More About Me...

Ebook For Programmer and IT Support , Free and Free...

Another Tit-Bit...

It's all about IT , Ebook , Tutorial , News ... Try to Share.... Technoly is Never Ending and Knowledge is Free....

Top 10: Microsoft's bug, Greenspan speaks, Android launches

This week's roundup of the top tech news stories includes Microsoft's critical bug, Android's launch, the tech economy, and more

Soon after Microsoft released a patch for a critical bug in its Windows Server software, attack code surfaced, and by Friday afternoon an early sample of the code was out, which led to the week ending on a warning note. Between the beginning and the end of the week, former Fed chairman Alan Greenspan blamed the U.S. economic crisis at least in part on the use of bad data. Perhaps next week will bring better news.


1. Attack code for critical Microsoft bug surfaces and New worm feeds on latest Microsoft bug: It didn't take long after Microsoft provided information about a critical Windows flaw, along with a patch, before attack code showed up. Developers of the Immunity security testing tool had an exploit written within a couple of hours of Microsoft's announcement on Thursday. Although the developer's software is only for paying customers, security researchers said they expected a version of the code to go public soon. That happened Friday afternoon when sample code appeared on the Web. The flaw, in Windows Server service, which is used to connect network resources, was also being exploited by a worm.

[ Video: Catch up on the news of the week with the World Tech Update ]

2. Greenspan, Cox tell Congress that bad data hurt Wall Street's computer models: Insufficient and faulty data used in risk management models contributed to the financial mess embroiling the U.S. and rippling across the globe, said former U.S. Federal Reserve chairman Alan Greenspan. Financial firms made business decisions using "the best insights of mathematicians and finance experts, supported by major advances in computer and communications technology," Greenspan told the House Committee on Oversight and Government Reform. "The whole intellectual edifice, however, collapsed in the summer of last year because the data inputted into the risk management models generally covered only the past two decades -- a period of euphoria."

3. Microsoft expanding Surface access: In order to get the SDK for Microsoft's touch-based apps platform, developers had to buy Surface hardware, which could be a pricey proposition. Well, no more: Microsoft will give the SDK to developers who attend a Surface workshop at its Professional Developers Conference next week.

4. Android phone launch day relatively quiet: Google's Android phone went on sale Tuesday, with people here and there standing in short lines outside of stores to be first to get their handsets. While there wasn't anything approaching the buzz surrounding the first iPhone sales, T-Mobile stores reported a steady stream of customers for its G1 phone, which is the first on the market to run the Android operating system.

[ Special report: All about Google Android ]

5. Intel repudiates executives' criticism of the iPhone: Comments from Intel executives who criticized the iPhone weren't appropriate, Intel said, after reports on the statements emerged from the company's developer forum in Taipei. Shane Wall and Pankaj Kedia said the iPhone is slow and incapable of running the "full Internet" because the smartphone has an Arm processor instead of, you guessed it, an Intel processor. "Apple's iPhone offering is an extremely innovative product that enables new and exciting market opportunities. The statements made in Taiwan were inappropriate, and Intel representatives should not have been commenting on specific customer designs," the company said later in a statement posted on its Chip Shots Web site.

6. Gmail activation problem in Apps finally solved: A problem was finally solved this week with Google Apps that kept those who recently subscribed to its Web-hosted office suite from being able to get to their new Gmail accounts. The problem kept Gmail accounts from being activated for new Apps users, starting late last week. The company said Monday the problem would be fixed by Tuesday, but it didn't work out that way, to the consternation of many Apps users, or would-be users.

7. Sun tussles with startup over noted systems designer: In an oddball of a story, startup Arista Networks set off a mini firestorm with Sun Microsystems when it announced that Andreas Bechtolsheim is the company's new chief development officer. Bechtolsheim, you see, is Sun's chief scientist and a top-notch systems designer, so Arista's news led to reports that he had resigned from Sun, which Sun denied, sending e-mail to journalists saying those reports were inaccurate and that he would continue at the company, though part time. That led Arista's director of marketing, Mark Foss, to say that as far as the startup is concerned Bechtolsheim is working full time at Arista, and that there was "a miscommunication" between his company and Sun that they were working to clarify. Bechtolsheim then did the clarifying -- he works full time now at Arista, which he cofounded and where he also serves as chairman, but he's going to advise Sun on a part-time basis of "no more than one day a week."

