Deploying IBM Lotus Connections

This article, part 1 in a six-part series about deploying IBM Lotus Connections, focuses on planning and architecture considerations to ensure that your deployment is built properly. Learn from an expert on recommended planning and architecture practices.

This article covers some of the most common steps to prepare for an IBM Lotus Connections deployment. At a high level, it outlines the architectural concepts and alternatives available so that you can plan a successful Lotus Connections deployment appropriate to your organization. The content of this article is intended for both I/T architects and I/T specialists.

Posted on: August 1, 2007 9:00 am

IBM virtual email security appliance

IBM has unveiled a virtual email security solution based on the existing Proventia Network Mail Security System from its Internet Security Systems division. By allowing robust email security to run alongside other applications within a single piece of hardware, the virtual version of this product is designed to enable organizations of all sizes to block the full realm of malicious code.

Posted on: August 1, 2007 9:00 am

3,900 servers on 33 mainframes

In what it touts as "the most significant transformation" of its worldwide data centers in a generation, IBM announced Aug. 1 that it will consolidate about 3,900 of its own servers onto 33 virtualized System z mainframes running Linux to save electrical energy and cut back on its carbon footprint.

A carbon footprint is a representation of the effect human activities have on the climate in terms of the total amount of greenhouse gases produced, measured in units of carbon dioxide. Such a footprint is often expressed as tons of carbon dioxide or carbon emitted into the air, usually on an annual basis.

Officials with the Armonk, N.Y., company expect the new server environment to use about 80 percent less power than the current setups and believes IBM will save more than $250 million over five years in energy, software and system support costs, a spokesperson said.

Posted on: August 1, 2007 9:00 am

JavaScript fuzzer for Firefox

Mozilla has distilled what it’s learned from pounding its Firefox browser and will release its home-brewed knowledge in a series of open-source tools, the first of which is a JavaScript fuzzer that will be released at the Black Hat conference in Las Vegas Aug. 2.

Security chief Window Snyder will detail the "gory details" of how Mozilla gets security done–something you don’t get out of a traditional vendor, she told eWEEK in an interview. "[At] Mozilla, the whole world’s watching–we couldn’t hide if we wanted to," Snyder said.

Posted on: August 1, 2007 9:00 am

Wi-Fi puts data at risk

Users who access Google’s Gmail or the Facebook social-networking site over Wi-Fi could put their accounts at risk of being hijacked, according to research from Errata Security, a computer security company.

It’s not just those sites but any rich Web applications that exchange account information with users, including blogging sites such as Blogspot or even software-as-a-service offerings such as Salesforce.com, that could pose a risk for users, wrote Errata’s Robert Graham, CEO, and David Maynor, chief technology officer, in a paper.

Posted on: August 1, 2007 9:00 am

Improved password security

ANIXIS announced the release of Password Policy Enforcer 5.0, an application that enhances the security of Windows Server operating systems. PPE 5.0 has six new password policy rules, improved support for Windows Vista, and new password expiry options to simplify the introduction of new password policies.

The rudimentary password policy features in Windows limit administrators to a single domain password policy with an on/off complexity option. Microsoft includes a programmer’s interface to add new password policy rules, but a solid understanding of Windows system programming is needed to make use of it. ANIXIS Password Policy Enforcer allows administrators to enforce granular password policies without programming.

Amongst the six new password policy rules in PPE 5.0 is a keyboard pattern rule, a first for the Windows platform. It detects simple keyboard patterns like QWERTY, and also more complex patterns like QAZXCV and QAWSDF. Pattern matching parameters are configurable, allowing administrators to strike a balance between security and usability.

Posted on: August 1, 2007 9:00 am

Share USB devices on a network

Keyspan’s USB 2.0 Server lets multiple users share USB devices on a network and extends a USB connection–between a host PC and the USB device–over any distance, including printers, scanners, digital cameras and flash-drive memory sticks over Ethernet and WiFi. The USB 2.0 Server eliminates the need to dedicate a PC as a host for a USB device. Students, wireless office workers and road-warriors alike can access USB devices from a laptop via WiFi.

Posted on: August 1, 2007 9:00 am

Update plugs security hole

Yahoo is urging users of Yahoo Widgets to upgrade to address a vulnerability hackers can exploit remotely to take control of a compromised system.

According to researchers at the French Security Incident Response Team, the issue is caused by a buffer overflow error in the "YDPCTL.YDPControl.1" (YDPCTL.dll) ActiveX control when processing malformed arguments passed to the "GetComponentVersion()" method. The flaw can be exploited by tricking a user into visiting a specially crafted Web page and could result in a denial-of-service attack or the takeover of an affected system.

Yahoo Widgets versions prior to 4.0.5 are affected by the flaw. The vulnerability was initially reported by the security firm Secunia, in Copenhagen, which rated it highly critical.

Posted on: July 31, 2007 9:00 am

New DB attack vector

Researchers at Core Security Technologies have donned their black hats and are preparing a presentation about a new database attack vector that relies solely on the inherent characteristics of the indexing algorithms.

The attack, which will be demonstrated Aug. 1 against the MySQL database engine at Black Hat USA in Las Vegas, affects database management systems using BTREE, the popular database indexing algorithm and data structure. Traditionally, database security breaches are mostly due to the abuse of wrongly configured authorization and actual control permissions or the exploitation of bugs in front-end Web applications through SQL injection, said Core Security Chief Technology Officer Ivan Arce.

Posted on: July 31, 2007 9:00 am

PDF Annotator 1.5

The new PDF Annotator revolutionizes the way users in business, educational, or home settings deal with their PDF documents. Now it’s possible to insert comments on PDF documents from any PC. Text boxes, highlighting, drawings and images–all are easy to add to any PDF document with PDF Annotator.

Posted on: July 31, 2007 9:00 am