEO Steve Ballmer should have listened to me. In December, I gave 10 reasons why Microsoft should buy Palm. Had he bought Palm, Microsoft's future phone strategy would be stronger and Windows wouldn't be weakened by a major partner adopting an alternative-OS strategy.

HP already has announced a WebOS-based tablet. HP's next, logical step is to release a laptop running WebOS. Losing HP is bad, but there may be more trouble coming. Sony is yet another traitor in the making. Last week, Sony announced plans to support Google TV by offering a television running Android. As part of a recent reorganization, Sony execs responsible for VAIO PCs are in charge of TVs. OS migration from Sony smartphone (the Xperia X10) or Google TV-based television to tablet or PC is logical next step. What about Dell, which already has adopted Android for smartphones? Windows is bloated and moribund compared to these lither mobile OSes pushing up into the PC market.

I'm making my proclamation today that the Windows era is over. But perhaps it's slightly premature. The defining moment, where people look back and say, "Ah, ha!", likely will be when Apple's market capitalization exceeds Microsoft's. As I write, $520 million separates the companies. How unbelievable is that?

Reblog this post [with Zemanta]

May 19, 2010

Trouble Updating Windows Vista

Image representing Windows Vista as depicted i...Image via CrunchBase

If you’re getting an error message with a code 0×80072F8F when you try to use the Windows Update site, check the date and time settings on the PC. If the computer’s date and time are too far off from the Windows Update servers, you may see errors. Microsoft has a full explanation online; the article also explains how certain system files may be causing the update error, and what to do about it.

If you find yourself regularly changing the system’s date and time in the Control Panel every time you start it up, the little CMOS battery on the computer’s motherboard may be dying. Your PC’s manual probably has specific instructions for replacing the battery or seek the help of a computer repair shop.

Reminder: Microsoft ended update support last month for Windows Vista systems that haven’t been updated with service packs. If you haven’t downloaded and installed any of the Vista service packs, you can get them online.

Reblog this post [with Zemanta]

May 17, 2010

Office 2010: Can it beat Google Docs at its own game?

By Christopher Dawson

Google vs Microsoft  --ChromeImage by michperu via Flickr


Although it was hard not to be enthusiastic about some of the Office and SharePoint features unveiled at Wednesday’s Office 2010 launch, I had to wonder how much of what was unveiled was just a pretty, expensive face on Google Docs. I also had to wonder if that pretty face was enough to beat Google Docs at its own collaborative game.

As Janice Kapner, Microsoft’s Senior Director of Information Worker Product Management, noted when we spoke after the launch, the word “collaboration” means different things to different people. From my perspective, Google had the market cornered on collaboration for quite a while, though, allowing for the simultaneous creation of content in their Docs products. For the low, low price of $50/user/year (or for free if you were an educator or were willing to sacrifice some features), Google Apps subscribers could share and create everything from websites to presentations to spreadsheets together, regardless of their physical location.

Sure, the documents might not be the most beautiful creations unveiled to mankind, but they could genuinely be team efforts without complicated commenting and versioning, emailing, and reconciling.

Other people, as Ms. Kapner noted, viewed collaboration in the context of social and communication mechanisms. While Google wasn’t Facebook, it certainly bundled enough powerful, fast communication tools with Apps that businesses could tap this aspect of collaboration quite handily as well.

Microsoft had introduced SharePoint a while back, improving document management and sharing capabilities within Microsoft-centric organizations, but the real time capabilities that Google could offer just weren’t there. Where Apps lived and breathed the connected Web for organizations that adopted it, Office and its approach to collaboration (however you want to define it) among information workers felt decidedly pre-Facebook.

That feeling changed, however, on Wednesday. Office 2010 combined with SharePoint 2010 is such a polished, powerful platform that it feels like it’s leapt ahead of Google Docs in collaborative potential. But was that just marketing spin and a great presentation at NBC Studios? After all, when the presenters noted that they could finally simultaneously edit documents using the features of SharePoint, I couldn’t help but wonder just how long that had been possible in Google Docs. Later, I tweeted

Speaker from KPN is talking about the idea of workspace so workers to [sic] do their jobs anytime anywhere. Sounds like Apps :)

As the presenters demoed Outlook 2010, it was like deja vu all over again:

Outlook now supports conversations. I think Gmail has been doing that for a while. Like since its inception.

So was Microsoft introducing anything particularly new in the 2010 products or were they just putting a better UI on old Google features? As it turns out, I think it was a bit of both.

To some extent, Office 2010 takes the best collaborative features of Google Docs, combines them with an improved Office look and feel, and even manages to render them on the Web and Windows Mobile smartphones with incredible fidelity. Not new, but pretty and highly usable.

On the other hand, the social layer introduced by SharePoint out of the box gives organizations an immediate in-house social network that can rival anything Facebook has to offer. The Office suite itself provides everything from extraordinary data mining and business intelligence capabilities natively within Excel to social networking and noise reduction features in Outlook that don’t exist anywhere else in terms of productivity software (in the cloud or on the desktop).

The trouble comes when trying to really assess the value proposition in the Microsoft vs. Google war. Google gives you everything it has with frequent updates to features and service for $50/user/year. SharePoint Online (Microsoft’s hosted version of SharePoint and the only product for which enterprise pricing is published) starts at $63/user/year and this doesn’t even include the initial cost of Office licensing. Microsoft cited Forrester research suggesting extraordinary returns on investment due to increased productivity from Office/SharePoint 2010 adopters, but the initial costs (particularly if organizations look to deploy SharePoint internally instead of using Microsoft’s hosted service) are tough to ignore.

In the end, as always, organizations must fully understand their needs if they want to invest in the right platform. However, while I think that ZDNet’s Zack Whittaker is wrong when he says that Google Docs no longer stands a chance, Google is suddenly the one playing catchup to some powerful and compelling features in Microsoft’s 2010 offerings.

So, um, Google…Got any plans for that Apps-integrated social network I was talking about?




Reblog this post [with Zemanta]

Hex Converter

Hex To ASCII Converter

Hex:
Ascii:

 

Integer to Byte converter


This is a tool to practice converting between decimal and binary representations. After you have practiced for a while and feel that you know how to do the conversions, take the quiz.
Decimal number to convert:
Binary representation:


Binary number to convert:
Decimal representation: