Monday, August 4, 2008

Security Woes Up, as PHP and OSS Make the List

Software vulnerabilities are up this year, especially Web browser-based ones, according to a new report from IBM Internet Security Systems. The X-Force 2008 Mid-Year Trend Statistics Report, released in late July, defined the problem broadly. A vulnerability is anything that results "in a weakening or breakdown of the confidentiality, integrity, or accessibility of the computing system."

Topping the list of companies reporting the most vulnerabilities were such tech mainstays as IBM, Microsoft, Apple and Cisco Systems. Microsoft had the third most reported vulnerabilities. However, an interesting dimension to this year's report is that open source software (OSS) or free software groups, such as Mozilla's Firefox, WordPress and Joomla, also made the list of programs with security holes in them.

Larger entities such as Microsoft or IBM make the list because of the volume of software they produce, explained Tom Cross, an X-Force researcher at IBM Internet Security Systems.


"Companies that make a lot of software are subject to more disclosures," Cross added. "But we're seeing for the first time that community-developed open source such as the Drupal and Joomla content management software packages for the Web also showed up on the list."

Drupal and Joomla are both OSS packages that have both been vulnerable to recent SQL injection attacks.

Overall, the study tracked more than 3,534 disclosed vulnerabilities in software for the first half of the year, finding a five percent increase compared with the first half of 2007. Leading the list of vulnerabilities were malicious spam, phishing and different strains of malware. The nearly 80-page report found that so-called "high risk" vulnerabilities were on the rise.

A big concern of the report was the use of the PHP scripting language, which was associated with many vendor-identified vulnerabilities.

PHP is mainly used by Web developers to help create dynamic Web pages. According to the PHP Group, a research organization, PHP was installed on more than 20 million Web sites and one million Web servers as of April 2007. It is doubtless double that amount now.

The Web is emerging as the most common vector hackers are using these days for entry into networks, as well as to deliver malicious software. The report's findings confirm other research saying that attacks against trusted Web sites are up.

Moreover, hackers seem to be keeping up with security bulletins. The report concludes that 94 percent of public exploits affecting Web browser bugs were released on the same day as the public security notice.


Open Source Needs Better Security Focus, Study Says
Apple finally patches dangerous DNS flaw
Apple ships massive Mac OS X 10.4 security upgrade

Saturday, August 2, 2008

Virtualization Showdown at Black Hat

Next week at the Black Hat conference in Las Vegas, security researcher Joanna Rutkowska promises to demonstrate how a malicious attacker, working remotely, could take control of the open-source Xen virtualization software.

If successful, Rutkowska and her team will be the first researchers to demonstrate how to compromise a Xen hypervisor, that crucial layer of virtualization software underneath all the virtualized environments running on a machine, one that provides direct connections to the processor, memory and hardware devices.

"Many people [have] argued that having a legitimate hypervisor installed prevents installation of virtualization-based malware. We will show that this is not the case," she said in an e-mail interview.


For the conference, Rutkowska will oversee three presentations, which will be given by herself, Rafal Wojtczuk and Alex Tereshkin. In addition to showing how to install the rootkit, they also plan to show how someone could bypass the security monitoring mechanisms that would normally detect such an attack. Finally, and perhaps most importantly, they will show how users could prevent such attacks.

Citrix system chief security strategist Kurt Roemer expects Rutkowska's disclosure will generate more publicity than prove to be a serious threat to operating instances of the software. He likens it to "sensationalist attacks," that frequently are weighed against virtualization software. Citrix offers a commercially-supported version of Xen.

Roemer has not seen Rutkowska's presentation, but he does point out that the attack will probably rely upon the attacker having root access to the server running Xen. "That's not a normal model," he noted.

Rutkowska confirmed that root access is needed. Much like root access is needed to install a root kit on a server, so too will administrative access be needed to breech Xen. Rutkowska argued, however, that her work is still important.

"Years ago other vendors tried to downplay the importance of ... [Microsoft] Windows kernel rootkits, saying that one needed to already be an administrator in order to install one. As we know, over the last couple of years, kernel rootkits became a very serious security problem," she commented.

The attack requires taking control of the Xen master domain, called Domain 0.

Within Xen, each virtualized environment is given its own space in memory, called a domain. In addition to these user domains (called Dom-U's), there is also a domain, called Domain 0, which is a privileged domain used for controlling the whole Xen system. "It is automatically created when the system boots, and does a lot of the management of the system. It builds all of the other user domains, and manages all of their virtual devices," Roemer said.

