Practical Technology

for practical people.

April 28, 2004
by sjvn01
0 comments

Internet Explorer Is Too Dangerous to Keep Using

OK, I confess it: I’ve used Internet Explorer a lot. After being a die-hard Netscape user, I finally got fed up with the sheer bulk of that browser and started using Internet Explorer on my Windows machines.

As time went on and open-source Mozilla matured, I started using Mozilla as my main Linux Web browser and as my secondary Windows browser. This past Friday, though, I started installing Firefox, the browser-only side of Mozilla, on every one of my production Windows machines.

Why? Because Internet Explorer, like Outlook, has finally become, to my mind, a permanent security hole that masquerades as a useful application.

Strong words? Have you really thought about this latest exploit? It could hit every Internet Explorer (IE) browser that merely visited any page served by an infected Microsoft IIS (Internet Information Server).

No anti-virus program would stop it, no firewall would slow it down and no shipping IE security patch would even notice it. Visit the page, get the infection. It was that simple.

Oh, but the few thousand people running Release Candidate 2 of Windows XP Service Pack 2 were not vulnerable to the client-side attack. And if you were one of the very few people who had all of the current critical patches installed and were running IE with its security settings at “high,” you’d be OK. That leaves, oh, say, 95 percent of all IE users wide open to this attack. I feel so much better now.

And just how bad was this attack? Boys and girls, let me tell you, this was the worst security violation I have ever seen. But dont take my word for it.

Johannes Ullrich, a handler at the Internet Storm Center at The SANS Institute in Bethesda, Md., wrote, “A large number of Web sites, some of them quite popular, were compromised earlier this week to distribute malicious code.

“The attacker uploaded a small file with JavaScript to infected Web sites and altered the Web server configuration to append the script to all files served by the Web server (IIS). The Storm Center and others are still investigating the method used to compromise the servers. Several server administrators reported that they were fully patched.”

What sites were spreading the infections? We still dont know. Neither the security companies nor the businesses running the infected sites are talking. Since theyre not being any help, I can only suggest that you update your anti-viral software and run it—now.

The only other thing I can say is that sites running IIS 5, which hadnt been patched up to Aprils MS04-011, were the ones targeted by this exploit. But, Im sorry to say, its still not clear that even sites that had been patched with MS04-011 were safe. There are reports that even patched IIS servers were infected.

What happened next was that after simply visiting what looked like a perfectly ordinary page, the JavaScript hidden with the page would direct your browser to quietly download and install one of several different programs from a Russian Web site. “These Trojan horse programs include keystroke loggers, proxy servers and other back doors providing full access to the infected system,” Ullrich said.

Many of the people talking about the exploit have discussed how your computers might be used by these back-door programs to launch a DDoS (distributed denial of service) attack. Yeah, thats bad news, but thats not the real problem.

In the few days that the sites provided the Trojan horses, hundreds of thousands or millions of users could have had their credit-card, stock-brokerage and bank-account numbers and passwords stolen.

Let me repeat myself: Millions of you may have every bit of your browser-driven online financial security information stolen.

Maybe this was just another massive Internet security prank. Maybe all that will happen is a DDoS attack. Well, you can hope thats all there is to it and continue to use IE. But as for me, Im done with it.

Yes, by Friday, most of the major anti-viral programs could stop this particular attack. But what about the next one?

According to the U.S. CERT (Computer Emergency Response Team), “Microsoft Internet Explorer does not adequately validate the security context of a frame that has been redirected by a Web server. An attacker could exploit this vulnerability to evaluate script in different security domains. By causing script to be evaluated in the Local Machine Zone, the attacker could execute arbitrary code with the privileges of the user running IE.”

There is, at this time, no shipping patch to stop this. Wonderful.

If you must run IE, and unfortunately, I do for at least one remote application I use every day, you can disable all active scripting and ActiveX on all IE zones. Between CERTs frequently asked questions about malicious Web scripts redirected by Web sites and Microsofts Knowledge Base article on how to strengthen the security settings for the Local Machine zone in Internet Explorer, you should be safe from most variations of this kind of attack.

Frankly, though, I think CERTs other suggestion is an even better one: Use a different Web browser.

