Archive for July, 2010

Is ’social engineering’ better than software skills to hack into computers?

July 31st, 2010

Hackers at DefCon are gathering to prove that smooth talk works better than software skills any day, in order to launch a computer network attack.

The contest challenges hackers to call workers at 10 companies including technology titans Google, Apple, Cisco, and Microsoft and get them to reveal too much information to strangers.

Other companies targeted were Pepsi, Coca Cola, Shell, BP, Ford, and Proctor and Gamble.

One employee was conned into providing specifications regarding types of software being used, details that would let a hacker tailor viruses to launch at the system.

“You often have to crack through firewalls and burn the perimeter in order to get into the internal organisation,” News.com.au quoted Mati Aharoni of Offensive Security, a company that tests company computer defences, as saying.

“It is much easier to use social engineering techniques to get to the same place,” he added.

“We wanted to show that social engineering is a legitimate attack vector.”

One worker nearly foiled a hacker by insisting he send his questions in an email that would be reviewed and answered if appropriate, but the hacker convinced him not to do that, saying he was under ‘immense pressure’.

“As humans, we naturally want to help other people. I’m not advocating not helping people. Just think about what you say before you say it,” said Offensive Security operations manager Christopher Hadnagy. (ANI)

Source:http://story.malaysiasun.com/index.php/ct/9/cid/d805653303cbbba8/id/666651/cs/1/

Software developers ignore microsoft security warnings

July 31st, 2010

Microsoft reports that third party software developers patched only 45 percent of the flaws the company’s security team reported to them between July 2009 and June 2010.

“The newest number, however, was more than triple that during the year-long stretch through June 2009, when developers patched a measly 13 percent of the bugs Microsoft reported,” writes Computerworld’s Gregg Keizer.

“Microsoft did not reveal the number of vulnerabilities its engineers found and reported to other companies in last 12 months, but did note that 97 percent of the bugs were rated by Microsoft as either ‘critical’ or ‘important,’ the company’s two highest threat rankings in its four-step scoring system,” Keizer writes.

Source:http://www.esecurityplanet.com/headlines/article.php/3895981/article.htm

Anatomy of a Cisco data center convert

July 31st, 2010

Cisco almost didn’t make the cut. NightHawk Radiology Services was ready to hand its data center consolidation project to another vendor until a facility leasing issue delayed its decision.

Cisco’s UCS is 1 year old

That gave Cisco an opportunity to pitch its Unified Computing System (UCS) proposal to the lab, which provides radiology services to 1,600 healthcare sites ��� 26% of all hospitals in the United States. NightHawk conducts 3 million studies per year with an average turnaround time of less than 20 minutes per study.

“Our project did not include UCS at the outset,” said Ken Brande, vice president, information technology at NightHawk. “A facility lease issue delayed the project and in that delay period Cisco presented UCS.”

Enter Cisco. NightHawk will replace 120 physical IBM and Dell server blades with 18 UCS servers in four chassis running virtualized workloads. Granted, it’s not a Google or Amazon.com or Yahoo scale data center with thousands of servers ��� but NightHawk fits the prototypical profile of a UCS target: one looking to consolidate, virtualize and reduce complex operations.

The NightHawk project entails consolidating ad hoc server rooms in multiple sites globally, reducing cycle times of new technology deployments, reducing capital and operational expenditures and simplifying management ��� all in support of handling 9,000 studies and 500Gbytes of image data per day, and 120 Terabytes of online data.

“The environment was difficult to manage,” Brande says. “When you have a bunch of disparate technology resulting from ‘Get the best for what we can get for the price today, and then push it out as fast as possible,’ it means that a lot of these spaces didn’t have the appropriate power.”

NightHawk IT was focused more on maintaining that type of environment rather than being responsive to new business requirements.

“It was hard to build a new business product with technology that was dispersed for no rhyme or reason,” Brande says. “And then the resources were too busy maintaining the assets and not available to help drive the new business.”

So NightHawk, working with Cisco systems integration partner World Wide Technology, embarked on its server room consolidation/data center strategy project last year. The lab sought to put its data center resources on a common platform with consistent management tools that let it rapidly deploy new technologies and services.