"The subverting techniques we will be presenting at Black Hat indeed assume that the attacker first obtained access to Domain 0," Rutkowska said. She brushed off that this would be a serious challenge though. "Domain 0, being an administrative domain, requires certain services to be run inside it. One such service is an [Secure Shell] daemon. This makes the attack surface on Domain 0 quite large."

Increasingly over the past few years, security researchers and malicious have sought ways for users to break into the Domain 0 from a virtualized environment.

In December McAfee researcher found (PDF here) that a file system utility, called e2fsprogs, that could allow a guest user to in such a way that a malicious command could be passed from the guest machine to the host machine.

"Over the last year it has been shown that Domain 0 is far from being bulletproof. With our presentations we take the game to the new level by studying how to compromise the hypervisor and what we can do to prevent it," she said.The researchers promise to show how a user can bootstrap up from Domain 0 into the hypervisor itself.

Roemer downplayed the impact of Xen’s security vulnerabilities, noting that those found so far have been only in versions of the software under development. They were found, and fixed, in the developmental open-source versions of the software, Roemer said. "Published Xen is configured in a secure way," he said.

Moreover, recent versions of Xen have guards in place to protect the hypervisor even from actions within Domain 0, involving the use of input/output memory management unit (IOMMU) found on newer peripheral devices such as network cards.

These initiatives do not seem to intimidate the researchers though.

"We will show how to bypass those protections and subvert Xen hypervisor memory," Rutkowska promised.

This is not Rutkowska's first brush with controversy within the emerging practice of virtualization security. At the 2006 Black Hat conference, she introduced what she called a virtualization rootkit, one dubbed Blue Pill. According to Rutkowska, Blue Pill could encapsulate an entire operating environment within a virtualized container, while offering the user no clue that the environment is actually under control by another party.

"We're going to see how it is presented. She's done some really cool stuff in the past, but in this case I don't see this applying to all of Xen," Roemer said.


Diablo 3 confirmed
Tougher Security Planned for Internet Explorer 8

Apple Reacts to Spoof Threats, Issues DNS Hotfix

Apple Inc. took action on Friday to address the infamous Domain Name System (DNS) problem. And none too soon.

This week saw a DNS server exploit divert AT&T Internet service users in Austin, Texas. The DNS trouble, which caused users to be sent to a bogus Web page, occurred more than a week after Microsoft issued its own warning about the dangers of a weak DNS framework.

In response to the threat, Apple released Security Update 2008-005, saying that its latest hotfix protects open scripting architecture libraries from certain vulnerabilities. If left unfixed, a hacker or internal enterprise user might leverage the exploit to "execute commands with elevated privileges."


On the whole, the patch addresses the DNS issue by implementing what the company calls "source port randomization to improve resilience against [DNS] cache poisoning attacks."

The patch is for Mac OS X Server 10.4 and 10.5, as well as for Mac OS X 10.4.11 and 10.5.4 operating systems.

For Mac OS X v10.4.11 systems, the Berkeley Internet Name Domain (BIND) is updated to version 9.3.5-P1. For Mac OS X v10.5.4 systems, BIND is updated to version 9.4.2-P1. The hotfix also closes the script-based local privilege escalation vulnerabilities in the MAC for Windows programs.

Apple responded to one of this year's most controversial security issues in issuing the hotfix, but there is already some push back. Security researcher Swa Frantzen, who works at the SANS Internet Storm Center, asserted that the hotfix is incomplete. Apple's fix hasn't quite done the trick.

"Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the [Internet] Protocol weakness," Frantzen wrote in a blog post on Friday.

The issue appears to be that, despite Apple's patch, BIND under OS X is incrementing the ports it uses to communicate DNS information in a predictable instead of random pattern.

Andrew Storms of San Francisco-based IT consultancy nCircle, says that Apple, like Microsoft, may have rushed the patch and let the buzz around the vulnerability dictate its actions instead of vice versa.

"We know with Microsoft that there were a few problems even installing their DNS patch," he said. "Now, with Apple, we're seeing that the current countermeasure to this DNS cache poisoning vulnerability is to introduce increased entropy by forcing randomization of the query ID and the source port."

