Google
You could also try tk Social Bookmarking Search or tk Video Search!
Showing posts with label news. Show all posts
Showing posts with label news. Show all posts

Wednesday, December 26, 2007

Happy2008, UHavePostCard!1! O Rly?

394 comments

As I continue to enjoy my holidays (while reluctantly welcoming the coming year), it seems that spam, trojans and generally nasty baddies are lurking around and having some fun as well.

If you're one of the lucky/unlucky ones, an email containing a link to uhavepostcard.com with a subject like "New Year Ecard" should be in your inbox/spam folder right now.

Happy2008, UHavePostCard or not...

Visiting the website seems to be fairly harmless for now, but following the site's instructions is not such a great idea. Especially not when the file they ask you to receive is the infamous .

You may think you're safe as you may have heard that antivirus software has since been able to detect the Storm Worm, however, the Storm Worm is able to evolve and change its signature so it'll be some time before newer variants are detected. Which is what this executable happens to be.

Friends don't let friends get infected, so spread the word and stay vigilant.

See more , and .

 

Thursday, December 20, 2007

Web Devs Rejoice as IE8 passes Acid2 Test

Comments

One of the biggest news in the tech world today is that Internet Explorer 8 has passed the . From the ,

As a team, we’ve spent the last year heads down working hard on IE8. Last week, we achieved an important milestone that should interest web developers. IE8 now renders the “Acid2 Face” correctly in IE8 standards mode.


Smiling for IE8

For those not in the know, the Acid2 Test was written to make it easy to test a browser's compliance with web standards like HTML4 and CSS2. There are 2 types of Acid2 Tests - with and . This was due to the fact that Internet Explorer and some other browsers do not support data URLs.

In a perfect world, browsers would have proper and consistent support for official web standards and you wouldn't need to worry about your users' browsers as long as your pages followed the official guidelines. The reason why this is such a big deal is because Internet Explorer has the largest market share and passing the test means that some time in the distant future, that perfect world may become a reality.

The ironic part about all this is that while internal builds of IE8 have passed the Acid2 Test, the Acid2 Test on The Web Standards Project site is and will fail to render properly even in compliant browsers! For a working alternative, use the one found at the .

 

And here's the Duke Nukem Forever Trailer!

Comments

As , 3D Realms has given us a quick glimpse at what Duke Nukem Forever may look like, that is, if it ever appears on the market. It isn't much, but from the looks of it, Duke's been keeping fit all these years. Still, I'd prefer some shots of Duke kicking ass to a couple of aliens screaming at me.

I'm looking for some alien toilet to park my bricks. Who's first?



or .

 

Wednesday, December 19, 2007

Duke Nukem Forever Teaser Trailer Coming Tomorrow!

Comments

Shacknews is reporting that 3D Realms has confirmed on their that a trailer for Duke Nukem Forever will be coming out tomorrow some time around noon Central time!

Tomorrow, Wednesday the 19th, around noon CST, we will release the first teaser trailer from Duke Nukem Forever. To tide you over until then, here is a screen shot taken from the teaser.


Duke Nukem

Download the at Shacknews.

[via ]

 

Orkut under Cross-Site Scripting (XSS) Attack

22 comments

Right at this very moment, a cross-site script has been spreading like wildfire in Orkut communities due to a flaw in Google's Orkut.

If you've read the following scrapbook entry in Orkut

2008 vem ai... que ele comece mto bem para vc

from one of your friends, you're infected. Simply viewing the message alone is sufficient for your Orkut account to be added a new community named "Infectados pelo Vírus do Orkut" and be an unwilling new host for the worm. At the time of this writing, the number of Orkut members in Infectados pelo Vírus do Orkut is already at the 400K mark.

According to a posting made by the author of this worm, Rodrigo Lacerda, this script is not malicious in any way, well except for making you an unwitting participant of his experiment. You can verify this for yourself as someone has posted the decoded javascript source of the script at . The original is located at . Still, changing your password isn't terribly difficult.

From what I can grasp from scanning through the script, it appears to work this way. First, it'll add you to http://www.orkut.com/CommunityJoin.aspx?cmm=44001818. Next, it'll load and extract your entire friends list and send itself to them, thus completing the infection cycle. It is able to do this because of the fact that Orkut allows HTML to be inserted into scraps.

Apparently "2008 vem ai... que ele comece mto bem para vc" is roughly translated into 2008 is coming... that it begins is really good for you. It doesn't seem to look that way for Orkut engineers.

