Thursday, December 6, 2007

Windows XP SP3 Twice as Fast as Windows Vista – Leaves Vista SP1 in the Dust

Forget about Windows Vista. And forget about Windows Vista SP1. Microsoft's latest Windows client has been quite sluggish to begin with. This in both consumer adoption and in terms of the performance it delivers. As the operating system was crawling along, while performing the most common of tasks, even "speed bumps" seemed an integer part of the road's landscape. Right, that was uncalled for... But still, even on its best day, Vista is slow, and the first service pack for the operating system will change nothing in this aspect. Windows XP SP3 simply flies in comparison to Vista, SP1 or no SP1.

Benchmark testing delivered by the researchers at Devil Mountain Software, a software-development company based in Florida, revealed that Windows XP SP3 is twice as fast as Windows Vista, with or without SP1 installed. The company threw the two operating systems one against the other on the following configuration: Dell XPS M1710, 2GHz Core 2 Duo CPU, 1GB of RAM and nVidia GeForce Go 7900GS video. While Vista SP1 delivered minor and disappointing growth in performance, XP SP3 faired quite well.
"Windows XP Service Pack 3 (v.3244) delivers a measurable performance boost to this aging desktop OS. Testing with OfficeBench showed an ~10% performance boost vs. the same configuration running under Windows XP w/Service Pack 2. XP SP3 is shaping-up to be a "must have" update for the majority of users who are still running Redmond's not-so-latest and greatest desktop OS. Of course, none of this bodes well for Vista, which is now more than 2x slower than the most current builds of its older sibling", revealed a member of Devil Mountain Sofware.

Windows XP SP3 finished the OfficeBench test in approximately 35 seconds, XP SP2 went over 40 seconds with Vista RTM and Vista SP1 both exceeding 80 seconds. The company then added another GB of RAM. Moreover, they also tested Vista in tandem with Office 2007 instead of Office 2003. But while Vista dropped under the 80 seconds milestone it still doesn't even come close to the performance of XP. Commenting the benchmarking Microsoft explained that both Vista SP1 and XP SP3 are still under development and as such, not delivering a complete experience. Vista SP1 is currently planned for the first quarter of next year, while XP has been announced by mid 2008.

"By providing Vista (SP1) with an additional 1GB of RAM (that's a total of 2GB for those of you keeping score) we managed to achieve a "whopping" 4% improvement in OfficeBench throughput. Moving from Office 2007 to Office 2003 definitely improved Vista's showing. Instead of being over 2x slower than XP on the same OfficeBench workload, Vista is now "only" 1.8x slower", the Devil Mountain Software added.

One-Click Linux Software Installation!

After months of hard work, Linspire is proud to announce the beta release of CNR.com. On the 23rd of January, 2007, Linspire announced for the first time that they are working to extend their CNR (Click 'N Run) website for other popular Linux distributions, such as Ubuntu, Fedora, openSUSE and Debian. The CNR service has already been available for all Linspire and Freespire users. Kevin Carmony, the President and CEO of Linspire Inc., stated that he had enough with complaints from MS Windows and Mac users about Linux, and that there are too many distributions and each one has a different way of installing software: "When we started Linspire, we knew that we'd need to overcome this complexity. This led to Linspire's CNR ("Click 'N Run") technology."

CNR is a FREE and easy way to access over 37,264 desktop Linux products, packages and libraries, all with a single mouse click. Finding, installing and managing software on your desktop Linux computer has never been that easy. CNR makes the finding of the right piece of software easy to do, with user reviews, screenshots, descriptions, charts, and so on. When you the software you want, with only one click, it will be installed on your computer and icons will be added to your desktop and to the Start Menu. Also, CNR notifies you when updates are available for the installed applications via the CNR.com website, which you can easily install with one click. CNR also offers dozens of commercial Linux software titles for sale, such as popular games, Sun's StarOffice, Win4Lin, CodeWeaver's Crossover Office, Parallels Workstation, TransGaming's Cedega, and many other commercial Linux products.

This is really a revolutionary moment for all computer users all around the world. I sure hope that it will bring many new users into the Linux world.

If you have Ubuntu 7.04 or Ubuntu 7.10 go right now at the CNR’s website, install the CNR client and grab your favorite applications with a single mouse click!

Getting started with CNR

· Go to Main Menu -> System -> Administration -> Software Sources
· Click on the Third-Party Software tab
· Click the Add button and add the following lines (one by one):

deb http://apt2.freespire.org/CNRUbuntuExtra gutsy-extra main restricted
deb-src http://apt2.freespire.org/CNRUbuntuExtra gutsy-extra main restricted


Note: We recommend to uncheck the Cdrom with Ubuntu 7.10 'Gutsy Gibbon' entry in the "Ubuntu Software" tab.