8. Intel shows off new laptop platform: Users got a glimpse of Intel's upcoming laptop platform, code-named Calpella, at the Intel Developer's Forum in Taiwan. The primary focuses of Calpella are efficiency and battery life.

9. Microsoft looks to secure Web content: At its Professional Developers Conference next week, Microsoft will show off its Web Sandbox initiative, which seeks to secure Web content by isolating it. The technology includes a cross-browser JavaScript virtualization layer that provides a secure standards-based programming model without requiring any add-ons.

10. Where the presidential candidates stand on tech issues: Both Democrat Barack Obama and Republican John McCain bring technology experience to the table as presidential candidates, though the experiences are quite different. Obama is an avid user of technology -- he's among the capital's BlackBerry enthusiasts -- while McCain admits he's not much for using electronic devices, but he has been on the Senate Commerce, Science and Transportation Committee for a long time, and a lot of technology-related legislation passes through that group before going to the full Senate. IDG News Service took a look at where they each stand on five key technology areas: telecommunications, national security, privacy, IT jobs, and innovation.
Office 2007 Service Pack 2 due in spring '09
SP2 of Office 2007 will introduce support for ODF and PDF as well as a more reliable calendar and faster performance for Outlook and other improvements

Microsoft said via a company blog Wednesday that Service Pack 2 (SP2) of Office 2007 will ship between February and April of next year.

The software maker had already said that SP2 will introduce support for the Open Document Format (ODF) used by Office's chief competitor, OpenOffice.org, the Portable Document Format (PDF) created by Adobe Systems, and its own XML Paper Specification (XPS) that is meant to compete with PDF.

The Office Sustained Engineering blog confirmed those features, and some others:

A more reliable calendar and faster performance for Outlook 2007;
Improvements to Excel 2007's charting;
Enabling Object Model support for charts in PowerPoint 2007 and Word 2007;
An uninstallation tool for Office 2007 service packs;
Improvements to server editions of Office 2007.

This is in contrast to SP1 of Office 2007, released last December, which mostly provided bug fixes rather than new features.

Office 2007 was released to businesses in November 2006, the same time as Windows Vista, with shipments to consumers and small businesses in January the following year.

Office 2007 was far different than prior versions, using a new "Ribbon" interface. Despite the risk of customer rejection, Office 2007 has been widely considered a sales and marketing success, unlike Vista.

Microsoft said it plans to divulge more details in Office blogs in the next few weeks. It will also begin inviting Office enterprise customers to a private SP2 beta in the next few days, which may or may not turn into a public one.
Google patches Chrome 'carpet bomb' bug
The months-old bug can be used to trick people into downloading and launching malicious code
Google has patched its Chrome browser to block a months-old bug that can be used to trick people into downloading and launching malicious code.

The fix has not been pushed out to most users, however.

[ For more on Google's Chrome browser, see InfoWorld's special report. ]

The security researcher who reported the vulnerability, which involves a combination of the "carpet bomb" bug with another flaw disclosed in August, called the fix "enough for the time being," but said Google's patch wasn't the final word.

Google plugged the hole in a developer-only version of Chrome that has not yet been sent to all users via the browser's update mechanism. Chrome users, however, can reset the browser to receive all updates, including the developer editions, with the Channel Chooser plug-in.

According to a Google blog, Chrome 0.3.154.3, which was released last week, changes the browser's download behavior for executable files, such as .exe, .dll, and .bat files on Windows.

"These files are now downloaded to 'unconfirmed_*.download' files," said Mark Larson, Chrome program manager, in the blog post. "In the browser, you're asked if you want to accept the download. Only after you click Save is the 'unconfirmed_*.download' file converted to the real file name. Unconfirmed downloads are deleted when Google Chrome exits."

