greg hughes - dot net
Note that the contents of this site represent my own thoughts and opinions, not those of anyone else - like my employer - or even my dog for that matter. Besides, the dog would post things that make sense. I don't.
 Tuesday, 11 July 2006
Yesterday at work, I had the privilege of spending a couple hours with this cool kid named Connor. He's the son of a friend and coworker, and is an all-around good kid. Every now and then he'll come to work with his mom for a day and we'll hang out for a bit. It sure beats back-to-back meetings, heh.
Sidebar: For what it's worth, I'd kill to be eleven years old again (if I could stay that age, that is - no point in going through all those intervening years again, heh...).
True to form, he asked if we still have an XBOX. People kind of freak out when I tell them I bought an XBOX 360 for work. We actually have a couple of them on campus. "Video games at work??" they ask me. Heck yeah - it's a great way for creative minds to take an occasional and much-needed brain break (as long as it doesn't become something that's overdone), and some of the best idea-generating conversations happen when you're kicking someone else's butt in DOA4 or some other game. It's also of great interest, it turns out, to eleven-year-old kids. Yeah, go figure.
But most of the time we spent hanging out on Monday was occupied with trying to find a clean whiteboard somewhere in the building that didn't say "SAVE" on it (what the heck is up with THAT anyhow?) and then talking about computers and networks and how they work. Teaching kids something they have yet to learn about is really a lot of fun. I explained the underlying technology basics of how web browsers and web servers work, using analogies like phone books (for DNS), mapquest data (for routes) and phone numbers (for IP addresses) to try to describe some pretty complicated, intangible and abstract stuff in a way that makes some sort of sense. You know - looking up a name in a phone book and finding the phone number is like looking up a URL in DNS and getting an IP address, and using mapquest to figure out how to get from one place to another one step at a time is a lot like finding the route to a web server... We got a little more detailed than that, but you get the idea. His face really lit up when - all of a sudden - he "got it."
Next thing I knew, he was explaining how it works to me. Which was really cool. :)
I used to teach middle school kids back in the day, and there's something about those "getting it" moments that are a lot of fun to watch. Seeing reality expanding itself in a kid's mind is a pretty amazing thing. They sure do learn quickly.
At any rate, Connor will be back again sometime soon, and we'll see who's teaching whom whenever that day comes. For my part, I'm betting on the kid.
 Monday, 10 July 2006
I'll be on the road (well, in the air actually) Wednesday through Friday this week, as I am traveling to Toronto, Ontario (Canada, of course), where I'll be speaking at a conference this Friday on the topic of strong authentication for web sites and the role of web site users in the security process. They say there will be somewhere around 2,000 attendees, so it should be an interesting conference. I've been doing a lot of this kind of presentation recently - there are many changes in the works in the financial services industry for performing strong authentication of people who access online banking and other secure web sites. That's pretty much everything I've been doing for the past year or so, in fact.
It's been several years since I have visited Toronto, so I am looking forward to the time there. It's always been one of my favorite cities - clean and attractive.
If anyone happens to be in the Toronto area later this week and wants to try to catch up, be sure to let me know. Email and phone info are in the menu bar on the right side of the page on this site.
 Sunday, 09 July 2006
The Firefox 2 Beta 1 release candidate I mentioned last night includes a new feature that I just noticed (after using it practically all day), and it's simply terrific. It may seem small, but often it's the little things that make a real difference.
As-you-type spell checking is built right in. Just right-click on anything Firefox doesn't recognize and you'll get just what you'd expect. Looks like it's a basic English dictionary that's used, so you'll have to add some commonly typed terms - even Firefox isn't in the dictionary.

In Internet Explorer I have used IESpell for a couple years and it's always been very useful. But it doesn't do the red-underline thing to show me what's out of whack as I type, though, so this is another case where the Firefox team is again raising the bar.
Nice stuff.