Storms said it's evident that many are spooked by an increasing pervasive vulnerability that few people know much about as of yet.

"The issue is that [DNS spoofing] is a silent killer," he said. "You usually won't know until it's over and it's more complex because it involves coding behind the spoofing and once you're redirected to what looks like a legit site, most of the hacker's work is done already."


RHSA-2008:0533-01 Important: bind security update
Microsoft Warns of ActiveX Exploit in Access
DNS Problem Is ‘Important’ To Patch, Microsoft Says
Apple fixes Safari ‘carpet bomb’ bug

Friday, August 1, 2008

First Instance of New DNS Exploit Reported

Reports are coming in that an AT&T Domain Name System (DNS) server may have been compromised with malicious code that exploits a vulnerability reported earlier this month. This apparently is the first instance of the exploit in the wild.

"The attackers had replaced the cache entry for www.google.com with a Web page that loaded advertisements hidden inside an iframe," wrote H.D. Moore, director of security research at BreakingPoint Systems Inc. in his Metasploit blog. "This attack affected anyone in the Austin, Texas, region using that AT&T Internet Services (previously SBC) DNS server."

The attack reportedly began Tuesday and was noticed by BreakingPoint workers, some of whose Internet traffic was being redirected.


"The attack itself was not malicious, did not load malware and, from an operational standpoint, had zero impact," Moore wrote in his blog.

But it did serve to underscore the importance of installing patches for this vulnerability, which were released July 8. "The lesson: Even if your own DNS servers are patched, make sure none of those systems use an upstream DNS that has not," Moore wrote. "Since we contacted the ISP [Internet service provider], this particular DNS server was taken offline."

DNS is a hierarchical system that translates written names, such as those in URLs and e-mail addresses, into IP addresses. Dan Kaminsky, director of penetration testing for IOActive Inc., discovered the bug about six months ago and helped to coordinate an industry response that resulted in the multi-vendor patch release. Kaminsky has not released details of the vulnerability, but some specifics have leaked out in the last three weeks and some proof-of-concept exploits have appeared.

Web poisoning exploits are already known to exist but because the new vulnerability is in the basic design of the protocol itself, it is potentially more dangerous because almost all DNS servers are vulnerable until patched. Redirected Web site requests could make it difficult, if not impossible, to trust Web-based data and transactions.

Although details of the vulnerability have not been released, Kaminsky said it involves a weakness in the transaction ID used in DNS queries. Currently, replies to a DNS query have to contain the proper transaction ID, which is chosen randomly from 65,000 values.

"For undisclosed reasons, 65,000 is just not enough," Kaminsky said. "We need more randomization."

That is being obtained from a source port ID, another random identifier in the packet. After patching, replies to DNS queries will require not only the proper transaction ID but also the proper source port ID. "We are making a system that was somewhat random more random," Kaminsky said.

"The use of randomized source ports can be used to gain approximately 16 additional bits of randomness in the data that an attacker must guess," US-CERT said in its bulletin.

The first exploit was not as bad as it could have been, according to Moore. "I want to be clear that, while this type of attack can be serious, in this case it was a five-minute annoyance that was designed as a [click-through advertisement] revenue generator for the folks who launched it," he wrote.

In describing the attack, Moore wrote that the affected system "accepted recursive requests from anywhere (not just subscribers) and is the default DNS server for anyone who purchased SBC Internet Services (in our case, a T1 line that was our primary until our fiber was run). Internally, we use two DNS servers, one going out the fiber, the other going out the T1 as backup."

According to Moore, when employees began noting problems on Tuesday, "We discovered that one of our internal DNS servers was still using SBC/AT&T as an upstream forwarder and that this server was returning the wrong results for www.google.com. Requesting the main Web page from the 'poison' www.google.com server returned a very different response from the real Google server. This server was returning four iframes, one of which showed a fake version of the Google Web site, the other three loaded automated ad-clickers from three other compromised servers."


Massive Patch Coming for DNS Vulnerability
Call of Duty 4 Patch v1.6 Released

Taking Stock: Microsoft's Virtual Power Play

Now that Microsoft Corp.'s Hyper-V technology is available (and a standalone Hyper-V Server is said to be imminent), it might be a good time to take stock of Redmond's virtualization portfolio.

Just how favorably does Hyper-V compare to established products from VMware Inc., Virtual Iron Inc. and Citrix Systems Inc., to name a few? How serious is Microsoft about competing in the virtual space?

