{"id":3172,"date":"2001-09-04T15:01:07","date_gmt":"2001-09-04T20:01:07","guid":{"rendered":"http:\/\/smperformance.wordpress.com\/2013\/08\/03\/stratvantage-consulting-llc-mikes-take-on-the-news-090401\/"},"modified":"2001-09-04T15:01:07","modified_gmt":"2001-09-04T20:01:07","slug":"stratvantage-consulting-llc-mikes-take-on-the-news-090401","status":"publish","type":"post","link":"https:\/\/stratvantage.com\/index.php\/2001\/09\/04\/stratvantage-consulting-llc-mikes-take-on-the-news-090401\/","title":{"rendered":"StratVantage Consulting, LLC &#8212; Mike&#8217;s Take on the News 09\/04\/01"},"content":{"rendered":"<table width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td>\n<h3><a href=\"http:\/\/evernote.com\/\">From Evernote:<\/a><\/h3>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<h1>StratVantage Consulting, LLC &#8212; Mike&#8217;s Take on the News 09\/04\/01<\/h1>\n<p>Clipped from: <a href=\"http:\/\/www.stratvantage.com\/news\/090401.htm\">http:\/\/www.stratvantage.com\/news\/090401.htm<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h1><strong>T<\/strong>he News \u2013 09\/04\/01<\/h1>\n<p><strong><em>In this Issue:<\/em><\/strong><\/p>\n<p><strong><em><a>Cybersquatting Is Legal \u2013 For Some <\/a><\/em><\/strong><\/p>\n<p><a>There\u2019s nothing like a monopoly<strong>.<\/strong> You get to make your own rules and wield power however you want<strong>.<\/strong> So I guess it\u2019s not surprising that, when <\/a><a href=\"http:\/\/www.icann.org\/tlds\/\">ICANN <\/a> gave monopolies to the registrars for the seven new top level domains (.biz, .name, .pro, .museum, .info, .aero, and .coop), there\u2019d be opportunities for abuse<strong>.<\/strong> Turns out abuse is practically mandated in the new domain operators&#8217; contracts, which entitles them to register up to 10,000 domains for themselves before allowing anyone else access<strong>.<\/strong> This means that 10,000 of the most valuable, juiciest domain names are likely to not be available to all comers<strong>.<\/strong> Names like business.biz, museum.museum and the like could be controlled by the domain registrar, who could auction them to the highest bidders<strong>.<\/strong> Afilias, a consortium of 18 companies and domain registrar for the .info domain, has registered search.info, for example<strong>.<\/strong> ICANN argues that a registry operator will need a wide range of addresses on that registry in order to work effectively<strong>.<\/strong> <a href=\"http:\/\/www.stratvantage.com\/news\/bizdomains.htm\">Here\u2019s <\/a> a list of names reserved by NeuLevel, the administrator of the .biz gTLD (generic Top Level Domain)<strong>.<\/strong><\/p>\n<p>As if that\u2019s not bad enough, other registrants have taken many desirable domain names in the early registration period, which is supposed to be available only to trademark owners<strong>.<\/strong> So if you had your heart set on getting sports.info, computer.info, bank.info, or finance.info, you can forget it<strong>.<\/strong> All have been <a href=\"http:\/\/www.zdnet.com\/zdnn\/stories\/news\/0,4586,2804606,00.html\">snapped up <\/a> by registrants who did not hold legitimate trademarks<strong>.<\/strong> Afilias says they\u2019ll take action in December, after their review of the early registration period ends<strong>.<\/strong> One <a href=\"http:\/\/www.domebase.com\/study.htm\">study <\/a> found that of 11,000 .info registrations, between 15 and 25 percent were bogus<strong>.<\/strong> My personal favorite bogus registration was for bible.info, which claimed its trademark number was \u201c1\u201d<strong>.<\/strong> Not according to the USPTO, it\u2019s not<strong>.<\/strong> With all this potential cybersquatting, Afilias has its work cut out for it if it hopes to clear it all up by yearend<strong>.<\/strong><\/p>\n<p>Domain registrar NeuLevel, which was awarded the .biz monopoly, has been <a href=\"http:\/\/www.zdnet.com\/zdnn\/stories\/news\/0,4586,2804302,00.html\">accused <\/a> by Amazon of running an illegal lottery, and has filed suit to defend itself<strong>.