2009年6月10日 星期三

內地新電腦下月起須裝過濾軟件

裝有過濾軟件的電腦你會買嗎 ?

文匯報

【本報北京新聞中心記者李雪穎9日電】內地即將開始一場大規模的「攔網」行動。中國工業和信息化部發文要求,7月1日後出廠和銷售的電腦將預裝一款名為「綠壩-花季護航」(簡稱「綠壩」)的綠色上網過濾軟件。據悉,該款軟件具備攔截色情內容、過濾不良網站、控制上網時間、查看上網記錄等功能,保護青少年健康上網。據悉,中央財政將為此投入逾4,000萬元(人民幣,下同)。

 來自工業和信息化部《關於計算機預裝綠色上網過濾軟件的通知》稱,這款被稱為「綠壩」的綠色上網過濾軟件,旨在「有效過濾互聯網不良文字和圖像內容」,進一步鞏固整治互聯網低俗之風專項行動成果,堅持懲防結合,切實保護未成年人健康成長,推動互聯網健康有序發展。

專家指行政命令方式不妥

 「綠壩-花季護航」是一款圖形過濾軟件,全稱為「金惠堵截黃色圖像及不良信息專家系統」,具有通過技術手段為用戶過濾掉不良互聯網信息、控制上網時間、管理電腦遊戲等功能,並且還可以查看此前的上網記錄,上述功能便於父母了解子女的上網情況,並免於互聯網不良信息的影響。

 中國人民大學新聞學院副院長喻國明對本報表示,品牌電腦預裝這款過濾軟件適合在特定的環境下,如有未成年人的家庭或者未成年人使用較多的場合,這樣能夠保護他們免受不良網站影響。但是,預裝軟件應該是民眾自願的,政府可以倡導企業和用戶安裝這種軟件,但不應採取行政命令型的手段。喻國明認為,如果民眾反應較為強烈,不排除官方修正這個規定的可能。

多家廠商稱正研新規細節

 對於此次規定,電腦廠商的表態也不盡相同。方正科技新聞發言人表示,支持工信部的這一政策,保護青少年健康上網也是方正應盡的社會責任,他預計7月起銷售的電腦將全部安裝綠壩-花季護航軟件。

 海爾電腦相關負責人表示,海爾電腦支持工信部的這一政策,由於只是前兩天剛接到這一通知,且無實施細則,目前內部正在研究如何落實政策。

 聯想集團相關負責人表示,目前無法就此事發表評論。

 中國惠普公司相關負責人表示,惠普公司正在與美國信息技術行業協會密切合作,以獲得進一步的信息,並對一些問題進行確認,同時監測相關進程。

 戴爾中國公司新聞發言人表示,戴爾已經接到有關這一方面的通知,目前已經在評估和研究具體的實施細節。

Facebook Username

tech.blorge.com

Get your thinking caps on because you have just a few days to figure out the vanity URL you want to have associated with your Facebook page. They’re coming, not just for celebrities and well-known people, but for us ordinary people who Facebook has finally decided are deserving of a name rather than a number.

The rumors that have been doing the rounds for a couple of weeks have proved true - Facebook is introducing vanity URLs this Saturday (June 13). From 12:01 a.m. EDT on that day you’ll be given the option to choose a username for your Facebook profile which will then form the URL. So it’ll go from Facebook.com/01010101 to Facebook.com/ilovevanityurls or whatever you want it to be.

There are multiple reasons Facebook is doing this, the first being that there’s been a demand for it, particularly in light of the popularity of Twitter and its vanity URLs. It will also help SEO, help people connect with other easier by simply giving out their Facebook username rather than instructing someone to search for them, and introduce the possibility for @myname type responses to be made. The last of which is likely to turn Facebook more into Twitter than it already is.

Facebook is setting some ground rules on the process. Most importantly, once chosen, the username cannot be changed. Ever. Which means you need to get it right the first time. Unless you fancy setting a new account up and rebuilding your friends list just to get a new username.

Not that you’ll be able to do that for a while. In an attempt to prevent username squatting, Facebook will initially not allow anyone who set an account up after 3 p.m. today to choose a vanity URL. At least for the time being. I suspect it’ll be at least a month or two until the situation changes.

