Showing posts with label Bug. Show all posts
Showing posts with label Bug. Show all posts

Sunday, September 30, 2007

Apple starts disabling hacked iPhones

After the release of the iPhone, there was some consternation over the non-release of the iPhone outside the United States; it was speculated that hacked copies of the iPhone would be available outside the United States and that this was a natural occurrence. Apple would not be able to do anything about this. Well, looks like the design of Apple's engineers had actually planned for this. So, the latest firmware update to the iPhone has actually disabled the iPhone, apparently permanently for those people who have hacked iPhones. But is this the last statement on this matter ?


The iPhone 1.1.1 update, released Thursday, breaks phones that have been hacked so that they work with providers other than AT&T Inc., the only U.S. provider Apple has allowed to carry its mobile phones. Apple has said that it would fight any attempts to unlock the iPhone. Earlier this week the company released a warning that unlocked iPhones "will likely result in the modified iPhone becoming permanently inoperable when a future Apple-supplied iPhone software update is installed."
The new software is Apple's biggest iPhone update to date, and it fixes a number of security flaws in the mobile phone's browser, mail client and Bluetooth networking server. The majority of the flaws do not appear to be critical, but the update fixes a larger number of bugs than the first iPhone update, released July 31.
Mobile phone users typically cannot update their own software, but Apple introduced this capability in the iPhone, which uses the update mechanism in the phone's iTunes music player. iTunes checks for these updates once per week, so it may take up to seven days for all iPhone users to see these updates. Apple advises users to install the update immediately.


Now, while this patch fixes bugs in the iPhone and should be installed by users, it is unlikely that the hacker community will accept this matter as a fait accompli. It's a gauntlet that Apple has thrown to the hacker community, and with the hacks spawning a new business, there is a major commercial angle to it. Thus, it is likely that hackers will now start to put their creative thoughts on how to defeat this latest attempt by Apple.

Sunday, September 2, 2007

Microsoft starts planning for the release of Vista SP1

It's the inevitable. After the release of a new application or Operating system by Microsoft, come the regular questions about the Service Pack. There are a number of people who actually believe that the software becomes stable only when the first Service Pack is released; so it is important for Microsoft to release information about the Service Pack. One can be sure that information will be released in bits and pieces, but it seems clear that the Service Pack will be available for restricted beta testing in September (this month) and then finally out sometime early 2008. Given the complexity of this new system, Microsoft will need a lot of time to make sure that the Service Pack can get as wide a testing as possible; after all, nothing hurts the company as much as the news about bad service packs. For example, when I installed Service Pack2 for Win XP, one of my hard disks became unusable and had to re-formatted losing all the data on the system. This may be an isolated case, but if it happens enough times, it makes for a lot of noise on tech forums and among Microsoft baiters.


After lots of whispers, rumours from beta testers and confusing messages from Microsoft executives, Microsoft has finally revealed the full details about Windows Vista's first service pack. The company confirmed a three-month launch window, with a beta testers getting their hands on the update during September.
Microsoft is saying only "a few weeks" and "September", which are, after all, one and the same, for the beta. As for the final release, the software maker finally acknowledged rumours circulating June that the service pack be fully available until the first quarter of 2008.


As time goes by, doubtless we will hear more about this service pack.

Sunday, August 5, 2007

Hacking the iPhone and ease of hacking the Mac

For a long time, Apple and Mac users have disdained the PC and Windows as very bad in security, and instead tom-tommed the relative lower number of hacks on the Mac. Microsoft has always been on the defensive in terms of security, and the large number of cracks and holes available on the OS and apps have always led them to be worried. There have been people who have been saying that Mac has not shown so many cracks just because it has a 5% market share, and people have not found it worth their while to try and break through the Mac OS security:


Though there has yet to be any documented criminal hijacking of the iPhone outside of a lab, Miller says his research shows the relative ease of hacking smart phones, as well as Macs in general. He spoke with Forbes.com about the iPhone's vulnerabilities, Apple's short-lived patch and the company's undeserved reputation for building secure computers.
There are two issues with the iPhone. First, the specific weakness that we found in its Web browser. But there's a more fundamental problem. The iPhone runs everything as "root." In other words, there are no privileges for different users. They should have built layers of security. Instead, if you can find a single crack, any user has the entire phone at their disposal. Last week they basically patched a hole in the wall. But inside, it's still pudding.
Bad guys aren't yet targeting Macs because they want to maximize their time. That means writing viruses that target 95% of computers rather than 5%. Apple currently has around 3.5% of the market, but its market share is growing by around 35% a year. As Mac's numbers creep up to 30% or 40%, cyber-criminals will start asking whether it's better to spend two weeks writing a bug for Windows or just a couple days to write one for Macs.