Open-source browsers, such as Mozilla Firefox, are simply more secure than IE. Yes, I know all of the tired, old arguments about how if open-source programs were as popular as Microsofts products; theyd be just as vulnerable. You know what? I dont have time today to deal with the fundamentally inane idea that security by obscurity is somehow the best way to secure software.

The bottom line is that for all practical purposes for today, open-source browsers are inherently more secure than Internet Explorer, and I still have half a dozen more workstations to switch over to Firefox. Go ahead, stick with Internet Explorer for everyday use. Its your funeral.

A version of this story was first published in eWEEK.

April 6, 2004
by sjvn01
0 comments

Progeny to Offer Red Hat 9 Support

With little fanfare, Red Hat Linux 9 is nearing its end of life. Red Hat Inc. is encouraging its business customers to move to Red Hat Enterprise Linux and is asking its Linux-enthusiast customers to try the Fedora Project. But Progeny Linux Systems Inc. has another suggestion for these customers: Continue using Red Hat 9 with support from Progeny Transition Service (PTS).

On April 30, Raleigh, N.C.-based Red Hat will stop producing new security, bugfix or enhancement updates for this well-known Linux distribution. On May 1, Progeny is set to launch its follow-on program, to be announced Wednesday. The program is an add-on to Indianapolis, Ind.-based Progenys existing PTS support lines for Red Hat Linux 7.2, 7.3 and 8.0. Support for all of these lines will continue through the end of 2005.

Progeny, an independent provider of Linux-platform technology founded by Debian Linux creator Ian Murdock, is known primarily for customizing Linux distributions for businesses. The companys Red Hat support aims to assist users who still rely on legacy versions of Red Hat Linux and arent ready to migrate to another Linux platform.

“Ongoing customer demand for a fully supported, reliable security update service has prompted us to extend PTS through December 2005,” Greg Duwe, Progenys director of sales, said in a statement. “Our subscribers prefer to tap into our experience to help them maintain their legacy systems, rather than having to do their own monitoring, packaging and patch testing.”

“Using the Progeny service has saved our organization time, money and needless risk by allowing us to migrate from Red Hat 7.2 on our terms, when it fits our business needs, not Red Hats,” said Rudy Pawul, lead system administrator of ISO New England Inc., a nonprofit corporation responsible for the day-to-day operation of New Englands power supply.

PTS costs $5 a month per machine or a flat rate of $2,500 per month for unlimited machines. Customers gain access to a software repository containing security updates for Red Hat Linux 7.2, 7.3, 8.0 and 9 and are notified of security vulnerabilities and available patches.

Dan Kusnetzky, IDCs vice president for system software research, said he thinks Red Hats strategy of moving to a pure enterprise play “is somewhat risky but very understandable, since they realized that they needed a steady, growing steam of revenue to provide the stability and support that enterprise customers want.”

So far, Red Hats move seems to have worked. Red Hat reported good results in its last quarter on higher-than-expected sales of its Red Hat Enterprise Linux line.

On the other hand, Kusnetzky said, “This leaves the door open for another company to pick up customers. Thats the risky side of Red Hats model. [But] this is part of open source: No program is left behind.”

Kusnetzky also said he thinks Novell and SuSE are looking forward to picking up customers of Red Hat 9 and earlier. But a Novell representative said Novell and SuSE are “not making a special effort to win Red Hat 9 customers. We have offerings, of course, but were not doing anything particular to get anyone to move.”

Red Hat customers who want to stay in the Red Hat family can go to the Red Hat Linux Migration Resource Center. Customers who want to try Progeny support can visit the Progeny Transition Service site.

Progeny to Offer Red Hat 9 Support. was first published in eWEEK.

April 1, 2004
by sjvn01
0 comments

Why SCO Thinks It Can Win

LINDON, Utah—In many pro-Linux circles, its a given that The SCO Group Inc. cant possibly win in court. Obviously, SCO disagrees.

In an exclusive interview, eWEEK.com Linux and Open Source editor Steven J. Vaughan-Nichols visited SCO CEO Darl McBride and Chris Sontag, senior vice president of the SCOsource division, at the companys headquarters in Lindon, Utah. There, they explained why they think SCO can win the legal battle.

