tag:blogger.com,1999:blog-61811376662454129222008-04-23T12:55:03.157-04:00TMI Engineering BlogEngineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comBlogger8125tag:blogger.com,1999:blog-6181137666245412922.post-37843395506033112232008-04-17T17:04:00.006-04:002008-04-17T18:22:39.665-04:002BAccessible.com Goes Live<img src="images/2ba-browser.jpg" alt="A 508 Complaint Website by TMI Web Solutions" style="float:left; padding-right: 10px;"/> TMI Web Solutions is proud to announce the launch of <a href="http://www.2baccessible.com/">2BAccessible</a> a website that will help bridge the gap between eCommerce and the vast untapped market of consumers with disabilities.<br /><br />More than ten million Americans are visually impaired and this number is expected to grow to 30 million in ten years. While the internet is an ideal medium for these people to purchase goods and services, many websites poorly implement the established standards that would make them accessible to screen readers.<br /><br />Following proper accessibility guidelines does more than just help people with disabilities navigate websites. The same standards that help screen readers parse websites also helps search engines such as Google and Yahoo! To find out how being accessible (also known as "508 Compliant") can help your website, contact the TMI Web Division at 703.505.4059Web Solutionshttp://www.blogger.com/profile/09265535926190862948noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-73342046579185133292008-03-31T21:50:00.003-04:002008-03-31T21:54:26.956-04:00Sophos - Top 10 Malware for February 2008<a href="http://bp2.blogger.com/_GuTu65rrMwg/R_GVwUAedFI/AAAAAAAAAB0/D67OmPOz5NI/s1600-h/Picture+2.png"><img id="BLOGGER_PHOTO_ID_5184089303317115986" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://bp2.blogger.com/_GuTu65rrMwg/R_GVwUAedFI/AAAAAAAAAB0/D67OmPOz5NI/s400/Picture+2.png" border="0" /></a>Sophos has released their malware statistics for the month of February. <div><br /><div></div><br /><div>For more information please see - <a href="http://www.sophos.com/security/top-10/index.html">http://www.sophos.com/security/top-10/index.html</a></div><br /><div></div><br /><div></div></div>Engineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-78389441136055402252008-03-28T14:31:00.005-04:002008-03-28T14:37:49.867-04:00Blackberry Scheduled Outage - Update!<a href="http://bp0.blogger.com/_GuTu65rrMwg/R-06B0AedDI/AAAAAAAAABk/oDNLAnkBPDI/s1600-h/blackberry_8800_zoom.jpg"><img id="BLOGGER_PHOTO_ID_5182862548988228658" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_GuTu65rrMwg/R-06B0AedDI/AAAAAAAAABk/oDNLAnkBPDI/s320/blackberry_8800_zoom.jpg" border="0" /></a> <strong>BlackBerry Infrastrcuture</strong>, database upgrade for all *NA Network subscribers. This affects all RIM customers in the Americas.<br /><br />Start Date & Time: 03/29/08 06:00:00 GMT<br />End Date & Time: 03/29/08 10:00:00 GMT<br /><br /><br />Downtime Duration : 4 hours<br /><br /><strong>BlackBerry</strong> subscribers may be unable to send or receive messages during the maintenance. Subscribers may also be unable to register their device, roam in another location, or use other services such as Internet browsing. BlackBerry Internet Service subscribers may be unable to use the BlackBerry Internet Service web site or perform activities such as creating new accounts, accessing their Internet mailbox, integrating third-party email accounts, or viewing email attachments during the maintenance. Devices may not receive new service books during the maintenance. BlackBerry Connect and BlackBerry-enabled devices that require a new PIN may be unable to receive the PIN. BlackBerry Enterprise Servers may be unable to connect to the BlackBerry Infrastructure during the maintenance.