Wednesday, August 13, 2008

Microsoft Virtualization Launch Planned for Fall 2008

Microsoft today announced a launch event for its virtualization products, scheduled for Sept. 8, 2008 in Bellevue, Wash. More information and a sign up link can be found here.

The Bellevue-based event will draw Microsoft execs to speak, with a keynote address by Bob Muglia, senior vice president of Microsoft's server and tools business, and Kevin Turner, Microsoft's CEO.

Microsoft has a complete line of virtualization products, in various stages of release, so there's some speculation about what Microsoft may announce at the September event. Microsoft has already released to manufacturing (RTM) its Hyper-V virtualization solution, which is part of Windows Server 2008.


The company's System Center Virtual Machine Manager 2008 solution was released as a public beta in April, with expectations for an RTM release in the second half of 2008. Given that schedule, it seems likely that Microsoft will announce the RTM status of Virtual Machine Manager 2008 at this event. The Virtual Machine Manager 2008 is designed to help IT administrators manage Windows Server 2008, Microsoft Virtual Server and systems using VMware's virtualization solution.

Another piece of the puzzle is Microsoft's Kidaro acquisition, which provided Microsoft with technology for desktop virtualization. Microsoft announced the acquisition of Kidaro in March with the idea that it will be part of the Microsoft Desktop Optimization Pack for Software Assurance customers. Kidaro's technology promises to let IT professionals create software images for desktop PCs that also allow individual users to run their own software concurrently, without conflicts.

Microsoft has said that it will ship Kidaro's technology under the "Microsoft Enterprise Desktop Virtualization" (MED-V) name. At its virtualization product launch event, Microsoft has a session called "Client-Hosted Virtualization With MED-V," which presumably will discuss the integration of Kidaro's technology.

The company also plans to talk about its "Microsoft Application Virtualization" solution, formerly known as SoftGrid, at the event. This software, which, among other things, allows applications to bypass conflicts caused by using shared resources, is currently available as version 4.5 in beta release.

Microsoft plans to make its Microsoft Application Virtualization product generally available in the third quarter of 2008 as part of the "Microsoft Desktop Optimization Pack and Microsoft Application Virtualization CAL for Terminal Services," according to the company's SoftGrid Web site. With that timeline, the general availability of this product might also be announced at this launch event.

Veteran Microsoft watcher Mary-Jo Foley speculated in her All About Microsoftblog that Microsoft might talk about application virtualization via streaming methods of delivery. The idea is that Microsoft could make a license change that could enable Microsoft apps to compete against hosted applications provided by Google.

In addition to this Bellevue event, Microsoft is planning to announce additional U.S. launch event sites to talk about its virtualization products, according to Microsoft's GetVirtualNow Web site.


Installing And Using OpenVZ On CentOS 5.2
Citrix To Enhance Virtualization Interop
Installing And Using OpenVZ On Fedora 9

Microsoft's August Patch Brings 11 Security Fixes

Microsoft's August patch, slated to be the largest patch rollout since 12 bulletins hit users in February of 2007, came up one short of that record with today's release. But Tuesday's release -- covering six critical issues and five important ones -- will still have IT Pros pretty active.

The August release might have equaled the record, except for a "quality issue" on a critical Windows Media Player patch, which got pulled.

"This is actually really interesting this month. By my count we have 11 advisories covering 26 vulnerabilities," said Security Engineer Tyler Reguly of nCircle in San Francisco of the August patch slate. "There were originally supposed to be 12 advisories but it appears as though the Windows Media Player Update was pulled. Since this was originally marked critical, it's not good that it's pulled."


Security pros say that the bad thing about Microsoft announcing a patch and then pulling it is that it lets potential hackers know where to look and what to focus on.

"It's like a being given a treasure map that's half completed…there's still a lot of space to cover, but it's significantly smaller than if you had no insight at all, "Reguly added, pointing out that Microsoft appears to be playing catch up by issuing such a large patch slate. "Also, four of the 12 advisories had vulnerabilities that had already been publicly disclosed and one half of those publicly disclosed vulnerabilities are already being actively exploited."

The critical patches address a wide breadth of products and services, from Windows OS versions to applications such as Internet Explorer, Access, Excel and PowerPoint.

