Eikonal Blog

2012.01.27

Literary Arts

Filed under: art and fun, books, literature — Tags: , , — sandokan65 @ 10:24

2012.01.24

Quacks everywhere

Filed under: atheism, critical thinking, education, superstitions — Tags: , , , , — sandokan65 @ 11:45

Bruce Lipton

2011.12.06

C|Net’s Download.Com trojans

Filed under: antimalware, antivirus, infosec — Tags: , , , , , , , , — sandokan65 @ 09:29
  • “C|Net Download.Com is now bundling Nmap with malware!” by Fyodor (nmap-hackrs email list; 2011.12.05):
    From: nmap-hackers-bounces@insecure.org On Behalf Of Fyodor
    Sent: Monday, December 2011.12.05 17:36
    To: nmap-hackers@insecure.org
    Subject: C|Net Download.Com is now bundling Nmap with malware!
    
    Hi Folks.  I've just discovered that C|Net's Download.Com site has started wrapping their
    Nmap downloads (as well as other free software like VLC) in a trojan installer which does
    things like installing a sketchy "StartNow" toolbar, changing the user's default search
    engine to Microsoft Bing, and changing their home page to Microsoft's MSN.
    
    The way it works is that C|Net's download page (screenshot attached) offers what they
    claim to be Nmap's Windows installer.  They even provide the correct file size for our
    official installer.  But users actually get a Cnet-created trojan installer.  That program
    does the dirty work before downloading and executing Nmap's real installer.
    
    Of course the problem is that users often just click through installer screens, trusting
    that download.com gave them the real installer and knowing that the Nmap project wouldn't
    put malicious code in our installer.  Then the next time the user opens their browser,
    they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as
    their home page, and whatever other shenanigans the software performs!  The worst thing is
    that users will think we (Nmap Project) did this to them!
    
    I took and attached a screen shot of the C|Net trojan Nmap installer in action.  Note how
    they use our registered "Nmap" trademark in big letters right above the malware "special
    offer" as if we somehow endorsed or allowed this.  Of course they also violated our
    trademark by claiming this download is an Nmap installer when we have nothing to do with
    the proprietary trojan installer.
    
    In addition to the deception and trademark violation, and potential violation of the
    Computer Fraud and Abuse Act, this clearly violates Nmap's copyright.  This is exactly why
    Nmap isn't under the plain GPL.
    
    Our license (http://nmap.org/book/man-legal.html) specifically adds a clause forbidding
    software which "integrates/includes/aggregates Nmap into a proprietary executable
    installer" unless that software itself conforms to various GPL requirements (this
    proprietary C|Net download.com software and the toolbar don't).  We've long known that
    malicious parties might try to distribute a trojan Nmap installer, but we never thought it
    would be C|Net's Download.com, which is owned by CBS!  And we never thought Microsoft
    would be sponsoring this activity!
    
    It is worth noting that C|Net's exact schemes vary.  Here is a story about their
    shenanigans:
    
    http://www.extremetech.com/computing/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations
    
    It is interesting to compare the trojaned VLC screenshot in that article with the Nmap one
    I've attached.  In that case, the user just clicks "Next step" to have their machine
    infected.  And they wrote "SAFE, TRUSTED, AND SPYWARE FREE" in the trojan-VLC title bar.
    It is telling that they decided to remove that statement in their newer trojan installer.
    In fact, if we UPX-unpack the Trojan CNet executable and send it to VirusTotal.com, it is
    detected as malware by Panda, McAfee, F-Secure, etc:
    
    http://bit.ly/cnet-nmap-vt
    
    According to Download.com's own stats, hundreds of people download the trojan Nmap
    installer every week!  So the first order of business is to notify the community so that
    nobody else falls for this scheme.
    
    Please help spread the word.
    
