Domain: netcraft.com
Stories and comments across the archive that link to netcraft.com.
Stories · 167
-
Netcraft Toolbar for Firefox Available
miller60 writes "Netcraft has just released the Firefox version of its anti-phishing toolbar, which blocks known phishing sites and suspicious urls, and displays the hosting information and risk rating for visited sites. Toolbar users have submitted more than 5,600 phishing sites since the IE version was released in late December." -
"Get the Facts" Campaign Working
brontus3927 writes "According to a Reseller Advocate Magazine write-up, Microsoft seems to be winning its war against Linux. Info-Tech Research Group recently ran a survey that is now being used on Microsoft's Get The Facts campaign. In it were some surprising results. 'After polling 1,400 IT managers and CIOs in SMB corporations, his group found that 48% were not interested in Linux, 15% were not sure about Linux, and only 10% plan to evaluate Linux." Despite this, two-thirds of all webservers run Linux. The disparity in these numbers comes from the fact that most smaller companies' websites are hosted by service providers running Linux servers even if the company itself isn't." -
Netcraft: 5,600 Phishing Sites Since December
miller60 writes "Netcraft has tracked and blocked 5,600 known phishing sites since the December launch of its anti-phishing toolbar, which it has now updated with a risk rating feature that warns users about new sites with phishy characteristics, based on trends observed in known phishing scams. It has also started a service that makes the full list available of phishing sites as a continuously updated feed for service providers and companies to use in mail servers and web proxies." One bad sign: the phishing attacks I see are getting (on average) more professional in their phrasing -- it used to be easy to toss out the trawlers based on their spelling alone. -
Netcraft: 5,600 Phishing Sites Since December
miller60 writes "Netcraft has tracked and blocked 5,600 known phishing sites since the December launch of its anti-phishing toolbar, which it has now updated with a risk rating feature that warns users about new sites with phishy characteristics, based on trends observed in known phishing scams. It has also started a service that makes the full list available of phishing sites as a continuously updated feed for service providers and companies to use in mail servers and web proxies." One bad sign: the phishing attacks I see are getting (on average) more professional in their phrasing -- it used to be easy to toss out the trawlers based on their spelling alone. -
Go Daddy Usurps Network Solutions
miller60 writes "Go Daddy has passed Network Solutions as the top domain registrar, and now manages more than 6.8 million domains. This marks the first time that any registrar other than Network Solutions has held the top spot. The change is no surprise, given the growth trends and pricing for the two providers ($8.95 for Go Daddy, $34.99 for Network Solutions), but its controversial Super Bowl ads no doubt helped put Go Daddy over the top." -
World of Warcraft Outage Charted
miller60 writes "World of Warcraft has had extended downtime in the past 24 hours, apparently due to problems with a content patch installation. Blizzard's first MMORPG had recurrent downtime problems in January. The performance problems haven't slowed the frantic growth for WoW, which now has more than 1.5 million subscribers (which, as the article notes, works out to at least $26,000 an hour in assumed revenue)." -
Big Gains for Fedora in Web Hosting
1sockchuck writes "Fedora is the fastest-growing Linux distribution for web sites, according to new data from Netcraft on the popularity of Linux distros. Red Hat continues to be the most widely-used distro, running twice as many sites as Debian. 'Red Hat seems to have the best of both worlds at the moment: market-leading status for Red Hat Linux, plus the fastest-growing community distribution in Fedora,' the analysis notes." -
Phishers Build Deceptive Links with DNS Wildcards
1sockchuck writes "In the continuing evolution of the phisher, the latest scams are crafting deceptive email links that include a bank's URL, but send victims to a phishing spoof site. The phishers are combining wildcard DNS, URL encoding and redirection services to construct the URLs. Netcraft has examples of emails that presented barclays.co.uk in the URL but sent clicks to a spoofed page at a server in Moscow. A DNS cache poisoning attack over the weekend also highlights the potential use of DNS tricks in 'pharming' (phishing using redirection rather than bait emails)." -
Phishers Build Deceptive Links with DNS Wildcards
1sockchuck writes "In the continuing evolution of the phisher, the latest scams are crafting deceptive email links that include a bank's URL, but send victims to a phishing spoof site. The phishers are combining wildcard DNS, URL encoding and redirection services to construct the URLs. Netcraft has examples of emails that presented barclays.co.uk in the URL but sent clicks to a spoofed page at a server in Moscow. A DNS cache poisoning attack over the weekend also highlights the potential use of DNS tricks in 'pharming' (phishing using redirection rather than bait emails)." -
100,000 Domains Sold for $164 Million
