
With Hollywood actor Mark Wahlberg failing to impress as the big screen iteration of videogame anti-hero Max Payne, ever-controversial software developer Rockstar Games has this week announced it’s preparing its hard-hitting franchise for yet another all-action outing.
Presently in production at Rockstar’s Vancouver-based studio in Canada, Max Payne 3 has been issued with a scheduled release of “Winter 2009” and will be available on the PlayStation 3, Xbox 360 and Games for Windows, according to an official statement.
“We’re starting a new chapter of Max’s life with this game,” enthused Sam Houser, founder of Rockstar Games. “This is Max as we’ve never seen him before, a few years older, more world-weary and cynical than ever.”
While little is presently known about Max Payne 3’s narrative or gameplay structure, an early poster image suggests adult themes typical of the series thanks to a heavily scarred Max sporting a greying beard and blood spattered liberally across his face and neck.
The only nuggets of information dropped by Rockstar see Max emroiled in a world of corruption, turmoil and intense violence as he leaves New York behind and drifts “from bad to worse” on a search for truth that involves being double crossed and trapped in a city filled with violence and bloodshed – staples of the first two series offerings.
“We experience the downward spiral of his life after the events of Max Payne 2 and witness his last chance for salvation,” added Houser.
Developer Rockstar Games is best known for its often controversial but critically acclaimed Grand Theft Auto games, along with similarly highlighted offerings such as Manhunt, Manhunt 2, and Bully (a.k.a. Canis Canem Edit).
Monday, March 30, 2009
ROCKSTAR GAMES ANNOUNCES 'WINTER 2009' RELEASE OF MAX PAYNE 3
Sunday, March 22, 2009
GOOGLE CHROME BOOSTS SPEED IN NEW BETA

Google has upped the ante in the browser speed wars and added a handful of features with a new 2.0 beta version of its Chrome Web browser (you can download the browser here)
. Though Chrome version 1.0 emerged from beta in December, Google decided to move it back into beta testing and tinker. For those who aren't interested in playing with a beta edition, Google still offers the stable version for everyday Chrome users, as well as a developer version.
According to the official Google Chrome blog, the new beta version processes Javascript 25 percent faster on its V8 (the engine on which Chrome is built) benchmark, 35 percent faster on the Sunspider benchmark, and twice as fast as its original beta. Chrome beta also includes features such as form autofill; a full-page zoom that captures not only text but images; autoscroll when you click your mouse's scroll button; and dragging tabs -- a neat feature that puts your tabs in side-by-side symmetrically-sized windows when you drag a tab outside of the original browser window.
Browsing with the Chrome beta and you will find that its speed boost and add-ons made the browser function like a quicker, cleaner version of Firefox. Downloaders should beware, though: Some reports caution that Chrome 2.0 beta is buggy and users have experienced problems with password management.
Last month Apple introduced a souped-up version of its Safari browser, claiming it was faster than its competitors Internet Explorer, Chrome, and Firefox. If Google's claim that this latest beta version of its browser is twice as fast as the original, It would be interesting to see where this leaves Apple and Google in the faster-is-better browser wars.
Friday, March 20, 2009
THIRD CONFICKER VARIANT EXPECTED APRIL 1

The third Conficker malware variant in infected machines is set to activate April 1, says the director of threat research at CA where the malware sample first discovered last week by Symantec is being examined.
"It's set to go off April 1, 2009 and Conficker will generate 50,000 URLS daily," says Don DeBolt, CA's director of threat research.
Generating that many URLs is a way to hide where it may be calling to download instructions from those who designed it to infected machines. It's not known exactly what those instructions might be but it could involve downloading more malicious code or destroying files.
Antivirus vendor Symantec has also warned of a third wave of Conficker attacks.
CA says it has some ideas about where Conficker originated but isn't discussing that at present.
Wednesday, March 18, 2009
IE8 FASTER THAN FIREFOX OR CHROME...MICROSOFT