Continue Reading →

March 12, 2004
by sjvn01
0 comments

Microsoft and SCO: FUD Brothers

So, we discovered on Thursday that Microsoft talked to BayStar Capital on SCOs behalf months before the investment house brokered a deal that led to SCO getting a cool $50 million round of funding. Well, well, well.

And recently, when SCO finally announced a real, live customer for its Linux IP license, it turned out that the company, EV1Servers.Net, is promoting Windows Server 2003 over Linux for its customers and is featured in a case study showing how Windows is better than Linux at Microsofts Get the Facts Web site.

OK, before these revelations I was willing to give Microsoft the benefit of the doubt. But I was wrong. Microsoft is behind SCO.

While Microsoft has been cheering SCO on and helping the Lindon, Utah, firm with purchases of excess Unix licenses, in the past I didnt believe that Microsoft was actually bankrolling the operation. And I still dont think that Microsoft is technically putting money directly into SCOs accounts. I do think, however, that the boys from Redmond look to be making sure that SCO has the money it needs to continue its reckless course of business by litigation.

And I still dont think, as some would have it, that when Bill Gates wiggles his fingers, SCOs Darl McBride launches another Linux FUD attack. At the same time, if it wasnt for Microsofts backing, SCO would most likely be trying to settle with IBM, and AutoZone and DaimlerChrysler would never have seen a SCO attorney at their doors.

If you look at SCOs financials, its clear that SCO needed that $50 million largely to stay afloat. Its also crystal clear that Linux IP licensing isn’t bringing in the dough. In the last quarter, SCOsource, SCOs IP division, made a whopping $20,000. I had a better quarter than that!

I doubt that the SCOsource program will be doing better anytime soon. SCOs Blake Stowell told me that the EV1Servers.Net deal was in the seven-figure range. EV1Servers.Nets CEO Robert Marsh responded, “We did agree to a one-time payment. However, we did not agree to pay a seven-figure cash payment.”

So, who’s right? I suspect they both are. Let me suggest a possible scenario. Suppose Microsoft heavily discounted EV1Servers.Nets Server 2003 licenses in return for EV1Servers.Net agreeing to pay SCO for its IP license. The net result of such a package deal could be that SCO gets over a million for its licenses, while EV1Servers.Net doesn’t exactly shell out a seven-figure cash payment.

I don’t have a bit of proof for this notion, but it would explain the facts, and it would certainly be a win-win for all three parties, wouldn’t it? Microsoft would get an anti-Linux, pro-Server 2003 story while funneling revenue to its anti-Linux stalking-horse SCO. SCO would get more cash, and it could finally say that it has a real Linux IP customer. And EV1Servers.Net, when all is said and done, would pay a minimal price for its Server 2003 licenses.

Unfortunately for SCO, even if that theoretical scenario were to be true, I couldn’t see Microsoft being able to afford to pull off such a trick many more times. As for SCO finding Linux IP customers on its own, well, the biggest company that has one, Computer Associates, has denounced it. With a customer like this, who needs an enemy?

In the bigger picture, SCO isn’t doing well. Regardless of whether you think SCO can win in the courts—and, personally, I think Ill see pigs fly first—McBride’s mission was to bring SCOs stock price up. For a while, SCOs anti-Linux FUD and lawsuit saber-rattling worked. But, since the news of Microsoft’s involvement and SCO’s newest lawsuits, SCOs stock has fallen to less than $10/share from its $20 range in the fall.

In response, SCO announced that it would buy back up to 1.5 million common shares of its own stock over the next 24 months since, at its current price, the stock represents an “attractive investment opportunity.” I don’t think so! From where I sit, SCO is simply trying to prop up its stock price.

Thanks to Microsofts funding, both indirect and direct (in the case of the Unix license purchase), SCO probably has the cash to keep its head above water and its stock price in the $10 range. And, thanks to Microsofts funding, will continue to see SCO spreading Linux FUD. The Evil Empire lives.

This story was first published in eWEEK. 

March 4, 2004
by sjvn01
0 comments

Leaked Memo Revives SCO-Microsoft Connection Furor

In the open-source community, the rumor that just won’t die claims that Microsof Corp. is funding The SCO Groups legal actions against Linux. On Thursday, those allegations rose again with reports of a memo that links Microsoft with a financial backer of SCO.