miller60 writes "Here's a news item that puts some hard data on the domain typo millionaires post from a couple weeks back. Marchex Inc. just paid $164 million to buy Name Development Ltd., an obscure company that displays pay-per-click keyword ads on 100,000 domains. It's not a stock swap, either, as $155 million of that was in cash. The seller reportedly built the portfolio by scarfing up expiring domains (including hardware-update.com, previously owned by Microsoft and linked from within the Windows 2000 OS) and replacing the content with pay-per-click ads." -
Mozilla Drops Support for International Domains
tsu doh nimh writes "Netcraft has the story that Mozilla has decided to drop support for international domain names in future versions of its Firefox Web browser. The decision comes after demonstrations by the Schmoo Group that the feature can be used to aid in phishing scams and other browser naughtiness." From the article: "The attack can be disabled in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration functions). The Mozilla development team today made this the default setting. Users who want IDN support will be able to turn it on, but will be warned about the risks involved." -
phpBB Forum Down After Defacement
kv9 writes "The phpBB forum has been closed down after the host was cracked into, apparently because of an AWStats hole. Several blogs have been attacked using the same method. Commentary on Netcraft, The Reg and SecurityFocus" -
Google Eyes Domain Registration Market
1sockchuck writes "Google is now an ICANN-approved domain name registrar, an intriguing move that could be tied to its blog hosting service, Blogger. Yahoo recently dropped its domain prices to $4.98, as hosting companies use domains as a cheap way to lure customers. Registrar status could allow Google to compete aggressively on price. Bloggers seem to resist paying for hosting, so cheap domains might help Google's plans for world domination." -
MelbourneIT Lapse Permitted Panix Hijack
McSpew writes "Netcraft reports MelbourneIT's CTO, Bruce Tonkin, has admitted the Panix domain hijacking occurred because of a loophole in MIT's domain transfer process. He doesn't go into detail about what that loophole was, or how it was closed. As a Panix user, I'd like more detail, and I'd like to know what can be done to stop this sort of nonsense happening to other domains." -
MacWorld Expo Traffic Analysis
Bioanarchism writes "MacWorld Expo has been the receiving end of the brute force of the Internet surfers. Netcraft also reports on the Internet traffic that other Apple websites have gotten since Steve Jobs gave the opening keynote." The Windows Server 2003-based MacWorld Expo site folded under all those hits, while Apple's sites, running Mac OS X, were only knocked into sluggishness. (Server load is a complex thing, of course -- more complicated than what OS is on the servers.) -
Netcraft Releases Anti-Phishing Toolbar
AgainstHate writes "Netcraft has released an Anti-Phishing Toolbar that provides detailed information about the website you are visiting (sites' hosting location, country, longevity and popularity) at all times to help users to validate fraudulent URLs. It also natively traps cross site scripting and other suspicious URLs. The toolbar also enables users to report phishing attacks to Netcraft, thus blocking any other unsuspecting users from being harmed (Netcraft supervisor validation is used to contain the impact of any false reporting). Currently the toolbar is only available for IE but a Firefox version is under development." -
Netcraft Releases Anti-Phishing Toolbar
AgainstHate writes "Netcraft has released an Anti-Phishing Toolbar that provides detailed information about the website you are visiting (sites' hosting location, country, longevity and popularity) at all times to help users to validate fraudulent URLs. It also natively traps cross site scripting and other suspicious URLs. The toolbar also enables users to report phishing attacks to Netcraft, thus blocking any other unsuspecting users from being harmed (Netcraft supervisor validation is used to contain the impact of any false reporting). Currently the toolbar is only available for IE but a Firefox version is under development." -
Comment Spams Straining Servers Running MT
dJ phuturecybersonique writes "Netcraft reports that 'Comment spam attacks on Movable Type weblogs are straining servers at web hosting companies, leading some providers to disable comments on the popular blogging tool. The issues are caused by bugs in MT, forcing publisher Six Apart to recommend configuration changes while it prepares fixes.' More..." -
New Rules Make Domain Hijacking Easier
Tanktalus writes "Netcraft seems to have a little ditty about new rules from ICANN that take effect on Friday making it easier to hijack domain names. Essentially, if someone tries to take your domain, and you don't answer within 5 days, they now assume you are okay with the transfer. Previously, the default answer was no, and you had to explicitly state your acceptance of the domain transfer. Owners of small domains, beware: no more computerless vacations that last more than 4 days at a time!" -
New Rules Make Domain Hijacking Easier
Tanktalus writes "Netcraft seems to have a little ditty about new rules from ICANN that take effect on Friday making it easier to hijack domain names. Essentially, if someone tries to take your domain, and you don't answer within 5 days, they now assume you are okay with the transfer. Previously, the default answer was no, and you had to explicitly state your acceptance of the domain transfer. Owners of small domains, beware: no more computerless vacations that last more than 4 days at a time!" -
Solutions to Ease the DDOS Trickle-Down Effect?
