29 Years of the Digest ... founded August 21, 1981

Add this Digest to your personal   or  

The Telecom Digest for August 06, 2011
Volume 30 : Issue 196 : "text" Format
Messages in this Issue:
Re: Security Holes Found in Siemens Control Systems(Thad Floryan)
APPLE-SA-2011-07-25-2 iOS 4.2.10 Software Update for iPhone(Monty Solomon)
APPLE-SA-2011-07-25-1 iOS 4.3.5 Software Update(Monty Solomon)
Re: OT: Has anyone heard from Pat? How is he doing?(Telecom Digest Moderator)
Re: Text error sends Scottish exam results a day early(David Clayton)

====== 29 years of TELECOM Digest -- Founded August 21, 1981 ======

Telecom and VOIP (Voice over Internet Protocol) Digest for the Internet. All contents here are copyrighted by Bill Horne and the individual writers/correspondents. Articles may be used in other journals or newsgroups, provided the writer's name and the Digest are included in the fair use quote. By using -any name or email address- included herein for -any- reason other than responding to an article herein, you agree to pay a hundred dollars to the recipients of the email.
Addresses herein are not to be added to any mailing list, nor to be sold or given away without explicit written consent. Chain letters, viruses, porn, spam, and miscellaneous junk are definitely unwelcome.

We must fight spam for the same reason we fight crime: not because we are naive enough to believe that we will ever stamp it out, but because we do not want the kind of world that results when no one stands against crime.  - Geoffrey Welsh


See the bottom of this issue for subscription and archive details and the name of our lawyer, and other stuff of interest.


