Sunday, February 6, 2011

Aussie desktop archaeologist's major Saudi sighting

Google Earth screenshots showing some of Professor David Kennedy's finds.

An Australian archaeologist working from his armchair in Perth has unearthed almost two thousand potential archaeological sites in Saudi Arabia.

Far and away from the Indiana Jones-style imagery archaeologists inspire, high resolution photography is allowing researchers to unearth world-changing discoveries using little more than Google Maps.

Professor David Kennedy, from the University of Western Australia, has never visited Saudi Arabia but scanned 1240 square kilometres of the country using Google Earth and found 1977 potential archaeological sites. This included 1082 ancient tombs shaped like tear drops.

Professor David Kennedy, who made the discovery.

Professor David Kennedy, who made the discovery.

Kennedy was able to confirm the legitimacy of two of the finds by asking a friend in Saudi Arabia to drive out to the sites and photograph them. He believes they may be up to 9000 years old.

In a similar instance in 2008, a PhD student at La Trobe University in Melbourne uncovered hundreds of previously unknown sites in Afghanistan using Google Earth. Like Saudi Arabia, Afghanistan can present hostile challenges to researchers and the online mapping service provides a safe way to explore the country.

"Saudi Arabia has a rich archaeological heritage but it is relatively poorly recorded and understood," said Kennedy in an email interview.

"The extensive remains of great prehistoric cemeteries in such places as Yabrin in the interior have been known for many years but little-explored. More widely, extensive and numerous ruins are known in many areas but seldom recorded even superficially."

Kennedy told New Scientist that Saudi Arabia was "not the easiest country to break into" and it was difficult to even fly over the nation - but he said Google Earth "can outflank them".

In his paper on the find, published in the Journal of Archaeological Science, Kennedy writes: "It is readily apparent that the use of GE [Google Earth] for the prospection and identification of sites has great potential when dealing with a huge area that is otherwise largely inaccessible on the ground."

However, further ground verification is needed to confirm the significance of the sites.

"Just from Google Earth it's impossible to know whether we have found a Bedouin structure that was made 150 years ago, or 10,000 years ago," Kennedy told New Scientist.

In the journal paper Kennedy said initial investigations revealed most of the discoveries were "pre-Islamic". It is thought that the Islamic regime in Saudi Arabia is hostile to archaeology because it may focus attention on pre-Islamic civilisations there.

Kennedy did not express a view on this but said Saudi Arabia was one of the least explored countries archaeologically.

"Saudi Arabia covers 2.15 million sq km - twice the size of the UK, France and Germany together," Kennedy writes in the paper. "On the other hand, it is one of the least explored countries archaeologically."

Britain's Daily Telegraph newspaper reported that 90 per cent of the archaeological treasures in the holy cities of Mecca and Medina had been destroyed to make way for hotels, apartment blocks and parking facilities. Last year, Saudi clerics reportedly renewed long-standing calls for the demolition of several historic Islamic sites.

In 2008 and 2009 other Google Maps researchers discovered rare meteorite impact craters in Western Australia and the Northern Territory.

In 2008, a Western Australia man said he felt like Charles Darwin after discovering - via Google Earth - an extensive formation of fringing coral reefs just west of the Kimberley.

In 2007 Google Maps revealed an aerial image of a US nuclear-powered submarine and, separately, evidence of China's nuclear submarine capability.

In 2006 an Australian granny living in a small Canadian prairie town discovered an intriguing rock formation that looks like an iPod-wearing native American.

But while Google Maps has been a boon for academics, it's also caused international conflicts with Nicaraguan troops blaming a Google Maps error for them invading Costa Rica in November last year. Other errors have created tensions between Morocco and Spain.

In December last year the Iranian government was reportedly furious after Google Maps satellite images revealed a Star of David painted on he roof of the Iran Air headquarters.

Greenpois0n Untethered iOS 4.2.1 Jailbreak Arrives

Greenpois0n Untethered iOS 4.2.1 Jailbreak Arrives

While Apple is currently seeding out iOS 4.3 beta builds to developers, the Chronic Dev Team has released untethered jailbreak for iOS 4.2.1 running devices. Available at http://www.greenpois0n.com, the jailbreak tool is meant for Mac OS X platform at this moment and a Windows version is promised soon. The new greenpois0n tool allows jailbreaking iOS devices like iPhone, iPad and iPod touch running the iOS 4.2.1 update. The process is easy and jailbreaks your device in a few clicks. However, iPhone 4 owners need to avoid this tool as it doesn't perform carrier unlock and updates baseband firmware. This means you won't be able use any custom micro SIM.