· Go to Main Menu -> Accesories -> Terminal and type:

sudo apt-get update

· If you get an error about a public key for the CNR repositories, ignore it and install the CNR client, from the command prompt with:

sudo apt-get install cnr-client

Once installed, you can activate the CNR client from System Tools -> CNR and let the client synchronize with the CNR.com website.

Here's CNR in action on Ubuntu 7.10

First Firewalls, Now Botwalls, What Will They Think of Next?

People are using computers and networks more and more to power up their business, the web is changing, so is the threat landscape, hackers are getting smarter and smarter, but security experts are not slacking either! One of the newest things one IT manager can add to his company’s security modules is the botwall, and as its name says it, it walls off bots.

This is one great utility, since botnets with their DDoS attacks have really become a threat. They say this is the year of the bot or of the botnet, so security experts have stepped up to the challenge, creating something to battle the top threat!

The botwall is going to use appliances from (inside) the data center and work with systems deployed at Internet service providers (ISP) ant third party technology partners, to form a "botwall network" that will fight off any bot.

Using a technique similar to that of a honey pot, a botwall will easily identify any "bad" traffic, and while cooperating with off-network botwalls, it can block any traffic that it considers to be malevolent.

The only company that offers anti-botnet protection via these botwalls is FireEye, Inc. and here is a link to see more on their product, right on their official page.

"The FireEye Botwall system redefines coordinated network security going beyond traditional security mechanisms, such as blocking at the perimeter or inspecting traffic on the internal LAN, to accurately and continuously analyze the network for both bots and botnet activities," said Ashar Aziz, CEO of FireEye. "We've created a solution geared to stop the threat of botnet infiltrations in a coordinated and easy-to-deploy system for our customers."

To be honest, every week we get news of some security product improving cyber-defense and how security is getting better, but also each week, there is more news about how things are going bad in security and how high-profile targets get hacked. I really hope that the botwall will make a difference, since it is supposed to address one of the worst threats we’re facing right now.

The Hidden Aspects of Hacking and Viruses

I wanted to write about this for a long time, since it is pretty important, but I never got the chance to do it; plus, there wasn’t enough material to back up my statements… until now. Sophos expert Fraser Howard wrote a great technical paper on "Modern web attacks" that is very inspiring and also explains things really well. In any case, in this article, I’m going to concentrate on explaining the way e-mail borne viruses function.

Perhaps you’ve read a lot of news either written by myself or by my peers in which they would explain how e-mail borne threats work. Most of the times, nobody bothered to detail this too much, journalists limiting themselves to "when you click on a link you get a virus", but there’s much more to it than that. Sure, in some cases, you get the powerful virus on your machine directly after clicking on a link. That would be the work of a lazy/sloppy hacker. But pros have other ways of doing things. It’s all about multi-stage attacks!

So, how do these work? Well, after the victim gets the message (probably part of a torrent of spam) and clicks on a link, a download function is activated. As Fraser Howard puts it, this can be written within a very small binary and in a myriad of ways. Some of these will pass through the e-mail gateway without being noticed. And here comes the part where the hackers get clever – the download does not always start immediately, as this could be dubbed malicious script by heuristic based software. Instead, the download will start at a later time, as there is no rush.

Furthermore, using the same primary payload would be dumb, as it could be instantly detected and blocked, that’s why the ones in charge of the attacks are always updating the remote content (primary payload).

And probably, the most clever part of all this consists in the multiple stages of download. Don’t go thinking that you get a Trojan downloader and then the virus. Oh, no – it’s far more complex. The first will download another that will download another and so on and so forth, or the primary download will download the virus piece by piece, from different hosts and URLs. Also, it may be possible for the initial downloader to retrieve a configuration file, which contains further instructions of content to download, as seen in the same report.

"Coupling the use of automation to frequently update the malicious files with multiple levels of downloading (potentially across multiple domains), often results in fairlycomplex infection mechanisms, involving numerous items of malware and URLs. From the malware author's perspective, such techniques provide a very flexible framework in which to operate.", Fraser Howard wrote in the report.

Coolest Security Tool Ever!

Now this is certainly something really nice! Researchers are advising users kindergarden-style! These people are going out of their way to help people stay secure. Of course, the best way of protecting yourself against the threats on the web is to know what they are and how to act against them. That’s why the brainy dudes at Carnegie Mellon University have designed a game to help people out!

