Saturday, May 31, 2008

What we know about Windows 7

This week, Microsoft Corp. went on a 24-hour marketing blitz to talk up the next version of Windows, simply called "Windows 7" for now.

Although some of what Microsoft's executives and spokespeople had to say was how much they weren't going to say and why, a few informational dribs and drabs have worked loose from Redmond.

What, exactly, do we know about Windows 7, the successor to Vista -- the operating system that if not troubled, then at least, as Gartner analyst Michael Silver puts it, carrying " a lot of perception issues"?

Not a lot. Certainly not nearly enough for some of those constituencies thirstiest for details. But here's what we do know, or at least know because Microsoft's said it's so.

When will Windows 7 be released? Depends on who's talking, apparently. Early Tuesday, two Microsoft executives, Chris Flores, a director with the Windows Client communications team, and Steve Sinofsky, the senior vice president who heads Windows development, both pegged the release of the Vista follow-on as early 2010.

"We're happy to report that we're still on track to ship approximately three years after the general availability of Windows Vista," said Flores in an entry on a company blog.

"[We] will continue to say that the next release of Windows, Windows 7, is about three years after the general availability of Windows Vista," Sinofsky told News.com that same morning.

Tuesday night, however, another company executive -- the one who heads the org chart, in fact -- said different. At The Wall Street Journal's All Things Digital conference, Steve Ballmer, Microsoft's CEO, put Windows 7's ship date as "late 2009."

The spread between early 2010, which would be the "three years after the general availability of Vista" -- that operating system went into general distribution at the end of January 2007 -- and "late 2009" may not sound significant, but only a few months separated Vista's actual release from an earlier date that would have meant the operating system made it into computers in time for those PCs to sell during the 2006 holiday season.

What will Windows 7 be like? Under the hood, a lot like Vista, according to the tidbits that Microsoft tossed out this week.

Flores was almost expansive on the subject, and noted that Windows 7 would "carry forward" the "long-term architectural investments" made in Vista. "Windows Vista established a very solid foundation, particularly on subsystems such as graphics, audio, and storage. Windows Server 2008 was built on that foundation and Windows 7 will be as well," he said.

In fact, Sinofsky and Flores confirmed other like-Vista aspects of Windows 7, including the fact that the new operating system will be released in both 32- and 64-bit versions -- there was some speculation earlier that it would be a 64-bit operating system only -- and would, as Flores said, run on the same hardware as recommended for Vista.

Has Microsoft said anything about specific features it plans to ship in Windows 7? A little, but only that. Tuesday night, Microsoft demonstrated a touch-screen feature that the company said would be integrated into Windows 7.

The feature, which incorporates technology Microsoft debuted last year as its Surface project, appears similar to the gesture-based, multitouch tools built into Apple Inc.'s iPhone and MacBook Air, though on the latter the touch is limited to a larger-than-normal trackpad, not the entire screen.

CPU-Z 1.45

                    883__cpu-z4

CPU-Z is a freeware utility that gathers information on some of the main devices of your system. CPU-Z does not need to be installed, just unzip the files in a directory and run the .exe. In order to remove the program, just delete the files and that's it. The program does not copy any file in any Windows directory, nor write in the registry.

CPU

  • Name and number.
  • Core stepping and process.
  • Package.
  • Core voltage.
  • Internal and external clocks, clock multiplier.
  • Supported instructions sets.
  • All cache levels (location, size, speed, technology).

Mainboard

  • Vendor, model and revision.
  • BIOS model and date.
  • Chipset (northbridge and southbridge) and sensor.
  • Graphic interface.

Memory

  • Frequency and timings.
  • Module(s) specification using SPD (Serial Presence Detect) : vendor, serial number, timings table.

System

  • Windows and DirectX version.

VMware Player 2.0.4

VMware Player lets you evaluate new or pre-release software contained in virtual machines, without any installation or configuration hassles. You can also share existing virtual machines with colleagues or friends just use VMware Player to run any virtual machine.

A virtual machine is a computer defined in software. It's like running a PC on your PC. VMware Player runs any virtual machine created by VMware Workstation, GSX Server or ESX Server. VMware Player also supports Microsoft virtual machines and Symantec LiveState Recovery disk formats.

  • Copy and paste. Copy text and files between the virtual machine and the host PC.
  • Drag and drop. Drag and drop files between a Windows host PC and a Windows virtual machine.
  • Integrated Google Search. VMware Player includes Google search capabilities, fully integrated for conveniently searching the web without launching a browser.