Chronic Dev Team's Greenpois0n released candidate 5 jailbreaks for iPhone, iPod touch and iPad. One of the team members Joshua Hill aka p0sixninja, stated in a Twitter update that the exploit used so far for device jailbreak has been patched in the iOS 4.3 beta builds. So, all those who care about jailbreaking their iPad, iPhone and iPod touch might be asked to stay away from iOS 4.3 update when it arrives.

New Greenpois0n tool for Mac OS X enables untethered jailbreak which means you won t have to jailbreak your device every time you want to restart it or it runs out of battery. Just plug your device to Mac, perform a clean iOS 4.2.1 restore and then jailbreak it using Greenpois0n tool. After the device restarts, tap on the Loader app and let it do the needful. Just in case you can't get Cydia package manager working, you can use redsn0w 0.9.7 to install it by unchecking rest of the options.

At this moment, greenpois0n.com is undergoing some trouble because when I tried to download the jailbreak tool, it gave me a very small archive with nothing inside it. So wait till it is fixed and then try downloading the tool. Many stated that the jailbreak doesn't work for them. Once again, I'll point out that you'll have to perform a clean iOS 4.2.1 firmware restore on your device before executing the jailbreak.

T-Mobile Galaxy Tab drops price down to $250



Could this be a pre-Honeycomb inventory dump? Perhaps, considering T-Mobile has slashed the Samsung Galaxy Tab price down to $250 which is at its cheapest to date. T-Mobile is offering the tablet device directly, but at that price point, it will be accompanied by a 2-year agreement, which makes you locked into it while you miss the range of Gingerbread tablets which are set to light up the world this summer. Of course, you might want to pick up the Tab on the cheap (at the moment anyways) as Samsung has reported that the return rate is clearly not as high as originally reported, so that ought to give you some added peace of mind. Some others might prefer to wait and pick up the iPad 2 when it arrives sometime this spring, assuming all speculations are right on the money.

Friday, February 4, 2011

Microsoft to patch 22 bugs, 3 zero-days next week

Computerworld - Microsoft today said it will issue 12 security updates next week to patch 22 vulnerabilities in Internet Explorer (IE), Windows, its Internet server and Visio, the company's data diagramming tool.

The company also announced it will provide patches next Tuesday for three bugs it has already acknowledged, including one that has been exploited by criminals for several weeks.

"The big news is that there are three zero-days that are being patched," said Andrew Storms, director of security operations at nCircle Security, talking about the trio of confirmed flaws.

Of the three unpatched-but-admitted vulnerabilities, one is in IE, a second is in Windows' rendering of thumbnail images and the third is in IIS (Internet Information Server), Microsoft's popular Web server software.

Microsoft acknowledged the IE bug on Dec. 22, several weeks after French security firm Vupen issued a bare-bones advisory that said all versions of IE, including 2009's IE8, were vulnerable. Shortly after that, Microsoft warned users that attackers were exploiting the bug.

The Windows flaw is in the graphics engine's rendering of thumbnail images inside folders. The bug was disclosed in mid-December 2010 at a South Korean security conference, and Microsoft published an advisory Jan. 4. At the time, the company said it would not release an emergency, or "out-of-band" patch for the problem.

Also in early January, Microsoft took the unusual step of listing the known bugs that it had yet to patch, detailing five unfixed flaws. Next week's updates will address three of those five.

"They're patching the red, orange and yellow," said Storms, referring to the color codes assigned by Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC).

"That's good news, great news," Storms continued.

Some vulnerabilities Microsoft has conceded will not be patched next week, however, including a flaw in the MHTML (MIME HTML) protocol handler that the company confirmed only last Friday. Security experts last week were unanimous in betting that the MHTML vulnerability would not be fixed with this month's round of updates

Of the dozen updates expected next week, three will be labeled "critical," Microsoft's highest threat ranking, while the remaining nine will be marked "important." Microsoft typically assigns a critical rating to vulnerabilities that can be exploited with little or no action on the part of a user.

This year's February patch batch is slightly smaller than 2010's, when Microsoft shipped 13 security updates that quashed 25 bugs

The majority of the updates -- 10 of the 12 -- affect Windows, with one of those addressing the IIS 7.0 and IIS 7.5 denial-of-service vulnerability in Windows 7 and Windows Server 2008 R2. The other two will fix one or more flaws in IE and Visio.

