Microsoft has issued a hotfix for a security permissions bug that can affect the root folder under the Windows 7 release candidate released last week. Microsoft also recommends that affected users reinstall the Windows 7 operating system.
Only the 32-bit versions of Windows 7 Release Candidate Ultimate (Build 7100) are affected, Microsoft said.
Microsoft's Knowledge Base article 970789 details the problem, described as an issue with the root folder of the system drive. That root folder contains incorrect access control lists.
"One effect of this problem is that standard users such as non-administrators cannot perform all operations to subfolders that are created directly under the root," the article states. "Therefore, applications that reference folders under the root may not install successfully or may not uninstall successfully. Additionally, operations or applications that reference these folders may fail. "For example, if a folder is created under the root of the system drive from an elevated command prompt, this folder will not correctly inherit permissions from the root of the drive," the article adds. "Therefore, some specific operations, such as deleting the folder, will fail when they are performed from a non-elevated command prompt.
In turn, users will receive an "access is denied" error.
The fix is available via Windows Update, which will push a Cleanwin7rcroot.exe version 6.1.7100.15 tool to a user's PC.
But to "make sure that this update does not affect your user experience," Microsoft recommends reinstalling Windows 7 from a clean, formatted partition, then immediately running the Cleanwin7 tool, apparently because the newly created folder do not inherit the proper security descriptors. Even after the tool is run, Microsoft says, the permissions/descriptors will not be propagated to any subdirectories.
The Knowledge Base story was first reported by ZDNet.
Selasa, 12 Mei 2009
Root Bug Hits Windows 7; Microsoft Advises Reinstall
Diposting oleh i'm händsomë™ di 04.46 0 komentar
Label: knowledge
Senin, 04 Mei 2009
Adobe Announces Acrobat, Reader Fix
Adobe has announced that they will release an update for a newly-reported vulnerability in Acrobat and Reader on all platforms by May 12th.
The vulnerability was the first of two acknowledged by Adobe on Wednesday. They say the updates will cover Windows versions of Acrobat and Reader 9.x, 8,x and 7.x, and UNIX and Mac versions 9.x and 8.x.Adobe also has confirmed the second vulnerability, but says they have only been able to confirm it as exploitable on UNIX. They are still investigating this issue. The researcher who reported the vulnerability only claimed to have tested on Linux.
In the meantime there are still no reports of exploits in the wild. If you want to mitigate the vulnerability(*) you can do so by disabling JavaScript in Acrobat or Reader. To disable JavaScript in the Reader or Acrobat follow these instructions:
1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the 'Enable Acrobat JavaScript' option
5. Click OK
Diposting oleh i'm händsomë™ di 09.43 1 komentar
Label: knowledge
Rabu, 29 April 2009
Microsoft Vine Beta Targets 'Societal Networking'

Is Microsoft learning something from its $240 million investment in Facebook? The software giant this week unveiled Vine, a beta social networking application intended to help families, friends, or neighbors keep in touch.
Vine is a downloadable dashboard accessible with a Windows Live ID, though it can also be accessed via mobile phones and e-mail.
Select your location, the people with whom you want to keep in touch, and start sending alerts or reports to those contacts.
"Microsoft Vine is appropriate for any small group of people who want to stay in touch, informed, and involved – families, neighbors, sports teams, school committees, volunteer groups, or faith-based groups," according to Microsoft.
Vine is currently available only in the U.S. To access it, users must request an invitation by sending in their e-mail address at Vine.net."Microsoft Vine aims to create an inclusive network so that ultimately anyone can participate, through a social networking application such as Twitter or Facebook or using e-mail, any computer connected to the Internet, or a mobile phone, kitchen phone, or special needs device," Microsoft said.
What's included in Vine?
When you specify your city, Vine will alert you when there's a news story or public safety announcement associated with your location via a blue notification. The company will pull from over 20,000 local media sources and public safety information from the National Oceanic and Atmospheric Administration.
Vine lets you specify which types of information you want to receive -- select alerts using the Vitals management area, and who can send alerts to you in the People management area.
Have something you want to share that you can't say on Facebook, Twitter, MySpace, in an e-mail, a text message, LinkedIn, or a phone call? Set up "alerts" for quick blasts of information, or write "reports" for more detailed information.
