/* -- STUFF -- */

LW: Labour day hackfest will have security systems crash and burn

Thursday, September 28, 2006


As a journalist at LinuxWorld Australia:

An underground community of Australia's "elite" will meet in Sydney for the fourth annual hacker conference, Ruxcon, this weekend. The two day conference kicks off on Saturday at the University of Technology, Sydney.

Ruxcon began in 2003 as non-profit event to bring together security enthusiasts and provide an opportunity for them to exchange ideas and techniques. While the technical focus of the event initially appealed to a small, specialised group of people, recent years have attracted a much broader audience, according to Ruxcon organizer Chris Spencer.

"We see Ruxcon as a computer security conference by the community for the community," he said.

Trivia, pool, a chili eating competition and of course hacking contests, are among the activities scheduled for the weekend. These are interspersed with 18 one-hour-long presentations on topics such as "Exploiting OpenBSD", "Anti-forensic rootkits", "Bypassing corporate email filtering", "Dynamic port scanning", and "Ajax security".

Highlights include "IPV6: Under the Hood" by McAfee principal security architect Mark Dowd, which will expose methods of subverting firewalls, creating covert communication channels, and discovering information about other hosts.

In another keynote presentation, titled "Attacks Against RFID", wireless and RFID security specialist and self-proclaimed ethical hacker Josh Perrymon will cover the ins and out's of Radio Frequency Identification (RFID) attacks, such as passport cloning. In addition to his lecture, Perrymon also hopes to unveil a world record long-range RFID antenna that he is building.

Ruxcon presenters hail from Australia, New Zealand, USA, Belgium, Greece and United Arab Emirates, and are either directly involved in the local computer security community, work professionally in the security industry, or are security enthusiasts.

Presenters and presentation topics were chosen by organisers earlier this year, based on technical merit and interest value.

"Every year we try and provide a unique line up of speakers presenting cutting edge talks with a strong technical focus on either offensive or defensive aspects of computer security," Spencer said.

Spencer expects up to 450 attendees at Ruxcon 2006. Previous years have attracted about 350 "white hat" and "black hat" hackers, who are typically system administrators, IT managers, law enforcers and University students aged between 18 and 40.

"Ruxcon could be described as the Australian version of [U.S. hacker conference] DEFCON," he said. "Obviously we are a lot smaller than the overseas conferences but Ruxcon has a unique Australian flavour and feels a lot more social and friendly."

more

CW: Academic study hopes to uncover the secrets of open source

Wednesday, September 27, 2006


As a journalist at Computerworld Australia:

Open source projects have produced some of the most sophisticated pieces of software while defying conventional wisdom about collaborative projects, according to researchers at the University of California Davis. The interdisciplinary research team, consisting of academics from the fields of computer science, mechanical and aeronautical engineering and management, has recently been awarded a three-year, $US750,000 grant from the US National Science Foundation (NSF) to investigate the open source phenomenon.

The researchers suspect that the structure of open source software will affect the way its developers are organized, and vice versa. The study will focus on the operation of developers of the Apache Web server, the PostgreSQL database and the Python scripting language, through information from message boards, bug reports and e-mail discussions.

Liz Tay speaks with professor of computer science and principal investigator of the study, Premkumar Devanbu.

How would you describe open source projects?

Open source projects adopt the approach of making the source code freely available to anyone who wants to read it. This flies in the face of most commercial software development, which regards the source code as the "family jewels" that must be protected at all costs from the prying eyes of competitors. While this approach may prima facie seem subversive or "socialistic", in fact it follows in a long tradition in scientific research of freely publishing and discussing ideas. If you regard software as nothing more than "hard-coded ideas", it seems completely natural. I'm certainly simplifying a lot here; I would refer people to books by Professor Weber of the University of California in Berkeley (an economist) and Professor Benkler (a Law professor) who have much more authoritative words on the matter. This is just my personal perspective as a computer scientist.

What is most interesting about how open source software is written?