Both are complicated questions. When it comes to virtualization, Microsoft isn't exactly viewed as a thought leader. There's an inescapable sense, after all, in which virtualization -- because it abstracts both operating system and application assets -- actually displaces the OS. Given Redmond's OS-centric business model, a disruption of this kind seems like a clear conflict.


That might account for Microsoft's protracted hedging of its bets with respect to virtualization: It was against it, in other words, before it was for it; it accommodated it, but it also wanted to pigeonhole it -- as anterior to the OS itself. By making several virtualization-specific acquisitions, Microsoft spent a sizeable amount of money precisely to pigeonhole it.

Late last year, Redmond bit the proverbial bullet, announcing an upcoming hypervisor offering (the eventual Hyper-V) that -- to a surprising degree -- looked a lot like everyone else's.

Virtual Disruption
Redmond had plenty to be afraid of. Virtualization technologies are disruptive because they're more fundamental than the OS. In the virtual space, the OS -- the former bedrock of one's application assets -- becomes just another asset or resource.

Microsoft, not surprisingly, initially viewed this as a threat to the dominance of its Windows brand. For the better part of 48 months, it struggled to embrace -- and co-opt -- virtualization on its own, Windows-friendly terms. Even though competitors VMware, Virtual Iron and Citrix were selling hypervisors that functioned independently of any specific operating environment, Microsoft seemed determined to push an operating system (i.e., Windows Server 2008) that is the hypervisor.

That didn't work out so well, so Redmond adjusted course last November, and announced a standalone hypervisor -- its Hyper-V Server (derived from Hyper-V, the official brand for the former Viridian technology) -- that would allow customers to virtualize heterogeneous workloads onto a single server.

In this regard, experts said, Hyper-V isn't all that different from VMware's ESX Server or any of a dozen other prominent hypervisors.

"Microsoft's decision to offer a hypervisor that's not part of the operating system [is] striking, given that they have been the most vocal proponents of the 'virtualization-as-a-feature-of-the-OS' point of view," said industry veteran Gordon Haff, a senior IT advisor with consultancy Illuminata, at the time.

Since then, Haff has had a lot of time to think about Microsoft's virtualization strategy. An idea can do a lot of gestating in nine months, and Haff -- who was initially high on Redmond's Hyper-V about-face -- sounds even more optimistic (and more pragmatic, too) these days.

That's in spite of the fact, Haff insisted, that Microsoft can't really compete with the big players, at least when it comes to features, performance and technology. Redmond's edge, he stressed, is the ubiquity of its Windows brand.

"If it were some arbitrary company, Microsoft's virtualization product portfolio wouldn't be mature and broad enough to deserve discussion in the same vein as Citrix and VMware," Haff said. "Microsoft has clearly been playing catch-up, especially in the hot area of server virtualization."

For a long time, according to Haff, Microsoft was content to trade blows with VMware, mainly to check that company's success and to blunt the potentially disruptive impact of virtualization itself. This meant accommodating virtualization on Microsoft's own terms, or -- in a now-familiar feat of triangulation -- "embracing and extending" that technology.

Redmond's acquisition of the former Connectix (with its still-gestating Virtual Server product) was an exercise in kind, according to Haff.

"[Virtual Server] gave Microsoft customers a server virtualization option that didn't involve heading over to VMware and thereby kept them more fully in Microsoft's fold. If Virtual Server wasn't up to the full virtual infrastructure play that VMware was increasingly running, it was sufficient for the basic slicing/dicing or test/dev provisioning that still represented how a lot of folks were using virtualization in practice," Haff said.

Virtual Server was far from a wash-out, he maintained. "If it ended up being largely a bridge for Microsoft customers while they waited for Microsoft to add integrated, native virtualization -- well, bridges can be awfully useful," he said.

Virtual Innovation?
It isn't as if Microsoft is playing catch-up with VMware and other competitors in vain. Haff cited Redmond's bleeding-edge take on application virtualization, which (admittedly) plays to its client-side strengths.

Application Virtualization -- called App-V -- is the fruit of Microsoft's 2006 acquisition of Boston-based Softricity (developer of Softgrid), so it has demonstrable best-of-breed roots. It also does away with one of the most onerous (and increasingly bloated) requirements of the Windows desktop model: the need for locally installed application instances.