“We wanted to minimize the number of issues that happen, be able to recover from them faster, and just have basic administration of your environment be a task that is easy to do and doesn’t consume you,” says Christopher Smith, manager of data center infrastructure at NightHawk.

NightHawk was attracted to UCS Manager, which the officials said presents a single intuitive interface among applications from Cisco, BMC Software and other partners. Alternatives offered less coherency among applications ��� the seams between applications from various independent software vendors were evident even though they may have been accessible from a single interface, the NightHawk officials say.

“We had hundreds of very disparate systems from different vendors with quite different ages and different classes of machines,” Smith says. “There’s quite a lot of difference in the hardware that made it a challenge to manage.”

Not that UCS was a total cakewalk either. NightHawk IT had to learn the concept of service profiles in which server deployment and workload allocation, configured through templates, is divorced from the physical servers themselves. Servers are “built” from these templates and the profiles can exist on any blade at any time.

Service profiles are intended to define and enforce resource access privileges for virtual machines, and follow VMs as they move across and between data centers.

“The idea of separating out the configuration of the hardware from the actual hardware itself” required some instruction, Smith says. The rest was just months of burn-in testing of myriad data center scenarios, online documentation review, policy definition and practice, practice, practice.

“Once you’ve got that in line the rest is pretty straightforward from there,” Smith says.

And the results are evident. NightHawk has cut its cabling and switch port requirements to a fraction of what they were: 24 connections ��� 16 network and eight Fibre Channel — were reduced to four 10Gbps Fibre Channel over Ethernet and four Fibre Channel with UCS, Smith says. The installation requires only 20% to 25% as many upstream switch ports to support the same level of performance and connectivity, he says.

Server expansion cost is 25% to 33% that of alternatives, NightHawk claims. Server deployments and updates have been reduced to minutes from hours.

NightHawk expects payback from the investment in about three years, including a 12% annual reduction in operating expenses.

Source:http://www.businessweek.com/idg/2010-07-30/anatomy-of-a-cisco-data-center-convert.html

Daon software selected for world’s largest identity program

July 31st, 2010

Daon, the award-winning global provider of identity assurance software and services announced today that India has joined a growing number of countries around the world who have chosen Daon software for identity management.

Daon’s software has been selected for use in India’s Unique ID (UID), the world’s largest identity program. The program, branded as Aadhaar, will eventually encompass 1.2 billion residents and the UID will become the single source of identity verification throughout the country.

In India, an inability to prove identity is one of the biggest barriers preventing citizens from accessing benefits and subsidies.

The Unique ID will allow citizens to access critical programs, while decreasing tax leakages, increasing revenue and significantly bringing down transaction costs as it transforms the delivery of social welfare programs.

Daon provides a centralized platform and client biometric infrastructure for a variety of uses including employee credentialing, government benefits programs, trusted identity services, border management, national ID, airport e-gate systems and immigration control.

Daon’s innovative Commercial Off the Shelf (COTS) software, industry recognized expertise and large scale program experience enables the delivery of solutions that reduce risk, schedule and cost. On the India program, Daon is responsible for the fusion-based ABIS solution that incorporates finger, iris and face modalities.

Commenting on this win, Daon’s CEO, Tom Grissen said, ‘We are very pleased to be part of this important and history-making venture. When you combine the population size, the rapid pace of deployment and the multimodal aspect of the program, you have a truly unique requirement.

With scalability, risk mitigation and multimodal enrollment as key factors, the UID presents the ideal environment for Daon. Our partners recognized the value of Daon’s COTS products early in the procurement process and we are gratified to have played an important role in securing this business.’

Source:http://gadgets.consumerelectronicsnet.com/articles/viewarticle.jsp?id=1167816

Research and markets global point of sale (pos) software &

July 31st, 2010

Owing to technological advancements, the POS Hardware market is witnessing a rapid expansion; with POS systems aggressively being adapted by the government and various industries such as Retail, Hospitality, Finance, Transport, etc.

Also, new technologies (such as display, storage, hard disks, operation platform, etc) are being continuously incorporated into the various component of POS system.

In addition, the market is also witnessing an increased preference for portable and wireless POS systems.

Further, the ability of POS software to help companies make more informed business decisions, increase inventory shrinkage, and decrease theft, wastage and employee misuse are the advantages because of which companies and organizations are adopting POS.