Edit: Btw, the excessive traffic generated by this script is partly due to the fact that it will continually attempt to contact Orkut's servers if it fails to do what it wants on the first try (force you into the above-mentioned community and load your friend's list).

Update: The original script location now returns an empty file. That should prevent any new infections from now on. Note that while many folks think that the flash file is somehow malicious, I'm quite sure that it isn't because http://www.orkut.com/LoL.aspx (source of the flash) doesn't even exist!

The embed code is simply the vector through which the malicious script is loaded. This is because it is crafted in such a way that your browser will parse and execute the javascript contained in the embed code. Hence the best way to mitigate this would be to use the rather than , since javascript is the real culprit here.

Btw, you should thank Rodrigo Lacerda for highlighting this vulnerability in such a manner.

Sources:
[]
[]

 

Ulteo launches Online OpenOffice.org Beta

Comments

has squeezed the entire suite online, which allows you to bring along your favorite open source office programs together with you, even if you don't possess a thumbdrive.

Online OpenOffice

According to Ulteo, all you'll need is

a modern web-browser with Javascript and the Sun Java Runtime 1.4+ Environment plugin enabled. It's been successfully tested on Firefox 1.5+, IE6/IE7, and Safari.


Ulteo's online OpenOffice provides a fairly generous 1GB of free storage upon registration of an account, comes with support for PDF output and the OpenDocument Format as well as collaboration features. Unfortunately, their OpenOffice servers are currently overwhelmed by enthusiastic users, so you can only register for an account and wait for the traffic to ease off.

For a quick preview of what it's like, check out . Strangely, the Ars writer could not find any of the collaboration features that . Like the Ars guy, I'm gonna attribute this omission to its beta status.

 

Monday, December 17, 2007

iNdependence 1.3.1 and iPhones' NCK Length (aka master unlock code)

Comments

iNdependence 1.3.1

Over the weekend, the 0perator updated the Mac jailbreaking software, , to version 1.3 and finally to 1.3.1. The most important features in these releases were the introduction of proper 1.1.2 and 7.5 compatibility, instead of the hacky workaround in older releases. See the changelog below or read the . A recently prepared also provides answers and hints on carrying out several tricky but common iPhone scenarios.


v1.3.1 (Hacker-Pschorr) - 12/15/07

- Added instructions for upgrading from 1.1.1 to 1.1.2
- Made UI look proper on Leopard (all text should have been black)
- Fixed a major bug in setting the correct file permissions for anySIM
- Added more credits for anySIM
- Added serial number to Info tab


v1.3 (Velvet Fog) - 12/14/07

- Added 1.1.2 compatibility
- Added iTunes 7.5 compatibility (no need for for the MobDev tool I created earlier) -- thanks to planetbeing for this
- Removed previous ringtone syncing code (not needed with 1.1.2 or MeCCA patched 1.1.1)
- Added anySIM 1.2 (in addition to 1.1) and baseband version detection so that the correct version of anySIM is installed
- Updated the documentation for firmware 1.1.2 and SIM unlocking
- Added Info tab which contains detailed status information


Download .

NCK Length of iPhones

Geohot has discovered that the master unlock code (NCK) of the iPhone is . This key is unique to each iPhone and allows the iPhone to be permanently unlocked, which makes it very interesting as a long term unlock solution. Attempting a brute force attack (trying all possible combinations) on such a long key length is neither feasible nor practical, and as such, he hopes to identify similarities between these NCKs in order to cut down on the time required to look through the entire key space.

However, as the iPhone allows only 5 tries of the NCK, the only sane way to carry out a brute force is outside the iPhone environment. This was made possible recently with the . Other folks are now looking into retrieving NCK codes for iPhones with the 3.9 bootloader so that they can stay unlocked forever. No luck for iPhones on the 4.6 bootloader though, an update from Apple is still required for this method to succeed.

Relevant Hackint0sh threads -


 

Friday, December 14, 2007

New Google Analytics Features/Code (plus a simple fix for Blogger errors)

Comments

The Google Analytics Team just released a of the popular site tracking software that sports a host of new features. Among them are the addition of metrics that provide comparison of various aspects of your site like visits and pageviews.

New in Analytics - comparison metrics


Along with these updates, the Analytics code has also been revamped and in order to gain access to newer features, you have to replace your old code. However if you copy and paste the code provided by the Analytics site into your Blogger template, Blogger will bug you about malformed code. Bummer.