Microsoft Corp. says that its own speed tests prove Internet Explorer 8 (IE8) is faster than either Firefox or Chrome.
In a report released last week, Microsoft spelled out how it tests browsers in-house, and again stressed that it doesn't buy the idea that benchmarks -- such as those that score JavaScript performance -- accurately compare the players.
"These benchmarks necessarily characterize only a narrow set of the browser functions in a very constrained way," Microsoft's report said. "End users, however, do not operate in a controlled environment."
Microsoft's tests pitted IE8 Release Candidate 1 (RC1), which launched in late January, against Google Inc.'s Chrome 1.0 and Mozilla Corp.'s Firefox 3.0.5, a version from mid-December. The company timed how long it took each browser to completely render the 25 most-popular destinations on the Web, as ranked by the Web metrics firm comScore Inc., which included google.com, facebook.com, amazon.com, and others.
IE8 was fastest in rendering 12 of the 25 sites, said Microsoft, while Chrome took second by beating the others on nine sites. Firefox, meanwhile, was a distant third, coming in first on just four of the 25 domains.
Microsoft did not test other browsers, such as Apple Inc.'s Safari or Opera Software ASA's Opera, said James Pratt, a senior product manager on the IE development team, because it wanted to focus on rivals that "had a good share on the Windows platform."
Both Opera and Safari for Windows have shares of less than 1%, according to the most recent data from Net Applications Inc., with the former, on all platforms, accounting for 0.7% and the latter just 0.3%.
Nor did Microsoft put IE8 in the ring with later versions of Chrome and Firefox. Chrome, for instance, is currently at 2.0.169.1 as a developer-only build, while Firefox just rolled out 3.1 Beta 2. Both browsers boast better performance, specifically faster JavaScript rendering. "IE8 RC1 is a release candidate, and was very close to being done," explained Pratt when asked why newer versions of Chrome and Firefox had not been used. "But Google and Mozilla were still actively working on [those newer browsers], and they weren't super stable."
JavaScript benchmarks have become a point of dispute between Microsoft and its rivals. While Mozilla, Google, Apple and Opera have all updated their JavaScript engines in the last eight months, and have then trumpeted scores in JavaScript test suites like SunSpider, Microsoft executives have dismissed the bragging as so much noise.
Dean Hachamovitch, IE's general manager, has called claims of competitors a "drag race" that Microsoft isn't interested in joining, while Pratt has downplayed comparisons of any kind. "We're at the point, with what people do in the browser, that users can't really tell the difference between browser [performance]," he said in a January interview.
Pratt said that the just-released report backed that up. "As you can see from the scores, the differences between the browsers are actually very small," he said.
When Computerworld last tested the major browsers' JavaScript performance, immediately after the release of the public beta of Safari 4, IE8 ranked last.
Although Google did not respond to a request for comment on Microsoft's benchmarks, Mozilla's Mike Shaver, who heads all development at the company, applauded any attempt to boost IE's performance. "I don't think anyone here has had a chance to really look at their methodology yet or tried to reproduce their results, but to whatever extent Microsoft is working to improve the performance of IE it's a good thing for the Web," said Shaver in an e-mail late Thursday.
Sunday, March 15, 2009
NOKIA PLANS TO PRODUCE MOBILE COMPUTING DEVICES
Is Nokia looking to play ASUS and Acer at their own hardware game?
Technology companies intent on increasing their product reach by implementing manufacturing crossovers seems to be a habit that’s gathering momentum.
Moreover, while Netbook heavyweights ASUS and Acer have recently expanded into the world of smartphones, mobile phone titan Nokia has announced a shift of focus towards computer hardware.
Speaking in a recent Finnish television interview with YLE, Nokia CEO Olli-Pekka Kallasvuo has said the Espoo-based market leader is considering plans to begin production of its own line of mobile computer systems, describing the new devices as capable of merging the features and functions of a PC along with those of a mobile handset.
“We don’t have to look even for five years from now to see that what we know as a mobile phone and what we know as a PC are in many ways converging,” said Kallasvuo regarding a move towards portable computing. “We are looking very actively also at this opportunity.”
According to tech publication ITProPortal, a related report offered up by the “well-connected” folks at Unwiredview claims Nokia has already progressed its plans to the point of creating a functional mobile computing device built on an open-source Linux operating system.
The report also suggests the platform could ultimately function on Nokia's own Symbian operating system and physically resembles the Nokia N800 touch-screen Tablet (pictured), which, if true, would eliminate a fully-fledged move into the ultra-portable Netbook or traditional notebook computer category.
Other features apparently crammed into the diminutive device, which is supposed to be on schedule for a 2011 arrival, includes ARM’s multi-core Cortex A9 Sparrow processor and a somewhat unusual button-equipped keyboard with diamond-shaped keys.
Saturday, March 14, 2009
PASSWORDS LIST USED BY THE CONFICKER WORM

