in

MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.

bits and bytes

June 2007 - Posts

  • Windows Vista Family Discount Program Ends June 30th

    Vista Team Blog

    "We’ve been pleased with the response to the program, which has enabled thousands of multi-computer families to upgrade more than one PC in their home to Windows Vista."

    You can still take advantage of this offer until 11:59 PM Pacific Time on 30 June 2007.

    Windows Vista Family Discount: http://www.microsoft.com/windows/products/windowsvista/buyorupgrade/familydiscount.mspx

  • The Microsoft MVP Program, a podcast in four parts

    The Voice of Support: Ed Hickey and Brian Boston.

    The MVP Program In-Depth (Part 1 of 4)  http://channel9.msdn.com/Showpost.aspx?postid=317571

    "The next 4 podcasts will focus on the ins and outs of the MVP program. Microsoft Most Valuable Professionals (MVPs) are exceptional technical community leaders from around the world who are awarded for voluntarily sharing their high quality, real world expertise in offline and online technical communities."

    Updates:

    The Voice of Support: April Spence and Ben Miller.

    The MVP Program In-Depth (Part 2 of 4)  http://channel9.msdn.com/Showpost.aspx?postid=319865

    The Voice of Support: April Spence and Mike Fosmire.

    The MVP Program In-Depth (Part 3 of 4)  http://channel9.msdn.com/ShowPost.aspx?PostID=323909

    Posted Jun 21 2007, 04:14 PM by tashi
    Filed under: ,
  • Exchange and Security MVPs Q&A chat

    TechNet: http://www.microsoft.com/technet/community/chats/default.mspx

    Exchange Server Q&A with the MVP Experts

    "Exchange MVPs will be on hand to answer your questions about Exchange Server, Outlook and Exchange for Small Business Server.


    Chat 1
    When:   Tuesday June 19th
    Time:    5pm PST or 8pm EST
    Where:  TechNet Chat Room www.microsoft.com/technet/community/chats/chatroom.aspx
    No password required

    Chat 2
    When:   Thursday June 21st
    Time:    10am PST or 1pm EST
    Where: TechNet Chat Room www.microsoft.com/technet/community/chats/chatroom.aspx
    No password required

    Q&A with the Security MVP Experts

    In this chat the MVP experts will answer your questions regarding online safety issues such as phishing, spyware, rootkits as well as server related topics. If you have questions on how to protect your PC, please bring them to this informative chat.
    When:   Thursday June 21st
    Time:    4pm PST and 7pm EST
    Where:  TechNet Chat Room www.microsoft.com/technet/community/chats/chatroom.aspx
    No password required"

  • OPERATION BOT ROAST

    FBI Press Release: 

    Over 1 Million Potential Victims of Botnet Cyber Crime

    "Today the Department of Justice and FBI announced the results of an ongoing cyber crime initiative to disrupt and dismantle “botherders” and elevate the public’s cyber security awareness of botnets. OPERATION BOT ROAST is a national initiative and ongoing investigations have identified over 1 million victim computer IP addresses. The FBI is working with our industry partners, including the CERT Coordination Center at Carnegie Mellon University, to notify the victim owners of the computers. Through this process the FBI may uncover additional incidents in which botnets have been used to facilitate other criminal activity.

    A botnet is a collection of compromised computers under the remote command and control of a criminal “botherder.” Most owners of the compromised computers are unknowing and unwitting victims. They have unintentionally allowed unauthorized access and use of their computers as a vehicle to facilitate other crimes, such as identity theft, denial of service attacks, phishing, click fraud, and the mass distribution of spam and spyware. Because of their widely distributed capabilities, botnets are a growing threat to national security, the national information infrastructure, and the economy.

    “The majority of victims are not even aware that their computer has been compromised or their personal information exploited,” said FBI Assistant Director for the Cyber Division James Finch. “An attacker gains control by infecting the computer with a virus or other malicious code and the computer continues to operate normally. Citizens can protect themselves from botnets and the associated schemes by practicing strong computer security habits to reduce the risk that your computer will be compromised.”

