Wednesday, May 4, 2011

Microsoft, Juniper urged to patch dangerous IPv6 DoS hole

MORE URGING: Microsoft security expert warns over SharePoint data at risk

Some Windows networking consultants are so concerned about the hole and Microsoft’s lack of interest in fixing it, that they have been warning users directly. “There is a serious Windows vulnerability for RA flooding as a denial-of-service attack on wired LANs. It only takes between 5 to 20 packets to CPU-bound every Windows 7 or Server 2008 machine on that subnet,” said Microsoft MVP Ed Horley, Principal Solutions Architect at Groupware Technology to attendees of the Rocky Mountain IPv6 Summit in Denver, Colo., last week. “I have heard rumor it can also lock out Playstation 2 and Xbox consoles. With enough packets it requires a hard reboot to recover.”



Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




Although several workarounds exist, each has a significant drawback. One is to turn off IPv6, http://www.networkworld.com/topics/ipv6.html which also disables new Microsoft technologies that rely on it, such as DirectAccess, a service that allows Windows 7 machines to have an always-on remote access connection to Windows Server 2008 R2 servers. Remote Access is touted as a money-saving option as it replaces the need for a separate VPN in Windows environments.

Experts also advise using a router that has implemented a Cisco technology called RA Guard - and while Cisco routers support RA Guard, not all routers do. RA Guard was submitted as an informational document to the IETF, RFC 6105, but it is not on track to become a standard.

Juniper, for instance, has no intention of implementing it and is instead waiting for IETF RFC 6164. “RFC 6105 IPv6 Router Advertisement Guard, published about nine weeks ago, is an informational RFC, as opposed to an IETF Standard, that documents Cisco's proprietary RA-Guard technology. Cisco asserts that at least one of their patent applications (US PPA 20080307516) covers this technology. While Cisco has stated that should RFC 6105 become a standard then they will make a royalty-free license available, since this is not yet a standard there is no such option. We can however achieve much the same functionality simply by applying access control lists,” said Juniper’s Peter Lunk, director of product marketing for high-end security systems.

Lunk added: “Conversely, RFC 6164, released last month, is a ‘standards track’ RFC (which is to say on the way to being, but not yet, a standard) supported by Juniper, Google and IBM and others that addresses many of the same issues in a much more open manner. We expect this to be ratified as a full standard at the next IETF meeting in July.”

BACKGROUND: Jeff Doyle on the case for enterprise IPv6

Heuse has also called Juniper out on the carpet for dragging its feet to fix the hole. Juniper’s Lunk argues that the RA advertisement problem stems from a flaw in the ICMPv6 protocol and should be fixed by the IETF.

“The flaw in the ICMPv6 protocol has only been identified in a small subset of older Juniper products, and only when configured as a host rather than a router,” he said. “According to the protocol, devices configured as hosts must accept and process all advertised routes. This is an inherently dangerous thing to do. If our customers must use auto-configure mode on the IPV6 host on an open LAN, then we strongly recommend whitelisting sources of acceptable routes which will protect them from bogus advertisements.”

Tuesday, May 3, 2011

FSF: Microsoft is Bound by GPLv3 Terms If It Distributes GPLv3 Code

Last month, Microsoft's legal department proclaimed it doesn't consider itself bound to the terms of version 3 of the General Public License, with respect to certificates it distributed for software, services, and support from Novell. Today, the Free Software Foundation responded by saying if Microsoft distributes software covered by GPLv3, then it's bound by the terms of that license.



Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




"Microsoft cannot by any act of anticipatory repudiation divest itself of its obligation to respect others' copyrights, reads today's FSF statement. "If Microsoft distributes our works licensed under GPLv3, or pays others to distribute them on its behalf, it is bound to do so under the terms of that license. It may not do so under any other terms; it cannot declare itself exempt from the requirements of GPLv3."

The crux of the dispute centers around whether, when Microsoft agreed to issue certificates for Novell's customers, it effectively distributed software on Novell's behalf. Microsoft has made the case that Novell is the distributor in this case, and that it's just picking up the tab.

The reason why it all matters is because version 3 specifically declares that a licensee doesn't have the right to claim to hold anyone to whom it distributes that code free from patent obligations. The basic theory here is that no distributor can claim ownership of any part of the software, so it can't then presume to hold someone to whom it distributes that software free from liability or infringement for it.