It's not possible to emphasise enough the importance of using sensible passwords on your network.
Not just on the areas of your network that you don't want your users to traipse through, but also on the default network shares that are present on installations of commonly used operating systems like Windows NT/2000/XP/2003.
One of the ways in which the Conficker worm (also known as Confick or Downadup) uses to spread is to try and batter its way into ADMIN$ shares using a long list of different passwords.
As you can see in the list below, it relies upon computers using poorly chosen passwords such as dictionary words, "password", "qwerty" or sequences of letters or repeated numbers:
click on the image for a larger view or save the image for your own guide:
One way to make it harder for password-cracking malware like Conficker from spreading across your network is to ensure that no-one is using a poorly-chosen password.
And, of course, please don't delay installing the critical security patch that Microsoft issued late last year.
Friday, March 13, 2009
SECUNIA REPORT SPARKS FIREFOX VS. INTERNET EXPLORER FEUD

A report by Secunia finds the vulnerabilities in Mozilla Firefox greatly outnumbered those in Internet Explorer, Apple Safari and other browsers in 2008. However, Mozilla was quicker to react than Microsoft when dealing with vulnerabilities disclosed publicly without prior vendor notification, Secunia says.
Mozilla's Firefox Web browser has been gaining market share against Microsoft Internet Explorer for years now. However, in 2008 it surpassed IE in a far less glorious category: number of bugs.
According to browser vulnerability research by Secunia(PDF) 115 security vulnerabilities in Firefox were reported in 2008—nearly twice as many as IE and Apple Safari combined. However, the news is not all bad, as the same report showed that Mozilla was much quicker to respond than Microsoft when flaws were publicly disclosed either prior to or without vendor notification.
Three Firefox vulnerabilities were publicized last year under those conditions. All three were patched, with the longest patch taking 86 days to arrive, according to Secunia. For IE, however, only three of the six such vulnerabilities were patched as of Dec. 31. One of the IE vulnerabilities remained open for 294 days in 2008, according to the report.
The report noted that not all vulnerabilities are created equal. The three aforementioned Firefox flaws were rated "less critical," while the Microsoft vulnerabilities were more of a mixed bag. The three unpatched IE flaws were rated either "not critical" or "less critical." Two of the patched bugs were classified as "moderate" and "high," while the third patched bug was considered "less critical."
On March 4, Mozilla released an update plugging eight security holes in Firefox 3.07, of which six were rated critical. The vulnerabilities affect the browser's garbage collection, PNG libraries, layout and JavaScript engines.
The critical vulnerabilities could enable hackers to run arbitrary code. But there is also a vulnerability rated "high" that could allow a Web site to use nsIRDFService and a cross-domain redirect to steal private data from users authenticated to the redirected Web site.
The update came a day after Opera Software issued a security update for its browser, and roughly a week after Apple released a beta version of Safari 4.
Friday, March 6, 2009
OPERA BROWSER UPDATE FIXES CRITICAL SECURITY HOLE, NEW WINAMP FLAW