dealsites asks: "Recently, The Electorial Vote website run by Andrew Tanenbaum was hit with a triple-threat. Not only was it Slashdotted, it was hit with a DDOS attack in conjunction with the busiest normal traffic day, due to the election. Netcraft has an article detailing the steps taken to mitigate the traffic. Andrew's host provider is also the provider of my site. I'm sure were are on separate servers, him a dedicated server and semi-dedicated hardware for myself, but I noticed dramatic slowdowns of my site during this triple-threat traffic onslaught to Andrew's site. Are there any techniques other than throwing more CPUs and bandwidth at the problem to remedy this type of situation? I'm sure I can't be the only one that has noticed this. Any comments on other similar stories?" -
New URL Spoofing Bug in Pre-SP2 IE
An anonymous reader writes "According to Netcraft a new security flaw has been found in Microsoft Internet Explorer which makes it possible to spoof a URL with just some simple HTML code, by enclosing two URLs and a table within a single href tag. The user will be sent to one site, but the status bar will show a fake URL. The bug apparently affects IE and Outlook Express up to but not including SP2. Firefox and Konqueror seem unaffected." -
New URL Spoofing Bug in Pre-SP2 IE
An anonymous reader writes "According to Netcraft a new security flaw has been found in Microsoft Internet Explorer which makes it possible to spoof a URL with just some simple HTML code, by enclosing two URLs and a table within a single href tag. The user will be sent to one site, but the status bar will show a fake URL. The bug apparently affects IE and Outlook Express up to but not including SP2. Firefox and Konqueror seem unaffected." -
Bush Website Blocked Outside N. America
acey72 writes "The BBC News are reporting that George W Bush's re-election website (don't bother if you aren't in the USA) is blocked to people accessing it from outside the USA. Netcraft spotted the change on Monday, and have a report on the matter. Oh well, at least John Kerry's site still works for us outlanders." At least some Canadians can access the Bush campaign site, but Europeans cannot (without going through a U.S. proxy). -
Bush Website Blocked Outside N. America
acey72 writes "The BBC News are reporting that George W Bush's re-election website (don't bother if you aren't in the USA) is blocked to people accessing it from outside the USA. Netcraft spotted the change on Monday, and have a report on the matter. Oh well, at least John Kerry's site still works for us outlanders." At least some Canadians can access the Bush campaign site, but Europeans cannot (without going through a U.S. proxy). -
ApacheCon 2004 Registration Open
Orbital Sander writes "Registration is now open for ApacheCon 2004, held on November 15-17 in Las Vegas. The conference features over 65 sessions about topics as diverse as the Apache httpd web server (which drives over 67% of all web sites on the Internet including Slashdot) to the foundation's Web Services projects. The weekend preceding the conference has a program of tutorials, three hour hands-on sessions presented by the finest minds in the Apache community. Wanna rub shoulders with the developers and power users of the Apache software? Registering before October 31 gets you $100 off." -
ApacheCon 2004 Registration Open
Orbital Sander writes "Registration is now open for ApacheCon 2004, held on November 15-17 in Las Vegas. The conference features over 65 sessions about topics as diverse as the Apache httpd web server (which drives over 67% of all web sites on the Internet including Slashdot) to the foundation's Web Services projects. The weekend preceding the conference has a program of tutorials, three hour hands-on sessions presented by the finest minds in the Apache community. Wanna rub shoulders with the developers and power users of the Apache software? Registering before October 31 gets you $100 off." -
Microsoft Issues Ominous ASP.Net Security Warning
An anonymous reader writes "A security flaw in Microsoft's ASP.NET apparently allows access to password-protected areas just by altering a URL. There's no patch yet, but in the meantime Microsoft is telling ASP.NET developers they can rewrite their applications to prevent exploits. About 2.9 million web sites run on ASP.NET according to Netcraft." Some more links: another Microsoft article, NTBugtraq, K-Otik and Heise. -