"Check in safe and well to let your family know you are okay, let trusted neighbors know you're headed out of town, keep people informed of situations that matter, or share general information like the team practice schedule for the week," Microsoft said.
Microsoft has dubbed the effort societal networking.
"Over time, the network will provide advanced capabilities to help individuals, communities, and organizations work together to fundamentally improve quality of life and be better prepared for any disaster," the company said. "Microsoft is working toward a new generation of software and services that will enable society to self-organize effectively toward a broad range of goals."
To access Vine, you must have a PC with Windows Vista or XP with SP2, a broadband Internet connection, Internet Explorer 6 or Firefox 3, 100MB of space for the Vine download, and 500MB for the .Net framework version 3.5 with SP1.
Diposting oleh i'm händsomë™ di 04.49 0 komentar
Label: knowledge
Senin, 27 April 2009
Microsoft Windows 7 Release Candidate: An Early Look

The Release Candidate puts some finishing touches on some new features and adds a good deal of polish to the OS.
The Windows 7 Beta, the next version of Microsoft's flagship operating system, was all about finalizing underlying changes to the system architecture. The Release Candidate, which the company will make available on the TechNet website on April 30th and available for public consumption on May 5th, puts some finishing touches on some new features and adds a good deal of polish to the OS. And that polish is apparent from the first moments you begin installing it: The install routine has been refined, with new icons and a few splash screens ("Checking video performance") with a starburst-type effect. Even the Starting Windows and log-on screens gain a cool, patterned background.The Windows 7 Beta was lauded for its stability. The Release Candidate makes the operating system feel just a touch faster; it's quicker to load and just a bit more responsive. And you'll be happy to hear that it installed in no time, too—as little as 20 minutes in my experience. Compared to the hour it often took to install Windows Vista, this thing flies.
Users will find many welcome additions to personalization options, including substantially more themes, more user icons, and new sound effects. New Aero Themes (they're no longer called Windows Themes) include Architecture, Scenes, and Characters, and you'll find 36 user icons rather than the 12 included in the beta. The aged Device Manager and the Control Panel have gained new icons as well, but more important, if you pin the Control Panel to the Taskbar, you'll note a very versatile new jump list. As you play with these "smart" jump lists, they become more and more useful, learning the most recently or most commonly opened files; how did we live with "dumb" Taskbar icons before?
The Control Panel itself has seen a few minor tweaks. A new "View by" menu appears beneath the Control Panel search box, which defaults to the category view but also lets you see all Control Panel items (rather than clicking the "All Control Panel Items" item, as in the beta). The Windows 7 Beta had a whopping 59 Control Panel items; the Release Candidate whittles that list down to 47. Gone are: Biometric Devices, ClearType Text Tuner, Default Location, Feedback (released just for the beta, this one doesn't really count, I suppose), Game Controllers, iSCSI Initiator, Offline Files, Pen and Touch, System Icons, Tablet PC Settings, Text to Speech, and Windows SideShow. Many of those features have been swallowed by the Devices and Printers control panel, but a few are surprising. What's happened to SideShow, for example?
On the Internet side, IE8 is out of beta! The Windows 7 beta came with a beta version of IE8, build number 8.0.7000.0. In the Release Candidate, the beta tag is gone, and IE8 is updated to version number 8.0.7100.0. Is this a newer version? Hardly. The build string of Internet Explorer is tied to the operating system you've got it installed on. The beta was build 7000, and the Release Candidate is build 7100. Install IE8 on an XP system and you'll see a 6001 in that build string.
Windows Media Center has gone through dramatic changes between Windows Vista and Windows 7. Eagle eyed users of the Release Candidate will note that PlayReady, Microsoft's new DRM scheme for protecting recorded television shows, is being updated to version 1.3—no word yet on what changes are included there, or when the scheme will be available for download on Microsoft's Web site. The inclusion of Internet TV in the Guide is a big leap forward, exposing even those without an integrated TV tuner to the fun of IP based TV. This feature was in the Beta, however, and despite the recent efforts to alphabetize items listed under the Movies, News, Sports, and other categories, the hoped for integration of Hulu, TV.com, and other IP-based TV doesn't exist. Yet.