To me, the most interesting part of it is how well they [open source projects] work. They are immensely successful - look at Apache, MySQL, Linux, Perl, etc - they are basically taking over the Web on the server side. I think this success is attributable for the same reasons why most software succeeds: they deliver the features customers want, with great speed and high quality (and of course at low cost). The reason for this, according to Eric Raymond (and others who have taken up this issue since) is the free flow of information about the system, via the source code, to the members of the community. There is a belief that this leads to rapid isolation, diagnosis and remedy of defects that would take traditional projects much longer to fix. Beyond defect isolation, it also makes possible for users to become developers...if you want a feature, you can figure out how to add it, and put it in.

From a researcher's perspective, OSS projects, by their nature, expose comprehensive longitudinal narratives of artifact evolution, social structure of artifact creators, and interactions with general users. This narrative is a valuable source of data for testing hypotheses relevant to software engineering practice.

What prompted you and your team to research this topic? Have you any personal interest in open source?

I have been writing software, teaching software engineering and researching software engineering tools and processes for more than 30 years now, and the phenomenon of open source confounds so many things that we've learned and taught over the years. One striking phenomenon in (traditional) software engineering projects is what is called "Conway's Law": essentially, it states that artifact structure recapitulates social structure. Thus, if you give an organization with two sub-teams the task of writing a compiler, they'll produce a two-pass compiler; if there are three teams, they'll produce a three-pass compiler, and so on. My colleagues and I are eager to see how this phenomenon plays out in open source projects.

First, in open source, the organization is not created by fiat, but evolves organically; second, whatever organization exists, it is more fully observable via the e-mail archives and IRC archives. In traditional projects, people always find ways of doing an end-run around the organizational structures that exist, in order to get their job done. In open source, the interaction between organizational structure and social structure is explicitly observable; the longitudinal study of this, is the goal of our project.

How do you plan on carrying out the research?

It's fairly traditional empirical software engineering - formulate hypotheses, extract data, and test it. The one difference is that we have a very high-powered team, with expertise in complexity physics, bio-informatics, and statistics. We hope to use novel methods in network theory, linear algebra, and physics of complex systems (that have yielded fruit in other areas like biology and social science) to study open source software systems.

What do you expect to find?

We hope to understand how/why some open source projects succeed and others don't; we hope to understand why some open source systems are highly innovative and dynamic while others are not; we hope to understand the process by which people are attracted to, and retained by, open source systems; we hope to understand how the social structure influences the redesign of the system, and vice versa.

It should be noted that while these phenomena are more easily observed and studied in open source projects, the lessons learned are universally applicable to software projects, and perhaps more broadly to complex human endeavours. Efforts are under way to bring the OSS approach to news creation, knowledge creation, etc ... our results would be relevant to these endeavours.

How do you feel about being awarded the grant?

Delighted. Funding for NSF and other research programs in the US have been dwindling, while the competition for grants has increased. Many colleagues have become discouraged, and I know of several who have even left the US and moved to Canada and Europe. We are therefore very grateful to the NSF for its support of our work in these constrained times.

more

PCW: Cyber criminal ring targets Australian inboxes

Tuesday, September 26, 2006


As a journalist at PC World Australia:

Trojan horse malware that provides its owners with credit card numbers, bank details, and other personal information has been discovered targeting Australian Internet Explorer users.

The Trojan was exposed last month by US-based anti-exploit development firm, Exploit Prevention Labs (XPL). However, according to Australian-born Roger Thompson, the company's Chief Technical Officer, it has been known among the whitehat community since April this year.

Victims receive what appears to be a Yahoo Greetings eCard, which directs Web browsers to an authentic eCard via an exploit server. If the exploit server detects browser vulnerabilities, it force-downloads post-logging software onto the user's computer.

This process happens so quickly that it is virtually unnoticeable, Thompson said, adding that some versions of the Trojan also force-download a rootkit which makes it invisible to Internet Explorer's add-on manager.

"It's very, very hard to tell if you've been infected," he said. "If your antivirus program can see it, that's fine. But if it doesn't, then you won't know it's there."

Although it is impossible to determine the exact number of affected users, Thompson expects there to be thousands of Australian computers at risk. XPL researchers have confirmed that accounts at nearly every Australian bank were affected.