<\/strong> At issue is the pre-registration period NeuLevel established in which applicants pay a small fee to reserve the rights to a name<strong>.<\/strong> On September 17, the company will randomly award contested names<strong>.<\/strong> I don\u2019t know about you, but that sounds an awful lot like a lottery to me<strong>.<\/strong> However, I don\u2019t really know how else a registrar can resolve multiple claims for a single name, unless there\u2019s trademark or other intellectual property rights at stake (like in cocacola.biz)<strong>.<\/strong> Amazon supposedly has said in a letter to the company, \u201cNeuLevel is deriving enhanced revenues by selling chances to register or to challenge registration of domain names that incorporate famous trademarks such as AMAZON.COM<strong>.<\/strong>\u201d NeuLevel counters with a reasonable-sounding point: other firms, such as Amazon Imaging Inc<strong>.<\/strong>, might reasonably stake a claim to the address www.amazon.biz<strong>.<\/strong> \u201cBecause amazon.com and amazon.biz exist in different top-level domains, they resolve to different and unique Internet addresses and thus can function and coexist without collision,\u201d the suit says<strong>.<\/strong> Where\u2019s Solomon when we need him?<\/p>\n<p>The bottom line on all of this is, as I\u2019ve said <a href=\"http:\/\/www.stratvantage.com\/news\/081501.htm\">before <\/a>, the new domain names will not provide any relief to the overcrowding of the .com top level domain<strong>.<\/strong> In a random check of .info registrations, the usual suspects held the domains coke.info, pepsi.info, nike.info, and nbc.info<strong>.<\/strong> How exactly is this better? If Amazon is insisting on getting Amazon.biz, even though they are by far not the only Amazon in the world, what can we expect of names like \u201cExcel,\u201d which are applied to various businesses in various industries<strong>.<\/strong> Trademark law allows this because a trademark only applies to a class of trade<strong>.<\/strong> The new gTLDs are not industry-specific, and so chaos will again reign, and the big companies will scoop up all the good names<strong>.<\/strong><\/p>\n<p>That being said, businesses need to evaluate the need for representation in the new gTLDs<strong>.<\/strong> Do you want your competition to register your name<strong>?<\/strong> Most businesses have no choice other than registering in all the gTLDs possible<strong>.<\/strong> It\u2019s a shame ICANN has not come up with a better solution<strong>.<\/strong> Heck, at this point, we may not ever see a better solution<strong>.<\/strong><\/p>\n<p><a href=\"http:\/\/www.it-analysis.com\/article.php?id=1569\">IT Analysis <\/a><\/p>\n<p><strong><em>Briefly Noted<\/em><\/strong><\/p>\n<ul>\n<li><strong>Shameless Self-Promotion Dept<strong>.<\/strong>:<\/strong> StratVantage\u2019s <a href=\"http:\/\/www.stratvantage.com\/directories\/p2pcos.htm\">P2P4B2B <\/a> \u2013 Peer to Peer for Business Directory was featured in the July 16th issue of Network World File Sharing newsletter, along with some nice mentions of white papers I\u2019ve done<strong>.<\/strong> Even more impressive is the fact that a search for \u201cStratVantage\u201d on Google now gets you two pages of hits<strong>!<\/strong> Hoohoo!<br \/>\n<a href=\"http:\/\/www.nwfusion.com\/newsletters\/fileshare\/2001\/00911439.html\">NWFusion <\/a><\/li>\n<\/ul>\n<ul>\n<li><strong><a>New Wireless SIG: <\/a><\/strong><a>Geneer has created the Midwest Wireless Application Developers Special Interest Group (SIG) a non-commercial group designed to promote discussion of wireless developer tips and tools<strong>.<\/strong> The first meeting is Tuesday, Sept. 18, 2001, and features Guest Presenter Rod Massie of Motient Corp<strong>.<\/strong>, provider of eLinkSM and BlackBerry\u2122 by Motient wireless email services<strong>.<\/strong> Rod\u2019s topic is Developers&#8217; Tips &amp; Secrets for Motient&#8217;s Terrestrial Network and Motorola&#8217;s DataTAC Technology<strong>.<\/strong> The free meeting runs from 6:00 PM to 8:30 PM at the Marriott Suites, 8535 W. Higgins Road, Chicago, Illinois<strong>.