Almost nothing in this interview is complementary to Mac, but one tends to agree with what he says. Windows is the dominant OS, and most hackers are anyhow biased against Microsoft, in addition people are ready to believe that Windows is inherently insecure, and hence most hackers target Microsoft. Now that the iPhone is a well advertised target, one can expect many more Black Hat hackers to target the iPhone for benefit, and for Apple to be on the backfoot.

Thursday, August 2, 2007

An apple patch that you might want to take

Apple has recently released a patch, 2007-007 update for MacOS X, 10.3 and 10.4. This is a mega patch, fixing over 45 defects, out of which 17 are serious security issues where hackers could compromise systems and are classified as equivalent to 'critical'. Since Apple also uses a number of open-source projects, approx 75% of the patches were in the open-source software that Apple blends in with its own code.
These open-source bug fixed include fixes in the following apps: Kerberos, PHP, Samba, SquirrelMail and Tomcat. Components of MacOS X patched as part of this release were CFNetwork, the Mac OS X library of network protocols; CoreAudio, the API (application programming interface) that handles sound on Macs; the zgrep file compression utility; iChat; and WebCore, the part of the WebKit application framework that handles HTML rendering. Fixes also included fixes in Safari (including a fix for a problem on Safari on iPhone)
One normally hears primarily of Microsoft releasing patches at regular intervals to fix security holes and other bugs, so it would be interesting to evaluate whether this gets an negative publicity for Apple. Microsoft would like to advertise this as claiming that OS X has also a number of flaws, and equally, open source technology has a number of security holes for which there are no clear owners, and the total cost of ownership of open source systems is high, as per the Microsoft argument.

Laser printers being a health risk

It was bound to happen. Almost everything that we come into contact with over a period of time will be classified as a health risk. So, the latest article to join the category of being classified as a health risk are some laser printers, model numbers unspecified. Why are they health risks ? Well, a report from the Queensland Institute of Technology in Australia has claimed that out of 62 printers tested, 17 laser printers generated enough spray particles that were so easily inhaled that they could be classified as a health risk:


A report from the Australia's Queensland University of Technology says the particles emitted from some laser printers were as harmful as cigarette smoking. They tested 62 printers. Seventeen printers generated enough fine particles that were easily inhaled and gave you some face time with a "significant health threat," according to Physics professor Lidia Morawska. Swell.
While the study named names -- Canon, HP Color Laserjet, Ricoh and Toshiba -- they unfortunately didn't say anything more about the brands other than "popular models in the U. S. and Australia sold internationally." Hey, come on kids, we need more.


So now, when evaluating a model of a laser printer, in addition to evaluating the dpi, the number of pages printer per minute, cost per page, etc, you will also need to evaluate the danger quotient. And soon, you might find a person filing a class action lawsuit against his company and against printer manufacturers for an unsafe working environment.

Saturday, July 21, 2007

Duke and iPhone resolve problems

Earlier this week, there was a major issue over the iPhone apparently causing a Denial of Service attacks on the Duke wireless network, and the issue quickly blew up. Apple would have been in the forefront of attempts to make sure that this issue gets resolved due to the potential bad publicity for the iPhone. Well, it's now blown over, and Apple gets a clean chit:


Initial reports of the problem placed the blame for the outages squarely on Apple's iPhones, which flooded the Cisco WAPs (Wireless Access Points) with thousands of address requests per second. However, in a statement released this afternoon, Cisco Systems admitted that the problem was caused by a Cisco glitch.
The problem could be particular to Duke. Other large universities—specifically the University of Wisconsin at Madison—have not experienced problems with its registered iPhones and Cisco-based Wi-Fi network, according to Dave Schroeder, an administrator in UW's Division of Information Technology. "We have seen upwards of 120 unique iPhones since June 30 on our campus-wide wireless infrastructure, which also uses Cisco 802.11b/g access points. To date, we have not encountered or detected any undesirable behavior from iPhones," said Schroeder. "As I have also not heard reports of errant 802.11 iPhone behavior from any other institution or site, it appears that the issue at Duke may be unique. There may be something unique to Duke's particular wireless installation configuration that the iPhone may be exposing," he added.