The Trojan was found to have been exploiting the Internet Explorer MDAC vulnerability through the Russian-developed WebAttacker script, which XPL has found to be the most prevalent Internet-borne exploit generator. While a patch for the MDAC vulnerability was released by Microsoft in April, Thompson said, many Internet Explorer users remain susceptible because not all users apply patches.

"A lot of work computers don't get patched, because when you patch, a lot of other things can get broken," he said. "A lot of companies don't like patching because of this, and because they think they are safe behind a firewall."

"But browsers are authorized to get past firewalls; that's how they access the Internet," he explained. "And once you're authorized, consumer firewalls don't have enough resolution to distinguish between evil Web sites and clean Web sites."

more

ARN: Security appliance battles porn in Brisbane

As a journalist at Australian Reseller News:

To combat time wasted at work, Internet security and productivity firm, NetBox Blue, has produced a security tool with a twist. Besides acting as a gateway that protects against viruses and spam, the NetBox also monitors traffic and generates reports that tell managers how employees have been using the Internet.

"Spam, firewall, etcetera has been done to death," NetBox Blue CEO, Trent Davis, said. "Our focus is mainly on monitoring usage with email and general traffic, blocking inappropriate access, and compliance by recording activity."

According to a recent survey, Brisbane residents conduct the second largest number of porn searches in the world.

Separate studies conducted by Brisbane-based NetBox Blue found that one company spent 18 per cent of Internet time browsing pornography sites. Porn sites were found to be among the top 10 websites used by staff of another large company.

"Firms are losing thousands of dollars in productivity because staff are viewing pornography and other non-work related websites instead of focusing on their proper tasks," Davis said. "The NetBox puts managers back in control of their network. It's designed to do everything to do with managing an Internet connection."

The NetBox is available in a range of models to cater for small and large businesses. Small offices with 5-10 users are typically recommended the NetBox appliance, retailing at $1290. Larger companies with up to 2000 users may purchase $300,000 IBM-certified NetBox software, which has been designed to work on IBM servers.

NetBox Blue has a direct reseller model with more than 60 resellers Australia-wide, although most of their resellers are located in the Eastern states. Margins range from 15 to 30 per cent, depending on the appliance or software model.

NetBox Blue also manages virus definition updates on all NetBoxes to simplify the support role of resellers, who are typically expected to provide end-users with product installation and support.

more

PCW: Telco answers call from God, censors mobile comms

Thursday, September 21, 2006


As a journalist at PC World Australia:

New SIM card technology launched this week will give parents, companies and even religious leaders greater power to censor mobile phone usage.

The technology relies on a four to six digit second personal identification number, PIN2, that can be used to unlock the "fixed dialling" function on mobile phones. Administrators may nominate up to 50 fixed dialling numbers that the phone is able to call. Outbound calls to any numbers not in the fixed dialling list are restricted.

The service was launched by Australian telecommunications reseller, Telcoinabox, and will be offered by its 70 service providers and franchises.

While Telcoinabox's managing director, Damian Kay, acknowledges that fixed dialling technology infringes on the personal freedom of users, he asserts that it may, in some cases, be a necessary evil.

"The SIM card is not for everyone," he said, "only for people who want to restrict their caller list. For example, a business may want to cap their sales reps calls to stop them from running up a bill the size of Texas. Or a religious group may want to prevent members from making 'inappropriate' calls."

Kay suggests that restricting call access may be the solution to the behemoth phone bill debts that teenagers too often accrue. He expects Telcoinabox service providers to target the new PIN2-enabled SIM cards towards parents and school associations, with the child market in mind.

"There are so many stories around about horrific phone bills from kids," he said. "This gives the parents control and helps control spend."

PIN2 technology has been around for a fair while, Kay said, but as the cost of implementing the technology far outweighs the benefit for major telecommunications carriers, there has been no incentive for these carriers to offer the service.