The rumors center around a $50 million investment in SCO by the Larkspur, Calif.-based BayStar Capital investment fund last October. At the time, online reports suggested that BayStar, which invests money from a variety of companies, had taken money from Microsoft for the SCO funding. However, in an interview last fall with eWEEK, BayStar officials denied that Microsoft was an investor in this transaction.

The latest twist surfaced Wednesday on the Web with a document that brings into question Microsofts claim that it had nothing to do with the BayStar Capital funding of SCO—and, by association, of SCOs lawsuits against Linux vendors and users.

The new memo was published to the Web on late Wednesday by open-source advocate Eric Raymond. The memo was picked up by the Slashdot Web site on Thursday morning.

Blake Stowell, SCOs director of communications, acknowledged that the leaked memo is real.

But, Stowell claimed, pundits had mischaracterized the memos context. “We believe the e-mail was simply a misunderstanding of the facts by an outside consultant who was working on a specific unrelated project to the BayStar transaction and he was told at the time of his misunderstanding. Contrary to the speculation of Eric Raymond, Microsoft did not orchestrate or participate in the BayStar transaction.”

Responding to the allegations, a Microsoft spokesman said: “The allegations in the posting are not accurate. Microsoft has purchased a license to SCOs intellectual property, to ensure interoperability and legal indemnification for our customers. The details of this agreement have been widely reported and this is the only financial relationship Microsoft has with SCO. In addition, Microsoft has no direct or indirect financial relationship with BayStar.”

The alleged memo, to which Raymond referred as the “Halloween X” memo, is dated October 12, 2003 and penned by Mike Anderer, whom Raymond identifies as a consultant with a company called S2 Strategic Consulting, which has ties to SCO.

S2 had been hired, according to the contract to help “with the formulation and implementation of various options for Intellectual property management.” In essence, S2 was to help SCO make money from its IP.

Four days after the alleged memo was distributed, on October 16, 2003, SCO received the $50 million cash infusion from BayStar Capital and other funders.

A number of industry watchers at that time questioned whether Microsoft had any involvement in the $50 million BayStar financing deal. Some pundits noted that by providing SCO with funding, Microsoft and/or other parties would be helping to fuel SCOs lawsuits against Linux vendors and customers, thereby benefiting Windows. Microsoft and BayStar officials both denied that Microsoft was involved in the funding deal in any way.

he Halloween X memo appears to link Microsoft to BayStar.

“I realize the last negotiations are not as much fun, but Microsoft will have brough(sic) in $86 million for us including BayStar,” said S2 Consultings Anderer in the memo.

“Microsoft also indicated there was a lot more money out there and they would clearly rather use BayStar like entities to help us get signifigantly(sic) more money if we want to grow further or do acquisitions,” Anders continued in the alleged internal memo.

Meanwhile, Microsoft is known to have made at least two lump sump payments to SCO in order to license Unix. Microsoft executives said in May that the company wanted to be on the right side of intellectual-property law. (Microsoft makes available a number of Unix utilities in the form of its Services for Unix product.) One of these payments was for $8 million, according to Securities and Exchange documents; the amount of the other is not known.

Raymond has published a number of alleged internal memos from a variety of companies, including several from inside Microsoft. Raymond referred to all of the leaked memos he posted to the Web as the “Halloween memos,” since he published the first of them on November 1, 1998, the day after Halloween.

Microsoft has verified the accuracy of several of the early Halloween documents that outlined the companys strategy to compete with Linux.

BayStar Capital spokesman Bob McGrath said “we have no way of knowing where it (the memo) comes from or anything about it.” He added that BayStar is standing by its statement from last fall that “Microsoft was not a participant in BayStars fund” that went to backing SCO.

A version of this story first appeared in eWEEK.

March 4, 2004
by sjvn01
0 comments

SCO Can’t Win

I think The SCO Group deserves every penny they’re asking for… if they were right, but theyre not. Ive been following SCO as a writer since the late 80s, and Ive been using its products for even longer. When Caldera came out with one of the first commercial Linux distributions, I was there too. In short, I know this company and its IP claims simply don’t hold up.

If SCO had just gone after IBM on contract terms, because of how IBM handled the attempt to bring AIX 5L to Intel (Project Monterey) that would be a different story. From what I know of that deal, I think SCO was treated shabbily.