FSF's motivation may be to find a way to legally extend some of that privilege Microsoft granted to Novell last year, to everyone else who might be a recipient of that same software even if Novell's not the distributor. That's probably why Section 11 of the new GPL reads, in part, as follows: "If, pursuant to or in connection with a single transaction or arrangement, you convey, or propagate by procuring conveyance of, a covered work, and grant a patent license to some of the parties receiving the covered work authorizing them to use, propagate, modify or convey a specific copy of the covered work, then the patent license you grant is automatically extended to all recipients of the covered work and works based on it."

Last July, Microsoft's proclamation contained the following: "While there have been some claims that Microsoft's distribution of certificates for Novell support services, under our interoperability collaboration with Novell, constitutes acceptance of the GPLv3 license, we do not believe that such claims have a valid legal basis under contract, intellectual property, or any other law. In fact, we do not believe that Microsoft needs a license under GPL to carry out any aspect of its collaboration with Novell, including its distribution of support certificates, even if Novell chooses to distribute GPLv3 code in the future."

Microsoft went on to say its Novell agreement does not grant any patent rights to any of Novell's customers, through its distributed certificates or otherwise - meaning, it's not granting Novell's customers the rights to use software whose rightful ownership Microsoft wants to retain the right to contest later. However, the company did decide to rescind the portion of its certificates which grant recipients the right to receive support on GPLv3 licensed code from Novell - which was actually in compliance with an earlier FSF request.

But the FSF didn't want last month's proclamation to be the last word. "Microsoft has said that it expects respect for its so-called 'intellectual property' - a propaganda term designed to confuse patent law with copyright and other unrelated laws, and to muddy the different issues they raise," reads the close of the FSF's statement today. "We will ensure - and, to the extent of our resources, assist other GPLv3 licensors in ensuring - that Microsoft respects our copyrights and complies with our licenses."

In the meantime, the issue of whether issuing a certificate toward the purchase of software by someone else constitutes legal distribution of someone else's software, remains open.

Monday, May 2, 2011

WinDVD gets Profile 1.1 certification from Blu-ray

Corel said Thursday that its WinDVD playback software had received certification from the Blu-ray Disc Association to playback discs that use the Profile 1.1 standard.







Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com


With the certification, WinDVD would become the first non-hardware playback option available on the market capable of supporting the updated standard. The first discs based on 1.1 are expected to hit the market in early 2008, as will the version of WinDVD with the capability.

Profile 1.1 allows Blu-ray publishers to use the picture-in-picture functionality that has been a standard on HD DVD discs since the beginning. Also added in 1.1 is mandatory internet connectivity support, among other enhancements. Many of the changes to the Blu-ray standard are likely in response to criticisms of the format by analysts, who say it lacks many of the next-generation features than HD DVD already had.

Sunday, May 1, 2011

Certification process begins for Verizon's open devices

The open network era officially begins for Verizon Wireless, as the company's first choice for testing and certification of anyone's CDMA devices, for customers to bring to the network at will, begins testing new equipment today.







Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




The first independent laboratory for the certification of wireless devices for enrollment by customers to Verizon Wireless' CDMA network, is now officially online. As previously announced as early as November of last year, that lab will be run by Intertek, an established global testing and certification service headquartered in London.

Under VZW's historic plan announced last November, the manufacturer of any handset that wishes to be able to use the VZW network may submit working prototypes to Intertek for testing and certification. All that Intertek will be testing is connectivity, and whether candidate handsets contain anything that may conceivably interfere with the network; beyond that, VZW does not care what operating system a candidate may contain, or what applications may be used. In fact, senior executives have suggested that the company encourage very specialized devices with unique applications be welcomed into the certification process.

Verizon won't necessarily be selling these devices in its outlets or to its customers; it's still up to each manufacturer to make the sale. However, it will be permitted to tout its certification for the VZW network once it's received from Intertek.

VZW's statement this morning made it clear that Intertek may be the first of several third-party labs, and that the relationship between the two companies is not exclusive; a quote from Intertek's VP of operations, David Dennis, characterized his company as "the first testing laboratory approved under the Verizon Wireless Open Development Initiative."

That said, Intertek's not a small operation by any measure. In the first half of this year, it racked up revenue of £457.4 million ($783.7 million at current exchange rates), an increase of 28.6% annually, with profit before taxes of £62.9 million. It lists its corporate founder as none other than Thomas A. Edison in 1896, through the founding of a department called the Lamp Testing Bureau within the company that would become GE. The Bureau then became the independent Electrical Testing Laboratories, which has since been absorbed by Intertek.

