Archive for April, 2009

Cisco IPS Active Update Bulletin – 04/30/09

No Comments »

 

 

 

 

Greetings! This bulletin describes updates to the Cisco IPS product line. Additional information, tips and expert advice is available in the Cisco IPS User’s Forum at: http://www.cisco.com/discuss/security. For technical support, sales or other issues, please contact your authorized Cisco reseller or Cisco TAC.

 

 

 

 

 

 

 

 

 

IN THIS ISSUE:

  1. Announcing the S397 Signature Update for IPS
  2. Cisco IDS 4235 and IDS 4250 sensors approaching end of signature support
  3. Cisco IPS Signature correlation available in the Cisco Security IntelliShield Alert Manager Service
  4. Subscribe to the Product Alert Tool for IPS Related Field Issues
  5. Subscription Information

 

1. Announcing the S397 Signature Update for IPS

The S397 signature update contains the following new signatures:

PLATFORM

SIGID

SIGNAME

ENGINE

SEVERITY

ENABLED

5.x,6.x

7420.0

Microsoft Help Workshop HPJ OPTIONS Section Buffer Overflow

string-tcp

medium

false

5.x,6.x

6430.0

Microsoft Internet Explorer CSS Memory Corruption

string-tcp

medium

false

5.x,6.x

6133.0

Microsoft Excel Cell Length Buffer Overflow CVE-2004-0846

string-tcp

high

false

5.x,6.x

6457.0

Lotus Notes URI Handler Argument Injection

string-tcp

high

false

5.x,6.x

6466.0

Squid WCCP Message Parsing Denial of Service

atomic-ip

low

false

5.x,6.x

6467.0

Mozilla Firefox Click Event Classification Vulnerability

string-tcp

low

false

5.x,6.x

6468.0

Multiple Vendor AV Gateway Virus Detection Bypass

string-tcp

high

false

5.x,6.x

6141.0

Macromedia JRun 4.x Server File Disclosure

service-http

low

false

5.x,6.x

6165.0

nfs-utils TCP Connection Termination Denial of Service

string-tcp

medium

false

5.x,6.x

6170.0

Novell eDirectory evtFilteredMonitorEventsRequest Function Overflow

string-tcp

high

false

5.x,6.x

6496.0

Microsoft Internet Explorer URL Spoofing Vulnerability Details

string-tcp

high

false

5.x,6.x

6173.0

Empty DNS Query

atomic-ip

medium

false

5.x,6.x

6710.0

Macromedia Flash Player LoadMovie DoS

string-tcp

medium

false

5.x,6.x

6727.0

Nullsoft Winamp Midi File Header Handling Buffer Overflow

string-tcp

high

false

5.x,6.x

6727.1

Nullsoft Winamp Midi File Header Handling Buffer Overflow

string-tcp

high

false

5.x,6.x

6245.0

IBM Tivoli Storage Manager Initial Sign-on Request Buffer Overflow

string-tcp

high

false

5.x,6.x

6247.0

Sun Microsystems Java GIF File Handling Memory Corruption

string-tcp

high

false

5.x,6.x

6248.0

HP Mercury Loadrunner Agent Command Processing Buffer Overflow

string-tcp

high

false

5.x,6.x

15012.0

Oracle BEA WebLogic Server Apache Connector Buffer Overflow

service-http

medium

true

5.x,6.x

15574.0

SoftEther P2P Activity

fixed-tcp

informational

false

5.x,6.x

16035.0

Iseemedia LPViewer ActiveX Buffer Overflows

meta

high

false

5.x,6.x

16035.1

Iseemedia LPViewer ActiveX Buffer Overflows

string-tcp

informational

false

5.x,6.x

16038.0

Adobe Flash Insufficient Data Validation Buffer Overflow

string-tcp

high

false

5.x,6.x

16096.0

IBM SolidDB Format String Bug

string-tcp

medium

false

5.x,6.x

16553.0

MailEnable SMTP Service VRFY/EXPN Command DoS

string-tcp

low

true

5.x,6.x

3408.1

Telnet Client LINEMODE SLC Option Overflow

string-tcp

high

false

5.x,6.x

16793.0

Adobe Reader getAnnots() Remote Code Execution

meta

high

true

5.x,6.x

16793.1

Adobe Reader getAnnots() Remote Code Execution

string-tcp

informational

true

5.x,6.x

16813.0

Adobe Reader customDictionaryOpen Buffer Overflow

meta

high

true

5.x,6.x

16813.1

Adobe Reader customDictionaryOpen Buffer Overflow

string-tcp

informational

true

The S397 signature update contains the following modified signatures:

PLATFORM

SIGID

SIGNAME

ENGINE

SEVERITY

ENABLED

5.x,6.x

3527.1

UW imapd Overflows

string-tcp

high

false

5.x,6.x

5435.0

Crystal Reports Remote Code Execution

string-tcp

high

false

5.x,6.x

3406.0

Solaris TTYPROMPT /bin/login Overflow

string-tcp

high

true

5.x,6.x

3169.0

FTP SITE EXEC tar

string-tcp

high

true

5.x,6.x

3527.4

UW imapd Overflows

string-tcp

high

false

5.x,6.x

3884.0

Cfengine Authentication Heap Based Buffer Overflow

string-tcp

high

true

5.x,6.x

6969.0

Microsoft Word Smart Tag Corruption Exploit

string-tcp

high

true

5.x,6.x

3333.0

SMB MSRPC Messenger Overflow

string-tcp

high

true

5.x,6.x

3347.2

Windows ASN.1 Library Bit String Heap Corruption

service-http

high

true

5.x,6.x

5464.1

Computer Associates License Suite Network Buffer Overflow

string-tcp

high

false

5.x,6.x

2158.0

Nachi Worm ICMP Echo Request

atomic-ip

high

true

5.x,6.x

3143.0

BERBEW Trojan Activity

string-tcp

high

true

5.x,6.x

3178.0

Denial Of Service in Microsoft SMS Client

string-tcp

high

true

5.x,6.x

3342.0

Windows NetDDE Overflow

service-smb

high

true

5.x,6.x

3342.1

Windows NetDDE Overflow

string-tcp

high

true

5.x,6.x

5455.0

Arkeia Type 77 Request Buffer Overflow

string-tcp

high

false

5.x,6.x

5469.0

TrackerCam PHP Argument Overflow

service-http

high

false

5.x,6.x

5487.0

IA WebMail Buffer Overflow

service-http

high

false

5.x,6.x

6222.0

HP OpenView Client Configuration Manager Radia Notify Daemon Code Execution

string-tcp

high

false

5.x,6.x

5438.0

Cisco IOS Call Processing Solutions DoS

string-tcp

medium

false

5.x,6.x

5825.0

SIP Malformed Invite Packet

atomic-ip

medium

false

5.x,6.x

5684.0

Malformed SIP Packet

atomic-ip

medium

false

Modified  signature details:  None.

IMPORTANT NOTES:

 

All signature updates are cumulative. The S397 signature update contains all previously released signature updates.

 

You must have a valid Cisco Services for IPS contract per sensor to receive and use software upgrades including

signature updates from Cisco.com.

 

A Cisco Services for IPS Services License is required for the installation of all signature updates. The Cisco Services

for IPS Services License can be requested from http://www.cisco.com/go/license for all sensors covered by a

maintenance contract.

 

To manage your maintenance contracts use the Service Contract Center:

 

http://www.cisco.com/cgi-bin/front.x/scccibdispatch?AppName=ContractAgent

SUPPORTED PLATFORMS:

 

The S397 signature update can ONLY be applied to E3 sensors.

 

IPS S397 Software Update Files:

 

 

Please note that the signature update download location has changed.

 

 

Sensor appliances, IDSM2, NM-CIDS, ASA-SSM-AIP modules: click here

 

IOS IPS in 12.4(11)T or later T-Train Releases:

http://www.cisco.com/pcgi-bin/tablebuild.pl/ios-v5sigup

Note: Posting of signature release files for IOS IPS may take a few additional days.

 

 

 

 

 

CISCO SECURITY MANAGER (CSM) NOTICE:

Note 1:

 

You can only apply the IPS-CS-MGR-sig-S397-req-E3.zip signature update file to CSM 3.0 or later and IPS MC version 2.2 or

later. The E3 Engine Update packages for sensors are deployed automatically the first time a signature set that requires

E3 is deployed by CSM. E3 updates are not listed or available for selection in the Apply Update Wizard and cannot be

applied independently by CSM. To ensure that the E3 update is applied to your sensors, please ensure

that you push the S366 package to your sensors.