Last month, Israeli security researcher Aviv Raff demonstrated how hackers could create a new "blended threat" -- so named because it relies on multiple vulnerabilities -- to attack Chrome. Raff's proof-of-concept code used an auto-download vulnerability (aka "carpet bomb") along with a user interface design flaw and an issue with Java.

Chrome contributed to the vulnerability by making downloaded files appear as buttons at the bottom of the browser's frame, Raff said then.

Tuesday, after examining the 0.3.154.3 developer build, Raff proclaimed the fix sufficient for the short term, but nothing more. "The fix is not good enough. [But] it's enough for the time being, until other small issues might popup and be used to exploit the auto download problem," Raff said in an interview conducted via instant messaging. "The best solution was if they just won't download the files until the user approves, or download them to a random directory..., as it's done with other browsers, like Internet Explorer's Temporary Internet Files folder or Firefox's random profile directory."

On the plus side, Raff said, Chrome shows the full filename -- the "unconfirmed_*.download" that Google's Larson described -- so that users can see if the file is, in fact, an executable and potentially dangerous.

But Chrome still has holes. "Even if [Google assigns executables] a random filename, it might still be possible to predict the downloaded filename," Raff said. "They delete the automatically downloaded files only after the user shuts down the browser. What happens if the browser crashes? The malicious files might still exist after the crash."

The best solution would be for Google to prevent any files from downloading through Chrome without user permission. "I think that downloading any file without user interaction to a predictable location, [for example] the default download directory, is still bad," Raff argued. "Even if the extension is not an executable, there might be other ways to execute those files. For example, through the Windows command line you can execute any file with a PE header, even if they have a different extension."

Chrome accounted for less than 1 percent of the browser market share during its first month of availability, according to data from Net Applications.
Attack code for critical Microsoft bug surfaces
Security developers were able to write an exploit code in two hours after Microsoft released an emergency patch

Just hours after Microsoft posted details of a critical Windows bug, new attack code that exploits the flaw has surfaced.

It took developers of the Immunity security testing tool two hours to write their exploit, after Microsoft released a patch for the issue Thursday morning. Software developed by Immunity is made available only to paying customers, which means that not everyone has access to the new attack, but security experts expect that some version of the code will begin circulating in public very soon.

Microsoft took the unusual step of rushing out an emergency patch for the flaw Thursday, two weeks after noticing a small number of targeted attacks that exploited the bug.

The vulnerability was not publicly known before Thursday; however, by issuing its patch, Microsoft has given hackers and security researchers enough information to develop their own attack code.

The flaw lies in the Windows Server service, used to connect different network resources such as file and print servers over a network. By sending malicious messages to a Windows machine that uses Windows Server, an attacker could take control of the computer, Microsoft said.

Apparently, it doesn't take much effort to write this type of attack code.

"It is very exploitable," said Immunity Security Researcher Bas Alberts. "It's a very controllable stack overflow."

Stack overflow bugs are caused when a programming error allows the attacker to write a command on parts of the computer's memory that would normally be out of limits and then cause that command to be run by the victim's computer.

Microsoft has spent millions of dollars trying to eliminate this type of flaw from its products in recent years. And one of the architects of Microsoft's security testing program had a frank assessment of the situation Thursday, saying that the company's "fuzzing" testing tools should have discovered the issue earlier. "Our fuzz tests did not catch this and they should have," wrote Security Program Manager Michael Howard in a blog posting. "So we are going back to our fuzzing algorithms and libraries to update them accordingly. For what it's worth, we constantly update our fuzz testing heuristics and rules, so this bug is not unique."

While Microsoft has warned that this flaw could be used to build a computer worm, Alberts said that it is unlikely that such a worm, if created, would spread very far. That's because most networks would block this type of attack at the firewall.

"I only see it being a problem on internal networks, but it is a very real and exploitable bug," he said.
Perl 6 isn't vaporware
A Perl project contributor takes me to task for selling the next-gen dynamic language short

At least one of you was a little miffed at something I said in last week's post about dynamic languages and virtual machines, and there was probably more than one of you, so I thought it would only be fair to air the issue in the open. Specifically, on the subject of Perl 6, I declared, "some would say it has officially graduated to vaporware status."