Developers of even the most limited set of handsets, even if they produce fewer than 100, won't need to ship prototypes halfway around the world. Intertek maintains over 1,000 laboratories in 110 countries, including throughout Asia, Eastern Europe, and South America.

Saturday, April 30, 2011

Report: Cisco to Target Consumers

In a move that will expand the company's market reach, Cisco Systems has plans to start selling a line of consumer products including phones, radios and home theater devices, the Financial Times reported on Sunday. Cisco believes it can define itself by adding Internet connectivity to these devices, thus creating a new market.





Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




Cisco is commonly known for its networking products, and owns Linksys, a maker of consumer network devices. Chief development officer Charles Giancarlo told the paper he believes Cisco's ties with Google and Yahoo will also give it an advantage over competitors. A release date for any new consumer products from the company was not given.

Friday, April 29, 2011

Hotmail fail: Microsoft lays an egg in the cloud

Microsoft lost all email for 17,000 Hotmail customers, then botched the response. Is this a harbinger of Office 365 hassles?

If this is the way Microsoft's going to handle Office 365 outages, we're in for some interesting times.

On Dec. 30, one of the largest SQL Server databases on the planet started having problems. The database in question just happens to belong to Microsoft. And the way the company reacted to the problems should raise red flags for anyone considering a move to the Microsoft cloud.






Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




According to a blog post by Chris Jones, a Microsoft vice president in Windows Live Engineering, the Hotmail servers had a problem with load balancing, resulting in 17,355 email accounts losing all of their data. It took Microsoft three days to restore the data. At least, Microsoft claims it had the data restored in three days. Voluminous postings on both the Windows Live Engineering site and the Windows Live Solution Center say that some people still haven't gotten their data back.

Data loss happens in the cloud, on corporate servers, and on the desktop. But this is, arguably, Microsoft's most widely deployed cloud application, backed by Redmond's best and brightest, and it failed for 17,000 users for at least three days.

Put aside the obvious technical questions, like why were the servers performing a load balancing act in the middle of the busiest time of year? How did the data disappear and then suddenly reappear? Why does it take three days to retrieve lost data? Can't SQL Server scale better than that? If you look at Microsoft's response to the disappearing data, you really have to wonder how the 'Softies would handle a data-destroying incident involving your company's data.

Consider: The initial problem notification, predictably, came on the Microsoft support board, the Windows Live Solution Center. Hundreds, then thousands of people reported that all of their messages were gone. The support staff handling the Solution Center must've realized they were facing a systemic problem, not a random sampling of clueless users. But instead of coming out with a definitive statement and posting it on the forum in blazing color, the support people just chased after individual reports, using cut-and-paste responses to users' cries of anguish.

Wednesday, April 27, 2011

Microsoft Releases Free Anti-Virus Software

Alright Windows users, no more excuses for not having up-to-date anti-virus or anti-malware protection. Microsoft has released its new Security Essentials software that offers real-time protection against viruses, spyware, and other malicious programs. It’s also free.

Although there are lots of anti-virus and anti-malware programs available (many which are also free), perhaps the Microsoft name and easy integration into Windows can help users who might not be familiar with some of the available programs get and stay protected.







Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




Microsoft says that Security Essentials is designed to run quietly in the background (no constant UAC alerts) and that it doesn’t hog CPU or memory usage. A constant complaint about some of the bigger name security suites is that they slow down the computer’s overall performance. Security Essentials also uses what Microsoft calls its Dynamic Signature Service, which is supposed to ensure that users are always protected and up-to-date, without having to wait for the next scheduled download.

windowssecurity3

Like any other standard security product, you can schedule full or quick system scans, exclude certain file types of processes from being scanned, and designate how you are alerted of various actions and what you want the default step to be.

Security Essentials is free — and no sign-up or registration is necessary — but you need to have a genuine copy of Windows XP SP2 or SP3, Windows Vista, or the upcoming Windows 7. Security Essentials will also run in Windows XP mode in Windows 7 — so if you plan on running XP mode to keep compatibility with older stuff, your security won’t be compromised.

With viruses and malware a constant threat to Windows users all over the world, it’s about time Microsoft offered an actual security package. One note, however — if you already have an anti-virus or anti-malware program installed, make sure you uninstall it before installing Security Essentials.

What do you use to protect your computers against viruses?