There was early speculation that the vanity URLs would have to be paid for but it looks as though Facebook has decided against charging for the pleasure of being a name rather than a number. Probably because only a tiny minority would have bothered paying the asking price. So free it is, thankfully.
StatCounter - Free Web Tracker and Counter

Related:
# Rumor: Facebook preparing to roll out vanity URLs
# Forget domain squatting, now it’s username squatting
# Facebook plans to launch Facebook Connect
# Google targeting Facebook and MySpace
# Facebook working to take on iTunes Store, Amazon MP3 Service

2009年6月3日 星期三

New malware attack infecting Web sites

news.cnet.com

Security firm Websense has put out an advisory warning Web site owners about malicious code that redirects surfers to seemingly safe sites.

About 40,000 Web sites appear to have been compromised with rogue JavaScript code that redirects Web surfers to a fake Google Analytics site, after which they get passed onto a site that tries to exploit Internet Explorer or Firefox vulnerabilities to infect that PC with malware, according to a Websense researcher quoted by Computerworld. Just for good measure, if the site can't find a browser vulnerability, it tries to trick the user into downloading a Trojan.

It's not clear how the sites were compromised, but Computerworld reported the redirect sites are being hosted in the Ukraine, implying that the Russian Business Network is behind the threat.

This is a separate scam from the Gumblar attack that made the rounds last week, according to Websense.

2009年5月21日 星期四

軟件缺陷15省市網絡大癱瘓

文匯報

【本報訊】自19日晚9時開始,內地多個省市的互聯網服務受到嚴重影響。至20日早晨,作為中國電信南方樞紐的南京電信部門仍然在忙於應付成千上萬的投訴電話:「網絡怎麼啦?是不是遭遇黑客攻擊?就算是黑客攻擊,能這樣大面積造成網絡癱瘓嗎?」

 從19日晚開始,內地使用電信網絡服務的網民就發現,上網出現嚴重問題:有的乾脆不通,有的則是不能瀏覽網頁。直到20日上午,許多網民還覺得網速比平時慢了許多,很多網頁不能正常打開。中國電信人工客服前晚起就忙於回應眾多網民的質詢,一直處於忙碌狀態。

 這種情況並非只出現在南京一個城市。據中新社消息,19日晚起,北京、天津、上海、河北、山西、內蒙古、遼寧、吉林、江蘇、黑龍江、浙江、安徽、湖北、廣西、廣東等地區均有網民反映上網出現故障,例如打不開網頁,QQ、MSN等即時通訊工具掉線,無法在網上收聽廣播、收看視頻等。

 對此,20日,中國電信江蘇分公司證實了這一說法。該公司的工作人員稱,此次網絡故障為全國範圍的故障。

製造商承認惹禍

 據電信部門稱,19日晚9點06分開始,由於暴風影音客戶端軟件存在缺陷,在暴風影音域名授權服務器工作異常的情況下,導致安裝了該軟件的電腦頻繁發起域名解析請求,引發網絡擁塞,造成大量用戶訪問網站慢或網頁打不開。據集團反饋的信息,全國範圍內各運營商在此期間也發生類似故障。

 對此,暴風影音的官方網站亦在20日下午發文承認了上述說法,並稱已在1小時內修復故障。

 對於罕見的網絡大癱瘓,許多網民稱,彷彿又回到了2006年底。當時台灣地震造成海底通信電纜中斷,內地網民對國際互聯網的訪問受到嚴重影響。

網民聲稱將索賠

 軟件故障引起這樣全國範圍的互聯網癱瘓,令業內人士大吃一驚,也引起很多網民不滿。有網民表示,網絡運行商不能按照合約提供網絡服務,將會對網絡運營商進行索賠。

 據悉,暴風影音是一個能播放大部分常見的影音檔案和網絡電視的影音軟件,在內地相當普及,僅其最新的2009年版本在新浪網就有超過4千萬的下載量。

小心 IIS 漏洞

轉用 Linux Apache server 啦 !

news.cnet.com

It apparently didn't take long for hackers to try to take advantage of a zero-day hole in Microsoft Internet Information Services (IIS).

Ball State University in Muncie, Ind., told The Register that servers running the program were breached on Monday, the same day Microsoft warned the public about the vulnerability.

Students accessing their iWeb pages on Monday saw messages saying the system had been hacked, The Register reported on Wednesday. There is no evidence data was stolen or malicious files uploaded, however the iWeb accounts were expected to be offline until Thursday or Friday, according to Patty Lucas, a senior help desk support administrator for the university's computing services department.