The service is more commercially viable for niche market MVNOs (Mobile Virtual Network Operators), he explained, such as Telcoinabox's service providers, who are essentially mobile service resellers with their own brands. The service only operates on the Telstra network.

Telcoinabox was prompted to offer fixed dialling services upon being approached by a "conservative and reclusive" religious group who could not be named.

"We were approached by a large global organisation, with a specific requirement to restrict the numbers that their members could call," Kay said. "They didn't want to go on a prepaid service because it's quite restrictive with having to get credits and everything, so this provides them with a non-interruptible, post-paid service that still allows them to control spend."

Fixed dialling was found to be the most efficient and easiest way to implement call control restrictions for mobile phone users after more than 12 months of research.

more

CW: Gardens Point Ruby programmer on compiling dynamic languages for .NET

As a journalist at Computerworld Australia:

Developers at the Queensland University of Technology are working on a Ruby compiler that will allow the language to be supported on the .NET platform. Liz Tay speaks with Wayne Kelly, project leader and senior lecturer at the university's School of Software Engineering and Data Communications, about the Gardens Point Ruby.NET project and his interest (or lack thereof) in Ruby, and .NET.

What are the long term goals of the project, and how far are you from achieving this?

We aim to achieve complete semantic compatibility for all programs written entirely in Ruby. This includes use of the building classes and modules but not other Standard libraries commonly shipped with Ruby - unless they are implemented entirely in Ruby.

Our solution will be fully compiled and produce entirely managed and verifiable .Net code.

Following that, we will work on improving interoperability between Ruby and .Net (such as allow programs written in other .Net languages to conveniently use Ruby.Net code and vice versa), and optimization of special cases so that our implementation runs faster.

We hope to be close to achieving compatibility by the end of this year and will complete interoperability and optimization goals sometime next year.

Why are these goals important?

The .Net platform was designed to support many different programming languages so that developers could choose to use their favourite source language while still providing high levels of interoperability between components implemented in different languages. All these languages are also able to make use of a large collection of libraries, used for example to connect to databases, process XML, help implement Web applications, and the like.

So, to existing .Net programmers, the Gardens Point Ruby compiler adds Ruby to the set of languages they can make use of to develop .Net applications.

Ruby is an increasingly popular language with many fanatic users.

For existing Ruby programmers, the Gardens Point Ruby compiler provides them with access to the facilities of the .Net platform and libraries, including, for example, a rich API for developing Windows forms applications.

The fact that .Net is managed (and so provides sandboxed type security) is also very important in some security-critical scenarios - for example implementing SQL Server stored procedures using fully verifiable .Net code.

This is why we aim to generate only fully verifiable managed code with no native invokes to untrusted code.

One of the wider research goals is to investigate support for dynamic languages on mainstream managed execution environments and to consider how interoperability might be achieved, especially with other dynamic languages such a Phyton.

How long has your team been working on this project for?

I started work on the project in early 2005. The project is co-directed by Professor John Gough and myself. John organized the project proposal and funding with Microsoft, and I have led most of the day-to-day development with John providing higher level guidance.

I led the initial implementation efforts.

How did you get involved in Ruby and .Net?

My research interests lie mainly in the area of parallel computing. The main way I got into Ruby is in the area of parallel computing; the way it's usually done is using a special compiler [like Ruby] to convert sequential code into parallel form.

We've been doing research related to Ruby from around 2000. Our faculty was invited by Microsoft to create compilers for .Net before it was released to the public, so we had a relationship with Microsoft from the pre-testing days.

The original project was to create a Perl compiler and we hadn't had much experience with Ruby before this, but after the project with Perl and .Net we decided to go with Ruby instead. It's cleaner.

I wasn't actually involved in the decision making. John Gough did all the communication with Microsoft.

What are your favourite languages? Have you any special interest in Ruby?

I've done most programming in C#.

I'm not sure if I want to admit this to the Ruby world, but I wouldn't list Ruby as one of my favourite languages - I'm not a big fan of dynamic languages.

But others love it, and there's certainly a demand for it. There is a very fanatical following in terms of the language. In the real world, there are many people who can't wait for us to get this done.