<br /><br />Wireless service providers and device resellers may be unable to use BlackBerry administration web sites or perform activities such as creating subscriber accounts or provisioning services for subscribers during the maintenance.Engineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-92214864954766544922008-03-25T14:26:00.003-04:002008-03-25T14:36:50.834-04:00Windows Vista SP1<a href="http://bp1.blogger.com/_GuTu65rrMwg/R-lGMEAedAI/AAAAAAAAABM/JQ0u5dwOqQw/s1600-h/mslogo.jpg"><img id="BLOGGER_PHOTO_ID_5181750019314578434" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_GuTu65rrMwg/R-lGMEAedAI/AAAAAAAAABM/JQ0u5dwOqQw/s320/mslogo.jpg" border="0" /></a> <strong>Windows Vista Service Pack 1</strong> is an update to Windows Vista that addresses feedback from our customers. In addition to previously released updates, SP1 contains changes focused on addressing specific reliability and performance issues, supporting new types of hardware, and adding support for several emerging standards. Windows Vista SP1 also addresses some management, deployment, and support challenges.<br /><br />Download <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=B0C7136D-5EBB-413B-89C9-CB3D06D12674">x86</a> <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=874A414B-32B2-41CC-BD8B-D71EDA5EC07C">x64</a><br /><br />Click <a href="http://technet2.microsoft.com/WindowsVista/en/library/005f921e-f706-401e-abb5-eec42ea0a03e1033.mspx?mfr=true">here</a> to see notable changes presented in SP1.Engineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-11392233345511790872008-03-18T15:40:00.003-04:002008-03-25T14:45:59.892-04:00Patch Tuesday Updates - March 11th<a href="http://bp1.blogger.com/_GuTu65rrMwg/R-lISEAedBI/AAAAAAAAABU/brf7NQTspoE/s1600-h/windowsupdate.jpg"><img id="BLOGGER_PHOTO_ID_5181752321417049106" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_GuTu65rrMwg/R-lISEAedBI/AAAAAAAAABU/brf7NQTspoE/s320/windowsupdate.jpg" border="0" /></a> <strong>Attention:</strong>The following updates have been applied to systems supported by TMI. If you have questions about these updates please contact us at <a href="mailto:tech@tmiva.com">tech@tmiva.com</a><br /><br /><strong>MS08-016</strong> – Critical: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (949030)<br /><br />Bulletin Severity Rating: <em>Critical</em> - This security update resolves two privately reported vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a malformed Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br /><br /><strong>MS08-009</strong> - Critical: Vulnerability in Microsoft Word Could Allow Remote Code Execution (947077)<br /><br />Bulletin Severity Rating:<em>Critical</em> - This critical security update resolves one privately reported vulnerability in Microsoft Word that could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.Engineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-55548846883965166042008-03-18T12:31:00.008-04:002008-04-21T11:03:55.990-04:00Blackberry Scheduled Outage....<a href="http://bp2.blogger.com/_GuTu65rrMwg/R-lKSUAedCI/AAAAAAAAABc/WaTFHvseWVg/s1600-h/rim.jpg"><img id="BLOGGER_PHOTO_ID_5181754524735271970" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_GuTu65rrMwg/R-lKSUAedCI/AAAAAAAAABc/WaTFHvseWVg/s320/rim.jpg" border="0" /></a><strong>Research In Motion</strong> has stated that there will be a total network outage on <strong><em>Saturday March 22nd.</em></strong> This outage will occur during their normal maintenance window [2:00AM-6:00AM EDT].<br /><br />This outage is scheduled for all BIS & BES users in the Americas, and will take the entire four hour window.<br /><br />For more information please see <a href="http://www.dataoutages.com/mailman/listinfo/bb-outage">DataOutages.com</a>.Engineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-24687606428960893902008-03-17T22:08:00.000-04:002008-03-17T22:17:39.463-04:00What is Patch Tuesday?<span style="font-weight: bold;">Patch Tuesday</span> is the second Tuesday of each month, the day on which Microsoft releases security patches.<br /><br />Starting with Windows 98, Microsoft included a "Windows Update" system, that would check for patches to Windows and its components which Microsoft would release intermittently. With the release of Microsoft Update, this system also checks for updates to other Microsoft products, including Office, Visual Studio, SQL Server, and others<br /><br /><span style="font-weight: bold;">Patch deployment costs</span><br /><br />The Windows Update system suffered from two problems, affecting opposite ends of the users scale. On the one hand, less experienced users were not aware of it, and did not run it. Microsoft's solution was to introduce the concept of "Automatic Update", which would pro-actively inform the user that an update was available for their system.