<\/strong><br \/>\n<\/a><a href=\"http:\/\/www.geneer.com\/mwadsig\/signup.asp\">SIG Signup <\/a><\/li>\n<li><strong><a>I Want This Gadget<\/a><\/strong><a>: In the Cool Tools Department this issue is the Clever Cam 360, a digital camera, Webcam and camcorder combination that is the size of a pen<strong>.<\/strong> The device captures 45 seconds of streaming video and can store up to 360 digital stills<strong>.<\/strong> Plus, with its USB interface, you can attach it to your laptop and send the family a live video stream from your lonely hotel room<strong>.<\/strong> Plus, kids, it\u2019s under $90!<br \/>\n<\/a><a href=\"http:\/\/www.comtrad.com\/cfusion\/template\/makepage.cfm?prod_name=Clever_Cam_360&amp;site=80290&amp;branch=unshocked&amp;category=0&amp;product_base_id=905\">TechnoScout <\/a><\/li>\n<\/ul>\n<ul>\n<li><strong><a>Fighting Back Against Code Red: <\/a><\/strong><a>Alert SNS Reader Andrew points out that there are more benign ways to fight back against the Code Red worm<strong>.<\/strong> Some server administrators use a script that \u201csimply exploits the ability to run an executable to fire up the NT command &#8216;net send&#8217; to send a pop-up message box on every machine in that domain with the text \u2018Your Webserver is infected with the Code Red Virus<strong>!<\/strong> Please remove it from the Internet and apply the Microsoft Hot Fixes to correct this<strong>!<\/strong>\u2019 This is not nearly as bad as rebooting some other person\u2019s server randomly<strong>.<\/strong> Rebooting a CodeRed II infected server does no good as the worm installs a backdoor allowing a cracker to come in at any time<strong>.<\/strong>\u201d This is indeed a more benign solution, but it still involves running a program on a server without authorization<strong>.<\/strong> However, it could be argued that this solution is no more invasive than sending an email<strong>.<\/strong> Your opinion?<br \/>\nThe URL listed below this item takes you to a page of possible FightBack responses that also includes the log of attacks on just one Web server<strong>.<\/strong> Two things are notable about this log. First, it represents more than 7,000 attacks since July 19th from more than 2,500 hosts<strong>.<\/strong> That\u2019s amazing. Second, many, if not most, of these attacks are coming from people with cable modems. In fact, Cox Cable, Las Vegas, represented more than 4,000 of the attacks compared with roughly 700 for Excite@Home and 500 for RoadRunner<strong>.<\/strong> What makes this interesting is the fact that most cable modem and DSL companies forbid their users from running any kind of server<strong>.<\/strong> <\/a><\/li>\n<\/ul>\n<p><a>One very confusing aspect about all the Code Red coverage involves whether or not Microsoft\u2019s Personal Web Server is vulnerable<strong>.<\/strong> Microsoft requires you to install PWS when you install FrontPage, their Web authoring tool<strong>.<\/strong> Many FrontPage users probably did the install back when they were still learning about the Web and have forgotten that they are running a Web server on their computers<strong>.<\/strong> However, neither Microsoft nor <\/a><a href=\"http:\/\/www.cert.org\/advisories\/CA-2001-23.html\">CERT <\/a> nor <a href=\"http:\/\/www.iwar.org.uk\/cip\/resources\/news\/assessment-01-018.htm\">Information Warfare <\/a> thinks PWS is vulnerable<strong>.<\/strong> Some <a href=\"http:\/\/searchwindowsmanageability.techtarget.com\/originalContent\/0,289142,sid33_gci762549,00.html\">reports <\/a> claim PWS is vulnerable to Code Red when run on Windows NT or 2000, but Information Warfare says it doesn\u2019t even run on 2000, and indeed I couldn\u2019t install it on my Windows 2000 machine<strong>.<\/strong> PWS does run on Windows NT Workstation, according to the site<strong>.<\/strong> Whatever the real deal is, it just may be possible that some of these attacks are coming from people who do not know they are running PWS or Internet Information Server (IIS)<strong>.<\/strong> However, your machine is not vulnerable unless you are running Windows NT or 2000<strong>.