Microsoft Issues Ominous ASP.Net Security Warning
An anonymous reader writes "A security flaw in Microsoft's ASP.NET apparently allows access to password-protected areas just by altering a URL. There's no patch yet, but in the meantime Microsoft is telling ASP.NET developers they can rewrite their applications to prevent exploits. About 2.9 million web sites run on ASP.NET according to Netcraft." Some more links: another Microsoft article, NTBugtraq, K-Otik and Heise. -
Vulnerabilities Found in WordPress Blogging Tool
ZuperDee writes "According to this Netcraft article, 'Security vulnerabilities have been found in WordPress, the popular PHP-based open source blogging application. Some scripts in WordPress are not properly validated, leaving the program open to cross-site scripting (XSS) attacks in which third parties could insert content into a WordPress-driven site.'" -
New Worm Installs Sniffer
fmorgan writes "Netcraft just posted a note saying that a new worm installs a network sniffer in the infected computers." When I read these things it kind of makes me wonder why it took this long. Update: 09/13 22:47 GMT by T : More innovation: Ant writes "The Register has a story about a piece of malware that 'talks' to victims. The Amus email worm uses Windows Speech Engine (which is built-in to Windows XP) to deliver a curious message to infected users. The message reads: "How are you. I am back. My name is mister hamsi. I am seeing you. Haaaaaaaa. You must come to turkiye. I am cleaning your computer. 5. 4. 3. 2. 1. 0. Gule. Gule." ("Gule. Gule" is Turkish for "Bye. Bye". "Hamsi" is a small fish, like an anchovy, found in the Black Sea). F-Secure has a copy of the sound file generated by the message." -
Yet More Google Gazing
povvell writes "Bob Cringely has joined the club and just set out his personal vision for the future of Google now that it's flush with cash, thereby joining a happy band of Google gazers. But is he right, and are they? My own guess is that the company intends to become the biggest advertising platform in the world. What's yours?" -
MSIE 7 May Beat Longhorn Out The Gate
Quantum Jim writes "InternetNews.com reports that a major upgrade for Microsoft Internet Explorer may be imminent. Apparently in response to the recent mass migration away from MSIE, top Microsoft developers have been soliciting for improvements in the old browser at a web log and at Channel 9, an aggregate journal previously discussed by /.. InternetNews.com speculates that improvements could possibly include support for tabbed browsing, better security, more PNG and CSS compliance, and RSS integration (which Firefox and Opera Mail already support). Go competition!" -
BSD Hacks
GMan00 writes "A flurry of BSD UNIX-related (Berkeley Software Distribution) books have hit the bookstores during the recent past, and more are on the way. From books specific to Secure Architectures with OpenBSD in April 2004 and the reissue of The Design and Implementation of the BSD Operating System for FreeBSD 5.x (expected in August 2004), to Michael Lucas' series of BSD Books from NoStarch Press, print documentation is certainly available for those interested in learning about the free, open source UNIX system which powers operations such as Yahoo! portal and Sendmail.org website, Verio and Pair hosting, not to mention web server survey site Netcraft. Dru Lavigne's BSD Hacks (O'Reilly and Associates, May 2004), is the latest book in these releases, and is an enormously useful resource for system administrators and end-users alike." Read on for the rest of George's review. BSD Hacks author Dru Lavigne pages 427 publisher O'Reilly & Associates rating 10 reviewer George ISBN 0596006799 summary A great array of hacks you can perform on your BSD box, many applicable to all the BSDs, including FreeBSD, NetBSD, OpenBSD and Darwin/OS X.Dru writes the BSD Basics column on O'Reilly & Associates' OnLamp. Her clarity and fluid style are perfect for those looking to understand aspects of the BSD operating systems. I have had some email communications with Dru about various New York City *BSD User Group-related activities, and managed to speak with her several times at BSDCan this past May.
Like most computer nerds, Dru has a sense of humor. Unlike most, however, she's actually funny.
