IT Masala

A Tech Curry with a Pinch of Indian Spice

14th April 2007

Cisco in space

The Department of Defense project to test Internet routing in space (IRIS) will be managed byintelsat_cisco.jpg Intelsat General, and the payload will convert to commercial use once testing has been completed. The IRIS project is one of seven projects — out of hundreds of applicants — funded and announced in fiscal 2007 as a Joint Capability Technology Demonstration (JCTD) by the Department of Defense.

Intelsat is the first commercial satellite company to be awarded a JCTD Program. The IRIS JCTD is a three-year program that allows the DoD to collaborate with Intelsat General and its industry team to demonstrate and assess the utility of the IRIS capability.

Cisco, the global networking leader based in San Jose, CA, will provide commercial IP networking software for the on-board router. In addition, SEAKR Engineering Inc. of Denver, CO, will manufacture the space-hardened router and integrate it into the IRIS payload.

via [ playfuls

14th April 2007

Cybercrooks exploiting new Windows DNS flaw

Cybercrooks are using a yet-to-be-patched security flaw in certain Windows versions tomicrosoft_dns_bug.jpg attack computers running the operating systems, Microsoft warned late Thursday.

The attacks target Windows 2000 Server and Windows Server 2003 systems through a bug in the domain name system, or DNS, service, Microsoft said in a security advisory.

What is the vulnerability: 

The vulnerability is believed to be caused by a stack overflow error in the Windows DNS Server's RPC interface implementation when processing malformed requests sent to a port between 1024 and 5000.

This means that remote unauthenticated attackers can execute arbitrary code with SYSTEM privileges by sending specially crafted requests to vulnerable systems. 

"An anonymous attacker could try to exploit the vulnerability by sending a specially crafted RPC packet to an affected system," Microsoft said in the advisory.

What is RPC?

RPC, or Remote Procedure Call, is a protocol that applications use to request services from programs on another computer in a network.

Red Alert : The French Security Incident Response Team deems the Windows DNS vulnerability "critical," its highest rating.

Which OS's are Affected : 

Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 are vulnerable, Microsoft said.

Caution to be taken : 

Security experts are advising that users for the time being disable remote management over RPC capability for DNS Servers or block unsolicited inbound traffic on ports 1024 to 5000.

via [ Microsoft security advisory ]

14th April 2007

Sunita Williams to run Earth race from space

Indian American astronaut Sunita Williams will attempt to do something 210 miles above Earth thatspace_museum.jpg no other astronaut has ever done. She will run the Boston Marathon while in orbit.

The 41-year-old plans to run the 26.2-mile race on a treadmill onboard the International Space Station (ISS) on Monday at 7:30 p.m. IST as this year's marathon begins in Boston at precisely the same hour.

Race organisers say this will be their first satellite venture, and they are thrilled about it. "Suni running 26.2 miles in space on Patriots' Day is really a tribute to the thousands of marathoners who are running here on Earth. She is pioneering new frontiers in the running world," said Jack Fleming of the Boston Athletic Association.

A space suit worn by astronaut Deke Slayton is seen at the Alameda, the nation's largest museum dedicated to Latino culture and art, in San Antonio, Wednesday, April 11, 2007. The new museum opens to the public Friday. Photo Credit: AP Photo.

via [ dnaindia ]

14th April 2007

Beware New Storm Worm E-mail Virus Deluge

alert2.gifThe Storm Worm is back. The e-mail virus, which first attacked in January, has returned with a vengeance during the last 24 hours, boosting the amount of virus traffic on the Internet to as much as 60 times the normal amount. The Internet Storm Center reported detecting at least 20,000 infections today.

Detection :  Nine engines caught the virus, some of which are eTrust-Vet, Fortinet, F-Secure, McAfee and Webwasher-Gateway.

Effects of this Storm Virus:

Once installed on a personal computer, the virus takes control of the machine, sending personal information stored on the PC back to the online criminals who created the malicious program. It can also send itself out to the entire address book of the PC's owner, and turn it into a "zombie" machine sending out more spam.

Speciality : Unlike the original Storm malware, which was hidden in an executable file, this one is hidden in the encrypted zip file .So if they can't detect it , how can they stop it ?

Types of Spam Mails Sent : New Storm Worm variants showing up attached to e-mails with subjects such as "Virus Alert!" or "I dream of you".

Inside the e-mail is an image and an encrypted zip file. The image has the password needed to open the zip file.

Spreading : Only possibility of spreading is through peer-to-peer network, as a standalone pc cannot do any damage outside itself ! 

Caution : So don't open any unexpected e-mail attachments. Even if its sent from somebody you know , check before you open the attachments as the virus picks up email ids from the infected pc to send out spam mails.

Solution :  As this virus spreads only when a user opens an attachment , so it depends on the user , so cant patch all users mind , can we ? . So it solely depends on your common sense !