Not to worry though, I've got a quick and easy fix right here.

<script type="text/javascript">
<!--
var gaJsHost = (("https:" == document.location.protocol) ? " https://ssl." : "http://www.");
document.write("\<script src='" + gaJsHost + " google-analytics.com/ga.js' type='text/javascript'>\<\/script>" );
//-->
</script>
<script type="text/javascript">
var pageTracker = _gat._getTracker(“UA-xxxxxx-x”);
pageTracker._initData();
pageTracker._trackVisit();
</script>


Notice the additional HTML code in red? Just add the red parts to your code, insert it into your blog template and you can be on your merry way.

For those wondering what that bit of code does, it's used to comment out javascript for browsers that don't support it. <!-- and --> are normal HTML comment tags, but //, which signifies a javascript comment, is added in front of --> to prevent javascript from parsing it and causing errors.

Apparently Blogger doesn't parse HTML comments (makes sense since it's not necessary), so by inserting these comment tags, Blogger ignores the javascript within these comment tags and allows you to publish it. Modern browsers however, will still be able to execute the javascript, giving you the best of both worlds.

Edit: Forgot to add that you can also test if you properly added the Analytics code by submitting your site to . Enter your email and site URL, choose to test for the new Analytics code, hit the submit button and wait for your results.

 

Wednesday, December 12, 2007

AppJet - Create Web Apps in a Flash!

Comments

AppJet

AppJet

Today is/was the launch of , a site that simplifies the creation of web applications. Based entirely on server-side javascript, AppJet applications are written with a combination of the core javascript language and their custom written libraries, which are relatively easy to pickup compared to other languages.

All you need to get started is your browser, as their browser based IDE includes syntax highlighting, preview and publishing features. Any app you write can be hosted for free on their site and a 10MB persistent storage is also provided if your application requires it.

AppJet IDE

As I browsed through the AppJet site, I decided to code a very simple app to see how long it would take, just to test out AppJet. ;) True enough, after about 30 minutes, I managed to finish . Much of my time was spent on reading the documentation and searching for relevant functions rather than coding.

A simple proxy uses the wget function to download the HTML of remote sites and spits that HTML back out into a div. It is very basic and will not retrieve anything other than text. If you happen to see images, you're downloading them from the originating server and not from AppJet.

After my short and pleasant experience with AppJet, I'm wondering if I should port over. It'll be neat to have data storage so that I can implement a last 5 charts feature or something similar.

 

Friday, December 07, 2007

Google Chart API = Charts Made Easy (it couldn't get any simpler!)

Comments

Google has done it again by releasing yet another excellent online API - . If you're easily frightened by that three-letter acronym, just see how easy it was for me to create the following diagram.

A study shows 83% of all statistics are made up on the spot.

So what spell did I cast? Oh I just took this URL:

http://chart.apis.google.com/chart?cht=p3&chd=t:83.0,17.0&chs=400x200&chl=Fake (83%)|Real (17%)&chtt=A+study+shows+83%+of+all+statistics+are+made+up+on+the+spot.


and stuck it into an img tag. Now that wasn't so hard, was it?

Ok, now you're wondering what all those URL parameters mean. For your benefit, here's what they stand for. :)

cht = chart type
chd = chart data
chs = chart size
chl = chart label (only for pie charts)
chtt = chart title


Want to know even more? Well, that's what the is for. ;)

 

Thursday, December 06, 2007

winChain - Quick Start to Native iPhone App Development on Windows

2 comments

If you've always wanted to code very own iPhone program but were afraid to try, Drakenza, the author of , has come up with a pre-built environment for developing iPhone apps on Windows.

winChain

A 500MB+ download in total, simplifies the setup and installation of required files and programs. winChain also comes with a Template Generator that can be used to create a skeleton application. You can then code in this skeleton application and build your first iPhone app. For detailed instructions on using/installing winChain, head over to the .

With the release of winChain, at least one major obstacle is out of the way. Now all you have to do is pick up programming. ;)

 

Wednesday, December 05, 2007

Open Source AnySIM coming this Friday!

Comments

AnySIM Open Source

A couple of days back, the iPhone Dev Team . Today they have made a decision to officially unveil the code on Dec 7 2007. To be licensed under GPL, the iPhone Dev Team hopes that this will prevent unofficial modifications of their work (). Code contributions from the public are also encouraged by the team. Could this move pave the way to speedier releases and an even more reliable AnySIM?

.