 

 

2. Cisco IDS 4235 and IDS 4250 sensors approaching end of signature support

Cisco IDS 4235 and IDS 4250 sensors approaching end of signature support Last day of signature support for IDS 4250 SX and IDS 4250 XL sensors is May 24, 2009. Last day of signature support for IDS 4235 and IDS 4250 TX sensors is May 31, 2009. If you are still using IDS 4235 and IDS 4250 sensors, please contact your Cisco sales representative regarding migration plans to newer Cisco IPS sensors. More information including recommended migration options is available at this web page: http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/prod_eol_notices_list.html

 

3. Cisco IPS Signature correlation available in the Cisco. Security IntelliShield Alert Manager Service Search Access Feature

The Cisco IPS Team is pleased to announce the correlation of Cisco IPS Signature information within the IntelliShield Alert Manager Search Access Feature. Cisco Services for IPS clients that subscribe to the service now have access to perform targeted searches to display Cisco IPS Signatures associated with different alerts to ensure they have the most up to date intelligence. Subscribers can view a new IPS Signature list page that is searchable and will display Cisco IPS Signatures associated with IntelliShield Alerts. IntelliShield Alerts also contain the associated Cisco IPS Signature information within each alert.

 

The IntelliShield Alert Manager Search Access Feature provides clients with access to one of the most extensive collections of vendor-neutral security intelligence alerts in the industry. Clients can access a fully indexed and searchable database that extends back over six years and contains more than 1700 vendors, 5500 products, and 20,000 distinct versions of applications.

 

To obtain access to the IntelliShield Alert Manager Search Access Feature, each user is required to provide either a valid IPS License File or a valid IPS Serial Number to authorize the creation of this user account. Only one user account is permitted for each IPS License File or IPS Serial Number. Please proceed to the registration page at the following link to obtain your access:

 

https://intellishield.cisco.com/security/alertmanager/intelliShieldSearch 

 

Email support is available for users of the Cisco Security IntelliShield Alert Manager Service Search Access Feature at  intellishieldsearch-support@cisco.com . Support is provided by Cisco during the hours of 7:00 a.m. and 7:00 p.m. Eastern Time.

 

4. Subscribe to the Product Alert Tool for IPS Related Field Issues

 

Interested in knowing the latest on field notices, product alerts, and end-of-sale information relating to your IDS and IPS hardware? We have recently updated the Cisco Product Alert Tool to include IDS and IPS appliances.

 

Simply visit: http://tools.cisco.com/Support/PAT/do/ViewMyProfiles.do  and follow these steps:

 

- Select Create a new Alert Profile.

- Name your profile anything you would like.

- Under Select Your Product, select: Intrusion Prevention System

- Click Add so that “Intrusion Prevention System” is added to the “Products in your profile” list

- Select the message types you wish to receive

- Confirm your email address

- Click Submit.

 

You will be kept up to date with the latest news on your IPS hardware appliances.

 

5. Subscription Information

 

If you wish to receive this bulletin, you can subscribe now.

Your opinions are important to us. If you have feedback about the Active Update Bulletin, please contact us at ips-news@cisco.com. For technical support, sales or other issues, please contact your authorized Cisco reseller or Cisco TAC. Please note that technical support or sales questions sent to this address will not be answered or redirected.

 

 

 

 

 

 

Additional Information

 

 

 

 

 

 

 

 

 

 

 

Links

  • Software Center – Download the latest Cisco IPS software.
  • User Forum – Participate in the IPS Forum, part of our Networking Professionals Connection.
  • Home Page – Visit our Cisco IPS home page for product literature, news, and awards.
  • Cisco Security Center- Visit the Cisco Security Center site for information on emerging threats and the Cisco network IPS signatures available to protect your network..
  • CRMS – Cisco Remote Managed Services for Security
  • Training – Learn about available IPS training courses and Cisco Security Certifications.
  • IPS Technical Documentation – Visit our Cisco IPS Technical Documentation site for configuration guides, maintenance guides, release and installation notes and more
  • IntelliShield Alert Manager Search Access Feature – Search through an extensive collection of security intelligence reports. Registration required.

 


NETWORKWORLD:Network World Wide Area Networking Alert [WAN@nwfnews.com]

No Comments »
Optimizing the Data Center
The Editors of Network World present this Executive Guide: Taking Virtualization Up a Notch. Read it and find out what you need to know about virtualization as it creeps into every corner of your data center. Learn More!
rule
Spotlight Story
The impact of VDI

By Steve Taylor and Jim Metzler
The last couple of newsletters looked at some of the challenges associated with implementing virtualized servers. This newsletter will examine some of the challenges associated with implementing a virtualized desktop infrastructure (VDI).
Read full story Steve Taylor is president of Distributed Networking Associates and publisher/editor-in-chief of Webtorials. Jim Metzler is vice president of Ashton, Metzler & Associates.