IsoBuster 2.4.0.1

                          iso

The Ultimate CD and DVD data recovery software! Rescue lost files from a bad or trashed CD or DVD!

Save important documents, precious pictures or video from the family, your only system backup ... IsoBuster can do it all!

One tool, to support all formats, for only one very democratic price. No accumulated cost if you need more than one type media supported.

IsoBuster is a highly specialized yet easy to use CD and DVD data recovery tool. It supports all CD and DVD formats and all common CD and DVD file-systems. Start up IsoBuster, Insert a CD or DVD, select the drive (if not selected already) and let IsoBuster mount the media. IsoBuster immediately shows you all the tracks and sessions located on the media, combined with all file-systems that are present. This way you get easy access, just like explorer, to all the files and folders per file-system. Instead of being limited to one file-system that the OS picks for you, you have access to "the complete picture". Access data from older sessions, access data that your OS (e.g. Windows) does not see or hides from you etc.

Combine this all-revealing functionality with far better read and recovery mechanisms, scanning for lost files functionality, workarounds for a wide range of drive and software bugs, limitations or shortcomings and you have an enormously powerful data recovery tool. IsoBuster is must-have-software for every PC user and is deliberately kept low priced to be able to offer a solution for everybody.

Top Story : Symantec backs off claim, says current Flash Player safe from attack

Symantec Corp. today said that "suspicious behavior" by a captured exploit had led it to mistakenly conclude that the most up-to-date stand-alone versions of Adobe System Inc.'s Flash Player are vulnerable to ongoing attacks from Chinese servers.

But a Symantec researcher said earlier today that Flash Player 9.0.124.0, the currently available version of the popular multimedia player, is not vulnerable to the ongoing attacks. Just yesterday, Ben Greenbaum, a senior research manager in Symantec's security response group, had claimed that while Flash Player 9.0.124.0 plug-ins were safe, stand-alone editions of the program were not.

"All versions of Version 9.0.124.0 on all platforms, plug-ins and stand-alone, are not vulnerable," Greenbaum said today.

The switch was the third change in Symantec's analysis in the past two days.

On Tuesday, Symantec first warned that legitimate Web sites were redirecting unwitting users to one of several Chinese servers, which in turn were trying multiple exploits, including some aimed at Flash Player. Then, Symantec said that older versions of the Adobe software -- version 9.0.115.0, which was replaced in early April -- and the current 9.0.124.0 could be successfully exploited.

Based on that analysis, Symantec dubbed the vulnerability a "zero-day" bug, meaning it was unpatched, and a threat to anyone with Flash installed.

Later on Tuesday, however, Symantec backtracked from the zero-day label. "Originally, it was believed that this issue was unpatched and unknown, but further technical analysis has revealed that it is very similar to the previously reported Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability (BID 28695), discovered by Mark Dowd of IBM," Symantec said.

Even so, Greenbaum maintained yesterday that while the vulnerability wasn't new, the in-the-wild exploit was effective against stand-alone versions of Flash Player 9.0.124.0. "Not all the versions are patched correctly," he said Wednesday.

Today, however, Greenbaum said that Symantec had come to the erroneous conclusion based on tests of the stand-alone Linux version of Flash Player 9.0.124.0. "While testing against the latest [Linux] version, we saw behaviors consistent with a successful exploit that failed to deliver the payload," he explained today. "[But] the exploit was not, in fact, successful against the latest version."

In a follow-up e-mail, a Symantec spokesman spelled it out in more technical detail. "The latest Linux player, when used to open the exploit file, would abruptly exit silently," said the spokesman. "Stack analysis revealed several internally handled segmentation faults, which is not normally desired behavior for a program." That behavior, in fact, is often a sign of a successful exploit that then uses incorrect offsets or payload code, he added.

"Further research was unable to produce a successful full exploitation, and Adobe confirmed that what we had observed was in fact expected and by design," the spokesman said.

For its part, Adobe stuck to its Wednesday claim that the current Flash Player 9.0.124.0 is not vulnerable. "This exploit does not appear to include a new, unpatched vulnerability as has been reported elsewhere," said Adobe spokesman Mark Rozen. "Customers with Flash Player 9.0.124.0 should not be vulnerable to this exploit."

Greenbaum said that spurious results on Windows test systems had also contributed to Symantec's claims that some versions of 9.0.124.0 were at risk. "We were also seeing compromises on the Windows side," he admitted, "on the latest version of Flash that we downloaded from Adobe's site." Later, Symantec's researchers realized that they had not downloaded an additional patch; when they did and retested, they found the Windows edition to be safe.