BSD Hacks is the first book that is almost solely focused on hacks for sysadmins, without boring you with the details for basic operating system installation and configuration that has been so well documented elsewhere. BSD Hacks is not just for sysadmins, though. Intermediate and advanced BSD users will also find the book an excellent tool. For those who find difficulty in BSD installs and other fundamentals, on the other hand, it's best to start with the FreeBSD Handbook, the NetBSD Guide or the OpenBSD FAQ.
There's lots of good hacks buried in the various BSD books, around the internet in different HOWTOs and tutorials. But BSD hacking is the sole purpose of BSD Hacks; there's no need to browse through install screens and overviews of TCP/IP before getting to the heart of the matter.
With 100 listed hacks, multiplied by an impressive level of detailed angles for each, Dru provides an array that demands the placement of this book right in your server room, not in a pile of "must-read-at-some-distant-point-in-the-future" texts.
The majority of hacks are applicable to all the BSDs, including Darwin and OS X, although some are specific to one BSD or another.
This review obviously can't list every hack, although you would be smart to sit and work through the book yourself over a weekend or two. But it is possible to provide a good flavor of BSD Hacks in brief. O'Reilly and Associates does give a good glimpse on their Sample Hacks page, but let's do a quick work through ourselves.
The first chapter is called "Customizing the User Environment," and is probably best for end-users looking to go beyond their first steps. But it does include some useful hacks, such as "Use an Interactive Shell" that certainly fit well into the arsenal of any sysadmin, not to mention Hack #12 "Use Multiple Screens on One Terminal."
The second chapter, "Dealing with Files and Filesystems" also contains gems for both end-users and sysadmins. The use of mtree, which maps a directory hierarchy, is mentioned as a tool for recovery. Later on in chapter 6, Dru details its use for making a hacked data integrity checker, thus filling the role often played by products such as Tripwire.
Another great tool Dru covers in the second chapter is g4u, a free ghosting program that gives you the ability to perform quick restores over ftp. Ghosting a drive image is an incredibly useful tool, whether it's about replicating servers or doing a quick reinstall and configuration when a server fails in an emergency.
Chapter 3 is entitled "Boot and Login Environments." It gives some hacks that aren't just for basic system administration, but also some useful security ones including changing your /etc/passwd file to Blowfish encryption and utilizing OPIE for one-time passwords, which is built into FreeBSD.
"Backup Up" is the focus of Chapter 4. It includes some very creative methods of dealing with maintaining that necessity, and also includes an excellent primer on Bacula, which is increasingly gaining prominence as a cross-platform backup system.
Chapter 5 covers "Network Hacks," and continues on educating a sysadmin. Included in this chapter is the tcpdump program, a vital tool for watching traffic flowing by your network interfaces.
There's a strong security focus in Chapter 6, entitled "Securing the System." While security hacks are sprinkled generously throughout the book, this chapter works with firewalling with IPF and PF, in addition to covering SSH and Snort. It also includes the earlier mentioned 'intrusion detection-lite' approach with mtree.
Chapter 7, "Going Beyond the Basics" explores scripting, analyzing dreaded buffer overflows and more. Dru also includes a bit on "Creating a Trade Show Demo," not something you'd expect documented in print anywhere, but nevertheless quite useful for anyone working for the BSDs at a conference.
Dru continues with "Keeping Up-to-Date" in Chapter 8, which includes useful details on upgrading and downgrading your installed ports.
The final chapter is "Grokking BSD." "Grok," as Dru comments, refers to the science fiction writer Heinlein's Martian phrase for having a "thorough understanding." Dru covers creating your own manual pages, dealing with custom patches, playing with dictionaries and more.
Certainly there are no walls between each chapter, as many of the hacks could be shifted around. All the more reason to work your way through the book from beginning to end.
One useful addition for this book could have been somehow denoting which of the BSDs (in some cases, it's all of them) to which each listed hack can be applied. Certainly not all are available to Darwin and Apple's OS X. And certainly there's no point in making the OpenBSD /etc/passwd file encrypted in Blowfish, since that is its default.
While many of the hacks are found somewhere in the manual pages, on some useful website, buried in another book or in the minds of some developer somewhere, they're not necessarily in the annals of official documentation. But there's no single book or site that provides the depth and breadth that Dru provides. She managed to tap into the thoughts of dozens of developers and sysadmins around the world, greatly enhancing the variety of hacks in this book.
