May 28th issue coming out Tues

We normally publish our Weekly Updates on the 7th, 14th, 21st, and 28th of each month. This month, May 28th falls smack-dab in the middle of the U.S. Memorial Day weekend, which extends through Monday, May 30th. As a result, and to allow your esteemed editorial team to take part in a burger-munching mania, the May 28th issue of the Weekly Update will actually be published on Tuesday May 31. We hope all of you have a great weekend — and let’s not forget the brave folks for whom this holiday is intended: be strong and be safe.

Posted on: May 27, 2005 9:00 am

Dell, HP gain on IBM

Hewlett-Packard and Dell gained in the server market at the expense of IBM and Sun Microsystems, while overall growth slowed in the first quarter of 2005, new figures show. The overall market grew 4.1 percent to $12.3 billion worldwide compared with the year-earlier quarter, a rate that was slower than that of each quarter since the second of 2003, according to figures Gartner released Wednesday. Servers are powerful systems used for networked computing tasks such as file storage, email routing and bank account transactions.

Posted on: May 27, 2005 9:00 am

Military computers spread worm

A new analysis of last year’s Witty worm by three university researchers documents the worm’s spread and claims that U.S. military computers and inside knowledge about vulnerable systems were an early propellant for the worm. The report, which was published by Abishek Kumar, a student at the Georgia Institute of Technology (Georgia Tech), claims to use a novel method to retrace the spread of the worm–which targeted vulnerable products from Internet Security Systems Inc.–by locating a machine in Europe that was the first computer infected by the worm. The techniques that the researchers developed could help with future worm studies, the authors say.

Posted on: May 27, 2005 9:00 am

Stanford network breach

The FBI is investigating a computer system security breach at Stanford University that may have put the personal information of nearly 10,000 people at risk, the university said Wednesday. The intrusion occurred at the Career Development Center on May 11, when someone gained access to the school’s network from outside the university, Stanford general counsel Debra Zumwalt said. The university said that it began notifying people about the incident on Monday, contacting about 9,600 clients–mostly students–and 300 recruiters who registered at the office since 1996.

Posted on: May 27, 2005 9:00 am

Outsourced security

The task of keeping up with security patches is one of the most demanding and frustrating jobs assigned to IT departments, which are often caught in a race to fix problems before an attack hits. For a network with more than 500 staff to serve, it can take more than 100 hours of work to do everything needed to fix just one flaw, according to Research and Markets. With that in mind, companies that promise to take over the job of defending corporate networks against intrusions and vulnerabilities are likely to see their prospects take off, analysts say–especially as regulatory compliance becomes more of a concern.

Posted on: May 27, 2005 9:00 am

Denial-of-service flaw in DNS

A high-profile security research outfit warned that a newly discovered flaw in the Domain Name System protocol could be exploited remotely to crash vulnerable servers. The vulnerability, which carries a "moderate risk" rating, was flagged by the U.K.-based National Infrastructure Security Co-ordination Centre. In a public advisory, the NISCC said the flaw exists in the recursion process used by some DNS implementations to decompress compressed DNS messages. "Under certain circumstances, it is possible to cause the DNS server to terminate abnormally," the Center said.

Posted on: May 27, 2005 9:00 am

Court takes dim view of encryption

A Minnesota appeals court has ruled that the presence of encryption software on a computer may be viewed as evidence of criminal intent. Ari David Levie, who was convicted of taking illegal photographs of a nude 9-year-old girl, argued on appeal that the PGP encryption utility on his computer was irrelevant and should not have been admitted as evidence during his trial. PGP stands for Pretty Good Privacy and is sold by PGP Inc. of Palo Alto, Calif. But the Minnesota appeals court ruled 3-0 that the trial judge was correct to let that information be used when handing down a guilty verdict.[Ed. note–This has got to be one of the dumbest things I’ve ever heard. Because I secure my date to prevent its theft, then I have criminal intent?]

Posted on: May 26, 2005 9:00 am

Worm, phishing scam hit IM

A new worm and a phishing scam are targeting members of the America Online and Yahoo instant messaging networks. In both cases, people receive an instant message with an apparent reference to the newly released "Star Wars Episode III: Revenge of the Sith" movie, encouraging them to click on a link. IMLogic has listed both the Yahoo and AOL issues as "medium" risk threats. McAfee has only had one report of the AOL worm.

Posted on: May 26, 2005 9:00 am

IBM tools fill development cracks

IBM’s Rational tools division has detailed early products to come out of an initiative to improve communication among people involved in corporate software development. At the Rational customer conference in Las Vegas, company executives on Monday displayed tools that will let companies more quickly pinpoint the source of application errors. The new Rational tools draw on IBM’s Tivoli systems management software to spot and report failures to software programmers.

Posted on: May 26, 2005 9:00 am

IBM supports open-source training

IBM announced on Tuesday a clutch of new initiatives to promote open-source technology in academic institutions. The computing giant said it’s expanding its relationship with Red Hat to promote teaching of open-source, standards-based skills at different levels. The two organizations will help academic bodies generate job skills on Linux, as well as training on IBM software and servers. IBM said the partnership includes a range of higher education institutions, from large research universities to vocational schools.

Posted on: May 26, 2005 9:00 am