    The FBI also wants to thank our industry partners, such as the Microsoft Corporation and the Botnet Task Force, in referring criminal botnet activity to law enforcement.

    Cyber security tips include updating anti‑virus software, installing a firewall, using strong passwords, practicing good email and web security practices. Although this will not necessarily identify or remove a botnet currently on the system, this can help to prevent future botnet attacks. More information on botnets and tips for cyber crime prevention can be found online at www.fbi.gov.

    The FBI will not contact you online and request your personal information so be wary of fraud schemes that request this type of information, especially via unsolicited emails. To report fraudulent activity or financial scams, contact the nearest FBI office or police department, and file a complaint online with the Internet Crime Complaint Center, www.ic3.gov.

    To date, the following subjects have been charged or arrested in this operation with computer fraud and abuse in violation of Title 18 USC 1030, including:

    • James C. Brewer of Arlington, Texas, is alleged to have operated a botnet that infected Chicago area hospitals. This botnet infected tens of thousands of computers worldwide. (FBI Chicago);
    • Jason Michael Downey of Covington, Kentucky, is charged with an Information with using botnets to send a high volume of traffic to intended recipients to cause damage by impairing the availability of such systems. (FBI Detroit); and
    • Robert Alan Soloway of Seattle, Washington, is alleged to have used a large botnet network and spammed tens of millions of unsolicited email messages to advertise his website from which he offered services and products. (FBI Seattle)

    The FBI will continue to aggressively investigate individuals that conduct cyber criminal acts."

    http://www.fbi.gov/pressrel/pressrel07/botnet061307.htm

  • FBI Takes Down Botnet

    ABC News reports the FBI has identified 1 million computer addresses that have been hacked by criminals who hijack other people’s computers, turn them into servers and use them to send out massive amounts of spam and spyware.

     http://www.abcnews.go.com/TheLaw/story?id=3274261&page=1

  • Yahoo! Messenger critical vulnerabilities

    Yahoo! Webcam ActiveX Controls Multiple Buffer Overflows


    "eEye Digital Security has discovered two critical vulnerabilities in ywcupl.dll (version 2.0.1.4) and ywcvwr.dll (version 2.0.1.4) included by default in all releases of Yahoo! Messenger 8.x. Ywcupl.dll is Yahoo's Webcam Upload ActiveX Control used by Yahoo! Messenger to stream content from a user's webcam to other users. Ywcvwr.dll is Yahoo! Messenger's Webcam Viewer ActiveX Control used to view any streamed content. These files are normally used only when viewing or streaming webcam content to and from Yahoo Messenger, but they are incorrectly marked safe for scripting and can be instantiated by any website. Furthermore they both fail to perform bounds checking on variables resulting in 2 stack-based buffer overflow conditions that could allow arbitrary code to execute in the context of the logged-in user."


    eEye Digital Security: http://research.eeye.com/html/advisories/published/AD20070608.html

    "Over the next several weeks, users worldwide will be prompted to update to a new version of Yahoo! Messenger upon signing into the service. If you choose not to update and you have not updated via this page or at messenger.yahoo.com, the vulnerability will still exist."

    Yahoo!: http://messenger.yahoo.com/security_update.php?id=060707

    Update now and install the new version manually, you can download the latest version of Yahoo! Messenger from http://messenger.yahoo.com.

  • Microsoft Security Bulletin Advance Notification for June 2007

    Microsoft planned to implement a change with June’s ANS release on Thursday, June 7, which can now be seen at TechNet. http://www.microsoft.com/technet/security/bulletin/ms07-jun.mspx

    The Microsoft Security Response Center (MSRC) http://blogs.technet.com/msrc/archive/2007/06/07/june-2007-advance-notification.aspx

    "This month, we’re planning to release six security bulletins:

    • Four Microsoft Security Bulletins affecting Microsoft Windows with a Maximum Severity rating of Critical. Three of the updates will require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer.
    • One Microsoft Security Bulletins affecting Microsoft Office with a Maximum Severity rating of Important. This updates may require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer.
    • One Microsoft Security Bulletin affecting Microsoft Windows with a Maximum Severity rating of Moderate. This updates will not require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer.