As a side note, the scope of BSD Hacks isn't limited to just the BSD family. Many of these are likely applicable to Linux and the other UNIX systems. But with recent, impressive increases in the BSD install base, there's a good chance that you can access a BSD box somewhere.
Whether you're a sysadmin managing hundreds of servers, or a power user ready to go beyond the obvious, BSD Hacks belongs next to your CRT.
You can purchase BSD Hacks from bn.com. Slashdot welcomes readers' book reviews. To see your own review here, carefully read the book review guidelines, then visit the submission page. -
Netcraft: Red Hat Still Top Linux Server Distro
darthcamaro writes "Looks like Red Hat is still the #1 distro according to Netcraft stats cited by Internetnews.com. Gentoo is now the fastest growing, replaced Debian which was the fastest growing distro just six months ago...and as we all know, and as the article rightly points out, the stats aren't accurate cause most webserver admins disable version reporting...right? So if all version were known, what would be the #1 distro for hosting? Read the Netcraft stats (without the context that they're BS) here" -
Hosting Service Closes 3000 Blogs Without Notice
marmoset writes "Citing the high costs of running the free service, performance concerns, and health problems, Dave Winer closed down the weblogs.com hosting service without any prior notice. As many as 3000 sites are now inacessible, and the users who want to transfer their data elsewhere have to ask (politely) for it to be exported. As might be expected, reactions range from understanding to enraged. Netcraft has a report, too." -
FreeBSD: Not Exactly Dead
quantumice writes "It would seem that despite being dead and there only being six of us who use it, FreeBSD has clocked up nearly 2.5 million active sites according to Netcraft. So by my estimates that must mean that I and each of my 5 friends run 416 667 sites. That might explain my high bandwidth usage." -
FreeBSD: Not Exactly Dead
quantumice writes "It would seem that despite being dead and there only being six of us who use it, FreeBSD has clocked up nearly 2.5 million active sites according to Netcraft. So by my estimates that must mean that I and each of my 5 friends run 416 667 sites. That might explain my high bandwidth usage." -
Webmasters Pounce On Wiki Sandboxes
Yacoubean writes "Wiki sandboxes are normally used to learn the syntax of wiki posts. But webmasters may soon deluge these handy tools with links back to their site, not to get clicks, but to increase Google page rank. One such webmaster recently demonstrated this successfully. Isn't it time for Google finally to put some work into refining their results to exclude tricks like this? I know all the bloggers and wiki maintainers would sure appreciate it." -
Netcraft Interviews Brian Behlendorf
thejackol writes "The co-founder of the Apache Web Server Project and the First Chief Engineer at Wired Magazine was interviewed by Netcraft's Rich Miller about Netcraft's growth, the SCO case's unexpected benefits and changing the world through software. Excerpt: 'It's a good rebuke to the cynical but widespread notion that all it takes is a big pot of gold to litigate your competition out of existance or otherwise win a legal challenge. Good did prevail in the end. Hopefully it won't make us too cocky, because the next challenge could be much harder to fight.'" -
Miguel de Icaza on Mono, Ximian/Novell, XAML
moquist writes "Netcraft has an interview with Miguel de Icaza, of Gnome and Ximian fame. Icaza expounds his thoughts on Mono (the .Net framework for open source), the current direction of Microsoft's .Net, Novell's acquisition of Ximian, Novell's Linux desktop environment, Linux for grandmas and kids, and "the greatest danger to the continuing adoption and progress of open source" (Hint: it's pronounced "XAML".)." -
Miguel de Icaza on Mono, Ximian/Novell, XAML
moquist writes "Netcraft has an interview with Miguel de Icaza, of Gnome and Ximian fame. Icaza expounds his thoughts on Mono (the .Net framework for open source), the current direction of Microsoft's .Net, Novell's acquisition of Ximian, Novell's Linux desktop environment, Linux for grandmas and kids, and "the greatest danger to the continuing adoption and progress of open source" (Hint: it's pronounced "XAML".)." -
Secret Repairs Preceded TCP Flaw Release
efranco cuts and pastes: "Only the math had changed. But the emergence of a workable exploit for an old TCP security hole prompted a secret initiative to fix the Internet, giving network operators a week to secure vulnerable routers. The clandestine repair effort livened an already intense period for security pros already juggling a bevy of Windows security patches." We ran a story on a this a few days ago. -
Phishing Scams Incorporate SSL Certificates