Related News:

Editor’s note: We will be changing how we send out Network World newsletters over the next few weeks. To ensure future delivery of your newsletters, please add nww_newsletters@newsletters.networkworld.com to your e-mail address book or

66.186.127.216 to your white-list file. Thank you.

The challenges of virtualization The recent IT Roadmap conference in Chicago began with Jim and two other analysts on stage being asked questions by John Gallant. Given the current economic conditions, the question and answer session focused on cost savings. One of the questions posed to Jim was, “Should IT organizations be looking to implement virtualization as a means of saving money?” Jim’s answer was yes, but only if they realize the impact that virtualization has on the WAN, on management, and on application delivery. The next few newsletters will explain exactly what that impact is.

The impact of server virtualization In the last newsletter, we began discussing some of the challenges associated with server virtualization. In this newsletter, we will continue that discussion by talking about some of the specific WAN challenges that are associated with server virtualization.

The impact of virtualization on networks and applications Over the last few years, there has been a lot of discussion in the trade press about virtualization. While some of these discussions make it appear as if virtualization is a new topic, it is not. We have had virtualized WANs since the advent of X.25, roughly 30 years ago and we have had virtualized LANs for almost 15 years. So virtualization is not new, but that doesn’t mean that we can ignore it. With that in mind, this WAN newsletter will begin the discussion of the impact of virtualization on networks and applications.

Cisco, NetQoS move a step closer to integrated network optimization, management Last time, we pointed out that network organizations have the opportunity to both show business value and do good things for the careers of network professionals by demonstrating how they ensure that the company’s key business applications exhibit acceptable performance. We also pointed out that ensuring acceptable application performance is difficult as it requires the tight integration of planning, optimization, management and control. Regrettably, most application delivery solutions do not provide a rich set of well integrated planning, optimization and management functionality. In fact, some WAN optimizations products can cause existing planning and management functionality to break. Today, we’ll discuss some of the problems with the current application delivery solutions and detail how NetQoS and Cisco have worked together to solve at least some of the problems.

What makes a WAN optimization controller? Choosing a vendor can be the most challenging part of a WAN optimization project, given the wide range of vendors, features and technology options available today. Enterprises in the market for WAN optimization …

Applications have a need for WAN speed Vendors are loading their gear with new features, but the core need for WAN speed should still guide WOC buying decisions. Application performance management and WAN acceleration are hard problems to solve and are part …

100% trade-in credit for Nortel products Cisco Subnet blogger Brad Reese takes note of Enterasys’ offer to Nortel customers: 100% trade-in credit for Nortel products.

CCNP Lab Build – Product choices Wendell Odom explains why he’d consider one router or switch over another with the goal of building a CCNP lab. What would you buy with $750 to spend on gear, and a $50 cable budget.

April giveaways galore

Cisco Subnet and Microsoft Subnet are giving away training courses from Global Knowledge, valued at $2,995 and $3,495, and have copies of three hot books up for grabs: CCVP CIPT2 Quick Reference by Anthony Sequeira, Microsoft Voice Unified Communications by Joe Schurman and Microsoft Office 2007 On Demand by Steve Johnson. Deadline for entries April 30.

Network World on Twitter Get our tweets and stay plugged in to networking news.


NETWORKWORLD: LaserJet turns 25…’PC LOAD LETTER’ still unfathomable

No Comments »

Live Webcast: Halve Campus Network TCO
The campus network has matured, but has also become more complex and expensive than ever before. Learn how to reduce your campus networks’ TCO by up to 50% without compromising high performance, security or reliability.

Spotlight Story
 

LaserJet turns 25…’PC LOAD LETTER’ still unfathomable
By Paul McNamara
The HP LaserJet desktop printer was a game-changer the moment it debuted in Atlanta at Spring Comdex 1984, then the computing industry’s premier trade conference, now but a memory. Since then the LaserJet line has accounted for more than 100 million unit sales … and earned itself a spot on the Hollywood walk of infamy.

Related News:

Editor’s note: We will be changing how we send out Network World newsletters over the next few weeks. To ensure future delivery of your newsletters, please add nww_newsletters@newsletters.networkworld.com to your e-mail address book or 66.186.127.216 to your white-list file. Thank you.

EFF calls Congress our last hope to monitor FBI data mining

The Electronic Frontier Foundation says Congress must apply serious oversight to the FBI’s massive and mysterious Investigative Data Warehouse program now because the Obama Administration has signaled its unwillingness to do so and EFF has already done all it can do through Freedom of Information Act requests.