    Of course the next step is to go after C|Net until they stop doing this for ALL of the
    software they distribute.  So far, the most they have offered is:
    
      "If you would like to opt out of the Download.com Installer you can
       submit a request to cnet-installer@cbsinteractive.com. All opt-out
       requests are carefully reviewed on a case-by-case basis."
    
    In other words, "we'll violate your trademarks and copyright and squandering your goodwill
    until you tell us to stop, and then we'll consider your request 'on a case-by-case basis'
    depending on how much money we make from infecting your users and how scary your legal
    threat is.
    
    [...]
    

  • “Does CNET Download.com’s new installer install malware?” (HighTechReality.com blog; 2011.08.30) – http://hightechreality.com/2011/08/cnet-downloadcoms-installer-install-malware/
  • “Download.com wraps downloads in bloatware, lies about motivations” by Lee Mathews (2011.08.22) – http://www.extremetech.com/computing/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations
      There was a time long, long ago when Download.com was the place I went for software. It’s been years, however, as the site repeatedly showed signs of devolving into a site every bit as bothersome as the many third-tier software repositories that hide genuine links below clever-placed advertisements and bundle toolbars with their “certified” local downloads.

2011.11.29

Oh well

Filed under: censorship, opression, propaganda, surveillance — Tags: — sandokan65 @ 14:11

2011.11.25

Life writing

Books

Sites, People

2011.11.21

Implementations of programming languages in other programming languages

Filed under: java, javascript, programming languages — Tags: , , , , — sandokan65 @ 10:26

Firefox GUI inside Firefox data frame

Filed under: java, javascript — Tags: , , — sandokan65 @ 10:16

This is a fun stuff. One can open another instance of FireFox GUI inside the browser area where content of web pages is displayed.

Source: “JavaScript JVM Runs Java” (SlashDot; 2011.11.21) – http://developers.slashdot.org/story/11/11/21/0454254/javascript-jvm-runs-java

2011.11.18

Reality of wave function in quantum mechanics

Filed under: physics, Quantum mechanics — Tags: , , — sandokan65 @ 15:39

Asperger’s syndrome, Autism, ASD

2011.11.15

New Facebook machinations

Filed under: FaceBook, privacy — Tags: , , , — sandokan65 @ 13:12
  • Facebook Privacy section at EPIC (Electronic Privacy Information Center) – http://epic.org/privacy/facebook/
  • “Facebook to alter privacy practices following FTC ruling” by Greg Masters (SC Magazine; 2011.11.29) – http://www.scmagazineus.com/facebook-to-alter-privacy-practices-following-ftc-ruling/article/217775/
    • Users were deceived by Facebook, and now the social media giant is paying the price.
    • “Facebook is obligated to keep the promises about privacy that it makes to its hundreds of millions of users,” Jon Leibowitz, chairman of the FTC, said in a statement. “Facebook’s innovation does not have to come at the expense of consumer privacy.”
    • The FTC charges chronicle a number of misleading or untrue assertions about privacy that Facebook made, but did not keep, including: not warning users when a change to its “Friend List” allowed private information to be exposed; stating that third-party apps would not access personal information beyond what they needed to operate; claiming that the “Verified Apps” program certified the security of participating apps; promising users it would not share personal data with advertisers; and insisting that it complied with the U.S.-European Union Safe Harbor Framework that governs data transfer between the United States and certain European nations.
  • “Facebook Settles FTC Charges That It Deceived Consumers By Failing To Keep Privacy Promises” (FTC; 2011.11.29) – http://ftc.gov/opa/2011/11/privacysettlement.shtm
    • In December 2009, Facebook changed its website so certain information that users may have designated as private – such as their Friends List – was made public. They didn’t warn users that this change was coming, or get their approval in advance.
    • Facebook represented that third-party apps that users’ installed would have access only to user information that they needed to operate. In fact, the apps could access nearly all of users’ personal data – data the apps didn’t need.
    • Facebook told users they could restrict sharing of data to limited audiences – for example with “Friends Only.” In fact, selecting “Friends Only” did not prevent their information from being shared with third-party applications their friends used.
    • Facebook had a “Verified Apps” program & claimed it certified the security of participating apps. It didn’t.
    • Facebook promised users that it would not share their personal information with advertisers. It did.
    • Facebook claimed that when users deactivated or deleted their accounts, their photos and videos would be inaccessible. But Facebook allowed access to the content, even after users had deactivated or deleted their accounts.
    • Facebook claimed that it complied with the U.S.- EU Safe Harbor Framework that governs data transfer between the U.S. and the European Union. It didn’t.
  • “24 year old student lights match: Europe versus Facebook” by Kim Cameron (Identity Weblog; 2011.10.13) – http://www.identityblog.com/?p=1201/li>
  • Europe vs Facebook – http://europe-v-facebook.org/EN/en.html
  • “Facebook Ireland accused of creating ‘shadow profiles’ on users, nonusers” by Laura Locke (CNet; 2011.10.21) – http://news.cnet.com/8301-1023_3-20123919-93/facebook-ireland-accused-of-creating-shadow-profiles-on-users-nonusers/
  • “Facebook Patent to Track Users Even When They are Not Logged In to Facebook” by Bruce Scheier (2011.10.24)- http://www.schneier.com/blog/archives/2011/10/facebook_patent.html