Of course, that is something that needs to be investigated further. There is something in the Duke network that was causing the problems to happen, and there is no certainty that such issues will not happen again.
There is an additional comment in the bottom of the article quoted above that could also cause certain problems

"My suspicion is that Duke's network requires Cisco's (Lightweight Extensible Authentication Protocol) security encryption and the iPhone doesn't have that incorporated into it. That could be a source of the problem," said Van Baker, a research vice president at Gartner in San Jose, Calif.
"Cisco's LEAP is an enterprise deployment not seen in the consumer market at all. The iPhone doesn't have a lot of the features you'd normally expect to see in an enterprise class phone," he added.


This was certainly a negative comment by an analyst, and this is something that Apple needs to quickly address. Apple would want this phone to be adapted in the enterprise segment as well, those segments carry a number of phones with them.

Wednesday, July 18, 2007

iPhone causing denial of service attacks

Could it be too good to be true ? The iPhone is one of the tech marvels that happens once in a few years, and it has shown itself to be a revolution in the designing of phones, although the restriction on carriers and the relatively slow network are acting as hobble-stones.
Well, in the latest news on this area, the iPhones have been caught to be behaving very strangely on the Duke University campus, with around 150 iPhones (a fraction of what would be available once the students come back from holiday) bring several wireless access points to a halt, in an imitation of a Denial of Service attack, probably the last thing that Apple wants to hear at this point:


The iPhone is flooding wireless access points at the US Duke University with MAC address requests, resulting in a denial of service-like attack that is taking out 20 to 30 access points for 10 to 15 minutes at a time – weird! The iPhones are asking for an address that isn’t on Duke University’s network, and when the iPhones don’t get a response, they keep on sending out requests, flooding the available bandwidth.
Help has been sought from Cisco, the maker of the school’s networking equipment, and technical support has been sought from Apple, although there is only speculation online as to precisely what might have caused the problem – Apple isn’t saying anything yet as it no doubt investigates the problem. When the fix inevitably comes, either the iPhone, Cisco’s equipment, or both, will simply be patched with a software update to resolve the problem.


So even though it will probably be a short-lived problem, the fact that such a problem occurred reflects badly on Apple's quality regime. And it is good that it happened at a time when the university was thinly populated, otherwise at peak times and if happening in a number of places at the same time, the problem would have been magnified many times and probably resulted in a loss of face for Apple.

Security company warns against using iPhone's web dialer

The iPhone has a great new feature, and since it is a combination phone and browser, the feature can work really well for most users. But like any other new great feature, there is tremendous capability for misuse, and seeing the ease of misuse, security companies are warning users against using this feature, or to be very careful when using this feature.
What is the feature? Well, the iPhone uses Safari as a web browser. Now, if the web site displays a phone number, all that the user has to do is to click on the phone number in the browser, and the number will get dialed. This is a great feature, but so is the scope for misuse. Imagine the phone in the hand of a neophyte who is viewing some 'interesting' site on the browser, and there is a number displayed along with a catchy slogan. Press the number, and if the number is an international number, or a fraud number, the calls could become very expensive very soon.


Attackers could exploit a bug in this feature to trick a victim into making phone calls to expensive "900" numbers or even keep track of phone calls made by the victim over the Web, said Billy Hoffman, lead researcher with SPI Labs. The iPhone could even be stopped from dialing out, or set to dial out endlessly, he said.
In order for the attack to work, the bad guys would have to either trick iPhone users into visiting a malicious Web site or make a legitimate Web site send untrustworthy information to the iPhone using what's known as a cross-site scripting attack. "Any time someone could control the content that's getting sent to the iPhone [the possibility of an attack] exists," Hoffman said.


It is not as difficult as it looks. It is actually as easy as letting the iPhone be used by a child or by somebody else who is not so experienced, and it is not difficult to create a site that will look attractive and feature this kind of mischief. But as of now there is no way to prevent it, so being careful is the only good way of dealing with this problem.

Saturday, July 7, 2007

Selling security exploits

The biggest fear of software makers, application system makers and the like (Microsoft, Adobe, Apple, and numerous other big entities) is coming true. Ever since software holes and bugs started to come into existence, there was always the pressure between the software company trying to release a patch, and hackers trying to exploit this defect. In the past, software makers would try to apply pressure on the defect finders to keep it quiet till the patch is released. If the patch was found by a big company, they would normally respond to pressure from the likes of Microsoft and not release into the public domain.
However, this was not happening more and more, with the security companies releasing their findings independently of the software makers. Some of them would even sell these to people who would exploit them for nefarious purposes. As an example, review the number of botnets that exist in the internet today, with millions of computers being hacked into and controlled. The situation was literally demanding a market-place for such bugs:


