Tuesday, March 18, 2014

Google Releases Security Updates for Chrome | US-CERT

Source:   Google Releases Security Updates for Chrome | US-CERT


Original release date: March 18, 2014
Google has released security updates to address multiple vulnerabilities in Chrome. Some of these vulnerabilities may lead to memory corruption or arbitrary code execution.
Updates available include:
US-CERT encourages users and administrators to review the Google Chrome release blog entries and apply the necessary updates.



Sunday, March 16, 2014

America the Beautiful - National Parks and Federal Recreational Lands Pass

Source:  America the Beautiful - National Parks and Federal Recreational Lands Pass



Seniors: Did you know you can get a lifetime Parks pass for $10? 


Where can I get a Senior Pass?

You can buy a Senior Pass in person from a participating Federal recreation site or office. See Site Locations that issue the Senior Pass.

You can buy a Senior Pass via mail order from USGS. Mail-order applicants must submit a completed application, proof of residency and age, the $20.00 ($10.00 fee for the Senior Pass, and an additional document processing fee ($10) to obtain a pass through the mail. Once the application package is received the documentation will be verified and a pass, with the pass owner's name pre-printed on it, will be issued to the applicant.

Senior Pass applications are processed and shipped within 3-5 business days from the day they arrive at USGS. Transit time varies, and is dependent upon the service selected:

• USPS - typically 5-10 business days
• FedEx Ground - typically 3-5 business days
• FedEx 2nd day - typically 2 business days
• FedEx Overnight - typically 1 business day

If you need your pass within 15 days or less, it is recommended that you either obtain your pass at the first site you visit, or request expedited shipping services for your order.



Critical Stuxnet-level vulnerabilities discovered in UK power plants - IT News from V3.co.uk

Source:  Critical Stuxnet-level vulnerabilities discovered in UK power plants - IT News from V3.co.uk


14 Mar 2014


Tilbury power station - photo RWE npower
Security researchers have discovered three critical vulnerabilities in a popular industrial control system used by more than 7,600 power, chemical and petrochemical plants across the globe.
Rapid 7 researchers discovered the vulnerabilities, specifically relating to Yokogawa Electric Corporation's Centum CS 3000 R3, Windows-based production control system.
Metasploit engineering manager at Rapid 7, Tod Beardsley, told V3 the flaws are troubling as the control system is used by numerous factories and power plants across the globe, including some in the UK, and could be utilised by hackers to mount a variety of attacks.
"If you take a look at Yokogawa's client list you'll see several companies that have global operations, including the UK. The threats that are enabled by the vulnerabilities described range from simple information leakage (screenshots of active engineering projects) to total compromise of the human interface station (HIS)," he said.
"The HIS is ultimately Microsoft Windows machines running server software – if they are reachable from the internet, then an attack can be sourced from anywhere in the world. Since an attacker can control an HIS, he can then take control of the engineering devices that the HIS is intended to manage. This can include things like power turbines and factory floor equipment."
The fact that the vulnerabilities could be used to manipulate physical processes in the plant is particularly troubling as it could allow hackers to mount Stuxnet-level cyber sabotage attacks against the UK's critical infrastructure. Stuxnet is a notorious malware that was discovered in 2010 targeting Iranian nuclear facilities.
The malware is believed to have been created by the Israeli and US governments but has since spread outside of Iran. It was discovered in a Russian nuclear power plant in 2013, and security experts have warned that it is only a matter of time before the Stuxnet malware appears in the UK.
Yokogawa is aware of the vulnerabilities and has begun releasing security patches to fix them. Rapid 7 recommended that companies install the patch on any Centum CS 3000 R3 control systems as soon as possible.
The flaw is one of many to be discovered in critical infrastructure systems this year. The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) called for businesses involved in critical infrastructure to be extra vigilant of a separate flaw in a commonly used SCADA system earlier in January.



Critical Stuxnet-level vulnerabilities discovered in UK power plants - IT News from V3.co.uk

Source:  Critical Stuxnet-level vulnerabilities discovered in UK power plants - IT News from V3.co.uk