The demand for POS software is on the rise. The Retail and Hospitality industries are increasingly implementing POS systems to enhance their operational efficiency and customer service level in stores.

Other business benefits such as productivity gains, control over operations, increasing the productivity of serving staff, fine-tuning of business model and return on investment are further driving the demand for POS systems.

Further, replenishment markets, wherein companies are looking to replace legacy systems, offer potential opportunities for the next generation advanced POS systems Availability of wireless POS systems, average life completion of many installed terminals, along with new software requirement for efficient utilization of old POS systems are also offering potential sales opportunity for POS software.

This bundled report by Technavio Insights highlights the scope of the Global Point of Sale (POS) Hardware and Software market, along with trends, drivers, growth inhibitors, and a few major vendors in the market.

Source:http://gadgets.consumerelectronicsnet.com/articles/viewarticle.jsp?id=1167728

Texas issues solicitation for field appraisal system software maintenance

July 31st, 2010

The Texas Comptroller of Public Accounts issued the following solicitation notice: RFO for Field Appraisal System Software Maintenance and Related Services Open Date: 08/16/10 02:00 PM Agency Requisition Number: 304-11-1831NK

NOTE: You will need to download all of the following files for complete specifications and other required document, including a HUB subcontracting plan (if required).

-Package 1 size: 562688 (in bytes) Type: Specification Format: Excel for Windows 97 The Comptroller of Public Accounts (CPA) issues this Request for Offer (RFO) to request pricing for Field Appraisal System (FAS) Software Maintenance and Related Services as described in this RFO.

Source:http://business-video.tmcnet.com/news/2010/07/31/4931527.htm

Mindfireans achieve microsoft certified technology specialist certification

July 31st, 2010

India’s leading SME Software Services provider Mindfire Solutions announced today that another batch of its software professionals have cleared the MCP certification exam 70-528 conducted by Microsoft.

Microsoft Certified Professional (MCP) exam is the most demanding programming certification offered by Microsoft for software professionals.

The current 70-528 certification is Microsoft® .NET Framework 2.0 Web-Based Client Development certification and can be taken up in multi-languages such as English, French, German, Japanese and Chinese.

“We consistently encourage our people at Mindfire to keep themselves abreast of latest developments in technology and appear in certifications whenever feasible in a quarter.

It is the passion to learn and appear for the certifications which finally helps Mindfireans to clear one certification after the other,” said Mr. Ansuman Sahu, Project Manager, Microsoft Technologies.

One of the Software Engineers who cleared the certification, Ms. Priyanka Dash was excited on clearing MCP 70-528. She had also cleared the MCP 70-536 few months ago. “I was quite confident to take up MCP 70-528 certification as I had cleared MCP 70-536 earlier.

In addition, the exposure to many projects and real-hands-on problems while working in Mindfire helped me a lot while preparing because I could identify with the situation in a much better way,” she said with a smile.

For MCP 70-528 certification candidates work on a team in a medium-sized or large development environment that uses technologies like Microsoft Visual Studio .NET 2003 Enterprise Developer or Microsoft Visual Studio 2005.

The minimum experience required for this certification is at least one year on developing Web-based applications by using the Microsoft .NET Framework.

The candidates should have the working knowledge of Visual Studio 2005 and a fair knowledge of the new features of ASP.NET 2.0. This helps the software developer to know how to create, describe, assemble and deploy web applications.

It also teaches the software developer how to integrate data into an application using Microsoft ADO.NET, XML, and data-bound controls.

“Mindfire is on its way to enrich its Microsoft technologies portfolio. A Microsoft Gold Certified Partner, Mindfire, has worked on various Microsoft technologies and platforms like Microsoft Visual Basic 2005, Microsoft Visual C# 2005, Microsoft Visual Studio

.NET 2003 Enterprise Developer, Microsoft Visual Studio 2005, Microsoft .NET Framework, ASP.NET 2.0 and many more”, said Mr. Subhendu Pattnaik, Manager, Marketing.

“We ensure that we will always encourage our people to learn and take up the certification examinations in their technical domain,” he added.

Source:http://www.earthtimes.org/articles/press/certified-technology-specialist-certification,1406302.html

Get Adobe Flash playerPlugin by wpburn.com wordpress themes