Gmail flaw exposes data

Google is facing some serious questions about the security of its applications after a researcher disclosed a flaw in its popular Gmail offering. The new issue is a variant of a cross-site scripting vulnerability in Gmail which could enable an attacker to silently forward emails and contacts from a remote user’s account to any email account he chose.

The problem, discovered and detailed by GNUCitizen, a hacking group that tracks flaws in so-called Web 2.0 applications, arises when a user who is logged in to Gmail visits a malicious Web page with a special bit of code embedded in it. The page performs an action that injects a filter into the user’s Gmail filter list.

Posted on: September 28, 2007 9:00 am

Attack of the killer bots

Once a computer has been infested, it waits for orders from criminal bot herders, who turn these zombie computers into massive bot networks that spew spam and other malware across the Internet.

You may not be able to block the botnet invasion completely, but with layers of bot-hunting technologies and common sense, you can minimize the effect on your network. Before you can battle the bots, you’ve got to understand the scope of the problem.

Posted on: September 28, 2007 9:00 am

Malicious emails balloon

The percentage of threats arriving in email that rely on links to malicious sites–rather than arriving as a file attachment–has ballooned 10-fold since the first quarter of the year.

In a report published Thursday, U.K.-based MessageLabs Ltd. said that 35 percent of the email threats it now detects use embedded links to infect computers instead of the more traditional file attachments. In the March-June time frame, that figure was 20.2 percent, said the company. And in the opening quarter of 2007, a mere 3.3 percent of the intercepted threats carried links.

Posted on: September 28, 2007 9:00 am

Ethics of outsourcing customer service

One problem with outsourcing customer service is that this practice can create nothing but negative word of mouth. Time is precious, and what customer wants to spend an inordinate amount of time in an often vain attempt to communicate with a company employee who is halfway around the world and cannot speak English effectively?

It’s a familiar scenario: A product you purchased recently has developed a problem, so you call the company’s toll-free number and are connected to a "customer service Relevant Products/Services associate" in India or the Philippines. You describe your problem but have a hard time understanding what the company representative is saying. You try several more times to communicate why you are calling but cannot get information that you can comprehend. You ask to be transferred to someone in the U.S. and are then put on hold for what seems like an eternity. You hang up in frustration and vow never again to purchase anything from this company.

More and more businesses are outsourcing not just manufacturing jobs but services ones too. On the face of it, this seems like a smart financial move: By slashing labor costs 25%, 50%, or more, companies that have had slim profit margins are now able to enrich the bottom line and keep shareholders happy. Outsourcing customer service, however, is not only unethical. It’s bad for business. Here’s why.

Posted on: September 28, 2007 9:00 am

Hamlet on the Endpoint

Symantec hass pushed its latest answer to enterprise security into a crowded playing field with the release of Symantec Endpoint Protection 11.0 and Symantec Network Access Control 11.0.

Symantec Endpoint Protection 11.0, code-named Hamlet, combines Symantec AntiVirus with advanced threat prevention in a single agent, managed through a single console. Slated to be available this month, Hamlet integrates a number of security technologies into a single agent at the endpoint with the goal of enabling customers to reduce costs and complexity.

It is NAC-ready, Symantec officials said, and the software is integrated into the same endpoint agent and management console–though users must buy a separate license to enable it.

Posted on: September 28, 2007 9:00 am

Integrating Lotus Forms with SAP

This tutorial outlines how to integrate IBM Lotus Forms with SAP, using Lotus Forms Services Platform, released as a component of IBM Workplace Forms V2.7. Using an embedded IBM WebSphere Transformation Extender runtime allows the easy mapping of data between Lotus Forms and SAP.

Posted on: September 27, 2007 9:00 am

Symphony attracts 100,000 users

IBM announced that Lotus Symphony, IBM’s new, free office productivity software, has been downloaded by more than 100,000 registered business and consumer users in its first week. The Lotus Symphony Web site, which is providing user community feedback for the Symphony beta software, has received more than one million visitors during this period.

Posted on: September 27, 2007 9:00 am

Spy charges for US computer duo

Two computer engineers in the US state of California have been charged with conspiring to steal microchip designs to sell to the Chinese military. US citizen Lee Lan and Chinese national Ge Yuefei are accused of stealing computer chip designs from their employer Netlogics Microsystems.

The two are alleged to have formed a company to develop chips based on the stolen designs. They then contacted the Chinese army to sell the chips, prosecutors said.

Posted on: September 27, 2007 9:00 am

mNotes5 Beta

CommonTime announced the beta release of mNotes5–secure, wireless Lotus Notes email for individuals. Now there is an easy way to set Lotus Notes free–wireless push email the easy way. "With mNotes5, the individual user gets a wired and wireless, secure, full email and PIM push solution without consuming any of their organization’s IT and support resources."–Rob Colver, Customer Support Director, CommonTime.

mNotes 5 brings information and communication to your fingertips, with enterprise strength security and device management features designed specifically for individual users. Renowned in Notes/Domino circles as the gold standard for enabling the use of Lotus Notes functionality on handheld devices, mNotes5 is the software for the next generation of Lotus Notes users.

Posted on: September 26, 2007 9:00 am

Video shows hacker hit on power grid

A government video shows the potential destruction caused by hackers seizing control of a crucial part of the U.S. electrical grid: an industrial turbine spinning wildly out of control until it becomes a smoking hulk and power shuts down.

The electrical attack never actually happened. The recorded demonstration, called the "Aurora Generator Test," was conducted in March by government researchers investigating a dangerous vulnerability in computers at U.S. utility companies known as supervisory control and data acquisition systems. The programming flaw was quietly fixed, and equipment-makers urged utilities to take protective measures.

There was no evidence any U.S. utility company suffered damage from hackers or terrorists using this technique, U.S. officials said. But these officials cautioned that affected systems are not routinely monitored as closely as many modern corporate computer networks, so there would be little forensic evidence to study after such a break-in.

Posted on: September 26, 2007 9:00 am