NOTE: The Beta 1 release is set to hit the streets this week. Also, I confirmed that this weekend's binary release is definitely a pre-beta-1 release candidate (one of the nightly builds) and so it's likely (even probable) that it's not the same code that will ship as the actual Beta 1 this week. So, as mentioned last night, downloader beware. You'll probably want to wait. Sorry to anyone reading for gun-jumping, but hey we're all geeks around here, and it's in my nature to test early and test often.
Note: Sometimes bleeding-edge is fun, but it's not for everyone. I mention that so you'll know that this blog post is not for average computer users. But for those that like to try the latest, greatest things the second they become available and don't mind installing pre-release software...
UPDATE 7/10/2006: Since this post was originally authored the RC2 binaries for FF2B1 have been released earlier today in the nightly builds area. I've removed the old links.
You know Firefox is a great browser, and if you're one of the hard-core, gotta-have-it types (like I am), you'll be glad to know binaries for Firefox v2 Beta 1 are available on the Mozilla.org FTP server. It won't be formally released they say 'til Tuesday, and the files could certainly change between now and then (this looks like it's labeled RC1 of Beta 1), but as you can see from the image at right the 2.0b1 English binaries are there. You can grab it now:
Download binaries for:
You know you want it. There's some nifty and subtle updates in the release, like close buttons on browser tabs and friendly, clean feed display in the browser window.
And by the way... Really, you should know how this stuff works, it's not magic, you know. People are organized and work hard to give you something you can download for free and which makes your life better. Have you said thank you yet?
So, why don't go and get to know the project a little bit? Find out what goes into the software you use. It is a community thing, after all. Here, I will help you with starter links and a few facts:
The codebase was frozen on July 5th in preparation for release this week. The latest status meeting notes are viewable here. The code name for the release up 'til now has been "Bon Echo." From the Firefox 2 section of the MozillaWiki (where you can get lots of geeky details for yourself, by the way - so go learn and amaze your friends) here's a touch of high-level Firefox 2 trivia:
Theme of Firefox 2
Firefox 2 will aim to build on the success of Firefox by addressing issues related to the problem of managing the vast amounts of use a pre-release code name taken from a public park. Bon Echo Provincial Park is located in Ontario, Canada. The name literally translates to "good echo", and reflects how it is our goal echoes that of Firefox information available on the Internet. Our goal is to provide a browser that helps users manage and organize their online information channels.
About Bon Echo
Continuing the tradition, Firefox 2 will x 1, once again focusing on improving the browsing experience for our users, making it simple, effective, fast and useful.
While the release notes are not yet up as of this writing, and while the binaries you see on the FTP site certainly may change before they're formally released, you might also be interested in taking a look at the changes that were made up through the latest Alpha release (Alpha 3).
 Saturday, 08 July 2006
Looks like a new variant of an old virus is making the rounds.
I got an email tonight in my personal email account that pretended to be from Microsoft and which contained a virus in an attached ZIP file. The attachment was called "Microsoft SMS Manager.zip" and contains two files - which are packaged as a .JPG file and a .HTA file. The JPG file is actually the infected binary and the HTA file is a real HTA with malicious content to call the binary and perform some other actions. The email came from an IP at an ISP located in Asia.
Of course I didn't get infected, because I saw it as obviously fake. Microsoft will never send software or updates via email, but in the social engineering department this one is bound to fool a number of people (despite the bad grammar), so it's a good idea to get the word out. I confirmed the virus infection with Symantec's AV software client on the local machine.