Study finds dip in satisfaction with government Web sites

Whether it’s statistically meaningful or not will be left to the experts, but the perception certainly isn’t what IT Team Obama would want to see: Satisfaction with the Web sites of federal government programs took a dip in the first quarter, according to a longtime performance tracker.

Just keep piling gear atop those poles; what could go wrong?

The fire destroyed 10 houses and caused the evacuation a 3-day evacuation of Malibu. Southern California Edison and four mobile-phone service providers stand accused of sparking the blaze by neglecting to consider that piling too much gear on old wooden poles would cause them to snap in even moderately high winds.

JetBlue’s Web site grounded most often among 42 airlines surveyed

JetBlue Airlines last week posted a quarterly profit for the first time in four years, and while lower fuel prices are being cited as the primary reason, one has to wonder if skimping on IT spending might be just as important.

April giveaways galore

Cisco Subnet and Microsoft Subnet are giving away training courses from Global Knowledge, valued at $2,995 and $3,495, and have copies of three hot books up for grabs: CCVP CIPT2 Quick Reference by Anthony Sequeira, Microsoft Voice Unified Communications by Joe Schurman and Microsoft Office 2007 On Demand by Steve Johnson. Deadline for entries April 30.

Network World on Twitter Get our tweets and stay plugged in to networking news.

 


NETWORKWORLD:Microsoft gives server app virtualization sneak peek; Microsoft targets Windows, Linux management

No Comments »
Virtualization’s Impact on Applications
A recent analyst report highlighted the impact of virtualization on application performance. The results reveal the challenges most organizations encounter, and contrast those challenges with the successes achieved when Best Practices are applied, following the model of Best-in-Class organizations. Get the full report at the link below.
rule
Spotlight Story
Microsoft gives server app virtualization sneak peek

By John Fontana
Microsoft Tuesday demonstrated for the first time its server application virtualization technology designed to enable on-demand deployment of applications.
Read full story

Related News:

Editor’s note: We will be changing how we send out Network World newsletters over the next few weeks. To ensure future delivery of your newsletters, please add nww_newsletters@newsletters.networkworld.com to your e-mail address book or 66.186.127.216 to your white-list file. Thank you.

Microsoft melding view of local, cloud-based virtual machines Microsoft Tuesday said it is working on a cloud federation feature for Virtual Machine Manager that will give users an integrated view of physical and virtual resources from a single point regardless if they are running internally or on a hosted network.

Microsoft targets Windows, Linux management Microsoft Tuesday opened its annual management confab saying it would ship the next version of Operations Manager by the end of June and laying out its efforts to manage datacenters and virtualized environments.

Microsoft plans to cut another $1 billion in costs Microsoft Subnet reports that Microsft has advised Wall Street that its 2009 operating expenses are expected to come in at $26.7 billion to $26.9 billion, which is as much as $1 billion less than previous guidance, notes a story in Barrons.

Linux out, Windows in at Electoral Commission The NSW Electoral Commission (NSWEC) will leave Linux for Windows Server when it develops its new vote counting and reporting application, which is slated to cost A$1.4 million over the next two years.

Obama names Microsoft’s Mundie, Google’s Schmidt to technology council The president today released the names of about two dozen people who will comprise his Technology Advisory Council. Among them are Craig Mundie, Chief Research and Strategy Officer at Microsoft and Eric Schmidt, chairman and CEO of Google (and a member of Apple’s board).

EDS to sell Microsoft online services On Monday, Microsoft began offering its hosted services to companies in 18 countries outside of the U.S. and said that EDS would help sell the services.

Windows 7’s virtual ‘XP mode’ could mean support nightmares Microsoft’s decision to give some Windows 7 users a tool to run Windows XP applications in a virtual machine may have been necessary to convince people to upgrade, but it could create support nightmares, analysts said …

Running Windows 7 on a netbook Microsoft made headlines recently when The Wall Street Journal reported that the company planned to equip netbooks with the Starter edition of Windows 7, a semi-crippled version that only lets users run up to three …

Microsoft Vine, Web Sandbox and other nifty beta apps Microsoft Subnet review’s Microsoft’s attempt to do Twitter one better, with a beta app called Vine, available for Seattle users at the moment.

Microsoft releases Office 2007 SP2 Microsoft today released Office 2007 Service Pack 2, Microsoft Subnet reports. When Microsoft announced the roadmap for Office 2007 SP2 in May, 2008, it promised that the suite would include support for several new document types.

Microsoft Surprises With XPM In Windows 7 To Help Sway Users From XP This week’s release of Windows 7 RC1 to the MSDN community, and next week to the general public, represents another significant milestone towards a market release of Windows 7, says Microsoft Subnet blogger Mitchell Ashley.