First, I should apologize. Weasel words like "some would say" and "many believe" are the crutches of lazy journalists everywhere, and I shouldn't have fallen back on such phrasing. Let me come clean, then, and confess that the "some" includes me, and from here on, I speak for myself. Perl 6, in my opinion, is pretty much vaporware.

As I said, however, not everyone agrees. (I'll leave it to someone else to decide whether the dissenting base consists of "some" or "many" people.) Reader "chromatic," a longtime contributor to the Perl codebase and the online managing editor of O'Reilly Media, weighs in:

I believe anyone who considers Perl 6 or Parrot to be "vaporware" has not bothered to look at the project or ask anyone involved with it about its current state. It's a small nit in an otherwise correct article, but it's a glaring nit.

As far as I've always heard, "vaporware" meant "a project, long promised by marketing, which doesn't actually exist." For that to be true of Perl 6, we'd have to have a marketing department (which we don't) and Perl 6 would have to not exist (which it does).

At this point, I should own up some more. I admit that I am not as in-tune with the Perl community as I once was. Years ago, back when I wrote more lines of code than sentences, I hacked out my share of incredibly functional Perl scripts and CGIs. I've since recanted. I've gone over to the camp that says Perl's loose C-like syntax encourages bad habits and results in maintenance-proof code, and I now think that Python is a better choice.

That said, I also have a hunch that a lot of professional developers are starting to agree with me. I don't hear much about large organizations -- such as Google, for example, or Oracle -- doing much with Perl. But here chromatic takes issue again:

How about Oracle (ships Perl), IBM (ships Perl), Microsoft (used in several build systems), Amazon (entire front end written in Perl), Morgan Stanley (heck, most of Wall Street, most of London's financial institutions)....?

Amazon's front end written in Perl? I'll take his word for it. But that's Perl 5; Perl 6 is another story.

I can accept that maybe Perl 6 "exists," as chromatic claims -- but so do countless other experimental languages, in labs and open source projects. At one time Ruby was just such a curiosity. The difference is that a couple of years went by and all of a sudden everyone is abuzz about Ruby. Major Web applications, such as Twitter, are now running (or stumbling) on Ruby. Where's Perl 6?

I fixed at least six bugs in Parrot today (which probably brings me to ten for the week, if not more). You can see my checkins at cia.vc or Ohloh and review the tickets I've closed at rt.perl.org. If Parrot and Perl 6 don't exist, what exactly what I was working on?

But come now -- there's existing and then there's existing. It only took two years to go from version 2.4 of the Linux kernel to version 2.6. That was a pretty significant upgrade, with an awful lot of people relying on that particular piece of software to work, work well, and work consistently. And yet they pulled it off. Further, it took only nine years to go from version 1.0 of the Linux kernel to version 2.6.

Meanwhile, Perl 6 has been in development for eight years, and there's still no production release in sight. And don't tell me there have been lots of upgrades to Perl 5 in the meantime; that might be true, but it doesn't count when everyone's supposed to be planning for an earth-shattering, backward-compatibility-breaking release that promises to be so important that Larry Wall started throwing around the word "apocalypse."

To me, it doesn't matter if there's a binary called Perl 6 that I can execute or not. How can the Perl 6 language not be vaporware if the Perl hacker community can't use it for real-world jobs?

Let's be generous and say that between Patrick [Michaud]'s funding (which has expired) and Jonathan Worthington's funding and Daniel Ruoso's funding ($3000 for SMOP, an alternate implementation), Perl 6 has 0.5 paid full-time developers. Off of the top of my head, I can name a couple of *dozen* full-time paid [Linux] kernel developers. That's at least an order of magnitude more potential work in that period. Even Fred Brooks might agree that, sometimes, more people can get more work done.

In my mind the question of "vaporware" hinges on "does it actually exist?" If you want to raise the question, "sure, it may exist, but will it ever be stable and widely deployed and ready for production use," that's a very different question -- but I don't believe that's a question of vaporware.