Diposting oleh i'm händsomë™ di 04.40 1 komentar
Label: knowledge
Conficker Virus Starts to Attack PCs, Experts Say
A malicious software program known as Conficker that many feared would wreak havoc on April 1 is slowly being activated, weeks after being dismissed as a false alarm, security experts said.
BOSTON - A malicious software program known as Conficker that many feared would wreak havoc on April 1 is slowly being activated, weeks after being dismissed as a false alarm, security experts said.Conficker, also known as Downadup or Kido, is quietly turning an unknown number of personal computers into servers of e-mail spam, they added.
The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote server that effectively controls an army of computers known as a botnet.
Its unidentified creators started using those machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response, the research arm of the world's largest security software maker, Symantec Corp.
Conficker installs a second virus, known as Waledac, that sends out e-mail spam without knowledge of the PC's owner, along with a fake anti-spyware program, Weafer said.
The Waledac virus recruits the PCs into a second botnet that has existed for several years and specializes in distributing e-mail spam.
Conficker also carries a third virus that warns users their PCs are infected and offers them a fake anti-virus program, Spyware Protect 2009 for $49.95, according to Russian-based security researcher Kaspersky Lab. If they buy it, their credit card information is stolen and the virus downloads even more malicious software.
Weafer said that while he believes the number of infected machines that have become active is relatively small, he expects a consistent stream of attacks to follow, with other types of malware distributed by Conficker's authors.
"Expect this to be long-term, slowly changing," he said of the worm. "It's not going to be fast, aggressive."
Researchers feared the network controlled by the Conficker worm might be deployed on April 1 for the first time since the worm surfaced last year because it was programed to increase communication attempts from that date.
The security industry formed a task force to fight the worm, bringing widespread attention that experts said probably scared off the criminals who command the slave computers.
That task force thwarted the worm partially by using the Internet's traffic control system to block access to servers that control the slave computers.
Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.
The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, southeast Asia, China and Latin America.
Diposting oleh i'm händsomë™ di 04.38 0 komentar
Label: knowledge
Kamis, 23 April 2009
Eizo Nanao Adds Presence Sensor to LCDs
Presence sensors are most often seen in air conditioning units, but Eizo Nanao announced an integration of the technology to its new LCD monitor models.
Two models - one a 20-inch display, the other a 23-inch model - will be fitted with infrared sensors that can detect the presence of a user and distinguish it from inanimate objects directly in front of the monitor such as office chairs. This feature, called the "EcoView Sense" can scan the area within 120 cm right in front of the LCD. If, within a 40-second scan, it fails to determine the presence of a human user, the monitor shifts to a power-saving mode that adjusts the screen display.
But the sensor doesn't just work to determine a user's presence, it also scans for the degree of ambient lighting and adjusts the backlight intensity to complement it. In power-saving mode, both models consume only 0.7 watts or lower, whereas the 20-inch and 23-inch monitors would normally use 25 watts and 18 watts of electricity respectively. Of course ordinary monitors available in the market today would already have a feature that could turn itself off after a pre-determined time of inactivity. The difference lies in the presence sensor's ability to adjust backlighting as was mentioned and, for what it's worth, the ability to quickly revert back to regular mode upon detection of a user.
Diposting oleh i'm händsomë™ di 22.59 0 komentar
Label: knowledge
Jumat, 17 April 2009
Why the Spam Carbon Footprint Study is Wrong

McAfee just released the details of a new study, conducted and published by ICF International, which seeks to measure the carbon footprint of spam. The study's conclusions: The global annual energy used to transmit, process, and filter spam is the equivalent to powering 2.4 million homes, and spam filtering saves 135 terawatt hours--the equivalent of taking 13 million cars off the road. The study decides that the average greenhouse gas emissions associated with an individual spam email are about 0.3 grams of CO2. Fascinating, right? But it's completely wrong.
There's one basic tenet of this study I take issue with, and it centers around the finding that most of the energy consumption associated with spam (nearly 80%) comes from end-users deleting spam and searching for legitimate email.
The study doesn't detail the methodology , but we can conclude that the real carbon footprint of a spam message lies in the energy wasted by PCs, notably the fixed amount of time users spend dealing with spam. The math sounds solid: Figure out the average power that a PC draws, the average amount of time spent dealing with each message, and the total volume, and calculate away.