Windows 7 Beta Exam comes and goes Randy Muller, in his All about Microsoft Certifications blog, noted how quickly the Configuring Windows 7 beta exam open and closed…in one day. That speaks volumes about the excitement that Windows 7 is generating.

April giveaways galore

Cisco Subnet and Microsoft Subnet are giving away training courses from Global Knowledge, valued at $2,995 and $3,495, and have copies of three hot books up for grabs: CCVP CIPT2 Quick Reference by Anthony Sequeira, Microsoft Voice Unified Communications by Joe Schurman and Microsoft Office 2007 On Demand by Steve Johnson. Deadline for entries April 30.

Network World on Twitter Get our tweets and stay plugged in to networking news.


NETWORKWORLD: Load balancing upgrade keeps MoveOn.org up to speed

No Comments »
Optimizing the Data Center
The Editors of Network World present this Executive Guide: Taking Virtualization Up a Notch. Read it and find out what you need to know about virtualization as it creeps into every corner of your data center. Learn More!
rule
Spotlight Story
Load balancing upgrade keeps MoveOn.org up to speed

By Ann Bednarz
Online visitors are a finicky bunch – not to mention impatient. Studies have shown Web visitors will abandon a site in just seconds if performance is subpar.
Read full story Ann Bednarz is associate news editor at Network World.
Related News:
 

Related News:

Editor’s note: We will be changing how we send out Network World newsletters over the next few weeks. To ensure future delivery of your newsletters, please add nww_newsletters@newsletters.networkworld.com to your e-mail address book or 66.186.127.216 to your white-list file. Thank you.

Coyote Point helps MoveOn speed Web traffic Political organization MoveOn.org started in 1998 when a couple of concerned citizens wanted to see the country “move on” from talk of former President Clinton’s personal affairs to more pertinent political issues. At its inception, the organization didn’t have to worry too much about overloading Web servers, but with about 2.7 million members now communicating via e-mail and the Web, performance has become a hot-button issue.

Best practices for speeding WAN application delivery The message is sinking in: Adding bandwidth isn’t a cure-all for application performance problems. Aberdeen Group found in a new report that more companies are looking to WAN optimization and application delivery solutions – instead of simply adding bandwidth to alleviate their application performance woes.

Swine flu threat raises telework questions The possibility of a widespread swine flu outbreak is prompting companies to think about business continuity and how options such as telework may become a necessity.

How Bluetooth got as fast as Wi-Fi Bluetooth last week stopped being chained to the low-power, low-throughput radio that has been both its strength and its weakness. New code lets Bluetooth applications now run over 802.11g wireless connections in the 2.4GHz, with a throughput jump to 20M to 24Mbps, from 1M to 3Mbps.

100% trade-in credit for Nortel products Cisco Subnet blogger Brad Reese takes note of Enterasys’ offer to Nortel customers: 100% trade-in credit for Nortel products.

12 killer freebie SharePoint add-ons Microsoft Subnet blogger Ron Barrett was surprised, but happy, to find 12 add-on tools for SharePoint that are free.

Is the Internet ready for a pandemic? As the dreaded word “pandemic” tops this week’s headlines about the swine flu virus spreading around the globe, many businesses are dusting off emergency plans for employees to work from home and schools are poised to send students home. If this turns out to be a full-fledged pandemic, not only will people fall ill, the Internet will too.

April giveaways galore

Cisco Subnet and Microsoft Subnet are giving away training courses from Global Knowledge, valued at $2,995 and $3,495, and have copies of three hot books up for grabs: CCVP CIPT2 Quick Reference by Anthony Sequeira, Microsoft Voice Unified Communications by Joe Schurman and Microsoft Office 2007 On Demand by Steve Johnson. Deadline for entries April 30.

Network World on Twitter Get our tweets and stay plugged in to networking news.