Date: Thu, 04 Aug 2011 08:09:58 -0700 From: Thad Floryan <thad@thadlabs.com> To: telecomdigestmoderator.remove-this@and-this-too.telecom-digest.org. Subject: Re: Security Holes Found in Siemens Control Systems Message-ID: <4E3AB646.3000700@thadlabs.com> On 8/3/2011 9:12 PM, Monty Solomon wrote: > Hard-Coded Password and Other Security Holes Found in Siemens Control Systems > [...] > http://www.wired.com/threatlevel/2011/08/siemens-hardcoded-password/ Much more interesting is this very long article with pictures and code samples which I don't recall seeing mentioned here before: http://www.wired.com/threatlevel/2011/07/how-digital-detectives-deciphered-stuxnet/ The above article is dated July 11, 2011.
Date: Thu, 4 Aug 2011 17:36:27 -0400 From: Monty Solomon <monty@roscom.com> To: telecomdigestmoderator.remove-this@and-this-too.telecom-digest.org. Subject: APPLE-SA-2011-07-25-2 iOS 4.2.10 Software Update for iPhone Message-ID: <p0624083eca60c118d6f6@[10.0.1.4]> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2011-07-25-2 iOS 4.2.10 Software Update for iPhone iOS 4.2.10 Software Update for iPhone is now available and addresses the following: Data Security Available for: iOS 4.2.5 through 4.2.9 for iPhone 4 (CDMA) Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS Description: A certificate chain validation issue existed in the handling of X.509 certificates. An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS. Other attacks involving X.509 certificate validation may also be possible. This issue is addressed through improved validation of X.509 certificate chains. CVE-ID CVE-2011-0228 : Gregor Kopf of Recurity Labs on behalf of BSI, and Paul Kehrer of Trustwave's SpiderLabs Installation note: This update is only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone is docked to your computer. To check that the iPhone has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.2.10 (8E600)". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (Darwin) iQEcBAEBAgAGBQJOKaO4AAoJEGnF2JsdZQeeZJAH/AgzQw32cHPdHMZMufmeTx7C q0I1yzI+uF8HDERM8VfDg98rjVFbhcKKyeA1FNe1lGz79sIpo6Px4QubCRKyt2RW FbLYNGlWNreNodBr8FhAQcVqYbHLogD1O/Y+MVeU9i4pVfO6gXFfaMHWZkaZDlZd m9DLyPxAJ9uRtb9AYz3YL7Dp52YoW5yApSnpqV2dm5LE9L7ysvZ6inDOme0figAH v8+MDE18x1Caw3n0f2cWd6Sz9jqjvIodgp8iYWMEYnsRUZtFlFyxbSQSJFeFq1Ul y8N12gycPaWCJsqQyfFEruTcqHnV9kBVZV9TACT6UdtRkULXtsFEsqi6+8PI2mo= =yzpz -----END PGP SIGNATURE-----
Date: Thu, 4 Aug 2011 17:36:27 -0400 From: Monty Solomon <monty@roscom.com> To: telecomdigestmoderator.remove-this@and-this-too.telecom-digest.org. Subject: APPLE-SA-2011-07-25-1 iOS 4.3.5 Software Update Message-ID: <p0624083dca60c118d6ee@[10.0.1.4]> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2011-07-25-1 iOS 4.3.5 Software Update iOS 4.3.5 Software Update is now available and addresses the following: Data Security Available for: iOS 3.0 through 4.3.4 for iPhone 3GS and iPhone 4 (GSM), iOS 3.1 through 4.3.4 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.4 for iPad Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS Description: A certificate chain validation issue existed in the handling of X.509 certificates. An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS. Other attacks involving X.509 certificate validation may also be possible. This issue is addressed through improved validation of X.509 certificate chains. CVE-ID CVE-2011-0228 : Gregor Kopf of Recurity Labs on behalf of BSI, and Paul Kehrer of Trustwave's SpiderLabs Installation note: This update is only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone, iPod touch or iPad is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone, iPod touch, or iPad. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone, iPod touch, or iPad is docked to your computer. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.3.5 (8L1)". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (Darwin) iQEcBAEBAgAGBQJOKaOnAAoJEGnF2JsdZQeeQQMIALAq3PesmBcGIB6z7OYonloO Fp68K1GNYjYbNUOxgfDuBRrLwNSMDYfRSKDNvHW+rbbHEss7WIQzXQc7s3QEhZ6y BYfZ8WyJTa3Pb3JRmoFSMjbZ35wFLs5vKnnOjurihaqewL6tLZr6j2PilBYZCsh2 DDMyIFus1VyXjpWoUmmt5Xt51xhDX8MnMXOrjJowBT+HLtGCzbYL6SIZbPbvU0LW +50De5Ml6kag/CvI29MV1axBEPdcyNm+6YCQiRxLNnVP587aUeEUavNPy8sOBj3F sAJFgsKdDNxxOrK31q4NZ9Nqks/v/St1thHLkj2wmLdiccfwv3SaQm+4npgShzc= =xc9n -----END PGP SIGNATURE-----
Date: Thu, 4 Aug 2011 10:50:55 -0400 From: Telecom Digest Moderator <redacted@invalid.telecom.csail.mit.edu> To: telecomdigestmoderator.remove-this@and-this-too.telecom-digest.org. Subject: Re: OT: Has anyone heard from Pat? How is he doing? Message-ID: <20110804145055.GB10560@telecom.csail.mit.edu> On Wed, Aug 03, 2011 at 04:24:33PM -0500, John Mayson wrote: > The subject says it all. I don't remember reading anything about him recently. You can reach Pat at: Regal Estate Nursing Home P.O. Box 627 Independence, KS 67301 U.S. Mail is best, frankly, because Pat is having great difficulting speaking. AFAICT, he is being well cared for, but he has suffered multiple strokes and there have been several hospital stays, and he is considered a "Total care" resident, in need of continuous monitoring. Pat gave permission to his caregivers to communicate with me, and I will pass along important news. I've been assured that Pat doesn't need any money and has all that he wants for the moment. Pat Townson is, sad to say, now approaching the sunset of his life. Bill P.S. I just found out that Pat's mother was gathered up last month, and I'll pass along any condolences sent via email so the staff can read them to him. Please mark any condolence emails with "[Pat]" instead of the usual glyphs: they will NOT be published unless the sender specifically requests it. Snail mail works too, of course. -- Bill Horne Moderator
Date: Fri, 05 Aug 2011 08:52:59 +1000 From: David Clayton <dcstarbox-usenet@yahoo.com.au> To: telecomdigestmoderator.remove-this@and-this-too.telecom-digest.org. Subject: Re: Text error sends Scottish exam results a day early Message-ID: <pan.2011.08.04.22.52.58.472893@yahoo.com.au> On Wed, 03 Aug 2011 22:33:44 -0400, Monty Solomon wrote: > Text error sends Scottish exam results a day early > > Exam officials launch investigation after 30,000 students in Scotland who > opted to get grades by text were sent them early > > Severin Carrell and Jessica Shepherd > The Guardian, Thursday 4 August 2011 > > Exam officials have launched an investigation after up to 30,000 students > in Scotland who opted to get their grades by text message were sent them > on Wednesday, a day early by mistake. > > Opposition leaders in the Scottish parliament said the blunder had given > these students a clear advantage in finding places at university because > the list of late courses available went live on the internet at a minute > past midnight on Thursday morning, nine hours before the results were > officially due to arrive. > > ... Perhaps a life lesson for those who don't embrace the new technology? -- Regards, David. David Clayton Melbourne, Victoria, Australia. Knowledge is a measure of how many answers you have, intelligence is a measure of how many questions you have.
TELECOM Digest is an electronic journal devoted mostly to telecom- munications topics. It is circulated anywhere there is email, in addition to Usenet, where it appears as the moderated newsgroup 'comp.dcom.telecom'. TELECOM Digest is a not-for-profit, mostly non-commercial educational service offered to the Internet by Bill Horne. All the contents of the Digest are compilation-copyrighted. You may reprint articles in some other media on an occasional basis, but please attribute my work and that of the original author. The Telecom Digest is moderated by Bill Horne.
Contact information:Bill Horne
Telecom Digest
43 Deerfield Road
Sharon MA 02067-2301
781-784-7287
bill at horne dot net
Subscribe:telecom-request@telecom-digest.org?body=subscribe telecom
Unsubscribe:telecom-request@telecom-digest.org?body=unsubscribe telecom
This Digest is the oldest continuing e-journal about telecomm-
unications on the Internet, having been founded in August, 1981 and
published continuously since then.  Our archives are available for
your review/research. We believe we are the oldest e-zine/mailing list
on the internet in any category!

URL information: http://telecom-digest.org


Copyright (C) 2009 TELECOM Digest. All rights reserved.
Our attorney is Bill Levant, of Blue Bell, PA.

 ---------------------------------------------------------------

Finally, the Digest is funded by gifts from generous readers such as
yourself who provide funding in amounts deemed appropriate. Your help
is important and appreciated. A suggested donation of fifty dollars
per year per reader is considered appropriate. See our address above.
Please make at least a single donation to cover the cost of processing
your name to the mailing list. 

All opinions expressed herein are deemed to be those of the
author. Any organizations listed are for identification purposes only
and messages should not be considered any official expression by the
organization.

End of The Telecom Digest (5 messages)

Return to Archives ** Older Issues