"Applications are packaged and stored on a server, then 'streamed' down to the client system when requested. The application executes on the client using local hardware resources in the usual manner, but without the need to actually install it. Application virtualization isn't unique to Microsoft, but Microsoft's technology here is quite sophisticated," Haff said.

App-V, as implemented by Microsoft, is a Big Idea, inasmuch as it brings improved manageability, reliability and (putatively, at least) scalability to Windows applications. "This type of application virtualization also introduces the idea of application containers. These bundle together an application's files, along with other components, such as shared libraries and custom configuration settings, which are needed to run the application properly," Haff said.

That's just the tip of the iceberg, of course. "In addition to providing a management structure to keep all the necessary parts together, application containers also deal with some of the conflicts that can keep two applications -- or two versions of the same application -- from co-existing on a single system," he said. "A common problem is that applications require different versions of the same library [e.g., a Windows DLL file]. Containers encapsulate and isolate those libraries and applications in a way that lets them co-exist on a single system."

Softricity wasn't Microsoft's only App-V-related acquisition. As Haff noted, Redmond is still incorporating technology from related acquisitions, such as the former Kidaro and Calista.

Far From Virtual Authenticity
In light of its about-face with Hyper-V and its arguable innovation with App-V, Haff thinks Microsoft is dead-serious about virtualization. What's striking, he argues, is that Redmond now conceives of virtualization as a technology that can help it sell more Windows licenses, not fewer.

"Microsoft has largely gotten past these concerns or, at any rate, decided that they're manageable in a world that's heading pell-mell toward virtualization with or without it," he said. "Part of this was getting license plans in place that include the licensing of Windows guests as part of premium versions of Windows Server. In other words, Microsoft has discovered that virtualization makes a nice carrot to upsell Windows licenses."

Haff added, "As for virtual appliances, they're still used mostly for demo software; Microsoft is pushing application virtualization as an alternative to simplify software installation without forcing 'one size fits many' choices as the appliance model tends to."

So what kind of force will Microsoft amount to in an already teeming virtual space? A potent -- if not quite dominant -- one, according to Haff.

"If a company is largely a Windows shop today, and isn't looking to implement a particularly complicated virtualized infrastructure, Microsoft's products are probably the most natural, lowest-cost, best-integrated, easiest to acquire and install path to server virtualization," Haff said.

On the downside, Microsoft's VM management tooling won't ship until later this year, and other VM management scenarios such as "live migration" (i.e., the shifting of a running VM from one system to another) aren't yet as straightforward in Hyper-V as they are in VMware or Xen.

"Microsoft has said that adding such 'live migration' is a development priority," Haff said. "Also on deck are performance enhancements -- such as taking further advantage of on-chip virtualization accelerators -- and making VM memory use more dynamic."

Does this mean that Hyper-V is a laggard -- at least, compared to its established competitors? Not necessarily, Haff said: "It's not that Hyper-V is unusually incapable, but it's a first pass and its features, level of tuning, and consequent adoption rate will all reflect that."

What's most surprising, Haff said, is that virtualization -- far from harming Microsoft's bottom line -- seems to have boosted it. "For all the fuss that Microsoft has made about getting Hyper-V into play, this has never been as important as Microsoft thought it was. The reality is that Microsoft has sold lots of licenses -- operating system, application and middleware -- in and around VMware virtualization," he said.

"The bulk of VMware's business is in and around those same products. For all the animosity between the two companies, I see them as more complementary than competitive."


Hyper-V Made Available
Virtual Users And Domains With Postfix, Courier, MySQL And SquirrelMail (Ubuntu)
Installing And Using OpenVZ On Fedora 9

Does Microsoft Have an Open Source Heart?

Microsoft's open source outreach effort, which started just a few years ago, isn't dead on arrival, if you hear Sam Ramji, Microsoft's senior director of platform strategy, talk about it. Rather, it's coming alive.

For instance, Ramji told the largely software developer crowd at OSCON last week that Microsoft was joining the Apache Software Foundation, a nonprofit group that focuses on open source Web server projects.

Even before that event, which was held in Portland, Ore., Ramji expressed optimism for Microsoft's nascent open source initiatives.


"A beating heart is the core of what we are going to be doing in the next several years with open source and Linux," Ramji said in an interview with Barton George prior to the event. Ramji is part of the Microsoft Linux/Open Source Software Lab and works with a corporate strategy and execution team.