Related here: Facebook privacy? What Facebook privacy? – http://eikonal.wordpress.com/2010/04/30/facebook-privacy-what-facebook-privacy/ | Facebook foolies – http://eikonal.wordpress.com/2011/05/12/facebook-foolies/ | Unending stream of Facebook privacy news – http://eikonal.wordpress.com/2010/11/22/unending-stream-of-facebook-privacy-news/ | More Facebook news – http://eikonal.wordpress.com/2010/10/08/more-facebook-news/ | Facebook monkeying again with user trust model – http://eikonal.wordpress.com/2010/09/22/facebook-monkeying-again-with-user-trust-model/ | Scan for your Facebook privacy – http://eikonal.wordpress.com/2010/05/23/i-want-you-to-scan-for-facebook-privacy/ | Facebook leaks users IDs to advertisers – http://eikonal.wordpress.com/2010/05/22/facebook-leaks-user-ids-to-advertisers/ | Facebook mulls U-turn on privacy – http://eikonal.wordpress.com/2010/05/19/facebook-mulls-u-turn-on-privacy/ | Mark Zuckerberg’s birthday present: Facebook in crisis – http://eikonal.wordpress.com/2010/05/16/mark-zuckerbergs-birthday-present-facebook-in-crisis/ | Temptest in a teapot – http://eikonal.wordpress.com/2010/05/15/1202/

2011.11.03

Aging

Filed under: health — Tags: , , — sandokan65 @ 10:30

2011.09.30

awk

Filed under: scripting, unix — Tags: , — sandokan65 @ 11:03

Passing shell variables to AWK

Thing that works well for me:

    awk '{print "'"$VARIABLE"'"}' 1 > 2
    

Related here: Scripting languages – http://eikonal.wordpress.com/2010/06/15/awk-sed/ | Unix tricks – http://eikonal.wordpress.com/2011/02/15/unix-tricks/ | SED tricks – http://eikonal.wordpress.com/2010/10/05/sed-tricks/ | Memory of things disappearing > nmap stuff > getports.awk – http://eikonal.wordpress.com/2010/06/23/memory-of-things-disappearing-nmap-stuff-getports-awk/

2011.09.29

SNMP

Filed under: networking — Tags: , , — sandokan65 @ 12:37

2011.08.17

eBooks and eBook Format Transformers

Sites


Articles


Devices and other readers

  • Amazon’s Kindle
  • barnes and Noble’s Nook
  • FBReader — e-book reader for Unix/Windows computers – http://www.fbreader.org/

eBook format transformers

Kindle blogs

PDF

2011.07.20

Lambert W function

Filed under: mathematics — Tags: — sandokan65 @ 13:38

Definition: A function W: {\mathbb C} \rightarrow {\mathbb C} defined by W(z) e^{W(z)} = z is named the Lambert W-function.