For the five important patches, four will affect Windows programs and one will plug vulnerabilities in Microsoft Office. Affected applications are Outlook Express, Windows Mail and Windows Messenger.

All of critical items in this month's patch have remote code execution (RCE) exploit considerations. All fixes but three are designed to stave off RCE bugs. The remaining three address what Redmond calls "information disclosure risk."

"Looks like summer vacation is over a little early for network security professionals. After a light July, the August patch Tuesday will be a very busy one," said Don Leatham, director of solutions and strategy for Scottsdale, Ariz.-based Lumension Security. "The critical updates will affect both desktops and servers, so IT departments will need to quickly and carefully assess which patches should receive priority."

Critical Items
Client-side vulnerabilities continue to be a priority for Microsoft's patch deployment, IT pros say. It's a means for attack that requires attention.

"The five critical patches need to get installed as soon as possible this month," said Jason Miller, security data team manager for St. Paul, Minn.-based Shavlik Technologies. "All of these patches can affect client by attack vectors that are used in day-to-day client-side computer use: visiting an evil Web site or by opening an evil document."

The first critical fix is said to resolve a privately disclosed vulnerability in the Microsoft Image Color Management System. This vulnerability can allow RCE exploits for users with administrative logon credentials. Microsoft's fix for the Image Color Management System affects users of Microsoft Windows 2000, Windows XP Service Packs 2 and 3, and all versions of Windows Server 2003.

Critical fix No. 2 is an across-the-board remedy for all versions of Internet Explorer sitting on every operating system from Microsoft 2000 to Windows XP, Vista and Windows Server 2003 and 2008. The vulnerability involves hackers embedding malicious code through a specially crafted Web page.

The third critical security update resolves a privately reported vulnerability in the ActiveX control for the Snapshot Viewer for Microsoft Access. An attacker could exploit the vulnerability by constructing a specially crafted Web page.

Critical patch four, Microsoft contends, resolves four privately reported vulnerabilities in Microsoft Office Excel that could allow an RCE attack if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. This patch is systemic and is a comprehensive patch for Excel on all Windows OS versions.

This security update resolves three privately reported vulnerabilities in PowerPoint and PowerPoint Viewer that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system.

The final critical patch addresses five privately reported vulnerabilities. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office.

Important Patches
The top important item will deal with a privately reported vulnerability in the way certain Windows Internet Protocol Security (IPsec) rules are applied to traffic flow. According to Redmond, the stated vulnerability could cause systems to inadvertently ignore IPsec policies and transmit network traffic in clear readable text, thus disclosing that info to hackers. This is an across-the-board Windows OS patch.

The next important issue remedies a couple of private reported holes in Microsoft Windows Event Systems that could allow remote code execution. Windows Event Systems is a planning application allowing users to map out different types and functions and real world events happening around them while collaborating with other services such as Windows Live Spaces and Windows Live Calendar. Through an RCE exploit, a user could literally and figuratively see what's happening on a system.

Outlook Express and Windows Mail are the targets of information disclosure vulnerabilities for the third important patch on the slate. Redmond said the vulnerability, which was privately reported for the e-mail and scheduling applications, could allow information disclosure if a user visits a specially crafted Web page using Internet Explorer.

The fourth important item is designed to plug a reported vulnerability in supported versions of the Windows Messenger application. A hacker with administrative privileges could carry out an information disclosure exploit through scripting an ActiveX control.

The fifth and final patch for this section is a Microsoft Word patch designed for XP SP3 and Microsoft Office 2003 SP2 and SP3 where RCE exploits are the issue. Hackers could enter the system when users open a maliciously crafted and coded Word file.

Of the 11 patches, six will require restarts.

Tuesday's heavy patch slate comes just two months before Microsoft is shoring up its efforts for greater transparency in the security hotfix space. Beginning with its October patch release rollout cycle, the software giant will provide an assessment of risk for the vulnerabilities outlined in each security bulletin. The aim is to help administrators prioritize patch installation.

Tricking users seemed to be the theme of this month's patch cycle.

"Continuing the ongoing trend, attackers are increasingly targeting common users and tricking them into accessing a malicious Web site or opening an unsolicited document," said Amol Sarwate, manager of vulnerabilities research lab at Qualys. "Today's bulletins mostly deal with user-driven applications, such Microsoft Office including Word, Excel, PowerPoint, Access and others such as Internet Explorer, Outlook Express and Windows Messenger. This is something people need to be aware of, and prioritize more sooner than later."