Opera today released an update to its Web browser that closes a number of security holes, including one the company rates "Extremely Severe."
The flaw would allow a specially crafted jpeg image to crash Opera and run any command on your PC, which is about as bad as it gets: If you browsed a site with one poisoned image, you could end up with malware.
The new version, 9.64 (release notes), also adds support for two Windows security mechanisms, Data Execution Prevention (DEP) in Windows XP and Address Space Layout Randomization (ASLR) in Windows Vista. So if you use Opera, get this must-have fix by clicking Help | Check for Updates. Opera still annoys with a lack of an auto-update feature, so you'll have to download and run the 5.4 MB installation file to upgrade.
Meanwhile, Secunia warned today of a security flaw in the Winamp media player that can also allow an attacker to have his way with your PC if you open a malicious CAF audio file. Secunia reports that the flaw exists in the latest downloadable version, 5.55, as well as 5.541 and possibly other versions as well. And there's no word yet of a fix, so be extra careful with CAF files.
Thursday, March 5, 2009
PSN AMASSED 20MILLION USERS DWARFS XBOX LIVE

If the videogame blogosphere is to be believed, the once mighty PlayStation brand is on the verge of flopping thanks to the pennywise dominance of Nintendo and Microsoft hardware and a consumer demographic unwilling to invest greater sums of money in Sony’s Blu-ray-equipped PlayStation 3.
However, Sony Computer Entertainment would beg to differ. Having this week rebuffed analyst claims of an imminent price cut to its PS3 console, and highlighting fiscal performance that’s on track for 10 million unit sales, Sony has also moved to draw attention to the successful spread of its PlayStation Network (PSN).
Sony has today announced it has taken the PlayStation Network just 27 months to amass more the 20 million registered users, a substantial figure that outstrips the 17 million users presently active on Microsoft’s Xbox Live network, which is in its seventh year of service.
While both PSN and Xbox Live offer largely similar platforms, including online multiplayer access, demo and trailer downloads, exclusive add-on content, and global gamer socialising, the two differ massively insofar as Xbox Live costs $50 USD per year for full access, while usage on the PlayStation Network is completely free.
Available around the world in 55 countries, the PlayStation Network currently offers some 14,500 downloadable media items (including game content, movies and TV shows) and has already delivered more than 380 million digital downloads with an accompanying value of $180 million USD.
Friday, February 27, 2009
NEW SNEAKY VIRUS INFECTS VIA GOOGLE'S DOUBLE CLICK ADS

Hackers infiltrated popular tech business site eWeek.com using Google's DoubleClick banner ads as a vehicle. Websense caught the malicious coding and published its results, which spurred eWeek to scour its code and remove all phony advertisements.
The pest, named Anti-Virus-1, is complicated and smart. The advertisements are for antivirus software, and when a user clicked on them, the ads redirect to a pornography Website through a series of iframes. Then a PDF pops up loaded with evil code, exploiting a weakness currently festering in the Adobe systems; or the file index.php redirects to the rogue ad server. The server places a file named "winratit.exe" into the user's temporary files folder and stays there without any user interaction.
If the user tries to cleanse the computer by visiting any of several popular software downloading sites, the hack has a twist of the blade waiting: the host file is modified to redirect to even more malicious Websites offering further rogue downloads.
eWeek may not be the first popular Website to be attacked."Given DoubleClick's tremendous reach,it's possible the rogue ads have shown up on Websites other than eWeek," Websense Vice President of Security Research Dan Hubbard told The Register.
Thursday, February 5, 2009
NEW RELEASE FIREFOX 3.0.6 FIXES CRITICAL SECURITY FLAWS

Mozilla developers released the latest version of their Firefox browser Tuesday, version 3.0.6, which fixes several security bugs in the software.
The most critical issues are bugs in the browser's JavaScript and layout engines that could be exploited by attackers to run unauthorized software on a victim's PC, Mozilla said. The flaws also affect Mozilla's Thunderbird e-mail client and SeaMonkey Internet software suite.
The update, Firefox's first of the year, also fixes five other security bugs in the browser, all of which are considered less critical.
The update includes some other performance and stability improvements, including new code that will help scripted commands, such as those used by Adblock Plus, to work better with plug-ins, and addresses a few display issues reported by users.
Friday, January 16, 2009
PARIS HILTON'S WEB SITE USED AGAIN IN MALWARE ATTACK