SCOs owners, the Canopy Group, should have, in my humble opinion, kept Ransom Love as CEO and continued to support Linux. Had they done so then SCO, with its close Novell ties, would have been acquired by Novell-not SuSE. $200+ million down the drain for Canopy.

As it is, the ownership decided they wanted to shift gears from being an operating system company to one that tries to make money from lawsuits. Now, personally, I don’t like this. Id rather make things than haul people to court. But those businesses can work. In fact, there are companies that do nothing but acquire patents, wait until someone has created something that may infringe on those patents and then swoop in like vultures.

In SCOs case, however, the company is trying to create a house of cards. If any one of those cards shifts, the entire litigious structure falls.

Darl McBride, SCOs CEO, talks about SCO being defending the rights of intellectual property like the RIAA. Its not. SCOs IP claims are much weaker. We know a song belongs to an artist and a label. SCOs copyright claims are much murkier.

First, SCO has to establish that it actually owns the copyright to Unix System V code. Novell says it doesnt. The agreements transferring the IP rights, to my non-lawyer eyes, dont clearly give SCO all the rights they need to make its sweeping copyright claims.

OK, lets suppose that the courts agree that SCO, not Novell, owns the IP and all the rights to control how its used. Next, SCO has to prove that IBM, or other companies, took code from Unix and placed it in Linux. I don’t see how they can do that. SCO has never presented a shred of significant evidence that there is any Unix code in Linux. Besides, we do know for a fact that SCO was trying to get Linux and Unix to work together. If any code duplication is found, SCO could have been the one doing the copying.

SCO was working on this even before Caldera bought out SCOs Unix division and intellectual property. Specifically, SCO added Linux compatibility to its Unix properties with operating system packages like UnixWares Linux Kernel Personality (LKP). The LKP enables UnixWare, one of SCOs Unix operating systems, to run Linux binaries.

So SCO was adding Linux functionality, Linux code, into its own Unix products, and was also considering bringing Linux functionality to its older OpenServer Unix. Given SCOs own reasoning, could all this Linux functionality be added to Unix without introducing Linux code into Unix? I think not.

Look at the history. When Caldera first bought SCO in August 2000, the company suggested that it was going to open source a good deal of Unix. That never happened. Because as Love explained, “We quickly found that even though we owned it, it was, and still is, full of other companies copyrights.”

But what Caldera did do, as described in a Caldera white paper dated March 8, 2001, “Linux and UNIX are coming Together” by Dean R. Zimmerman of SCO, was to try and merge the best features of both operating systems. In the first pages of the white paper, theres a line that fits perfectly with open-source gospel: “For a programmer, access to source code is the greatest gift that can be bestowed.”

And then, deeper into the white paper, “Caldera has begun the task of uniting the strengths of UNIX technology, which include stability, scalability, security and performance with the strengths of Linux, which include Internet-readiness, networking, new application support and new hardware support. Calderas solution is to unite in the UNIX kernel a Linux Kernel Personality (LKP), and then provide the additional APIs needed for high-end scalability. The result is an application deploy on platform with the performance, scalability and confidence of UNIX and the industry momentum of Linux.”

So here we are, SCO/Caldera software developers were not only working on their own Linux— and with SuSE on what would become UnitedLinux— but were adding Linux kernel functionality to Unix too.

Oh, and lest we forget, if there is Unix system code in Linux, it doesnt matter anyway. For you see, SCO has another major legal problem. It was given the code that SCO claims was stolen via the GPL. That basically means that SCO itself has already open-sourced any Unix code that might be in Linux.

If SCO actually owned the IP in question, had any proof that it was stolen, and sourced the code from somewhere other than the GPL, maybe SCO should win. But, at best, I dont how SCO can prove any of the above, except possibly that SCO, and not Novell, owns the copyrights.

Enough! This is just silly. SCO cant win and it shouldn’t win. In the short run, SCO can get some cash from foolish companies like Computer Associates and EV1Servers that are willing to waste their money. And, so long as they can keep the anti-Linux FUD coming, Microsoft will keep supporting them. In the long run though, SCO will rightly lose.


A version of this story was first published in eWEEK.