Since April, Microsoft has asked IT pros to consult a monthly knowledgebase article to find out about new nonsecurity content releases in Windows Update and Windows System Update Services. Junk mail filters, Windows Home Server Power Pack 1 and comprehensive updates for Windows Server 2008, Vista, XP and Windows Server 2003 are on tap this month.


GLSA 200805-19 ClamAV: Multiple vulnerabilities
Seven Critical Fixes Expected on Tuesday
July Patch Cycle Elicits Some ‘Critical’ Opinions

Green IT Goals, Actions Far Apart

It's hard to "go green" or pursue eco-friendly IT policies when you don't know how much energy you're consuming. Unfortunately for U.S. firms, that's precisely the shape they're in, according to a new survey from reseller giant CDW Corp.

When it comes to green IT, according to CDW, there's a credibility gap between what enterprises are saying about energy efficiency and what they're actually doing about it.

According to CDW's new Energy Efficient Information Technology (E2IT) Report, while an overwhelming majority (94 percent) of IT executives say they care about energy efficiency, many simply don't know how much energy they're using.


More to the point, the E2IT survey indicated, IT executives aren't exactly putting their money -- their budget dollars -- where their mouths are when it comes to green IT. When prioritizing purchasing decisions, CDW found, energy efficiency is frequently passed over in favor of other considerations -- only slightly more than one-third (34 percent) of IT chiefs actually make purchasing decisions on the basis of energy efficiency.

CDW points out that even when IT organizations do buy energy-efficient gear, many of them aren't wringing as much as they can from it -- ignoring, for example, embedded power management tools or other "green" amenities.

Take Energy Star 4.0 certification, for example. It describes a power-management feature set achieved by many desktop PCs. Even in cases where shops prioritize the purchase of Energy Star 4.0-compliant desktop systems, most (62 percent) aren't using the included power management tools.

The good news, CDW said, is that IT chiefs are aware of the problem. They're starting to push for more insight into their own energy consumption habits, along with more information from vendors (to make it easier to identify energy-efficient equipment options), and -- of course -- the development of industry standards to help codify the dos and don'ts of energy-efficient IT.

"While energy efficiency has become a 'motherhood' value in IT -- more than 90 percent of IT buyers say they care about it -- there is often much uncertainty about what to do, primarily because good information is severely lacking," said CDW Vice President Mark Gambill in a statement.

"The first step in reducing energy consumption is to know what you are spending, yet more than 40 percent of technology professionals say they don't see their organization's energy bill," he said.

Even in the absence of clear industry standards -- or straightforward information from vendors, for that matter -- some IT shops are cutting energy costs, CDW found. Almost two-fifths (39 percent) of shops with energy management initiatives were able to reduce their total IT energy costs, in some cases by up to as much as 40 percent, through

purchasing equipment with low-power or low-wattage CPUs, purchasing Energy Star 4.0-compliant devices, creating policies (and training employees) to power down equipment when it isn't in use, and consolidating servers and ratcheting up their use of virtualization to boost overall utilization rates.

Significantly, the shops that are saving money take advantage of the native power management tools or features that ship with everything from desktop computers to datacenter-class uninterruptible power supplies.

"Organizations that are successful at reducing IT energy costs dig deeper, attacking the problem more consistently across all facets of their IT systems than other organizations do," Gambill said. "More than 90 percent of them take ownership of their energy bill and advocate efficiency improvements throughout IT operations."


New Prefetching Scheme Saves Computing Time, Energy
System Center Update Promises Energy Savings
Power Supply OEM ManufacturerCWT Claims 90% PSU Efficiency Crown
PlayStation 3: same power usage as five refridgerators

Tuesday, August 12, 2008

Report Finds Dip in Microsoft's Browser Share

Microsoft lost browser market share over the last year, and the company's Windows Vista operating system has had "slow" market adoption among individuals and enterprises, according to a report issued by management consulting firm Janco Associates Inc.

While Microsoft Internet Explorer still leads the pack in terms of browser use, its market share dipped from 65 percent in August 2007 to 58 percent in August 2008 -- a seven percent loss, according to the report.