Here is the info about the infected contents of the ZIP file (specifically the JPG file):
Scan type: Auto-Protect Scan Event: Threat Found! Threat: W32.Gavgent.A File: C:\DOCUME~1\*********\Temp\Temporary Directory 1 for Microsoft SMS Manager.zip\Product.jpg Location: C:\DOCUME~1\*********\Temp\Temporary Directory 1 for Microsoft SMS Manager.zip Computer: ******* User: ******* Action taken: Delete succeeded : Access denied Date found: Saturday, July 08, 2006 11:22:31 PM
If the AV software is correct and it's actually a W32.Gavgent.A virus in this file, this is an older worm (1995) that was not too prevalent at the time. The dates on the files in the ZIP are 8/2005, so it's entirely possible this is a reuse of an older virus. The HTA file in the package is an actual HTA file, and it references "Gavgent.B" in it's contents, so it's likely this is a repackaging of the Gavgent.A variant. At this time, there is no reference to Gavgent.B at Symantec Security Response. Luckily the old Gavgent.A variant is what trips the Symantec software, so detection seems to be easy enough. Below is the header from the HTA file. The executable section contains a lot of obfuscated VBScript and an IFRAME that loads the microsoft.com site with some extra arguments on the query string.
<HTA:APPLICATION ID="GavGent.B-ID" APPLICATIONNAME="GavGent.B" CAPTION="Microsoft SMS Manager" SHOWINTASKBAR="yes" SYSMENU="yes" WINDOWSTATE="maximize">
This virus does the classic network worm thing and collects email addresses and spreads via the common methods. It tends to restart the computer it infects and is generally an annoying dude. It will also try to kill AV and other security processes upon execution. Details are available here.
The original email I received is below. The subject line was "SMS Manager from Microsoft."
Developer@microsoft.com wrote:
Dear Customer,
This email provides you information about new product from Microsoft
Corporation, called Microsoft SMS Manager.
These product would help your activities, you can send and receive SMS
messages through your PC with no charge before December 31, 2005 (trial
period).
It's compatible with most of GSM and CDMA operators.
The Installation's document is attached (Microsoft SMS Manager.zip).
For further informations, please contact support@microsoft.com
Best Regards,
---------------------------------------------------------------------
Microsoft Corporation
http://www.microsoft.com
© Copyright 2012 Greg Hughes

This work is licensed under a Creative Commons License.
 | This page was rendered at Wednesday, 11 July 2012 20:04:35 (Pacific Standard Time, UTC-08:00)
newtelligence dasBlog 2.1.8015.804
|
"Computers used to take up entire buildings, now they just take up our entire lives."
- Unknown
"So how do you know what is the right path to choose to get the result that you desire? And the honest answer is this... You won't. And accepting that greatly eases the anxiety of your life experience."
Syndication [XML] and .net Alerts
For lazy, highly-technical or enlightened people, get this site's content without the use of a web browser. I use FeedDemon for this, but you can choose your own. Subscribe - click the icon for my feed... or sign up for Microsoft Alerts to receive updates through your MSN Messenger, e-mail, or mobile device. Click the orange button thingie to sign up with your Passport account: 
Contact
Drop me an email: Phone: 503-766-2258
Add me to MSN Messenger
Monthly Archive
June, 2012 (1) |
November, 2011 (1) |
October, 2011 (7) |
July, 2011 (1) |
May, 2011 (1) |
April, 2011 (1) |
January, 2011 (2) |
December, 2010 (3) |
November, 2010 (2) |
October, 2010 (1) |
September, 2010 (1) |
July, 2010 (1) |
June, 2010 (13) |
May, 2010 (4) |
April, 2010 (10) |
February, 2010 (1) |
January, 2010 (2) |
December, 2009 (1) |
November, 2009 (2) |
September, 2009 (2) |
August, 2009 (1) |
July, 2009 (2) |