The reason why Microsoft wanted this done is to test that .Net would work with dynamic languages. So this project, from a research point of view, is to investigate what the issues are in compiling dynamic languages on the .Net platform.

What are you currently working on?

We're still trying to complete the implementation. What was released in June was incomplete; we need to work on it so that it supports all Ruby functions.

I'm currently working on getting a few benchmark applications running so we can get an idea of our baseline performance. The shootout benchmark was easily accessible so I've just grabbed those.

Have you made any significant progress or encountered any difficulties since the last beta release of your Gardens Point Ruby .Net compiler?

The release was in June, no. Progress has been relatively slow since then due to other commitments. (If only I didn't have to teach :)

When will the next version be released, and do you still expect to achieve a version with fully semantic compatibility by the end of the year?

We will definitely have the next version out by the end of the year. We may release earlier versions if we feel we have made sufficient progress.

We hope the version at the end of the year will have full semantic compatibility but we are probably a bit behind schedule due to other commitments.

We currently have a couple of casual research assistants working on the project, but we could do with a few more - so, if anyone in the Brisbane area would like a job ...

more

CW: Netspace to go national with ADSL2+

Wednesday, September 20, 2006


As a journalist at Computerworld Australia:

Melbourne-based ISP, Netspace will join the handful of providers that offer high-speed, ADSL2+ broadband to Australian homes. On Tuesday it announced that it has embarked on a national rollout of ADSL2+ technology, and expects to start providing ADSL2+ to new and existing customers within the next three months.

The move comes shortly after Telstra's recently announced impasse with its Fibre-to-the-Node (FTTN) plans. According to Netspace's regulatory affairs manager, Ben Dunscombe, the company was hesitant to make a decision with Telstra's plans still up in the air as there was still some uncertainty as to how the broadband market would react.

"ADSL2+, at its inception point, was a bit of a chicken-and-egg scenario," Dunscombe said. "We weren't sure if it was the products [such as streaming video files] that were going to drive the need for high-speed broadband, or if it was the high speed broadband that was enabling new products."

Now, Dunscombe said, "there has been some regulatory clarity with Telstra kicking the FTTN rollout."

"The market has matured a little more now, so the value propositions we can offer our customers have become a little clearer," he said.

The company's cautious approach towards ADSL2+ also involved a beta trial that took place in Melbourne early this year.

"We deployed a number of Melbourne exchanges and with a couple of test cases going forward," Dunscombe said. "It really proved to us that we had the capability to deploy the infrastructure and the technology to support it."

Netspace's ADSL2+ network will operate on a combination of its own new infrastructure and existing framework via wholesale agreements with infrastructure providers that could not be named.

When fully deployed, the combination of new and existing infrastructure is expected to form a network with a breadth and reach of ASL2+ services that rivals any other Australian provider, the company claims.

No details on pricing or when new services will become available have yet been released. However, Dunscombe expects the launch to take place early in the fourth quarter this year.

"It's not expected to be a Christmas present," he said.

more

ARN: Great Bay Software signs inTechnology

As a journalist at Australian Reseller News:

Queensland-based distributor, inTechnology, has entered into an exclusive agreement to distribute Great Bay Software's end-point profiling solution, Beacon.

The platform is a software and hardware application designed to facilitate the timely deployment of 802.1x, and systems that rely on this framework, by allowing a network manager to control all devices on the network from a centralised location.

Great Bay joins major vendors Juniper, InfoExpress, Cisco and Microsoft in the distributor's five-step Endpoint Security (NAC) solution. According to inTechnology director of sales and marketing, Mark Winter, Beacon is a fitting addition to its portfolio.

inTechnology was approached by Great Bay Software about three months ago, Winter said.

The distributor is looking for new channel partners to help it grow the brand locally. The product is expected to generate revenues of more than $1 million in the coming 12 months.

Services that could be offered by resellers include training programs and marketing campaigns. inTechnology already has a product awareness campaign planned for the first week of December. Following that, Winter expects there to be a market for training programs held at channel partner venues or as webinars.