Microsoft, meanwhile, said it has investigated a public report of a targeted attack on the IIS hole, but did not specify whether it was the Ball State University breach that was looked into.

The investigation "revealed that the vulnerability was not exploited to accomplish this attack," a Microsoft spokeswoman wrote in an e-mail late on Wednesday. "Microsoft is still not aware of attacks that are trying to use this vulnerability or of customer impact at this time."

The computing services department referred a call from CNET News on Wednesday afternoon to the communications department, which was already closed for the day.

The security vulnerability could allow an attacker to gain access to a location that typically requires authentication by using a specially crafted anonymous HTTP request, according to the Microsoft security bulletin. The problem exists in the way that the WebDAV extension for IIS handles HTTP requests.

According to a posting to the Full Disclosure security e-mail list on Friday, the IIS security vulnerability was discovered on May 12 by Nikolaos Rangos.

2009年5月20日 星期三

Gmail增翻譯功能一按完成

蘋果日報

Google 周 二 開 始 在 旗 下 的 免 費 電 郵 服 務 Gmail 加 入 自 動 翻 譯 功 能 , 讓 用 戶 只 要 按一 按 滑 鼠 鍵 , 就 可 將 電 郵 訊 息 翻 譯 成 另 一 種 語 言 , 目 前 可 供 翻 譯 的 語 言 達 數 十 種 之多 。

2009年5月14日 星期四

中國勁 !

蘋果日報

中國開發麒麟作業系統
力敵美國網絡戰
2009年05月14日
中美網絡軍備競賽已悄悄展開。美國《華盛頓時報》昨天(周二)報道,北京已自行開發一套「麒麟」電腦作業系統,在政府和軍事電腦網絡應用,以防堵美國軍事和情報發動網絡戰。北京也加強招攬黑客和強化攻擊網「鬼網」,網絡作戰能力跟美國和俄羅斯成鼎足之勢。
據報道,美國國家情報局和戰略司令部顧問科爾曼( Kevin Coleman),上月底在國會聽證會透露,中國已部署好打網絡戰,早於 2001年開始研發麒麟電腦作業系統,政府和軍方前年開始轉用,大大強化伺服器安全防衞能力,使美國網絡攻擊能力大為削弱。美國網絡戰向來針對安全性較低的微軟視窗、 Linux和 UNIX,面對中國國產麒麟,暫未做到知己知彼。
黑客加「鬼網」發動攻堅

科爾曼說,北京正以「戰爭狀態」在網絡大舉搜尋美國政府和工商界的機密資訊,網絡戰能力已跟美俄旗鼓相當;而且中國正加強保護電腦和資訊網絡,反守為攻能力加強,相反美國作業系統採用開放程式碼,較易受入侵。他警告:「我們正處於網絡戰軍備競賽初期,需要作出回應。」
中國依賴麒麟加強防守,攻堅則由黑客和「鬼網」發動。
加拿大電腦安全專家羅賀辛斯基( Rafal Rohozinski)透露,他經兩年調查發現,中國政府贊助的「鬼網」策劃了一個極度精密的全球電腦攻擊網,鬼網的電子攻擊源自海南島的電子郵件,專門針對大使館和非政府組織電腦。
中國軍方又不斷招募黑客,像 2005年招募了四川大學研究生譚代林(譯音),連續 30天每天 16小時訓練他發動網絡攻擊,同年年底他已成功入侵五角大廈電腦。
美國《華盛頓時報》

2009年4月27日 星期一

Netbooks 2.0

www.reuters.com

SAN FRANCISCO (Reuters) - A new class of cheaper, smaller netbook computers might upset the IT establishment this year and potentially usher in new players in a hotly competitive market.

The biggest change in the new pint-sized laptops is what they won't have: Intel Corp (INTC.O) chips or a Microsoft Corp (MSFT.O) Windows PC operating system, which dominate netbooks today.

The new netbooks, which use less energy, will run on the low-power ARM processor platform now used in nine out of 10 mobile phones, rather than Intel's x86-based Atom chip. The U.K.-based ARM Holdings Plc (ARM.L) licenses the chip technology.

As many as 10 ARM-based netbook models could hit the market this year, according to ARM, which declined to identify specific manufacturers. Major PC players and Asian contract manufacturers alike are interested, analysts say.