I published working Perl 6 code three years ago. That means people could have downloaded, read, run, and modified working Perl 6 code every day for over a thousand days. If you're going to introduce the question of utility for a majority of a language's hackers, Python 3000 will be vaporware for a couple of years. Heck, PHP 5 is barely not vaporware, if you look at installed base among $4.95- a-month virtual hosting plans.

So what's the bottom line for Perl 6, then? Is it here now or isn't it?

While the software isn't finished ... it does exist and has existed for years. We do all of our development in public; we even have a graph of passing specification tests updated daily.

Through Pugs and Rakudo (and other projects -- Perl 6 is a specification which we expect to have multiple compatible implementations), people have been able to and have in fact run real Perl 6 code for over three years. In fact, the Parrot project has released a new stable version of Parrot on the third Tuesday of every month for the past two years. This includes a new stable version of Rakudo, the Perl 6 implementation running on Parrot.

Indeed, their most recent release was this Tuesday. And there you have it, folks!

infoworlds.com

Looking for job security? Try Cobol
As long as there are mainframes, there will be Cobol. Learn the language and the culture and you might land a job that that lasts until retirement

A career as a Cobol programmer might not be as sexy as slinging Java code or scripting in Ruby, but if you buckle down and learn hoary old Cobol, you could land one of the safest, most secure jobs in IT.

Analyst reports indicate that Cobol salaries are on the upswing. The language is easy to learn, there's a healthy demand for the skills, and offshore Cobol programmers are in short supply -- plus, the language itself holds the promise of longevity. All that loose talk about mainframes going away has subsided, and companies committed to big iron need Cobol pros to give them love.

[ To learn about other skills in high-demand during tight times, read "Recession-proof IT jobs." ]

In a troubled economy, with analysts forecasting IT spending slowdowns, secure IT positions could quickly become scarcer than they are today. Seasoned Cobol programmers, in contrast, "should be in pretty good shape job-wise. If they have a position at an organization that intends to keep its legacy Cobol apps, then they are probably set for life," says industry analyst Jeff Gould, director of research at Interop Systems. "Many mainframe customers with large mission-critical Cobol apps are locked into the mainframe platform. Often there is no equivalent packaged app, and it proves to be just too expensive to port the legacy Cobol to newer platforms like Intel or AMD servers."

Why Cobol is alive and well
William Conner, a senior manager in Deloitte's technology integration practice, comments that "salaries for Cobol programmers have been rising in recent years due to a lack of supply. Demand is outstripping supply because many Cobol programmers are reaching retirement age and college leavers tend to focus on Java, XML, and other modern languages."

Deloitte also found that three-fifths of respondents are actually developing new and strategic Cobol-based applications. Yes, right here in 2008.

Retired Cobol programmer William C. Kees, who coded in Cobol for 25 years, says that the language is easy to learn and that he mastered it without taking any classes. Another career Cobol programmer requesting anonymity seconds that sentiment: "It's easy to learn, read, and follow. After looking at code for .Net or VisualBasic, give me Cobol any day. At least it's readable."

What's more, Cobol programmers are not as prone to having their job outsourced, according to Brian Keane, CEO for Dextrys, an outsourcing company based in China and the United States. "The Chinese don't have mainframe experience. Because Chinese computer science graduates have come late to the technology table they are starting with the latest architectures and systems and don't have the experience with legacy languages and systems," he says.

Latin American countries are in a situation similar to that of the United States, according to Gabriel Rozman, executive vice president for emerging markets at Tata Consultancy Services. "Many Latin countries are still stuck with legacy mainframes where Cobol is a common skill," says Rozman, "so that anyone who has [that and] the latest Java skills, for example, would be sought after."

Bridging the old and the new
Mainframes aren't going anywhere mainly because they do an extremely reliable job with high-volume transaction processing. But increasingly, companies are benefiting from integrating legacy mainframe Cobol applications with the rest of the enterprise, to leverage their power and work toward real-time business operations.

SOA, for instance, opens all sorts of opportunities to expose Cobol apps to the wider world. "Many mainframe users are actively pursuing SOA as a way to integrate their legacy Cobol apps with newer nonmainframe apps," explains Jeff Gould of Interop Systems.

infoworld.com
Palm vs. Pocket PC-The Great Debate
Is there a right choice?