June, 2009 (4) |
May, 2009 (7) |
April, 2009 (3) |
March, 2009 (5) |
February, 2009 (1) |
January, 2009 (10) |
December, 2008 (7) |
November, 2008 (7) |
October, 2008 (18) |
September, 2008 (18) |
August, 2008 (18) |
July, 2008 (35) |
June, 2008 (16) |
May, 2008 (12) |
April, 2008 (16) |
March, 2008 (22) |
February, 2008 (32) |
January, 2008 (9) |
December, 2007 (6) |
November, 2007 (4) |
October, 2007 (19) |
September, 2007 (36) |
August, 2007 (19) |
July, 2007 (17) |
June, 2007 (16) |
May, 2007 (13) |
April, 2007 (11) |
March, 2007 (5) |
February, 2007 (14) |
January, 2007 (16) |
December, 2006 (16) |
November, 2006 (4) |
October, 2006 (23) |
September, 2006 (14) |
August, 2006 (21) |
July, 2006 (34) |
June, 2006 (25) |
May, 2006 (20) |
April, 2006 (20) |
March, 2006 (17) |
February, 2006 (34) |
January, 2006 (30) |
December, 2005 (23) |
November, 2005 (39) |
October, 2005 (30) |
September, 2005 (49) |
August, 2005 (31) |
July, 2005 (21) |
June, 2005 (35) |
May, 2005 (53) |
April, 2005 (54) |
March, 2005 (60) |
February, 2005 (27) |
January, 2005 (59) |
December, 2004 (70) |
November, 2004 (58) |
October, 2004 (55) |
September, 2004 (64) |
August, 2004 (53) |
July, 2004 (65) |
June, 2004 (50) |
May, 2004 (49) |
April, 2004 (26) |
March, 2004 (20) |
February, 2004 (26) |
January, 2004 (28) |
December, 2003 (12) |
October, 2003 (8) |
September, 2003 (11) |
August, 2003 (1) |
On this page
Search and Translate this Site
Blog Posting Categories
Navigation Links
Blogroll
Scott Adams' Dilbert Blog
Scott Adams is the creator of Dilbert, and his blog is an incredibly smart, clever and often funny (sometimes very serious) look at the world. Everyone should read this blog. |
Alex Scoble
Alex is a former coworker who blogs about a variety of IT-related topics. |
Brent Strange
Brent is a cool dude and a great QA guy that I used to work with. His blog is, appropriately, focused on QA and testing technology. |
Chris Brooks
Chris was formerly my boss at work and is an avid board gamer and photographer. He always has some new info about top-notch board games you may have never heard of, so if you're into them, you should check out this blog. |
Chris Pirillo
Lockergnome by trade, Chris is always up to something new. If you are not familiar with the Lockergnome newsletters, be sure to check them out, too. |
Matthew Lapworth
Matt's a software developer and friend. He seems to enjoy extreme sports. That's fine as long as he doesn't, like, die or something. |
Milind Pandit
Milind writes about all sorts of interesting stuff. We worked toegther for eight years, and he worked at our employer longer than I, which pretty much makes him old as dirt in company time. :) |
MSFT Security Bulletins [RSS]
RSS feed for all Microsoft security bulletins provides an always-up-to-date list of updates along with complete descriptions of each. |
neopoleon.com
Rory Blyth is one of the funniest and most thought-provoking bloggers I read. And I blame him for everything. Literally. |
Scott Hanselman
Scott's computerzen blog is a popular spot for all things .NET and innovative. I used to work with him, but then he went off to Microsoft. He's one of the smartest guys I know, and arguably the best technical presenter around. |
Sign In
Who Links Here
Total Posts: 1889 This Year: 0 This Month: 0 This Week: 0 Comments: 3450
Android (7) Apple (67) AudioBlogging (42) Aviation (2) Blogging (154) Fireworks (5) Geek Out (130) GnomeDex (20) Google Voice (1) Helping Others (27) Home Servers (5) Humor (144) IT Security (218) Kineflex Artificial Disc Surgery (16) Management (8) Microsoft Office (4) Mobile (139) Movies (31) Mt. St. Helens (13) Office 2003 (52) OneNote (29) Personal Stories (163) Photography (29) Random Stuff (642) RSS Stuff (47) RunAs Radio (28) Safe Computing (39) SharePoint (56) Tablet PC (42) Tech (1036) Things that Suck (69) Windows (6) Windows Media Technology (27)
|