Janco's 58 percent market share for Internet Explorer is much lower than the share reported in Net Application's Market Share report, which indicated that IE had a 76 percent market share in August of 2008.


The next runner up in the browser wars, according to Janco's report, is the No. 2 Firefox browser. Its market share grew 2.6 percent year-over-year -- from 16 percent to 19 percent.

People continue to use the Netscape browser, which grew 1.6 percent year-over-year to hit an 11.6 percent market share. The report chided Time Warner for giving up on the browser.

"Time Warner's short-sighted decision to abandon Netscape shows technology decisions are long-term ones and companies that want to create value in that market need to look beyond quarter-to-quarter earnings," stated Janco's CEO, Victor Janulaitis.

He added that the bigger lesson of the report is the "continued erosion of Microsoft's market share," in which the company can't rely anymore on quickly moving users to new products.

The report put the market share for Vista at just under 15 percent in August 2008. In 2007, Vista had a near one percent market share. While the report characterizes that growth as slow, Microsoft execs have typically claimed that the Vista adoption rate has historically outpaced that of Windows XP.

An enterprise survey conducted by Forrester Research found Vista's adoption to be lower than Janco's figure. Forrester's survey found an 8.8 percent adoption of Vista by June 2008.

Janco's press release did not indicate the number of users sampled for the study. However, the company's Web site states that the data for the report are based on "international accesses for business to business Internet users" and about half of the responses came from the United States.

For more info, or to purchase Janco's report, "Browser and OS Market Share White Paper," go here.


Safari, Mac usage climbs online in May
Forrester: Vista rejected like ‘new Coke’ by enterprises
IE Is Least-Patched Browser, Report Says

Monday, August 11, 2008

Survey: IT Hiring and Pay Still Up, But Employers 'Cautious'

With the U.S. economy still circling  and unemployment on the rise, it's a good time to be in IT -- relatively speaking.

In a survey released last week, research firm Gartner found that 57.9 percent of U.S. IT organizations project an increase in staff for the coming fiscal year. However, that increase is down 8.4 percent from last year's survey. Moreover, organizations projecting a 10 percent or greater increase in headcount dropped by 3.6 percent.

Gartner had surveyed 285 IT firms about their future expectations, which was defined as the period starting in March 1, 2008 through February 28, 2009.   


Gartner Vice President Lily Mok said that  while hiring rates remained relatively consistent with last year, the survey shows employers are becoming more cautious when it comes to hiring.  

"This year's data show a slight decline in hiring projections across different industries," Mok commented  in an e-mail interview. "We believe companies are being conservative in their planning based on the current market conditions. Industries such as insurance, public and non-profit reported a lower than last year's headcount increase projection."

And while some IT organizations may not grow as fast in the months ahead, the good news, according to Mok, is that the IT industry is not seeing extreme measures, like hiring freezes, taking place -- at least not on a widespread basis.

Nationally, in a report released on Aug. 1, the U.S. Bureau of Labor Statistics pegged the unemployment rate at 5.7 percent, up a full point from the same period last year. But according to the survey, the current economic climate has yet to significantly affect overall IT pay rates.

Projected median pay bumps for most IT positions will be comparable with those in 2008, which was reported at about 3.6 percent. A conservative projection by Gartner for 2009 estimates a median increase of 3.5 percent  for the next year, with an emphasis on the retention of "high performers."

Difficult-to-hire positions, such as database administrator, network engineer, enterprise architect, Web application programmer and project manager, reported receiving above-average pay increases during the last year. And 81 percent of IT organizations said they had or would be implementing an incentive or bonus package for high-value staff, according to the survey. These trendy variable-pay programs are a key component in managing compensation strategy for IT retention, according to Mok.

"As IT becomes more business oriented and is run like a business, those individuals that have IT skills plus business knowledge and experience -- or degrees -- will likely have the fast track into roles which often have executive level exposure," Mok said. "After all, IT organizations are looking at not only technical skills but, more importantly, business skills."

While 2008 will certainly not qualify as a banner year for U.S. business expansion, it's good to know that IT is still a good place to be in the employment food chain.

Gartner describes the scope of its annual IT Market Compensation Study here.


Compliance, New Threats Drive Security Spending
Long-term care costs higher in Florida

Microsoft Rolls Out SP1 for .NET and VS 2008

Microsoft provided some enhancements for developers by releasing two important service packs at the SP1 stage to manufacturers today.