    Additional details about the bulletins and the affected versions can be found in the Advance Notification.

    We also have an update to the Microsoft Windows Malicious Software Removal Tool, and we are planning to release seven high-priority non-security update on Microsoft Update. No non-security updates are planned for Windows Update this month.

    As we do every month, I would like to remind everyone that the information in the Advance Notification is subject to change as we continue testing until we release on Tuesday. If anything changes or we have new information, we will let you know through the MSRC weblog."

  • Zango's tango

  • House Passes another Spyware Bill

    The House passed a cyber-security bill that would allow for civil penalties of up to $3,000,000.  H.R. 964: Securely Protect Yourself Against Cyber Trespass Act or Spy Act.

    The bill, introduced by Rep. Adolphus Towns (D-New York), to protect users of the Internet from unknowing transmission of their personally identifiable information through spyware programs, and for other purposes.

    "Makes it unlawful for any person who is not the owner or authorized user (user) of a protected computer (a computer exclusively for the use of a financial institution or the U.S. Government, or a computer used in interstate or foreign commerce or communication) to engage in unfair or deceptive acts or practices in connection with specified conduct, including: (1) taking unsolicited control of the computer; (2) modifying computer settings; (3) collecting personally identifiable information; (4) inducing the owner or authorized user to disclose personally identifiable information; (5) inducing the unsolicited installation of computer software; and (6) removing or disabling a security, anti-spyware, or anti-virus technology"

    "Makes it unlawful for a person to: (1) transmit to a protected computer any information collection program (a program that collects personally identifiable information and uses the information to send advertising), unless such program provides notice required by this Act before execution of any of the program's collection functions; or (2) execute any collection information program installed on a protected computer unless, before execution, the user has consented to such execution under notice requirements of this Act. Provides an exception with respect to Web pages visited within a particular website when the information collected is sent only to the provider of the website accessed."

    "Jun 6, 2007: This bill passed in the House of Representatives by roll call vote. The vote was held under a suspension of the rules to cut debate short and pass the bill, needing a two-thirds majority. The totals were 368 Ayes, 48 Nays, 16 Present/Not Voting."

    http://www.govtrack.us/congress/bill.xpd?bill=h110-964

    Other Bills with the Same Title:

    108th Congress: H.R. 2929 http://www.govtrack.us/congress/bill.xpd?bill=h108-2929

    109th Congress: H.R. 29  http://www.govtrack.us/congress/bill.xpd?bill=h109-29

  • Zango article at the Washington CEO

    Keith Smith, co-founder and chief executive officer of Zango Inc., an online advertising and media company.

    http://www.washingtonceo.com/index.php?id=90&tx_ttnews%5Btt_news%5D=783&tx_ttnews%5BbackPid%5D=146&cHash=a729775d91

    "Every company runs into obstacles. My company, Zango Inc., has encountered more than most."

    "Then we encountered an obstacle that threatened our existence. The third-party software distribution network we had established had to be dismantled. Some of these partners, despite contractual agreements, were defrauding us and, more importantly, harming consumers’ computers. Zango became the subject of a Federal Trade Commission (FTC) investigation. We had long since ceased our partnerships and, in some situations, had filed legal actions against these no-gooders, but we nonetheless worked cooperatively with the FTC, outlining steps to provide additional protection to consumers. In the end, we reached a settlement that stipulated a list of rules by which we must abide, almost all of which we had already implemented as part of our distribution and technology transition."

    Spyware Still Cheating Merchants and Legitimate Affiliates

    Ben Edelman. May 21, 2007 - Updated, May 22, 2007

    http://www.benedelman.org/news/052107-1.html

    Posted Jun 01 2007, 10:25 AM by tashi
    Filed under: , ,


Copyright © is the original authors. Blog site is an independent site not sponsored by Microsoft. The Yoda blog server and the Brianna SQL server would like to thank www.ownwebnow.com and www.exchangedefender.com. They wouldn't be here and broadcasting without the generosity of Vlad Mazek and his companies.

Powered by Community Server (Commercial Edition), by Telligent Systems