 

Sunday, December 02, 2007

The Inner Workings of 1.1.2 Secpack and Open Source AnySIM?

Comments

Offtopic: After a week of speculation and endless waiting, we are somewhat closer to a 1.1.2 software unlock. The key may lie in the pairing of with the . But for now...

How the 1.1.2 Secpack works

Yes, I know the is old news. But after downloading it, did you know what to do with it? The iPhone Elite Team is here to help by . Assuming you understand all the jargon in the article, you may be on your way to a once you connect all the dots in the 1.1.2 mystery. I exaggerate, but you'll still be at least $20 richer. :P

Open Source AnySIM?

Open Source AnySIM?

Amid mountainous requests for AnySIM to go open source, the iPhone Dev Team has relented and . At the moment, those in favor of opening up AnySIM greatly dwarfs the number against the idea, while there are some who haven't got a clue what AnySIM is all about. With the way things are going, don't be surprised to see AnySIM code at a near you.

Edit: .

 

Saturday, December 01, 2007

Who Will Win The 1.1.2 Unlock Bounty? Maybe Geohot?

Comments

The 1.1.2 Challenge

A new 1.1.2 unlock challenge was setup by to speed up efforts in breaking the pesky 4.6 bootloader found on current iPhones. The first person to provide ample proof of a 1.1.2 unlock will stand to win a small sum of money. The bounty currently stands at $20 but will increase as more donations are received.

To collect the prize, one must post a detailed software based unlock guide with screenshots before anyone else. Any unlocking software used for the unlock must be available for both Windows and OSX as well as its source code. Reverting the bootloader to an older version is also disallowed.

Visit for more details.

Geohot announces new bootloader exploits

Geohot has uncovered not one but ! Although the first one is a hardware exploit, any exploits that are found at this point could turn out to be useful in the future. The second exploit is software based, which could lead us closer to a new unlock, but it would require some smarty pants to figure out how to spoof the necessary bits. Maybe the bounty above will spur Geohot or other aspiring hackers to take a crash course in RSA encryption schemes.

 

Friday, November 30, 2007

Official iPhone Unlock for 100 Euros (if you happen to be in France)

Comments

An interesting tidbit from Hackint0sh member un4:

If you are already a member of ORANGE FR network then you can go to orange and ask them to unblock your phone for 100eur.

Ie: You can buy a 1.1.2 bootloader 4.6 USA phone and go to orange (if you are part of orange network intially) and they will unlock your phone using IMEI and special apple authorization to do so.

This unlock procedure is OFFICIAL and LEGAL since its done but the operator with apple's authorization. ie: You can update legally using itunes...

They have access via apple to unlock any phone they like...

I myself am a client with orange... But I've already got bootloader 3.9 so I'm OK.

Just thought i'd share my information being a French citizen and haven seen this with my own eyes.


Another member DjMiX adds that

This works the same way in Germany... Orange actually adds your IMEI to a list of a iPhones that can be unlocked. Then, when your iPhone is connected to iTunes, it gets in the official unlock process... nothing new actually.


The important bit here is that Orange will unlock your iPhone for 100 euros regardless of where it was bought. The same appears to be happening in Germany as well. Considering that US iPhones are sold at a "cheap" 399 USD (270 euros), it may be worthwhile to ship them to France (50 euros?) for unlocking (100 euros) and resell them at say 650 euros. That is still 100 euros cheaper than an unlocked iPhone (without a plan) in France.

Will we begin to see an influx of officially unlocked US iPhones on ebay?

 

Wednesday, November 28, 2007

Unlocked French iPhones for 749 Euros?

Comments

According to a , the parent company of Orange, it'll be bundling iPhones at 399 Euros with 4 different plans, ranging from 49 euros to 119 euros per month.

However, Orange is also selling the iPhone at 549 euros to customers "who do not wish to benefit from one of the four "Orange for iPhone" plans" (whatever that means...) and 649 euros without a plan. Unlocking the iPhone is a flat fee of 100 euros, regardless of the package selected.

It would appear that if you were to buy a French iPhone without a plan (649 euros) and choose to unlock it (100 euros), it'll be far cheaper than an unlocked German iPhone, which is daylight robbery at 999 euros. I'm unsure, however, if the 649 euro iPhone qualifies as one of the packages. Still, even if this were true, an unlocked iPhone at 749 euros is far too expensive for my taste.

I guess we'll know the intricate details soon enough as it won't be long before it's Wednesday, November 28, 2007, 6.30pm in France.