<br /><br />The second problem affected large deployments of Windows, such as can be found at large companies. Such large deployments found it increasingly difficult to make sure all systems across the company were all up to date. The problem was made worse by the fact that, occasionally, a patch issued by Microsoft would break existing functionality, and would have to be uninstalled.<br /><br />In order to reduce the costs related to the deployment of patches, Microsoft introduced the concept of Patch Tuesday. The idea is that security patches are accumulated over a period of one month, and then dispatched all at once on an anticipated date which system administrators can prepare for. This date was set not too close to the beginning of the week, and yet far enough from the end of the week to allow any problems that may arise to be resolved before the weekend. System administrators can mark the second Tuesday of the month as the "day in which machines are updated", and plan accordingly. The name "Patch Tuesday" has been in use since the third quarter of 2004. It is becoming synonymous for the day any software vendor issues a vulnerability patch. Some editors/analysts talk about "Exploit Wednesday" as the day after, or even "Day Zero" immediately following the update, when hackers can launch attacks against the newly announced vulnerabilities.<br /><br /><br /><span style="font-weight: bold;">Security implications of Patch Tuesday</span><br /><br />The most obvious security implication is that security problems that have a solution are withheld from the public for a period of up to a month. Implicitly, this policy assumes that most attacks use information reverse engineered from the security patches that fix the vulnerability, rather than true "Zero day attack" exploits. It is unknown to what extent this assumption is true.<br /><br />In the past, there were some cases where either vulnerability information or actual worms were released to the public a day or two before patch Tuesday. This does not leave Microsoft enough time to incorporate a fix for said vulnerabilities, and thus, theoretically, leave a one month window for attackers or the worm to exploit the hole, before a patch is available to formally fix it. This phenomenon is unrelated to Exploit Wednesday.<br /><br /><span style="font-weight: bold;">Exploit Wednesday</span><br /><br />Many exploits are seen shortly after the release of a patch. By analyzing the patch, exploit developers can more easily figure out how to exploit the underlying vulnerability. Therefore the term "Exploit Wednesday" was coined. Also, starting to abuse an exploit on this day gives malicious code writers the longest period of time before a fix is supplied to users. Malware authors can sit on a new exploit until after a given patch Tuesday, knowing that there will be an entire month before Microsoft releases any patch to fix it.<br /><br /><span style="font-weight: bold;">Other consequences</span><br /><br />Immediately following Patch Tuesday, millions of computers are rebooted within a short period of time. This causes an exceptional strain on other internet companies. For example, in August 2007, Skype experienced a two-day outage following Patch Tuesday.<br /><br /><span style="font-weight: bold;">For more information see...</span><br /><br /><ul><li><a href="http://www.microsoft.com/technet/security/bulletinsandadvisories/default.mspx">Microsoft: Bullitens & Advisories<br /></a></li><li><a href="http://support.microsoft.com/">Microsoft Support Website</a></li><li><a href="http://windowsupdate.microsoft.com/">Microsoft Windows Update</a></li></ul><br />From : <a href="http://en.wikipedia.org/wiki/Patch_Tuesday">Wikipedia</a>Engineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.comtag:blogger.com,1999:blog-6181137666245412922.post-86395291177558030822008-03-17T21:51:00.000-04:002008-03-17T21:55:46.612-04:00Welcome to TMI's Engineering Blog....Evening,<br /><br />This is the first of what will hopefully be many posts. We will be using this blog as a means to communicate critical updates, outages and news.<br /><br />We hope that you will take advantage of this blog and come to take advantage of it's information.<br /><br />Joshua MorehouseEngineeringhttp://www.blogger.com/profile/07298920745720419418noreply@blogger.com