Paris Hilton's Web site has been hacked and is serving visitors a malicious Trojan program designed to steal sensitive information from their computers.
The hack was discovered by security vendor ScanSafe, which said that Parishilton.com (note: this site is not safe to visit as of press time-Jan. 13-2009) had apparently been compromised since Friday. Visitors to the site are presented with a pop-up window urging them to download software in order to enhance their viewing of the site. Whether they click "yes" or "no" on this window, the site then tries to download a malicious program, known as Trojan-Spy.Zbot.YETH, from another Web site.
"The popup points to a directory on that Web site; that's where the malware is being loaded from," said Mary Landesman, a security researcher with ScanSafe. Once installed, the Trojan steals online information and tries to install more malicious software on the victim's computer.
Landesman believes thousands of other Web sites may also be serving up this variant of the attack her firm uncovered. However, Parishilton.com, the celebrity's official Web site, is the best-known target. "The big thing with Paris Hilton is the number of visitors that she gets," Landesman said. "It's always doubly concerning when we see a high-profile Web site get compromised."
To make things worse, most antivirus products are not identifying the Trojan program being served by Parishilton.com. On Monday afternoon, only 12 of the 37 vendors tested by VirusTotal identified the Trojan.
Wednesday, January 14, 2009
WINDOWS 7 Beta IS NOT ANTIVIRUS-FRIENDLY

Users trying the Windows 7 beta who keep their computers safe with McAfee virus protection are in for a bit of disappointment -- and a loss of security. According to a Channel Web report, when you try to run McAfee Total Protection in the Windows 7 beta, an error message pops up. "The version of Windows installed on this machine is not supported. Please refer to the product documentation for a list of supported operating systems."
McAfee's antivirus tool isn't the only one affected by the Windows 7 beta. A thread on Norton's community forums mentions errors that occur when running Windows 7. The official response from Norton? "At this time, we do not support Windows 7. Once Windows 7 is released, we will provide solutions for the OS." In the past, prerelease copies or even early shipping versions of Windows updates were often flagged as "potential viruses" by antivirus programs (prompting lots of jokes about Windows being fingered as a virus).
One popular virus protection software that seems to be immediately compatible with Windows 7 beta is Spyware Doctor, which reports in its forums that the software is running smoothly.
Personally, I use Avast on my PC, although I haven't gotten around to checking out Windows 7 yet. It looks like Avast does have some issues, though for the most part it still runs in Windows 7.
The main problem seems to be that Windows 7 is still in beta, so no virus protection software has been optimized for the OS yet. As always when installing beta software, you do so at your own risk. Just know that this risk could impact your entire PC's security.
Saturday, January 10, 2009
MORE DETAILS ON SUPERSPEED USB 3.0

Intel's Jeff Ravencraft, who is also president of the USB Implementers Forum, discussed more details about USB 3.0 today at the Storage Visions conference in Las Vegas.
The focus of the new spec is three-fold: Retain backward compatibility, increase speed, and provide better power handling.
"USB has been the most successful interface in history of personal computing," Ravencraft noted. "Over 6 billion products are in the market, and over 2 billion ship a year now."
Compatability
Backward compatibility shows up in the new standard. USB 3.0 maintains the extensive device class driver infrastructure of USB 2.0, and a USB 2.0 devices will work via a 3.0 connector.
Performance
Performance improvements are notable, too. "We have research that shows that after 1 minute, 1.5 minutes waiting for a transaction, users get impatient.," says Ravencraft. "The transfer times have to get much faster." Hence the evolution of USB SuperSpeed's Sync & Go concept.
SuperSpeed USB 3.0's 5Gbps data rate (compared with Hi-Speed USB 2.0's 480Mbps) should help--and with very clear real-world advantages. For example: A 25GB HD movie will take 13.9 min to transfer with USB 2.0, and 70 seconds with USB 3.0, says Ravencraft.
Practically speaking, the implications are tremendous. Imagine not having to wait hours on end for your full-drive data backup to complete, or not having a lengthy delay when off-loading 32GB flash memory cards from your digital camera.
Power
As for power consumption, "power today is king for portable devices. It is the pinnacle, the focus for the PC, the notebook, and all devices. All of these new specs had to be optimized for power efficiency," says Ravencraft.
For example, there's no longer any device polling, so connected USB devices can enter a virtual sleep mode; more power will be able to go to the device (which will hopefully eliminate some of the power issues we see today with portable hard drives that require extra power from a second USB port); and USB 3.0 will no longer broadcast information to all connected devices, thereby saving power, too. Plus, when a device's battery is drained, it will now still be recognized by a laptop, for example, so you can charge it (this doesn't work with USB 2.0).
The intention is for SuperSpeed USB 3.0 to provide headroom for the next five years.
Thursday, January 8, 2009
COMMERCIAL GAMES FOR DOWNLOAD AS FREEWARE