dettifoss writes "Netcraft reports: `Internet "phishing" scams are incorporating the use of SSL certificates in their efforts to trick users into divulging sensitive login information for financial accounts.' Perhaps more disturbingly: `Scammers can also configure their web server so that deceptive SSL certificates won't trigger an alert in the user's browser. "One of the SSL encoding methods is 'plain text'," Neal Krawetz from Secure Science Corporation noted in the SANS post on the issue. "Most SSL servers have this disabled by default, but most browsers support it. When plain text is used, no central certificate authority is consulted and the user never sees a message asking if a certificate should be accepted.'" -
Celebrating Spam's Ten-Year Anniversary
khalua writes "Netcraft has a story that 10 years ago today, the first widely recognized spam was sent by... oh the irony...a law firm. Hate to see what a beast it grows into when it's 20." Reader prostoalex writes "Ever wonder why spam is so prevalent and who buys all those revolutionary products sold at unbelievable prices? Direct Marketing Association estimates $11.7 billion was spent on goods and services pitched via unsolicited e-mail. The average buy was $155, which exceeds the average of $114 that opt-in e-mail generated. It's worth noting that US e-commerce sales in general generated $50 billion total last year, however, the data was presented by a different researcher." -
Celebrating Spam's Ten-Year Anniversary
khalua writes "Netcraft has a story that 10 years ago today, the first widely recognized spam was sent by... oh the irony...a law firm. Hate to see what a beast it grows into when it's 20." Reader prostoalex writes "Ever wonder why spam is so prevalent and who buys all those revolutionary products sold at unbelievable prices? Direct Marketing Association estimates $11.7 billion was spent on goods and services pitched via unsolicited e-mail. The average buy was $155, which exceeds the average of $114 that opt-in e-mail generated. It's worth noting that US e-commerce sales in general generated $50 billion total last year, however, the data was presented by a different researcher." -
Netcraft Jokes About SCO's Virus Fears
Elektroschock writes: "Through the media SCO Group sent the message that a virus writer that targets its website would be a Linux enthusiast. Netcraft has its own funny remarks in a dogfood article." Some of you might get a cackle out of the third solution. -
Debian Fastest-Growing Distro, Says Netcraft
Oskuro writes "According to this story at news.netcraft.com, Debian was the fastest growing distribution in the last 6 months, closely followed by SuSE and Gentoo. RedHat, while still reigning, has started to lose sites in Netcraft's survey after they announced the end of support for their desktop releases. The survey is based on the stats from webservers which include the distribution name in their webserver's header." Maybe it would grow even faster when Java issues are worked out -- read more below on that.adamy writes "For people like me that use both Free/Open Source software and Java, the two have come together with two major exception: The Java Virtual Machine and the Base Libraries. Seems the folks trying to get Java packages ready for Sarge could have listed the issues. This is an interesting example of dependency tree pruning: Several packages are orphaned because they depend on Ant, which depends on Swing. Swing has been lower priority for the Classpath because most of the java pacakages are server side or lack a UI componenet."
-
Debian Fastest-Growing Distro, Says Netcraft
Oskuro writes "According to this story at news.netcraft.com, Debian was the fastest growing distribution in the last 6 months, closely followed by SuSE and Gentoo. RedHat, while still reigning, has started to lose sites in Netcraft's survey after they announced the end of support for their desktop releases. The survey is based on the stats from webservers which include the distribution name in their webserver's header." Maybe it would grow even faster when Java issues are worked out -- read more below on that.adamy writes "For people like me that use both Free/Open Source software and Java, the two have come together with two major exception: The Java Virtual Machine and the Base Libraries. Seems the folks trying to get Java packages ready for Sarge could have listed the issues. This is an interesting example of dependency tree pruning: Several packages are orphaned because they depend on Ant, which depends on Swing. Swing has been lower priority for the Classpath because most of the java pacakages are server side or lack a UI componenet."
-
MyDoom Windows Worm DDoSing SCO
We mentioned the myDoom Worm just a few hours ago, but more information is available now, mainly that its ultimate goal is apparently to DDoS SCO. You can see some more detail at NetCraft. Obviously SCO has a lot of enemies out there right now, but it's always sad to watch someone stoop to this level.