An eBay-like auction site that sells vulnerabilities will improve security by ensuring researchers get a fair price for their work, its founders say. "The existing business model to reward researchers is a failure," said Herman Zampariolo, chief executive of WSLabi, and the man behind the WabiSabiLabi auction site. A tiny minority of vulnerabilities currently get patched, he said, because IT experts aren't paid for their work in uncovering them.
"As long as vulnerabilities are bought and sold privately, the value can't be the right one," Zampariolo said. "Our intention is that the marketplace facility on WSLabi will enable security researchers to get a fair price for their findings and ensure that they will no longer be forced to give them away for free or sell them to cybercriminals," he added.
So far, no bids have been posted, possibly because of delays in identifying the buyers, each of whom must use snail mail or fax to deliver proof of their identity and their bank account--electronic currencies are not accepted on the site. Around 20 buyers have been registered so far, as well as 30 sellers, who have provided another batch of flaws that should be on the site next week.


In this case, the intention may be genuine; however, where is the control mechanism to ensure that these sales are happening to the right people. If we are just dependent on the operators of the exchange, then there is no guarantee. Later, if the number of such buyers increases, it would be very easy for the cyber-criminals to pretend to be a genuine buyer and get access to top-notch holes on a very quick basis.

Friday, June 15, 2007

Safari on Windows already with 1 million downloads

When Steve Jobs released the beta of its web browser, Safari on Windows at a worldwide developer's conference, he may not have expected this kind of response. This release was also broadcast as the release of the fastest surfing software for Windows.
Even though the browser got hit by security problems and Apple has already released 3 patches to fix major security issues (and Steve Jobs would certainly not have been happy at such adverse publicity about such major problems), it was successful in another front. Within 48 hours of release, Safari got more than 1 million downloads.
Whether this spurt will continue or not is unknown, although Apple would be hoping that it become as popular in the browser application area as iTunes is in the cross-platform music buying and playing software. Safari is currently trailing IE and Firefox in the browser wars, with only 5% (native Mac users) as opposed to IE's 80% and Firefox's 15% market share. If Apple wants to come out with some strength in the browser wars, it will need to push the browser much more.
It will have to come out with more plugin support, not be too different in terms of interface from IE and Firefox, and be very easy to use.

Thursday, June 14, 2007

Anti-botnet campaign by FBI

Botnets are a major nuisance on the internet. These are a large number of computers having inadequate protection, that have been compromised and are under the control of people wanting to use these large number of computers (in many cases, in the thousands) for a number of activities such as launching distributed denial of service attacks where these computers together attach a web site or network, used as relays for mass distribution of spam and malware, used for phishing, click fraud, and a variety of other attacks.
How does a computer get compromised? The computer may be running a version of Windows that has a hole, and this hole has been exploited to gain control of the computer. In addition, the computer may not be having an active firewall and virus protection. Botnets are increasingly being found on the internet and cause a high degree of costs by causing down-time, by actual losses due to phishing and click fraud, etc. And the biggest problem is that users do not even know that their computer has been compromised; they find that their computer has gone slower, or becomes active suddenly, but there are no easy ways of knowing that their computer has been used by a crime or is compromised. Typically, when a computer has been infected and is a part of a botnet, it can be used to attack hundreds of other computers.
Given this situation, and the dangers posed by the menace of botnets, the FBI has been investigating and found more than 1 million botnet victims so far. Along with the Justice Department, the FBI has been running a program called Operation Bot Roast to disrupt botnets. They have caught people; however, as long as security patches determine the safety of a computer, there will be infected and compromised computers in the wild. Refer this article:


The FBI is working with industry partners, including the Computer Emergency Response Team Coordination Center at Carnegie Mellon University, to notify the victim owners of the computers. Microsoft and the Botnet Task Force have also helped out the FBI. Through this process the FBI may uncover additional incidents in which botnets have been used to facilitate other criminal activity, the FBI said in a statement.
Bots are widely recognized as one of the top scourges of the industry. Gartner predicts that by year-end 75 percent of enterprises "will be infected with undetected, financially motivated, targeted malware that evaded traditional perimeter and host defenses," and early reports from beta customers of a yet to be released product from Mi5 show how nefarious these infections can be. Mi5 says it installed a Web security beta product at an organization with 12,000 nodes and in one month detected 22 active bots, 123 inactive bots and was watching another 313 suspected bots. That may not sound like a lot, but those bots were responsible for 136 million bot-related incidents, such as scanning for other hosts inside the firewall.