Who wants scads of commercial PC games for free? No, I don't mean the kind you download illicitly, silly. I'm talking about older but as well a few newer games, including the occasional award-winner, that publishers have made available over the years and on the house.
Games like Richard Garriot's pre-Ultima RPG Akalabeth (1979). Revolution Software's Beneath a Steel Sky (1994). The original Command & Conquer Red Alert (1996). SSI's Dark Sun: Shattered Lands (1993). Rockstar's Grand Theft Auto 2 (1999). Sierra's Tribes 2 (2001). Even S2 Games's just-last-January Savage 2 (2008).
No comment on Wikipedia's value as a repository for factual data, but its "List of Commercial Games Released as Freeware" is both convenient and verifiable. It's an alpha-sorted collection of older and some not-so-old titles with links to their Wiki pages, which in turn link to each game's freeware storehouse.
Have a look. There's Abe Lincoln Must Die! (2007), the fourth in the recently released gonzo Sam & Max series -- obviously bait for the other five episodes outstanding, but worth a look just the same.
Remember Bungie's pre-Halo Marathon Trilogy? Yep, all three, available gratis (and the first one's a whole 4.7MB!).
Pick of the litter? Possibly Virgin's SubSpace. It's a simple two-dimensional multiplayer space shooter, easy to learn, challenging to master, and pathologically habit-forming. It was also still being updated, according to Wikipedia, through 2007.
Tuesday, December 23, 2008
ANOTHER LIFE EXTENSION FOR WINDOWS XP

Microsoft has once again put Windows XP on life support, extending the OS's death date to May 30, 2009. This reprieve comes two months after rumors swirled about another potential bail out.
In the new agreement -- first discovered by ChannelWeb -- distributors can purchase XP licenses until January 31, 2009, the original date in which XP was supposed to turn to dust, but take delivery against those orders through May 30.
Windows XP was supposed to stop shipping on January 30, 2008, but that date has been extended several times. It will live on Netbooks until 2010. XP is also still a booming business: Dell started charging $150 per Vista downgrade -- three times as much as the original fee.
Meanwhile, Windows 7's rumored release date hovers around October 2009. With each extension of Windows XP's death, Microsoft inches closer to Windows 7's release, thereby sublimating Vista and its skimpy chances at some kind of late-blooming success. Given the market's resistance to Vista -- and Microsoft's own perceived uncertainty -- we should expect Windows 7 to arrive sooner rather than later so the monstrous software company can save face.
Monday, December 22, 2008
NEW SAMSUNG ANDROID

Samsung will roll out a mobile phone based on the Google Android operating system by the second quarter of 2009, according to a report from Korean news agency ETNews. While details are sketchy, Samsung will reportedly release the phone via cellular carriers Sprint Nextel and T-Mobile.
The phone will likely be a touchscreen model similar to Samsung's Instinct and Omnia handsets, both of which more closely resemble the Apple iPhone than HTC's less sleek T-Mobile G1, currently the only Google Android phone on the market. Samsung's device will provide all the Google essentials we'd expect, include search, mapping, mail, and instant messaging, the report states, but it's a safe bet that other Google tools will be added as well.
It would appear that Samsung has high hopes for its Google phone. It has reportedly "accelerated" development of the project, adding 30 Linux and Java experts to a design team that now has up to 80 members. It seems likely that Samsung will beat other Open Handset Alliance members to market, including Asus, LG, Motorola, and Sony Ericsson, all of whom have Android-based projects in the works.
The growing interest in the Android OS, as well as the staggering popularity of the iPhone, which now commands over 30 percent of the U.S. smartphone market, is more bad news for Microsoft's Windows Mobile, which is declining in popularity among end users and phone manufacturers alike.
Let's hope the Samsung handset will borrow some of the iPhone's elegance, but a slide-out keyboard would be nice too.
Saturday, December 20, 2008
IE BUG USED TO EXPLOIT WORD DOCS