Now, I knew that some warnings and pieces of news were for the tech-savvy users that knew too much about security already, but they’re dumbing down security measures so much that even a 10-year-old could stay safe on the web. If this doesn’t make a difference, then I don’t know what will!

The game is called Anti-Phishing Phil, and you can play it by clicking on this link. Not only is it entertaining – I really like that fish – but it’s also going to teach you a lot. So, this is a great initiative – these people are making it stupid-proof – web users should understand phishing threats and know how to watch out against them a lot better after playing the game. And you can play it just for fun, if you’re a security geek. Or you can play it just to test your knowledge – in any case, I like this initiative a lot.

I’ve seen a similar thing on Agnitum’s website – it’s a quiz that will tell you if you’re a security wizard or not. That was pretty cool, but this fish beats the crap out of any other web threat awareness tool ever!

Be my guest and click on the link above to Anti-Phishing Phil. You’re bound to like it! And I wonder what’s next, are researchers going to come up with a game with "Sexy Lisa" warning against "porn-related spam"?

How to Remain Secure on Cyber Monday

With Cyber Monday almost here, it's very important to equip your computer with powerful and well-developed technologies which would be able to defend you and keep your data secure during the entire holiday shopping season. Today, the Zone Alarm developers, Check Point Software Technologies, offered several pieces of advice on how to remain secure and buy products online without any threat.

For those of you who don't know what Cyber Monday is, it marks the beginning of the holiday shopping season. This day is usually the best time for shopping because most merchants launch special offers and prices for a wide category of products, all of them accessible via the Internet. Because millions of consumers will go online for shopping, some bad-intended persons a.k.a. attackers, phishers, scammers, hackers (you can call them however you want) will surely attempt to steal your money, products or even financial information.

"Internet holiday attacks get more advanced each year, but many people are still relying on outdated or nonexistent security solutions, which put their computers and identities at risk," said Laura Yecies, vice president and general manager of Check Point’s ZoneAlarm consumer division. "To stay safe online this holiday season consumers need to educate themselves on the latest types of threats, and make sure they are running up-to-date and comprehensive security software on their PCs."

Now that we understood that we have to secure our computers against hackers and attackers, what can we do to reach this goal? Well, the Zone Alarm creators give us some advice which might be really useful for an online holiday shopper:

1. Secure your computer with a powerful firewall, antivirus, antispyware and other security solution which could be able to block malicious attempts targeting your system.
2. Avoid publishing your details and especially the financial information on untrusted websites which doesn't seem to be genuine as some of them might be actually some phishing attacks.
3. Secure your browser in order to be able to protect your privacy as well as your identity. Beware! In the last few months more and more users became victims of identity theft!
4. Do not donate money to the organizations or websites promoted by email spam. Only donate money to trusted charities!
5. Buy stuff from the known merchants and websites. Some attackers might attempt to create fake online shops in order to steal users' information.

Google to Launch Its Operating System Next Week

A while ago, the Internet world talked about a potential GooglePhone, especially created to fight with the Apple iPhone. At that time, the Mountain View company avoided commenting on the speculation; the only thing mentioned was that Google will remain a software firm and not a hardware one. So no GooglePhone; but in the meantime, the search giant released several new mobile flavors of its products. Take the example of Gmail, Google Search, YouTube, Google Calendar. Now, what do you understand from this: Google remains a software company, but it develops mobile versions of its products? That's right, Google wants to conquer the mobile software industry but how else can you do it if not through a mobile operating system?

The most recent rumors sustain that the Mountain View company prepares a mobile operating system that is scheduled to be released very soon, maybe sometimes next week. The folks from Engadget claim that it might be entirely based on a Linux platform, because several Googlers are quite experienced in this domain. "At Google, Andy's team has developed a Linux-based mobile device OS (no surprise) which they're currently shopping around to handset makers and carriers on the premise of providing a flexible, customizable system -- with really great Google integration, of course," Ryan Block from Engadget wrote.

Obviously, the entire operating system would be bundled with Google's technologies such as search, YouTube or Gmail. Actually, I think it would probably contain all sorts of shortcuts to allow the handheld owner to access the Google services in a matter of seconds if an Internet connection is available.

But the main question is: which mobile companies will implement the operating system into their devices? As you might know, Google signed deals with some famous phone producers such as Samsung, but there is no evidence that the Mountain View company might bring the OS on their devices. In fact, the entire operating system might be only pure speculation, so...