<\/strong><\/p>\n<p>Regardless of the possible Code Red vulnerability, you should probably not be unintentionally running a Web server, as they can expose you to threats without your knowledge<strong>.<\/strong> You can check to see if PWS or IIS is running on your machine<strong>.<\/strong> One easy way is to see if you have either of the following directories: C:\/Webshare\/Wwwroot or C:\/InetPub\/Wwwroot<strong>.<\/strong> These are the default root directories of various versions of PWS and IIS<strong>.<\/strong> Another way is to go to Control Panel and see if you have a Personal Web Server icon<strong>.<\/strong> If you are running PWS, I recommend uninstalling it just to be safe<strong>.<\/strong> If you are running IIS, a patch is available on Microsoft\u2019s Code Red <a href=\"http:\/\/www.microsoft.com\/technet\/treeview\/default.asp?url=\/technet\/itsolutions\/security\/topics\/codealrt.asp\">page <\/a><strong>.<\/strong> By the way, it is important to note that the Microsoft patch that fixes the vulnerability only prevents future infections<strong>.<\/strong> If you are infected, you need to remove the file \/inetpub\/scripts\/root.exe in order to disable the backdoor installed by Code Red<strong>.<\/strong><\/p>\n<p>Finally, system administrators can get a scanning tool to identify vulnerable computers from <a href=\"http:\/\/www.eeye.com\/html\/Research\/Tools\/codered.html\">eEye <\/a><strong>.<\/strong> And Microsoft has released <a href=\"http:\/\/www.microsoft.com\/technet\/mpsa\/start.asp\">Personal Security Advisor <\/a>, which takes a look at your NT or 2000 system and finds common misconfiguration problems.<br \/>\n<a href=\"http:\/\/salfter.dyndns.org\/codered.shtml\">FightBack Script <\/a><\/p>\n<ul>\n<li><strong><a>Insurer Charges Premium for Using Microsoft: <\/a><\/strong><a>Insurance broker J.S. Wurzler Underwriting Managers has started charging up to 15 percent more in hacker insurance premiums to clients that use Microsoft&#8217;s Internet Information Server software<strong>.<\/strong> Oddly, they made this decision before Code Red caused an estimated $2 billion in damage<strong>.<\/strong> They based their action on Wurzler their finding that system administrators working on open source systems tend to be better trained and stay with their employers longer than those at firms using Windows software<strong>.<\/strong> Thus bug patches are more likely to be applied<strong>.<\/strong><br \/>\n<\/a><a href=\"http:\/\/www.zdnet.com\/intweek\/stories\/news\/0,4164,2805929,00.html\">ZDNet <\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/www.stratvantage.com\/news\/mikestake.htm\">Return <\/a> to Mike\u2019s Take<\/p>\n","protected":false},"excerpt":{"rendered":"<p>From Evernote: StratVantage Consulting, LLC &#8212; Mike&#8217;s Take on the News 09\/04\/01 Clipped from: http:\/\/www.stratvantage.com\/news\/090401.htm The News \u2013 09\/04\/01 In this Issue: Cybersquatting Is Legal \u2013 For Some There\u2019s nothing like a monopoly. You get to make your own rules and wield power however you want. So I guess it\u2019s not surprising that, when ICANN &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/stratvantage.com\/index.php\/2001\/09\/04\/stratvantage-consulting-llc-mikes-take-on-the-news-090401\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;StratVantage Consulting, LLC &#8212; Mike&#8217;s Take on the News 09\/04\/01&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-3172","post","type-post","status-publish","format-standard","hentry","category-sns","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/posts\/3172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/comments?post=3172"}],"version-history":[{"count":0,"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/posts\/3172\/revisions"}],"wp:attachment":[{"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/media?parent=3172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/categories?post=3172"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stratvantage.com\/index.php\/wp-json\/wp\/v2\/tags?post=3172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}