Attackers are exploiting the just-patched vulnerability in Internet Explorer (IE) by hiding malicious ActiveX controls in Microsoft Word documents, a security company said Thursday.
"Inside the document is an ActiveX control, and in that control is a line that makes it call out to the site that's hosting the malware," said David Marcus, the director of security research and communications for McAfee Inc.'s Avert Labs. "This is a pretty insidious way to attack people, because it's invisible to the eye, the communication with the site."
Embedding malicious ActiveX controls in Word documents isn't new -- Marcus said he had seen it "a time or two" -- but using an ActiveX control to ping a hacker's server for attack code is "definitely an innovation," he added. "They're stepping it up."
The rogue docments can be delivered as attachments to spam e-mail or offered up by hacked sites.
Attackers have been exploiting the IE bug since at least Dec. 9, when reports first surfaced about malicious code found in the wild and on several Chinese hacker servers. McAfee was one of the first security companies to report the emerging exploit.
Since then, Microsoft acknowledged the bug, then offered up a series of advisories urging users to take protective steps until a fix was available.
Wednesday, the company released the patch.
Although other researchers continue to claim that thousands of legitimate Web sites have been compromised, then used to serve "drive-by" attacks against unpatched browsers, Marcus wasn't certain about the numbers he's seen bandied about. "But absolutely, there's been a lot of activity around this," he said. "A lot of the bad guys have embedded IFRAMES in their sites to attack IE."
According to other reports, the IE exploit has been added to one or more multi-strike hacker toolkits that try several different exploits when users visit a compromised or malicious site. "If it's not in one of those yet, it probably will be," said Marcus. "Some of the exploits in those kits are years old, so a good one like this, unpatched until yesterday, will make its way into them."
Marcus recommended that users be cautious about opening Word documents, keep their security software up-to-date, and apply the IE patch as soon as possible.
Friday, December 19, 2008
GOOGLE'S SHUMAN GHOSEMAJUNDER EXPLAINS CLICK FRAUD - a SES Video
Click fraud is a very complex issue. Unfortunately, much of the information available has been misinterpreted due to that complexity. In this video, Shuman Ghosemajumder of Google gives some information that will hopefully clear up that gray area.
For starters, click fraud is driven by 2 major incentives:
1. Attacking advertisers - when an advertiser tries to hide one of his competitors
2. Inflating affiliates - when an AdSense publisher tries to fraudulently increase his own revenue by generating false clicks
Methods of click fraud stem from simplistic techniques to sophisticated techniques. Simplistic methods include manual clicks such as when a fraudster personally clicks ads on his own computer. It gets a little more sophisticated when a fraudster organizes botnets and uses them for click fraud. Click farms, which consist of individuals or organizations that try to hire people to click on ads continuously, fall somewhere in the middle of the simple and sophisticated click fraud techniques.
Shuman does point out that: “the impact of invalid clicks at Google is minimal.”
Google detects click fraud through simple rules and statistical anomaly detection. Google’s simple rules consist of certain rules they have already defined as what they classify as an invalid click. Since some simple rules can be easily broken, statistical anomaly detection is more effective because it looks at specific activities on websites and compares the expected behavior to the observed behavior. This data gives Google a better understanding of how to detect invalid clicks.
For advertisers wanting to take proactive measures to prevent click fraud, Shuman advises keeping the return on investment (ROI) as the central focus. Research and gather as much data as possible, test everything, and track all results. If you apply these actions and your ROI drops for no reason, you have a good reason to suspect undetected click fraud and should file a claim.
Tuesday, December 16, 2008
IS CHROME 1.0 READY FOR PRIMETIME?