NETWORKWORLD: Verification of cloud security

No Comments »
Live Webcast: SaaS, SOA, cloud computing
Bring disturbed applications to your remote sites with confidence. Leverage modern application architectures including SaaS, cloud computing, and app centralization. Topics covered will include: guaranteeing mission critical services and supporting dynamic bandwidth allocation. This live event scheduled for Tuesday May 12, 2009 at 1:00 p.m. ET/10:00 a.m. Register for this Live Webcast now.
rule
Spotlight Story
Verification of cloud security

By Tim Greene
Verification of cloud security is difficult but also important so businesses need to figure out the best way to handle this.
Read full story Tim Greene is senior editor at Network World.
Related News:
Editor’s note: We will be changing how we send out Network World newsletters over the next few weeks. To ensure future delivery of your newsletters, please add nww_newsletters@newsletters.networkworld.com to your e-mail address book or 66.186.127.216 to your white-list file. Thank you.Group proposes cloud management standard DMTF creates new group dubbed the Open Cloud Standards Incubator, which will be dedicated to addressing the need for open management standards for cloud computing. Cloud computing security: Who knew? Bradner: Security has not been much of a consideration in cloud computing – but that may be about to change. Cloud Standards: Trickier than Nailing Jell-O to a Wall Just try creating a definition of cloud computing that’s broad enough to encompass all its permutations and narrow enough to provide technical guidance on how to get one cloud talking to another. Security promises in the cloud A survey released this week at RSA is troubling in that it says businesses using cloud services are concerned about security, but don’t verify what providers do to meet the security promises they make. April giveaways galore
Cisco Subnet
and Microsoft Subnet are giving away training courses from Global Knowledge, valued at $2,995 and $3,495, and have copies of three hot books up for grabs: CCVP CIPT2 Quick Reference by Anthony Sequeira, Microsoft Voice Unified Communications by Joe Schurman and Microsoft Office 2007 On Demand by Steve Johnson. Deadline for entries April 30. Network World on Twitter Get our tweets and stay plugged in to networking news.

VMWARE: VMUG Newsletter

No Comments »

 

VMware VMUG Newsletter
Become a Member

VMUG Communities

East Region April Newsletter

Come network with an innovative group of VMware users as we share ideas and learn how to get the most out of your VMware solutions!

Upcoming VMUG Meetings
May

 

 

05/01/09 Sylvania, OH Toledo Area VMware User Group

Register

Details

05/12/09 Knoxville, TN East Tennessee Area VMware
User Group

Register

Details

05/14/09 Northern IN Northern Indiana Area VMware
User Group

Register

Details

05/19/09 Central Ohio Central Ohio Area VMware
User Group

Register

Details

05/28/09 Orlando, FL Orlando Area VMware User Group

Register

Details

Please note that this is a listing of all confirmed meetings scheduled for April and May. Be sure to check next month’s newsletter for any additional meetings.

Full-Day User Conferences
04/30/09 Newport, RI New England Area VMware
User Group

Register

Details

Come network with an innovative group of VMware users as we share ideas and learn how to get the most out of our VMware solutions!

05/19/09 King of Prussia, PA Philadelphia Area VMware
User Group Technical Conference

Register

Details

It’s a great opportunity to meet with your Philadelphia based peers to discuss virtualization trends, best practices, and the latest technology!

05/29/09 Charlotte, NC Carolina VMware User
Summit 2009

Register

Details

Featuring some of the industry’s best virtualization experts from across the globe, the Carolina VMware User Summit (CVUS) 2009 will be even more exciting this year!

06/09/09 Pittsburgh, PA Western PA Area VMware
User Group

Register

Details

Mark your calendars for our upcoming Virtualization Technology Symposia. Come to network, share ideas, and learn how to get the most out of your VMware solutions.

Tech Tips: Read More >

VMware vSphere 4: Learn More >

 


US-CERT Current Activity – Symantec Releases Security Advisories

No Comments »

 

Original release date: April 30, 2009 at 4:03 pm Last revised: April 30, 2009 at 4:03 pm

  

Symantec has released three security advisories to address multiple vulnerabilities in Symantec Alert Management System, Log Viewer, and Reporting Server. These vulnerabilities may allow an attacker to execute arbitrary code, bypass security mechanisms, or leverage phishing attacks.

 

US-CERT encourages users and administrators to review the following Symantec Security Advisories and apply any necessary updates or workarounds to help mitigate the risks:

  * Symantec Alert Management System 2 Multiple Vulnerabilities

  * Symantec Log Viewer JavaScript Injection Vulnerabilities

  * Symantec Reporting Server Improper URL Handling Exposure

 

US-CERT also encourages users to continue following the best practices provided in the advisories to minimize future risks.