Literature:

2011.07.08

Auditing Unix Security

Misc

2011.07.06

Derivatives of numbers

Filed under: mathematics, number theory — Tags: , , — sandokan65 @ 23:45

Definitions:

  • p'=1 for every prime number p
  • (a b)' = a' b + a b' (Leibnitz rule) for every two natural numbers a, b \in {\Bbb N}

Concequences:

  • 1' = 0.
  • (p^n)' = n \cdot p^{n-1}
  • for any natural number n=  \prod_{i=1}{k} {p_i}^{n_i} one has n' = n \sum_{i=1}^{k} \frac{n_i}{p_i}.
    • Eg: 40' = (2^3 \cdot 5)' = 3 \cdot 2^2 \cdot 5 + 2^3 = 68.
  • in general (a+b)' \ne a' + b'
  • \left(\frac{a}{b}\right)' = \frac{a' b - a b'}{b^2}
  • (p^p)' = p^p for any prime number p is equivalent of the exponential function’s property that its derivative is itself.
  • If n = p^p \cdot m for prime p and natural m>1, then n' = p^p (m+m') > n, n^{(k)} \ge n+k, and \lim_{k\rightarrow \infty} n^{(k)} = \infty.
  • For infinitely many natural numbers n there exist suitable k s/t n^{(k)}=0
  • Ufnarovski and Åhlander give following conjecture: for every natural n, as we observe its derivatives n^{(k)} (as k grows to infinity), the limit will be either 0, \infty, or n itself (if n=p^p for some prime p).
  • If n'=0, then n=1.
  • If n'=1, then n = p (for all possible primes).

Sources:

  • “Deriving the Structure of Numbers” by Ivars Peterson (Ivars Peterson’s MathTrek) – http://www.maa.org/mathland/mathtrek_03_22_04.html
  • “How to differentiate a number” by Ufnarovski, V., and B. Åhlander (Journal of Integer Sequences 6; 2003.09.17) – http://www.cs.uwaterloo.ca/journals/JIS/VOL6/Ufnarovski/ufnarovski.html
      Abstract: We define the derivative of an integer to be the map sending every prime to 1 and satisfying the Leibnitz rule. The aim of the article is to consider the basic properties of this map and to show how to generalize the notion to the case of rational and arbitrary real numbers. We make some conjectures and find some connections with Goldbach’s Conjecture and the Twin Prime Conjecture. Finally, we solve the easiest associated differential equations and calculate the generating function.
  • “Investigations of the number derivative” by Linda Westrick – http://web.mit.edu/lwest/www/intmain.pdf

2011.06.26

Lyme disease

Filed under: health — Tags: , — sandokan65 @ 21:47

Movie: Under our skin

A RI PBS is just airing a documentary from 2008 on the Lyme disease. I just never knew how scary the long term consequences of untreated disease are. It is essentially a bacteria related to syphilis bacteria, and has about the same comprehensive effect on all parts of the body/brain, with indications that in very long time scale causes ALS, MS, Parkisons, and Alzhaymers.

In the same time the movie shows to what degree the medical profession is corrupted by conflicts of interests, where the most influential doctors on IDSA are on payroll of insurance companies and/or own patents in research on Lyme.

2011.06.20

Web applications

Mozilla Prism (aka WebRunner) & Chromeless

Embedded IE


Related here: HTML5 – http://eikonal.wordpress.com/2011/03/04/html5/ | Scripting user interfaces – http://eikonal.wordpress.com/2010/07/22/scripting-user-interfaces/

2011.06.03

Collatz conjecture

Older Posts »

Theme: Silver is the New Black. Blog at WordPress.com.

Follow

Get every new post delivered to your Inbox.