Edit: Looks like it's 749 euros after all.

 

Tuesday, November 27, 2007

4.6 Bootloader Progress, Exploit Found But...

Comments

Ever since , much progress has been made in cracking the 4.6 bootloader that comes with new 1.1.2 iPhones.

But first, let's take a look at . The options available are



As you may have noticed, each of the hardware unlocks mentioned above come with several major drawbacks. With this in mind, we'll now look at the devious plans of iPhone hackers.

Hackint0sh member pspsully has . The first two deal with hardware based unlocks which wouldn't be very useful to many people. The last item, which focuses on a software exploit for the 4.6 bootloader, .

However, that a new firmware needs to be released by Apple in order for this to be of any use, due to a logic change in the new bootloader. In the , he explains this issue of requiring a new firmware release in further detail.

Unfortunately, all this means that

When we get the next firmware update, once the secpack is retrieved, we should have no problem unlocking 1.1.2 with bootloader 4.6, however, after the next firmware comes out, we WILL NOT be able to update to it as we will then need the secpack from the one AFTER THAT to unlock it.


In short, if no workaround is found, software unlockers will always be one version behind Apple's latest firmware.

 

Sunday, November 25, 2007

Death of an iPhone Begets Birth of Freedom

Comments

Shortly after , ta_mobile successfully dumped the new 4.6 bootloader by dissecting an iPhone and ripping apart its contents. Gory details of this operation can be found . Prepare to avert your eyes as the innards of an iPhone lay bare for all to see.

This iPhone won't be making any more calls...

As we mourn the death of an infant iPhone, take heart in the fact that . Soon the world will learn of the secrets and mysteries behind the impenetrable fortress that imprisoned it. And someday, its fellow brothers, like the ancestors before them, will be liberated from their captivity and be free to roam the world once more.

Disclaimer: No iPhones were harmed in the making of this post.

 

Saturday, November 24, 2007

Just Out: iDemocracy 2.0.2

Comments

Offtopic: There was no update yesterday since nothing much happened, despite official unlocked iPhones floating around Germany. Today, however, is much more eventful. The , which may lead to an unlock for 1.1.2 iPhones. That is something that hasn't occured yet, so for now, let's look at something concrete - iDemocracy 2.0.2.

iDemocracy 2.0.2

Drakenza has updated again and this time it should be easier to check for updates as comes with an update checker. The rest of the changes can be summarized by this statement from Drakenza or you can .

iDemocracy has been updated to 2.0.2, which features bugfixes for the infamous virginizer and anySIM 1.2 problems, as well as an important new feature: Check for Updates! Grab the patcher update now from the downloads section.


More were also implemented in this version. Two of them are really just aesthetics or easter eggs (Fake Update and Window Transitions), but the last one (Jailbreak/Re-Jail/Activate 1.0.2 iPhones) could be useful if you come across a 1.0.2 iPhone.

 

Thursday, November 22, 2007

Updates: iDemocracy, MoreAppSpace, Windows 1.1.2 Unlock Guide (Not for OTB iPhones)

Comments

Offtopic: So the latest news is that Germany will see (preliminary injunction). Wonder if there are any German hackers in the iPhone Dev Team?

Here's . As I was typing this, it seems that some rich Netherlands dude just bought one of these unlocked German iPhones at 999 euros. Apparently, the official unlocking appears to be done via iTunes. More specifically, your Apple store account is tweaked by Apple and when you activate, you're home free. Read about it at or if you read (Dutch?), here's the original post: .

iDemocracy

Drakenza is working on

the iD2 tutorial guide, and a new website and domain name coming soon!


Coincidentally, Mark @ Hack the iPhone was about to work on an iDemocracy guide (he's already got a ).

MoreAppSpace

The iPhone Elite Team has written a new guide about "freeing up" application space on your iPhone titled . It involves moving your programs to another disk and creating a symlink (similar to a "we have moved" sign). This probably isn't new though, I recall seeing it on a few weeks ago.

Windows 1.1.2 Unlock Guide (Not for OTB iPhones)

Mark @ Hack the iPhone has finished . It's not any shorter than and requires about the same amount of effort and time (lots).

Just a quick note: He recommends using iWorld at the end to fix the crashing SMS/phone apps issue. Although this will fix the crashing issue, it appears that your caller ID won't work (I believe it'll show numbers). You would still need to in order to resolve this.

 
Google
You could also try tk Social Bookmarking Search or tk Video Search!