Storms said that it's a "safe bet" to assume the Visio update will tackle a file format bug.

It was tough to glean any clues about what specific components Microsoft will patch next week from the advance notification's limited information, added Storms. "With 12 bulletins, it's pretty difficult to guess at what the others will include," he said.

"It's going to be a big day for everybody," Storms said. "It'll be interesting at the end of the day what applications are involved."

Even so, he speculated that one of the updates -- marked today only as "Bulletin 4" -- may address a kernel bug in Windows Vista and Windows 7, as well as Windows Server 2008 and 2008 R2. According to Microsoft, Bulletin 4 will not affect the older Windows XP and Windows Server 2003, the reason Storms pegged the kernel, which Microsoft revamped in Vista and later editions, as a potential suspect.

Last month, Microsoft patched a bug in Vista only that was attributed to the operating system's Backup Manager. That update was the seventh Microsoft has released to repair "DLL load hijacking" or "binary planting" vulnerabilities that researchers disclosed last August.

Microsoft will release the 12 updates at approximately 1 p.m. ET on Feb. 8.

Facebook Malware Preys on User Fears of Losing Site Access

Three new scams play on a variation of users losing Facebook access, whether it’s because Mark Zuckerberg is shutting down the site or because the account has been suspended, said security researchers.


Security researchers have identified several new malware strains claiming to take away users’ access to Facebook over the past few days.

Users receive messages, either via instant message, e-mail or on Facebook, claiming that their accounts will be shut down. However, the scams promise to restore access if the users follow instructions, the researchers said.

"Once again cyber-criminals are using social engineering to trick victims and infect them with malware," said Luis Corrons, technical director of PandaLabs.

PandaLabs reported on Feb. 1 a worm that hijacks Facebook accounts and prevents users from logging in unless they subscribe to a paid service. The Lolbot.Q worm is distributed across instant messaging applications such as AOL Instant Messenger, MSN and Yahoo Messenger, according to Panda Security.

When a user clicks on the malicious link in the message, the site downloads a worm, designed to hijack Facebook accounts, to the computer, the researchers said. Once downloaded, users are blocked from logging in because their accounts are “suspended” and they need to complete a questionnaire before the accounts can be “reactivated,” the company said. In addition to reactivating the account, users are promised various prizes such as free laptops and iPads for answering the questions.

After several questions, users are directed to a different campaign that requires them to subscribe with their cell phone numbers. Once subscribed, the users are charged a fee of $11.60 per week on their cell phone and get a new password that reinstates access to their account, PandaLabs said.

There have also been a number of scams recently purporting that Facebook CEO Mark Zuckerberg has decided to shut down the social-networking site unless users take action.

A new one made the rounds on Feb. 1, according to Graham Cluley, a senior technology consultant at Sophos. Users saw Wall posts encouraging them to click on a link to “verify” their accounts to remain active, he said.

Clicking on the link took users to a normal Facebook application permissions dialog, but once installed, the rogue application would repost the message to the user’s Wall in order to spread the link virally, Cluley wrote. Along with an “account-verification process” screen, users are asked to fill out surveys that may spawn even more Wall spam, he said.

Another scam spams users with e-mail messages from “FaceBook Service” claiming their Facebook accounts had been hijacked to send spam, according to PandaLabs. Claiming their login credentials had been changed “for safety,” users are encouraged to open the attachment to get the new password, the security researchers warned. While PandaLabs researchers said the attachment was a .EXE file masquerading as a fake Word document, Sophos senior technology consultant Graham Cluley reported a variation that came with a .ZIP file, instead.

Regardless of the file name, once opened, it downloads other pieces of malware, which opens all available ports on the computer and connects to the multiple mail service to spam more users, the researchers said. PandaLabs named the Trojan Asprox.N while Sophos detected it as Agent-QAY.

Despite the awkward language used in the e-mail, the scam can succeed because there are “many Facebook addicts” who would “panic” and “rashly click on the attachment without thinking,” Cluley said.

Kenneth Cole Feels Wrath of the Web After Egypt Twitter Gaffe

Kenneth Cole Embroiled in Web Smackdown After Egypt Twitter GaffeFashion designer Kenneth Cole learned the hard way about the power of social media Wednesday when an insensitive tweet linking the uprising in Egypt to the launch of his spring collection resulted in some serious Internet backlash.

Earlier this morning, the company's official Twitter feed put out the following tweet: "Millions are in uproar in #Cairo. Rumor is they heard our new spring collection is now available online."

