Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, March 22, 2008

Is KB950627 News For You ??

I was just looking at my favorite news aggregator, Techmeme when I saw a news link ==> Microsoft Security Advisory (950627) for Microsoft Word. And I asked myself, does Techmeme always show every of these vulnerability messages?? Coz I never thought these to be " tech news" in the real sense unless they were really something serious and has already caused havoc around the world.

If you look at the vulnerability being talked about, you'll realize that similar vulnerabilities have existed previously without much wide-spread exploit. And not just for Microsoft products, but a lot of other products and OS. Infact these "zero-day" exploits are pretty much available for someone who can find exploits in every OS, software and quite a few other things in life :))

But the problem I think here is that Microsoft is always the favorite target of journalists and media people. It also happens to be the favorite punch-bag for a lot of tech evangelists. There are lots of other "real news" that can be aggregated or linked by popular sites. Or is it just a flaw with algorithmic aggregators, where links are all that matters and not the content or significance??

Monday, February 11, 2008

Download drivers to make Asus EEE PC on 1024x768

Anyone who has used the Asus EEE PC will know that the 7" screen does get small at times. During those times, you wish you had a larger screen or sometimes you want to increase the screen resolution. The default resolution on the EEE is very small and would be great to have it increased to 1024x768. I had seen videos on youtube showing off the higher resolution, but couldn't find how to do it.

Today I found a driver which is able to increase the resolution to 1024x768. Its a Win XP driver and will scale 800×600 and 1024×768 down to the EEE PC’s native resolution. The site also specifies for the newbie how to install the driver and get the higher resolution running.

You can download the drivers here.

*Disclaimer* If your Eee breaks for some reason its not my fault TRY AND YOUR OWN RISK

Monday, December 24, 2007

Apple Wants OSX Genuine Advantage

According to this patent filing, we can see that Apple wants something similar to Windows Genuine Advantage (WGA) that is part of Windows. The patent was OSX-CDfiled by Apple on Dec 13, 2007 and has the subject, "RUN-TIME CODE INJECTION TO PERFORM CHECKS". Apple wants to have code injection into any running application and make checks if the application is valid or not and if it has necessary rights to run on the specific hardware or software platform. Thus, this is a DRM thing that Apple wants to add to OSX.  

DRM or Digital Rights Management is one way to govern data/applications and has been "talk of the town" for media files and content. If memory serves me right, Steve Jobs was last seen complaining against DRM to audio companies, but somehow he thinks that adding DRM to the OS is a good thing. Yes, it can be used for good things, when users are given the rights to manage the applications or data. But looking at the abstract, "an authorizing entity (e.g., an application owner or platform manufacturer)", it doesn't seem like the owner of the computer has much of the rights.

Vista has special checks of DRM as part of WGA and Microsoft uses it to check the validity of Windows users. WGA hasn't been able to prove the genuineness of the applications running maliciously on Windows and is only a waste of CPU cycles. Also it checks for genuine copy of Windows, but has been flagging some legal copies as pirated copies for sometime now.

Apple may or may not bring those ill-effects by implementing DRM in a different way, but in its very nature DRM is a hindrance to freedom. May be some people will claim DRM to be the price for freedom, but in my humble opinion, its only a way in which powerful people can show their might. Let's hope Apple doesn't bring it to OSX anytime soon!!

Thursday, September 20, 2007

MPSC Website Defaced

The Maharashtra Public Service Commission (MPSC) which selects the best brains from Maharashtra for government jobs had their site defaced on the 18th Sep, 2007. The government of Maharashtra owns the website and hosts a lot of different content on it. Different government documents along with student results for new jobs and job posting are also hosted on this website.

The MPSC website: http://mpsc.maharashtra.gov.in as of writing this post, is not working and was not reachable. Although the clean up work was done(by cleanup I mean, stopping access), it could not escape the hands of Google's cache. The smaller screenshot of the naughty work by the Saudi hackers is below. You can go bonkers by seeing a larger, clearer version from google's cache!!

The Maharashtra Government has recently been pushing a lot of e-governance, which means government officials are asked to leave their big paper books and get on the computer. This has resulted in a large number of people accessing computers for their daily work in government offices. The irony of the matter is that Mumbai, which is the state capital of Maharashtra boasts of having India's very powerful cyber cell, which looks to prevent cyber crime as well as book cyber criminals. But lately it has been only giving directives to cyber cafes how to monitor people on what they are doing!! Basically, they just want to easvesdrop on people's privacy. Instead of doing that, if they would have invested in basics of network security and better safegaurding of government servers, such incidents would not happen.