14 Mar 2014


Tilbury power station - photo RWE npower
Security researchers have discovered three critical vulnerabilities in a popular industrial control system used by more than 7,600 power, chemical and petrochemical plants across the globe.
Rapid 7 researchers discovered the vulnerabilities, specifically relating to Yokogawa Electric Corporation's Centum CS 3000 R3, Windows-based production control system.
Metasploit engineering manager at Rapid 7, Tod Beardsley, told V3 the flaws are troubling as the control system is used by numerous factories and power plants across the globe, including some in the UK, and could be utilised by hackers to mount a variety of attacks.
"If you take a look at Yokogawa's client list you'll see several companies that have global operations, including the UK. The threats that are enabled by the vulnerabilities described range from simple information leakage (screenshots of active engineering projects) to total compromise of the human interface station (HIS)," he said.
"The HIS is ultimately Microsoft Windows machines running server software – if they are reachable from the internet, then an attack can be sourced from anywhere in the world. Since an attacker can control an HIS, he can then take control of the engineering devices that the HIS is intended to manage. This can include things like power turbines and factory floor equipment."
The fact that the vulnerabilities could be used to manipulate physical processes in the plant is particularly troubling as it could allow hackers to mount Stuxnet-level cyber sabotage attacks against the UK's critical infrastructure. Stuxnet is a notorious malware that was discovered in 2010 targeting Iranian nuclear facilities.
The malware is believed to have been created by the Israeli and US governments but has since spread outside of Iran. It was discovered in a Russian nuclear power plant in 2013, and security experts have warned that it is only a matter of time before the Stuxnet malware appears in the UK.
Yokogawa is aware of the vulnerabilities and has begun releasing security patches to fix them. Rapid 7 recommended that companies install the patch on any Centum CS 3000 R3 control systems as soon as possible.
The flaw is one of many to be discovered in critical infrastructure systems this year. The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) called for businesses involved in critical infrastructure to be extra vigilant of a separate flaw in a commonly used SCADA system earlier in January.



Thursday, March 13, 2014

Web History Timeline | Pew Research Center's Internet & American Life Project

Source:   Web History Timeline | Pew Research Center's Internet & American Life Project




MARCH 11, 2014

World Wide Web Timeline

Since its founding in 1989, the World Wide Web has touched the lives of billions of people around the world and fundamentally changed how we connect with others, the nature of our work, how we discover and share news and new ideas, how we entertain ourselves and how communities form and function.
The timeline below is the beginning of an effort to capture both the major milestones and small moments that have shaped the Web since 1989. It is a living document that we will update with your contributions. To suggest an item to add to the timeline, please message us.

1989


1990

  • 42% of American adults have used a computer.
  • World’s first website and server go live at CERN, running on Tim Berners-Lee’s NeXT computer, which bears the message “This machine is a server. DO NOT POWER DOWN!”
    800px-First_Web_Server
    The NeXT Computer used by Tim Berners-Lee at CERN. (Wikipedia)
  • Tim Berners-Lee develops the first Web browser WorldWideWeb.
  • Archie, the first tool to search the internet is developed by McGill University student Alan Emtage.

1991

  • xcoffeeResearchers rig up a live shot of a coffee pot so they could tell from their computer screens when a fresh pot had been brewed. Later connected to the World Wide Web, it becomes the first webcam.

1992

  • The term “surfing the internet” is coined and popularized.
  • LHC5
    Credit: Silvano de Gennaro / CERN
    Tim Berners-Lee posts the first photo, of the band “Les Horribles Cernettes,” on the Web.
  • The line-mode browser launches. It is the first readily accessible browser for the World Wide Web.

1993

)

1994


1995


1996

)

1997


1998


1999


2000


2001

  • Only 3% of internet users say they got most of their information about the 9/11 attacks and the aftermath from the internet.
  • The average internet user spends 83 minutes online.
  • Jimmy Wales launches Wikipedia. Users write over 20,000 encyclopedia entries in the first year.

2002

  • 55 million people now go online from work and 44% of those who have internet access at work say their use of the internet helps them do their jobs.
  • Screenshot by Wired
    Screenshot by Wired
    Social networking site Friendster.com launches, but is quickly overtaken by Facebook.
  • Microsoft launches Xbox Live, its online multiplayer gaming service.”Critics scoffed at the idea, noting how uncommon broadband connections were at the time.”

2003

  • Credit: CNET
    Credit: CNET
    Apple launches the iTunes Music Store with 200,000 songs at 99¢ each. The store sells one million songs in its first week.
  • Skype, a voice-over-IP calling and instant messaging service, launches and quickly becomes a verb, as in “Skype me.”
  • Professional networking site LinkedInlaunches.
  • MySpace.com is founded and quickly adopted by musicians seeking to share music and build their fan bases.
  • President George W. Bush signs the CAN-SPAM Act into law, establishing the first national standards for the sending of commercial email.
  • WordPress blog publishing system created.

2004


2005

  • 8% of adult American internet users say they participate in sports fantasy leaguesonline.
  • 9% of internet users (13 million Americans) went online to donate money to the victims of Gulf Coast hurricanes Katrina and Rita.
  • About one-in-six online adults – 25 million people – have sold something online.
  • Broadband connections surpass dial-up connections.
  • Community news site Reddit is founded. It is bought by Conde Nast a year later for $20 million.
  • Rupert Murdoch’s News Corp. buys MySpace for $580 million and sells it in 2011 for $35 million.
  • YouTube is founded on Valentine’s Day. The first video, an explanation of what’s cool about elephants, is uploaded by co-founder Jawed Karim on April 23. Google acquires the company a year later.
)

2006



2007


2008


2009

)

2010


2011


2012


2013



2014

BookMark