Enderle Group analyst Rob Enderle called the new netbooks "incredibly disruptive," saying: "This is a market that puts the existing PC structure at risk."

While analysts say it's not yet clear if consumers will embrace the ARM devices, interest has been galvanized by the emphasis on power efficiency, prices as low as $200 and the promise of anywhere, anytime computing on PCs small enough to slip into a purse.

What's sacrificed is users' familiarity with PC-based interfaces and systems and sheer processing power. The current $300-$400 Atom netbooks are already mainly good for just surfing the Web and less graphics-intensive applications.

"We're right in the middle of a huge shift in the market," said Eric Openshaw, U.S. technology leader for Deloitte LLP.

Openshaw said non-Windows netbooks will need to demonstrate a simple and accessible user interface at the application level if they hope to gain traction with consumers.

Windows XP can't run on ARM, so the new netbooks will have Linux-based software, including, analysts and industry executives say, Google Inc (GOOG.O) Android, which has been used so far in smartphones.

But don't count Microsoft out just yet. Although the software giant declined to comment when asked if it is planning an operating system for the new netbooks, analysts say it could easily enter the market if it chose.

Intel pointed out there are as yet no ARM netbooks on the market and that its Atom chip has a full year's head start.

"We're not slowing down, we fully expect competition and we continue to believe that Atom is the right choice for our customers and consumer," said spokesman Bill Calder.

NEXT WAVE

The still-evolving netbook market is growing thick with players from all over the tech sector. Wireless carriers such as AT&T Inc (T.N) are helping lead the charge, while graphics chipmaker Nvidia Corp (NVDA.O), wireless chipmaker Qualcomm Inc (QCOM.O) and Freescale Semiconductor Inc have all designed ARM-based processors that can be used in netbooks.

2009年4月25日 星期六

世界最強電腦病毒Conficker

hellostation.blogspot.com

據法新社最新消息,已經潛入全球百萬部電腦的超強電腦病毒將在四月一日愚人節再度演化,導致日後更難加以根絕,但預料還不致於帶來大浩劫。

微軟公司已經組成專案小組,想盡辦法要剿滅這隻叫做Conficker或DownAdUp的病毒,還懸賞25萬美元緝拿撰寫這隻電腦蠕蟲的元兇。

專案小組人員之一,趨勢科技網路威脅研究員佛格森 (Paul Ferguson)說,這隻難纏的電腦蠕蟲將根據程式設定在25日進行演化,變得更難遏止。

佛格森說,「目前沒有證據顯示這個病毒會在四月一日變為攻擊模式或降低任何電腦的有效負載。」

沒有持續更新微軟RPC伺服器服務的電腦或網路,這隻電腦病毒就會入侵並進行自我複製。

它會透過網路感染,也會躲在儲存資料的USB隨身碟,從一個電腦傳染到另一個電腦。一旦進入電腦,就會深深紮根,還會建立防衛系統讓外界很難移除。

惡意軟體可能因此啟動,竊取被感染電腦中的資料,或將控制權置於駭客之手,讓他們集合所有「殭屍電腦」變成「殭屍大軍」。

Conficker最厲害的是它會利用殭屍電腦來破解密碼。

微 軟已經修改免費的惡意電腦軟體移除工具(Malicious Software Removal Tool )來偵測和消滅Conficker。該公司安全反應部門主管巴德(Christopher Budd)說,「由於這隻病毒持續演化,微軟和其他合作公司將持續找出瓦解Conficker威脅的新方法,讓消費者有更多的時間來更新系統。」

建議電腦使用者持續更新目前使用的防毒工具以及微軟系統,並且用更牢靠的密碼來保護電腦和檔案。

Conficker被設定為一天攻擊250個網站,從控制殭屍電腦的主機下載指令。根據電腦安全公司F-Secure的海波寧 (Mikko Hypponen)表示,從25日開始,這隻電腦蠕蟲將開始每天連結5萬個網站,而且更難偵測得到。