Opinion
Google's chief of user experience Marissa Mayer told TechCrunch' Michael Arlington at yesterday's Le Web' 08 conference in Paris that Chrome is coming out of beta. Period. No further explanation was provided and the company did not even issued a press release. The only official information is a low-key Google blog post.
It is very unusual for any vendor to move such a young product out of beta after just 100 days of availability. That is especially true for Google, which had no problems with freezing flagship products in beta for years so far. Gmail is five years old and still carries the beta label, as does the three-year old Docs service.
What about Chrome? If we leave aside for a moment that the 1.0 version is virtually identical with the most recent beta version that preceded it, the removal of a beta label typically implies that a product is reliable enough for everyday use and that it is feature complete. Such a message tries to attract users who were previously put off by a beta product, which usually yells “be careful, bugs!” If you think about it, beta always means "work in progress." Also, any product development team typically aims to test a feature-complete version of a product in a beta or at least release candidate phase, before rolling it out as a final. Chrome may be lightning-fast, but, in our opinion, Chrome is not only rough around the edges. It is also far from being feature-complete.
Stable enough for everyday use? Feature complete?
The company's blog post states that audio and video plug-ins are improved, claiming "better performance and stability." The 1.0 Chrome release still has issues with the Flash plug-in and stopped working on several websites we accessed. Yes, there were thirty-something tabs open, but the Flash plug-in should not crash in a 1.0 browser release regardless of the number of open tabs. Simply put, Chrome 1.0 is as stable as the 0.4.154.22 beta was and Google can’t wiggle itself out of this claim.
Google highlights a bookmark manager and more granular privacy controls in a manner that implies changes in the 1.0 version whereas, in fact, they were first rolled out nearly a month ago in a release with version number 0.4.154.22, followed shortly by a bugfix-only release with the version number 0.4.154.22. The latter was the 13th release in a row, followed by yesterday's 1.0 release.
Google may have a different definition of what is feature-complete and not and it may want to keep the browser as streamlined as possible. But Chrome needs more security and privacy options, its minimal user interface and the variety of configuration options could use some improvements. Right now, Chrome seems to appeal to a very specific user group that looks for uncompromised performance, whereas Firefox appeals to a much broader range and provides a much more reasonable compromise between feature set and streamlined browser design. The product itself is clearly not yet competitive enough to play with the big boys.
Marketing reasons?
Chrome is not a final version in a traditional sense. It is just not a good idea to replace a beta label simply with a final label and hope that it magically becomes final as a result.
The only reasons that make sense to us are marketing related. Beta browsers tend to be stuck below the 1% market share level and are not as strongly adopted as “final” browsers. Perhaps Google got tired of being compared to the market shares of Opera and IE8 Beta? From our perspective, the decision to remove the beta label is a sign of desperation and pure marketing move designed to inflate Chrome's market share.
Also, think about Google’s intention to bundle Chrome with PCs. If you were a PC vendor, would you give your customers a beta browser? As a customer, would you like to get beta software on your PC? Of course not.
Conclusion
The bottom line is: End-users do not benefit from Chrome 1.0 compared to Chrome 0.4.154.22 beta in any way. From a marketing perspective, the removal of the beta status will probably drive Chrome's market share, but the gains will be short lived, if there aren’t any substantial updates that do not offer widespread plug-in support and new end-user features in a timely manner.
Delivering the features users want may be the easiest way to drive user numbers up and create a loyal following. Resort to cheap tactics like pushing a beta product into an official 1.0 status out of the blue is a risky attempt to inflate user numbers and may backfire. As a final product, Chrome has lost its beta benefit in browser comparisons and may not fare as well anymore. Even worse, the credibility of final versions delivered by Google may suffer.
I would have no problem with their removal of the beta label at all if a) Chrome 1.0 brought a jump in quality compared to the most recent beta version or b) if Google provided a Chrome roadmap months in advance, as Mozilla does, to let users know which beta release should be considered the final candidate release.
We still believe that Chrome may become a fantastic browser overall. But yesterday’s 1.0 rollout was wrong. Chrome should still be labeled as a beta product. Sure, it is difficult to downgrade it back again to a 0.9 version. But what about an upgrade to 1.5 beta?
By Christian Zibreg