 

Relevant Url(s):

<http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_01>

 

<http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_02>

 

<http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00>

 

====

This entry is available at

http://www.us-cert.gov/current/index.html#symantec_releases_security_advisories


Microsoft: Special Edition: Windows 7 Release Candidate Ready for Download

No Comments »
Dear Microsoft U.S. Partner,We hope you are as excited as we are about today’s milestone, as we make the Microsoft Windows 7 Release Candidate (RC) broadly available for download to managed Beta program participants, including MSDN and TechNet subscribers. If you are not among those who participated in one of the managed Beta programs, you only have to wait until Tuesday, May 5, when the RC will be available through the Customer Preview Program.In this bulletin, you will find important links and answers to questions that are always top of mind for partners and customers in a release like this. Please look for our regular U.S. partner newsletter on Monday, May 4, with more details and resources for Microsoft partners, including training recommendations.Sincerely,

The Microsoft U.S. Partner Team Download Windows 7 Release Candidate.Why upgrade to Windows 7 RC?

Several new features, including XP VPC, are available in the RC build of Windows 7. Also, you will experience continued improvements in overall system performance and polish.
If you are using Windows 7 Beta, migrating to Windows 7 RC will avoid the July 7, 2009, beta expiration date. Failure to migrate before the beta expiration date will cause frequent system reboot prompts.
There will be no limits on the number of keys provided or the number of Windows 7 RC downloads supported, and we anticipate that RC downloads will be available at least through June 2009.

What is the recommended path to migrate to Windows 7 RC?
The recommended path to migrate to Windows 7 RC depends on what operating system you are currently running:

Current OS Recommended Path to Windows 7 RC
Windows XP If your hardware meets the minimum recommendations for Windows 7, we recommend you do a clean install of Windows 7 RC when available. The recommended minimum hardware for Windows 7 Beta can be found at http://www.microsoft.com/windows/windows-7/beta-faq.aspx. (Hardware recommendations will be roughly the same for RC.)
Windows Vista We recommend you upgrade to Windows 7 RC.
Windows 7 Beta We strongly recommend you do a clean install of Windows 7 RC when available. You do not need to first reinstall Windows Vista and then upgrade to Windows 7 RC.

In all of these scenarios, the Windows Easy Transfer tool can be used to make it easier to restore files and settings after a clean install.When will the final version of Windows 7 be available?
The final engineering milestone is the release to manufacturing (RTM), typically 3-5 months after the RC. We believe the product is high quality and to date have received very positive feedback. This might result in RTM delivery before the 3-5 months timeframe. Ultimately, you’ll decide the quality and assess the delivery once you download and use the RC. Customer and partner feedback will determine how quickly we release.
How will Microsoft collect and use feedback from Windows 7 RC?
With this release, we are focused on verifying that all the changes and fixes we made based on the beta tests and feedback are working correctly. We do that by gathering the automatically generated information (called telemetry) that your PC sends us when you use Windows 7 RC. Telemetry tells us when your computer hangs, crashes, or has performance issues, and what applications or devices you were using when you experienced problems. It is important that we gather this data from thousands of different hardware configurations to confirm that the fixes we included based on beta feedback work on a wide range of hardware. It will also help us identify any new problems.



Cisco NetPro Newsletter

No Comments »
Product Launches
Product Launches
Cisco ASR 1000 Series: Make the Cloud Part of Your Enterprise Network – April 21, 2009
Cisco Unified Computing System – April 16, 2009
Cisco UCS Manager Software – April 16, 2009
Cisco Products Launch RSS Feed
Simplify Compliance, Improve Security with Cisco Services
Cisco Smart Call Home
The Cisco IT GRC Security Assessment Service directly addresses a significant challenge for today’s IT manager-how to allow for the business need to share and collaborate while at the same time protecting information and conforming to industry standards, regulations, and best practices.Learn more
Cisco Live 2009

Registration is now open Cisco Live, Cisco’s IT and communications conference, takes place June 27-July 2, 2009, in San Francisco. This year marks the 20th anniversary of Networkers, Cisco’s flagship technical education program, and offers more than 250 technical sessions across multiple product tracks, including Security.
Register now

Events

Ask the ExpertAuthentication, Authorization and Accounting

Learn how to secure your infrastructure with AAA with Cisco expert Mike Griffin. Ends May 8, 2009
Join the Discussion


Ask the ExpertGroup Encrypted Transport VPN

Learn how to encrypt any-to-any IP and Multiprotocol Label Switching networks with Cisco expert Anand Nuggihalli. Ends May 8, 2009 Join the Discussion

Ask the ExpertCisco EnergyWise Technology

Have you missed the event on the new innovative power management architecture with Cisco experts Berna Devrim and Scott Lennartz. Read the archived Q & A

Ask the ExpertIntegrating Service Module on Virtual Switching System

Have you missed the event on Integrating Service Module on Virtual Switching System with Cisco expert Reza Saadat. Read the archived Q & A
SEO Powered by Platinum SEO from Techblissonline