One service pack is for Microsoft's .NET Framework 3.5, adding some improvements that will help users deploy Windows applications faster. The other improves on some of the development tools in Visual Studio 2008.

The release of these service packs also marks a high point for Microsoft by enabling the integration of the framework and development environment with Microsoft SQL Server 2008. Microsoft released that new relational database management system to manufacturers just last Wednesday.


SQL Server 2008 was the third element of Microsoft's product blitz, which also included Windows Server 2008 and Visual Studio 2008, injecting new competition in the enterprise space.

The SP1 improvements in Visual Studio 2008 are mostly performance related. Microsoft added improved tools for working with AJAX applications and provided a better JavaScript environment in Visual Studio 2008. Microsoft also enhanced the designers in Visual Studio 2008 that work with Windows Presentation Foundation and the ADO.NET Entity Framework.

A new .NET Framework enhancement in the service pack is called the ".NET Framework Client Profile." With this improvement, Microsoft claims that it has reduced the .NET Framework's size by "86.5 percent," which allows users to download and install Windows apps faster.

Microsoft also says the .NET Framework SP1 speeds up start times for managed code and lets developers use a security feature in Windows Vista called "Address Space Layout Randomization."

Web application development gets a boost from the SP1's support for "ASP.NET Dynamic Data." This feature helps create rich Internet applications "without writing code," according to an announcement issued by the company.

There is also a boost for integrating data and Web services. The .NET Framework SP1 enhanced the ADO.NET Data Services and ADO.NET Entity Framework components, helping to speed the rollout of services by providing a modeling environment for developers.

The new SP1 for Visual Studio 2008 can be accessed here.

Those wanting SP1 for the .NET Framework 3.5 can access it here.


At last — native apps for Motorola Linux phones
Microsoft Says SQL Server 2008 To Ship This Quarter
Nvidia Does Accelerated Programming

Networking Job Sector Is Booming, IDC Says

If The Graduate's Mr. McGuire were to give Ben Braddock one word of career advice today, it might very well be "networking" and not plastics.

According to a recent study from market watcher IDC, there's currently a 60,000-person shortfall of networking talent, with demand expected to outpace supply through 2011. Right now, IDC said, about 14 percent of the North American IT workforce works on IP networks; over the next four years, however, that tally is expected to more than double to 30 percent, or 780,000 workers.

IDC cited shortages in a handful of skill areas, including network security, wireless and voice. In fact, more than one-third of respondents identified a pressing need for networking pros with voice specialties, while almost 20 percent cited wireless needs.


In addition, IDC expects that 11 percent of security positions will remain in 2011 -- again, because of an absence of networking talent.

"This...confirms what many managers in the workforce are already keenly aware of: There is an acute and growing need for more IT professionals," said IDC analyst Cushing Anderson in a statement. "With more and more businesses moving critical operational functions over to the network, the IT department is assuming a much more strategic role in the organization and needs its infrastructure to be designed, implemented and maintained by highly skilled, highly trained individuals."

It's shaping up to be an increasingly networked future. According to the IDC survey, employers in all industries and market segments hope to hire more skilled networking personnel over the next few years. But they'll have trouble doing so, IDC projected, resulting in about 60,000 fewer full-time skilled workers than there are positions each year over the next three years.

This will occasion huge disruptions, first in terms of how enterprises hire, and second, in how they scale or deploy networking pros or networking services, with organizations placing a premium on certification (in lieu of outright experience) and service providers offering more and more managed networking services.

"[T]here is a 'skill gap.' The difference between the supply of skilled workers and the demand for those skills represents a challenge for networking vendors and their clients and an opportunity for IT professionals," wrote Anderson, Marianne Kolding and Susan Lee in IDC's report. "The overall gap between supply and demand for networking professionals is about 8 percent of the total demand. The good news is that the overall gap isn't getting any bigger. The bad news is that in some specialties, such as wireless networking, the gap is large, and in other segments, such as network security, the gap is growing very fast."


Security Certification Rules Could Shake Up IT Management
Documentary on Wireless Philadelphia Released
Tap-In Launches In Atlanta - Area Program Looks To Recruit Retired Medical Professionals, Respond To Uninsured
Windows DNS Patch Strands ZoneAlarm Users