He added that Microsoft has increased the number of its employees working on open source projects worldwide, from 14 to 15 people about a year ago to 112 people today.

Even a number like 112 is still a tiny blip on the screen. As of May, Microsoft had a total of 89,809 worldwide employees, according to a Seattle Post-Intelligencerreport. So that means that just 0.124 percent of Microsoft's employees currently concentrate on open source.

Microsoft's engineers have submitted over 300 projects on Codeplex, Microsoft's open source developer portal, Ramji said. Another open source milestone for the company was Microsoft's acceptance of the Open Source Initiative's authority on licensing, he said.

Microsoft has two open source licenses that were vetted by that nonprofit body, which maintains an open source definition standard. Those licenses include the Microsoft Public License, a BSD-like license according to Ramji, and the Microsoft Reciprocal License, which is Microsoft's "copy-left" license.

The mistake that Microsoft has made with its products is to not be agnostic, according to Ramji. He added that Microsoft plans to focus more on interoperability, working with platforms such as Linux or Solaris.

Ramji clarified the open source comments by Steve Ballmer, Microsoft's CEO, spoken earlier this month. Ballmer denied that Microsoft's products would become open source at the company's Worldwide Partner Conference in Houston. Ramji explained that Ballmer was referring to Microsoft's core products, such Exchange, SQL Server and others.

Ballmer described it this way at the conference, per a Microsoft-issued transcript.

"Number one, are our products likely to be open sourced? No," Ballmer said. "We do provide our source code in special situations, but open source also implies free, free is inconsistent with paying for lunches at the partner conference. (Applause.) With that said, there are a number of different things. Will we interoperate with products that come from like Linux, from the open source world? Yes, we will."

Still, Ramji will have a tough time convincing some in the open source community. The Free Software Foundation, while not an advocate of open source software per se, does believe that software should be free to all.

Peter Brown, executive director of the Free Software Foundation, said of Ballmer's comments that Microsoft is trying to establish a better relationship with the open source software community to the detriment of GNU Linux.

"Microsoft wants people to build code to the Windows platform rather than GNU Linux, but the FSF's view is to build an ecosystem with free software," Brown explained.


Microsoft Joins Apache Software Foundation
Open source phone goes mass-market
EU, Microsoft Foes Wary of Microsoft’s Open Document Format Support

Thursday, July 31, 2008

Microsoft Launches Free Collaboration Tools for Researchers

This week, during a summit of researchers in Redmond, Microsoft announced a set of free software tools for helping researchers publish, preserve and share data.

The utilities include an authoring add-in for Word 2007 for capturing document metadata; a Creative Commons add-in for Office 2007; an e-journal service for self-publishing of online-only journals; a research output repository platform; and a collaborative workspace for researchers.

"Collecting and analyzing data, authoring, publishing, and preserving information are all essential components of the everyday work of researchers -- with collaboration and search and discovery at the heart of the entire process," said Tony Hey, corporate vice president of Microsoft's External Research Division. "We're supporting that scholarly communication lifecycle with free software tools to improve interoperability with existing tools used commonly by academics and scholars to better meet their research needs."


The Article Authoring Add-in for Word 2007 lets researchers capture metadata at the authoring stage to preserve document structure and semantic information throughout the publishing process. The Creative Commons Add-in for Office 2007 allows authors to embed Creative Commons licenses directly into an Office document (Word, Excel, or PowerPoint) by linking to the Creative Commons site via a Web service.

The Microsoft e-Journal Service provides a hosted platform for self-publishing of online-only journals to facilitate the availability of conference proceedings and small and medium-size journals.

The Research Output Repository Platform helps capture and leverage semantic relationships among academic objects -- such as papers, lectures, presentations and video -- to facilitate access to these items.

In partnership with the British Library, a workspace will be hosted on Microsoft Office SharePoint Server 2007, providing researchers a way to collaborate throughout a project's lifecycle, from seeking funding to searching and collecting information, as well as managing data, papers and other research objects throughout the research process.

Microsoft partnered with researchers on the development of the tools to meet academic community needs. The company's product groups also submitted feedback on how the Microsoft technologies could optimally address the entire research process.


AT&T Says Fie on Free Fi for iPhone (Again)
Microsoft Opens Up Office to New Document Formats
EU to probe Microsoft’s ODF move