From About.com

Talking PDAs is a lot like talking Politics. Everyone has their own opinions and sometimes it's easier to respect those opinions than to argue them. But what makes a person so passionate about their PDA? A lot of it has to with how you use it and how much you rely on it. Power Users sometimes have their lives so interwoven with their PDAs that to lose it or have it break can be downright gut-wrenching. Now don't smirk, I bet the last time your computer crashed, you remembered a few choice words from your college days. If you've ever lost your Day Runner you know what I mean--you thought it was just a binder till everything was gone. The great thing about a PDA is that it's a Day Runner that has the ability to be backed up, saving all of your valuable information.

What truly brings out passionate conversation is the question: What's better: Palm or Pocket PC. Heck, that question alone has resulted in some scenes reminiscent of those infamous Thanksgiving get-togethers (of course you've never had one of those have you?).

The first thing we need to do is clarify some facts versus perceptions.

Some facts are:

* Pocket PC multitasks (you can run several programs at once), Palm is intended to run one program at a time (although Palm OS 5.0 introduced some multitasking ability)
* In 2001, there were over 13,000 commercially available software programs for Palm versus 1,600 for Pocket PC (although the gap is shrinking)
* In 2001 Palm had a market share of 72% while Pocket PC had about 15%
* Palms start at around $99 while Pocket PCs start around $200.

Some (sometimes faulty) user opinions/perceptions are:

* Palm is easier to learn and use
* Palm is more stable, Pocket PC crashes more
* Pocket PC is more powerful
* Pocket PC integrates better with Windows Office
* Palm has more freeware and the software is cheaper
* Palm is an Organizer, Pocket PC is a computer

As you see, the users' opinions are as varied as the users themselves. Palm has been a more popular platform in the past mainly because of the perceived easier learning curve and the price. In fact, until late last year, a Palm would cost you around $200 while a Pocket PC would run about $500. Many people weren't willing to spend $500 to see if they would even use a PDA. In fact, many Pocket PC users will tell you their first PDA was a Palm because of low cost, but they upgraded to Pocket PC because they wanted the Windows feel. Currently both platforms offer PDA's around the $200 range, making it affordable to try either Pocket PC or Palm.

Is the Palm easier to use use than Pocket PC? If you're somewhat computer illiterate, the Palm may be a little easier to use. If you're familiar with computers, than both platforms will probably have the same learning curve. One of the biggest misconceptions of Pocket PC is that it runs regular windows programs. It does not. Programs for Pocket PC are developed for Pocket PC and will not run on Windows computers and vice versa, although many Pocket PC programs were developed from the same source code as their Windows counterpart. The thing that many developers for both Palm and Pocket PC are doing is creating a desktop and PDA version of their product. That way information can be entered on either the PDA or the computer and then synced to the other.

A big part of the debate over which PDA to use is a lot like the Mac vs. PC debate. Many people feel that Mac is easier to use and many even enjoy bucking the "Everyone should use a PC" trend. If you hate Windows and think Bill Gates is the epitome of evil, you'll probably want to stick with Palm. If you love Windows and want the Windows feel, you'll probably want to try Pocket PC. The best way to know is go to your local electronics store and play around with different PDAs. Also do some research online. There are a lot of sites dedicated to handhelds with news and reviews of different PDAs. PDA forums are great if you want to solicit some opinions on the best bet for you (be ready to open Pandora's box!). In reality, both Operating Systems are more similar than some people want to give them credit for. With a few exceptions, they have equal power to help you run your business or your everday life.

One thing to remember is the validity of a PDA user's opinion. While the opinions of others can be beneficial to making a buying decision, be sure to ask questions. Some PDA users will tell you the Operating System they use is the best while the other one sucks. The thing to know is that many of those die-hards have never tried the other Operating System. If you want a true comparison, talk to someone who has used both platforms so that you can understand how the PDA they use might compare to your needs.

Hopefully you weren't looking for the answer to which PDA is better. Only you can answer that question, but hopefully we've given you some things to think about so that you can make an informed buying decision.