But is that energy wasted really associated with spam? Do people turn on their PCs, read their email, and then turn them off? Or would their PCs simply be on anyway? If you had absolutely no spam in your inbox, would you turn your PC off earlier--or use the extra time you've saved to play more World of Warcraft? Business users leave their PCs on all day regardless of whether they've finished sorting their inboxes, so in my eyes you can't count any of the energy exhausted by their PCs. Besides, many email users don't have to deal with (much) spam anyhow, with filters on the job. (Well, my old Hotmail account gets hundreds of spam mails a day, but really, I only have to deal with them when the computer is supposed to be on anyway).
In my eyes, you could really substitute "Bejeweled" or email in general or any other computing activity for spam and reach a similar computing, if all we're doing is quantifying uptime. Bottom line: PCs waste energy, and humans leave them on too long, wasting energy. But spam? It's kind of meaningless here.
Diposting oleh i'm händsomë™ di 08.21 0 komentar
Label: knowledge
Rabu, 01 April 2009
Your Conficker To-Do List
Worried about Wednesday's Conficker update? Here are eight action items that will help you weather the potential storm.
Unless you're living in a cave, by now you've heard that a worm known as Conficker (or Downadup, or Kido) has infested computer systems around the world, and that it will do something April 1st, though nobody knows exactly what. How can you be sure your computer doesn't become a casualty? Here are eight action items—things you can do yourself to weather the potential storm.Double-check Windows Update
The worm weasels into computer systems through a Windows vulnerability that was patched last October, and once in place it interferes with the Windows Update system, to protect itself. So, verify that your system is up to date. XP users should launch Internet Explorer (no other browser will do), visit www.windowsupdate.com, and click the "Review your update history" link. Vista users should launch Windows Update from the Start menu and click the "View update history" link. In particular, you want to see KB958644 in the list—that's Conficker's entry point. If your latest update is any older than March 2009, that's not good. Go back to the main Windows Update page and install all critical and security updates.
Turn Off AutoRun
Sure, it's convenient that CDs and DVDs automatically launch their programs when you put them in. You may even be happy to see the window that asks what you want to do when you insert a USB key. But Conficker and other worms subvert this handy feature to spread their infestation. Use a Conficker-tainted USB key to share pictures or music with a friend, and you're sharing the malware, too. The feature's convenience just isn't worth that risk. Here are instructions to turn off AutoRun.
Update Your Protection
It goes without saying that you should always keep your security software and malware definitions up to date. Don't just rely on automatic updates, as the worm has been known to interfere with these. Dig into your security software and manually launch an update, then watch to make sure it completes the process successfully. Now launch a full system scan.
Get a Second Opinion
Your security software can probably handle the Conficker worm, but why take a risk? Visit the Conficker Working Group's Repair Tools page to find the latest collection of threat-specific cleanup tools. At present, this page links to tools from AhnLab, ESET, Kaspersky, F-Secure Malware Removal Tool, McAfee, Microsoft, Sophos, Symantec, and TrendMicro. Run one or more of these to verify that your system is clean.
Check Your Servers
Conficker also attacks network shares using what's called a dictionary attack. It tries to gain Administrator access using a bunch of common passwords and often lucks out. If you're responsible for a network, whether it's an office or home network, check all of the network shares and make sure they're protected with a strong password. While you're at it, check the root folder of each drive for the presence of an AUTORUN.INF file or any unrecognized software—these are clues that Conficker is already in residence.
Inoculate Your Servers
Products like Faronics Anti-Executable prevent the launch of any program that's not pre-approved. On an individual workstation where installing new software is common, this kind of program can prove annoying, but server configuration is much slower to change. It's a little late to apply this kind of program-whitelist protection now, but going forward you'll want to consider it for your servers. When no unapproved program is allowed to launch, it doesn't matter how cleverly malware morphs—it's powerless.
Back Up, Back Up, Back Up
Conficker isn't the only possible threat to your important data: Your computer could fail; thugs could steal it; a car might drive through your office wall and flatten it. If you have a backup system in place, make sure that it's operational and that you have a recent full backup. If not, get yourself a high-capacity USB drive and copy all your most essential files onto it. (After making sure you've disabled AutoRun as described above, of course.)