"We apologize for the confusion," said Greenbaum. But he defended the analysis, noting that changing updates are common in the security trade as researchers spend more time investigating a problem.

Adobe has recommended that Flash users double-check the version they're running and update to 9.0.124.0 if necessary. Adobe maintains a Web page devoted to Flash Player that displays the current plug-in version from any browser. Users, however, must run the check for each installed browser.

Know what? Apple patches 40 security vulnerabilities in Mac OS X

Apple Inc. yesterday patched 40 security vulnerabilities in more than 25 different components and applications bundled with Mac OS X, including Flash Player, iCal and Apache.

The year's third update fixed fewer than half as many flaws as the previous collection, which Apple issued two months ago to plug nearly 90 holes.

Apple tagged 16 of the 40 patches in Wednesday's update with its "arbitrary code execution" phrasing, putting them into the category most other vendors would label "critical."

According to the Security Update 2008-003 advisory, the most-patched components by vulnerability count were Apple's version of the Apache open-source Web server (eight bugs fixed) and the version of Adobe's Flash Player that Apple tucks into Mac OS X (seven flaws patched).

Fixes to Flash Player, said Apple in its Security Update 2008-003 advisory, update the popular multimedia player application to Version 9.0.124.0, the one currently available for download from Adobe itself. Adobe released that version nearly two months ago to patch the same seven vulnerabilities Apple fixed yesterday. Among the seven was one used to claim a $5,000 prize at a hacker challenge in late March.

Coincidentally, earlier versions of Flash Player are currently being exploited by attackers who have hacked legitimate Web sites and are infecting Windows users with a variety of malware.

Also notable in the update was a fix for one of three iCal vulnerabilities that had been disclosed last week by Core Security Technologies. Apple patched the most serious of the trio, marked as CVE-2008-1035, Core's chief technology officer, Ivan Arce, confirmed today. "Yes, I can say that they patched the most serious of the vulnerabilities, but I cannot confirm that they have patched, or haven't patched, the other two."

Core reported the three iCal bugs to Apple in January 2008, and then went public with information about the vulnerabilities last week after it tired of Apple's patch delays. Core's researchers and Apple's security team also disagreed over the severity of the two bugs still unpatched, according to notes Core posted online.

Arce confirmed the disagreements last week in an interview, and mentioned them again today. After several rounds of e-mail messages, he said, Core told Apple that it appeared the two lesser vulnerabilities were "crash-only," and could not be used to inject malicious code. "But that doesn't mean that they're not security bugs," Arce argued last week.

"If you look at our timeline, you'll see that there was some disagreement about whether the two bugs were security bugs," Arce said today. According to that timeline, Apple said it wanted to classify the two vulnerabilities as having "no security-related consequences." Core disagreed.

Arce said Core will be running tests through Friday to see whether Apple added behind-the-scenes patches for the second and third bugs -- possible because Apple may have decided on its own that they are more design flaws, and less security vulnerabilities.

Apple has not replied to e-mails asking if it has fixed the remaining two Core-disclosed vulnerabilities in iCal.

Other patches included in the Wednesday update address vulnerabilities in AppKit, CoreFoundation, the Help Viewer, Image Capture, the Mac kernel, Mail and Single Sign-on. The risks to users run the gamut from the critical "arbitrary code execution" and password exposure to cross-site scripting and denial-of-service attacks.

The majority of the 40 patches apply to both Mac OS X 10.4 (Tiger) and Mac OS X 10.5 (Leopard); separate updates are available for Intel- and PowerPC-based machines, as well as for Mac OS X Server.

Security Update 2008-002 can be downloaded manually from the Apple site, or installed using Mac OS X's integrated update service, though Leopard users won't see the update on the latter, since the security patches have been rolled into the Mac OS X 10.5.3 upgrade released earlier Wednesday.

Flock 1.2.1 the latest....

                  1064__flock5

Flock is a free web browser that makes it easier than ever to share photos, stay up-to-date with news from your favorite sites, and search the Web.

Flock is built on fast and secure Mozilla technologies. Share photos, get your news, blog freely, and search your world with Flock. Flock makes it easier than ever for you to connect with your friends. Download the first beta and let us know what you think.

When you use Flock to do something cool, you're a Flockstar. It could be anything you want to share with your friends or the world: a photo of your new ride or a song your band just recorded.

Download Flock 1.2.1 (10.72MB)