It can get pretty hairy for people. Suppose the computer of a unsuspecting user is used to break into a protected military installation or a bank, or used to break down a major network, the first path for investigators will be to find the computers that were used, and in the case of a compromised computer, the owner will have no idea.
This will also start to increase pressure on software companies to make their software more secure from the ground up, such that they do not land in the situation where the security of the system is dependent on patches.

Saturday, May 26, 2007

Microsoft delaying release of Halo 2 due to nudity scenes

Halo was one of the top selling games on the original Xbox, and helped increase the popularity of the Xbox. The next version of the game is eagerly awaited, but now Microsoft has released a statement that the release of Halo 2 for Windows Vista has been delayed by around a month due to 'content' issues. And what are these content issues ? Well, Microsoft discovered that due to an error in Halo 2's map editor, there are scenes of partial nudity, and hence unless these are repaired, the game cannot be released. Refer to this article:


Halo 2 for Windows Vista is now expected to hit the stores sometime in the first week of June, approximately two weeks behind the revised May 22 schedule. The game was originally scheduled for release on May 8, but was delayed due to some technical problems, Microsoft said at the time.
The software giant attributes the most recent delay to an "obscure content error" found in the initial production of Halo 2's map editor. That error was partial nudity.
The company has no plans to change the rating of its game, given it affects only the initial run of games and not subsequent shipments. Warning labels will be placed on packaging for the affected games, and Microsoft has developed a patch that can be downloaded to remove the content in question.

However, after the furore over similar scenes discovered in Grand Theft Auto and the political questions over it, it was impossible for Microsoft to discover that something like this occurs in the game, but is not yet fixed. They would rather bite the schedule and take a fix.

Friday, May 4, 2007

Busy week for Microsoft patching

Next week promises to be a busy week for systems administrators of companies where there are a number of Microsoft systems. These would consist of security updates for Windows, Office, Exchange and Biztalk. Microsoft normally does not disclose details of the updates, but this article provides some details of what the expected updates would be.
These are one of the issues with using Microsoft updates, in terms of the number of updates that need to be installed on a regular basis. And many of these updates require reboots, causing downtime on systems that are in regular use. Doing downtime on a production system requires some amount of coordination and making sure that users are aware of this downtime. Refer this article:


Two of the seven bulletins slated for the May 8 release involve Windows, three affect Microsoft Office, and one each impact Microsoft Exchange and the cryptography API within BizTalk Server. At least five of the seven updates will be pegged critical, Microsoft's highest threat score in its four-level system, according to the advance notification posted today.
As usual, Microsoft did not disclose details of the updates, but intelligent guesses are not difficult. One of the Windows updates, for example, will likely be a fix for the DNS (Domain Name System) zero-day bug found in all editions of Microsoft's server line, including the current beta of Windows Longhorn Server. While researchers predicted last month that Microsoft would issue an out-of-cycle fix for the DNS server service flaw, the company's security team instead has repeatedly blogged that it would probably wait until the regularly scheduled patch day.
If Microsoft issues the seven updates, users will have seen 29 bulletins in the first four months of the year, and at least 49 patches; more than half of those will have been marked critical. During the first five months of 2006, Microsoft issued 20 updates with 36 patches.

These are a significant number of updates. The biggest problem is that in the time that Microsoft releases a patch, the information about the bug is already being exploited by hackers. Microsoft normally releases a patch with some delay after reporting, while trying to make sure that information about the defect is not available publicly. However, with a reported market in defects, it would seem to be losing this battle.

Sunday, April 15, 2007

Programming error lead to loss of Mars Global Surveyor

Programming errors are something that are inevitable when any computing system is involved. In a normal application development, these are known as bugs that get fixed. But errors in any kind of programming can happen anytime and any place, including at locations millions of kilometers from the earth. Earlier, there was the time when a craft sent to the moon had crashed due to incorrect conversion between different units of measurement.
The Mars Global Surveyor was an accomplished success for NASA. It was originally supposed to have a life of 2 years, but given how it was working, this life period was extended 4 times, and it gave a good new perspective of Mars, including the latest presentation of a couple of months back that water still flowed on the Martian surface from small springs.
So what went wrong ? In June last year, a command that oriented the spacecraft was sent to the wrong address. This caused the solar power panels to get wrongly positioned. A couple of months later, when the spacecraft detected the positioning error, it tried to go into safe mode, which unfortunately caused one of the batteries to get exposed to direct sunlight, in turn causing over-heating. Sensors shut down the charging system, and this eventually drained the batteries, and communications were lost with earth. Refer this article.