Scared? Hide Under the Covers
Does the fact that Conficker's final aim is unknown give you the willies? Are you shaking with worry that a hitherto-unknown "D" variant will show up tomorrow and zap your computer? OK, it's not very likely, but if you're concerned, take a day off from the Internet! Unplug the network cables from your computers, disable the wireless connections, and spend the day working on local documents or revisiting your favorite pre-Internet games.
Diposting oleh i'm händsomë™ di 03.37 0 komentar
Label: knowledge
Microsoft Names Mobile Apps Store Partners
Microsoft on Monday announced more than two dozen partners for its upcoming Windows Marketplace for Mobile, including EA Mobile, Pandora, and Netflix.
Mobile apps from the companies will be available in the Windows app store when it debuts later this year. Other partners include AccuWeather.com, Associated Press, CNBC, Facebook, MySpace, Gameloft, Sling Media, and Zagat Survey. Users with Windows-based phones will be able to buy the apps with their credit cards or have the purchases posted to their mobile phone bills. Don't like what you bought? The Marketplace will offer the opportunity to return the app for a refund within 24 hours.
Developers will also be able to add updates to their apps for free.
"We know it's the experiences that mobile phones can offer to people that really matter," Robbie Bach, president of the Entertainment and Devices Division at Microsoft, said in a statement. "The continued support from the world's top mobile operators, manufacturers and developers means you can choose the Windows phone, applications and experiences that are right for you."
"EA Mobile develops some of the world's most fun and advanced mobile gaming applications, and we understand the importance of product quality and consumer discovery as keys to success," said Adam Sussman, vice president of Worldwide Publishing for EA Mobile.
The app store will also focus on social networking. MySpace has announced support for Microsoft Windows Mobile and Microsoft Silverlight, and LG will pre-load the MySpace application on phones that are expected to be available in the second half of 2009.
In addition, Microsoft has created a new Facebook application, which will be available for free in April, that makes it easier for people to take video on their phone and upload it to Facebook.
Windows Live for Mobile will also be available in 25 languages as a free download starting April 2. It includes mobile versions of Hotmail, Messenger, Contacts, Live Spaces, Search, and a photo uploader. Users with Windows Mobile version 6 phones can download it Thursday at wl.windowsmobile.com.
The mobile version of Hotmail will also get a revamp, with an updated interface, navigation enhancements for touch-screen phones, the ability to view HTML within e-mail, and improved e-mail search functionality. The beta version will be available at m.mail.live.com.
But how does it look? Microsoft also announced that it will partner with the Design Museum London and the Council of Fashion Designers of America to develop custom themes for Windows-based phones. The first in a series of designers to create themes will be Isaac Mizrahi.
"Phones are just as much a fashion statement as the clothes you wear," Mizrahi said in a statement. "Cast aside your old black phone, and make this year about color and fun."
Later this year, Microsoft will also offer the Theme Generator, which lets Windows phone users set pictures from their PCs as background images that they can color and personalize via their navigation bar.
Diposting oleh i'm händsomë™ di 03.30 0 komentar
Label: knowledge
Dell Adds 720p Resolution Option to Mini 10
Dell has said previously that the Inspiron Mini 10 netbook would eventually come with two screen resolution options, an internal HD TV tuner, and a high-capacity battery. On Tuesday, the company lived up to the first part of its three promises. In addition to the ho-hum 1,024-by-576 resolution that came with the previous version, a 1,366-by-768 (or 720p) option is now available for a $35 upgrade. So far, the Mini 10 is the only netbook that offers such a resolution.
The HP Mini 2140 was the first netbook to offer dual resolution options when it announced earlier this year, but has yet to sell the 720p option on its website. The Mini 10 is not the only netbook sporting a WXGA resolution, though. The Inspiron Mini 12 is the company's 12-inch netbook that ships with a standard 1,280-by-800 resolution. Recently, Samsung has also announced a 12-inch netbook, the NC10-14GB, that will undoubtedly feature a 1,280-by-800 resolution.
Diposting oleh i'm händsomë™ di 03.27 0 komentar
Label: knowledge