Cole later tweeted that he did not intend "to make light of serious situation. We understand the sensitivity of this historic moment." The offending tweet has since been removed, and Cole issued a lengthier apology on his Facebook page.

"I apologize to everyone who was offended by my insensitive tweet about the situation in Egypt," he wrote. "I've dedicated my life to raising awareness about serious social issues, and in hindsight my attempt at humor regarding a nation liberating themselves against oppression was poorly timed and absolutely inappropriate."

The Internet, however, is not ready to let this die. A fake @KennethColePR Twitter feed has popped up with tweets that similarly link disasters or political situations to fashion, much like the @BPGlobalPR feed that made fun of BP's disastrous handling of the Gulf oil spill. Sample: "Of course there are no gays in Iran, they're all shopping at my new outlet in Dubai. Holla!" and "Searching for you missing daughter in Aruba? At least, you don't need to be a van der SLEUTH to find our resort wear!"

Other tweeters are adding their own contributions with the #KennethColeTweets hashtag ("Chase down Anderson Cooper in style with our new lightweight canvas loafers!"), and "Kenneth Cole" is currently trending in most of the major U.S. cities. Someecards has also rounded up the top 10 best and most horribly offensive Cole-related tweets.

Egypt, of course, is in the midst of a political uprising that resulted in the government cutting off access to the Internet for several days. According to the latest reports, eight people have died and nearly 900 people have been injured since the protests began.

Scrabble-Like iOS App Crosses Platforms to AndroidScrabble-Like iOS App Crosses Platforms to Android





Before Angry Birds mania swept mobile device users everywhere, the masses were interested in words.

The Scrabble-like Words With Friends app, that is. An upcoming new platform release for the game may prove that while pigs may be dying in droves, words are still alive and well.

Previously exclusive to iOS mobile devices, the Scrabble-like Words is coming to the Android OS as soon as next week, says social game developer company Zynga. Playing the game on an Android device will be pretty much the same as if you played it on your iPhone, the company says.

Now, people will also be able to play in the same game across both platforms. That means no more Droid lovers feeling left out while their iOS-using pals are geeking out on triple-word scores.

Words With Friends on the iPhone/iPad platform has proven its immense popularity in the past. The app boasts 2.5 million daily active users, with over 10 million downloads since its creation. Currently supported by ads, the app is free for download from Apple’s app store. A paid version with no ads displayed will be coming soon to the Android Market and Apple app store.

But releasing the app on Android is not as simple as slapping a bunch of iOS code onto your Android phone.

“We wrote Words from the ground up with Android in mind,” Zynga Senior Engineer Jason Tomlinson told Wired.com in an interview. “For instance, because there’s so many different resolutions across Android devices, screen size compatibility is a serious issue.”

Leading a small team of three or four engineers, Thompson and his crew worked since October writing code in Java, the primary programming language for the Android OS. Knowing software update fragmentation across devices has been a serious issue for Android users, Tomlinson’s team made the Words app compatible with hardware running the most up to date 2.3 version (Gingerbread) all the way back to 1.6 (Donut). It will also run on Google’s yet to be released version 3.0 (Honeycomb), the version of Android optimized for tablets.

Some transitions to the Android OS environment were easier than others. “The art ports over mostly seamlessly,” Words co-founder Paul Bettner told Wired.com. “Same with the sounds we use. And the same set of servers on the back end are supporting both iOS and Android users,” Bettner said.

But when Bettner founded Newtoy Inc., the developer studio that created Words, in 2008, the whole studio was focused on iOS coding, and has continued to be until last year.

“When a relatively new platform like Android comes along,” Bettner said, “it’s difficult to find coders in the beginning. Even the most experienced Android developers in the world would have only a few months of experience doing it. Once Google’s OS started growing in popularity, the requests for an Android version of the app came flooding in. That’s when we started looking for help.”

Help came in the form of Tomlinson, who has worked with Google on Android since the open-source code’s inception. Tomlinson worked with the existing engineers to help acclimate them to coding in Java rather than the Apple-preferred language, Objective-C.

“Whichever platform an engineer begins programming for, there’s always going to be a few hurdles jumping from one to another,” Tomlinson told Wired.com. “Generally, however, the learning curve for switching from Objective-C to Java is much simpler, as Java is easier to pick up.”

With the success of the iOS version of the game in mind, Zynga is preparing its servers for “the most optimistic projections” of new user adoption rates, says Bettner.

If the game takes off for the Android OS, it’s probably not a stretch to expect other big cross-platform releases in 2011.