海波寧說,「基本上他們提高賭注,讓我們日子更難過。」他說,「他們發現好人已開始攔截主電腦與殭屍電腦之間的聯繫。」

防毒專家說,這種病毒的擴散速度在年初非常快速,現在已經變得緩慢,但是還沒更新微軟系統的電腦還是可能會感染。

海波寧在F-Secure網站上發佈一則訊息表示,已經有100萬至200萬台電腦遭到Conficker入侵,據信這批電腦大部分感染的是較早版本的Conficker,裡面沒有4月1日演化的指令。

www.searchsmbhk.com

02 Apr 2009

初步估計已感染超過1200萬部電腦的超級電腦病毒Conficker,被預計於昨日的愚人節發出新指令,發動大規模攻擊,進行網絡犯罪活動,但防毒軟件公司稱暫未發現有任何明顯的破壞活動出現。

Conficker 主要經由Windows 伺服器修補漏洞、猜測網絡密碼、以及 USB 記憶體。它們會找尋不同域名的網站伺服器,然後看準保安漏洞,把啟動程式下載至系統,蠕蟲引發的最典型問題是網絡用戶無法登入其個人帳戶,這是由於蠕蟲試 圖猜測或利用密碼破解方法竊取網絡密碼所致。當蠕蟲三次輸入密碼失敗,密碼便會自動鎖上,令用戶無法登入。

一 旦電腦受到蠕蟲感染,病毒便會發揮強勁的自我保護功能。而變種 Conficker 每天可自行衍生50,000個域名,然後利用其中 500個地址進行繁殖和散播病毒。此外,它還可自行破解使用簡單密碼的網絡共享程式和軟件,然後將惡意程式複製到資料匣,再感染其他使用者;此外,還會嘗 試透過其他可攜式儲存設備擴大感染範圍,更嚴重的是,黑客可利用遭受 Conficker 感染的電腦組成大型殭屍網絡(Botnet),將惡勢力進一步擴張。換言之,一旦用家的電腦中了 Conficker,就表示電腦變成國際網絡犯罪集團一分子。

F-Secure 保安事故應變經理謝榮輝指,儘管Conflicker破壞力強勁,但暫時沒有迹象顯示有具破壞性的事故發生,懷疑他們故意保留實力,伺機再出擊。

根據F-Secure 保安實驗室的數字,截至2009 年2 月香港共錄得4544宗Conficker感染個案,約佔總數的0.24%,在全球排行榜佔第40 位。

「感 染此蠕蟲的症狀之一,是會阻擋電腦存取網際網路安全公司的網站,」McAfee Avert Labs 專家 Dave Marcus 說。「一個很好的測試指標,就是試著連線到可下載防毒軟件的網站。如果無法連線,那您最好馬上利用搜尋功能到網上下載工具,掃描與清除已經中毒的電腦。您 也應該安裝 Microsoft 的修正程式來避免蠕蟲再次自我安裝。」

由 於 Conficker 會阻擋知名的安全網站。如果使用者無法取得 Stinger 清除工具,則可以利用搜尋功能到網際網路搜尋「stinger virus removal」。使用者也可以從未中毒電腦下載該工具,並利用 USB 磁碟機將其傳輸到中毒電腦進行清除作業。

用戶可到以下兩個網址,下載免費掃毒工具:

http://support.f-secure.com/enu/home/onlineservices/fsec/fsec.shtml
http://www.mcafee.com/us/enterprise/confickertest.html

防毒專家稱,要避免Conficker肆虐,用戶應經常更新和安裝最新修補程式,及安裝有效的防毒軟件。


2009年3月20日 星期五

2009年4月5日WordCamp

WordPress 是一套知名的開放源碼網誌軟件,讓使用者自行建立網誌。

WordCamp 是一個由 WordPress 創辦的會議活動,讓 Bloggers、 WordPress 使用者、WordPress 開發者互相交流分享。WordPress 創辦人之一 Matt Mullenweg 和 Automattic 公司的將會來臨香港進行演講和交流,也讓 Matt 藉此了解香港 bloggers、使用者、WordPress 開發者。

WordCamp 將會首次在香港舉行,詳情如下。

日期:2009年4月5日(星期日)
時間:上午10時至下午3時(9時開始登記)
地點:香港科學園
費用:港幣 25 元(Early-bird登記只收 10 元)

香港 WordCamp 官方網頁: http://hk.wordcamp.org/
WordPress 官方網頁: http://www.wordpress.org/

歡迎各位轉載消息給其他人。

Sammy Fung

Software Developer, Engineer.
Personal Blog - http://sammy.hk