The partnership is Great Bay's first step into the Australian market, which Winter said was a perfect launch pad into Asia-Pacific.

more

CW: Industry effort aims to advance women in computing

Tuesday, September 19, 2006


As a journalist at Computerworld Australia:

Eight of Australia's leading CIOs and technology leaders have come together to initiate the second phase of the Women in IT Executive Mentoring (WITEM) program. The program aims to address a number of issues which women face in the technology sector.

The Australian Bureau of Statistics 2005 Labour Force Survey found that women make up only 20.5 percent of the IT workforce. According to Joe Kremer, vice president and managing director of Dell Australia and New Zealand, the percentage of women in the IT workforce further diminishes in senior positions.

Because there are so few female IT executives, Kremer suggests that women in the industry may lack role models on whom to base their career development. To this end, WITEM puts volunteer mentors together with high-potential female executives. The mentoring program is expected to accelerate the development of leadership competencies, such as general management expertise and confidence, of mentees.

"We're trying to create more balance in the organization," he said, "because I think if an organization under-represents women at senior levels, then they are at a disadvantage because they lose a certain point of view."

The first phase of WITEM was initiated by Dell in December 2005. It involved managing directors from eight technology companies, including Cisco, EMC, Ingram Micro, Intel, Lexmark, Altiris and LAN Systems, each mentoring a female executive from across marketing, sales, legal counsel and channel management functions of another company.

Phase II, launched in July this year, takes a different approach, as it targets women working in IT departments of companies that are not necessarily in the IT industry. The eight phase II mentors come from seven companies in the public and private sector, including Centrelink, Deloitte, Department of Finance and Administration, Ernst & Young, NSW Department of Education and Training, Westpac and Woolworths.

The phase II view of IT careers gives the program a wider spread in the Australian labour force, which reflects the pervasiveness of technology in businesses, Kremer said.

"When they [the public] think about IT, they think of someone writing code in a dark basement somewhere. But I think the potential for CIOs is amazing now," he said. As businesses become increasingly dependent on technology to succeed, Kremer expects there to be greater potential for IT professionals to advance their careers. "I think that 15 years from now, CEOs will be chosen from CIOs," he said.

Even in early stages of the mentoring program, Kremer has already noticed changes, for the better, in the dynamics of his own organization. Employees are more communicative and more readily raise concerns such as the conflict arising between early morning meetings and childcare, which led to renegotiated timing.

"This program has opened doors," he said. "We have found more of a voice for women in the company. I think that if people are talking, then it's a very good thing for the company"

CW: Ballarat camp to EXITE girls about IT

Monday, September 18, 2006


As a journalist at Computerworld Australia:

Twenty-four girls in Year 10 will attend IBM's Exploring Interests in Technology and Engineering (EXITE) Camp in Ballarat this week.

The camp aims to introduce girls living in the Ballarat area of Victoria to career opportunities in IT, and to encourage greater learning of technology. It will be held at the Mt Helen Campus of the University of Ballarat from September 18-21

"We want to highlight career opportunities to people living in rural areas, and particularly to women who aren't very well represented in the industry," said Cameron Woolfe, EXITE Leader of the Ballarat camp.

"[Computing is] a non-traditional area for girls," he said, "so the camp is really targeted towards having fun and showing that computers are not just about programming and cutting code."

This will be the first EXITE camp to be held in Ballarat and follows a Gold Coast camp as the second of three EXITE camps to be run in Australia this year.

Students from Ballarat Grammar, Ballarat High School, Ballarat Secondary College, Beaufort Secondary College, Damascus College, Daylesford Secondary College, Loreto College, Mt Clear College and Sebastopol Secondary College have been chosen to attend the Ballarat camp.

Participants will attend a career expo and a site visit to the Sovereign Hill historical park to see the evolution of technology, as well as workshops on online media, programming, robotics, and crime investigation.

Girls will also be paired up with volunteer female mentors from IBM's Ballarat facility, who will provide academic assistance and career counselling during the camp and throughout the remaining school year.

"Women in IT can pretty much do anything they want to do," Woolfe said. "The sky's the limit."