Home » 2012 » July

Netflix Lawsuit E-mail

I have received a lot of e-mails regarding this e-mail people are confused as to if this is real or a spam scam.  I have verified that this is a real lawsuit again Netflix.  The lawsuit is regarding

Netflix unlawfully kept and disclosed information, including records on the movies and TV shows its customers viewed.”

This e-mail lets you decide if you would like to opt in or out of the lawsuit. This is for users who are and were subscribers.  It has not been said how much money each customer will be paid but from what I have read on

http://arstechnica.com/tech-policy/2012/07/class-action-lawsuit-settlement-forces-netflix-privacy-changes/

and from the e-mail itself

Netflix will pay out $9 million into a settlement fund. $2.25 million of that will go to attorneys’ fees, $30,000 to be split between the two named plaintiffs, and the rest going to charitable donations.

A copy of the e-mail is listed below for those who did not get one or want to verify you received the same e-mail and information.

If You Are a Current or Former Netflix Subscriber
A Class Action Settlement Could Affect You

Para una notificación en Español, llamar 1-866-898-5088 o visitar www.VideoPrivacyClass.com

Our records show that you were a current or former Netflix subscriber as of July 5, 2012. We are emailing to tell you about a Settlement that may affect your legal rights. Please read this email carefully. Go to www.VideoPrivacyClass.com for more information.

A Settlement has been reached in a class action lawsuit that claims Netflix unlawfully kept and disclosed information, including records on the movies and TV shows its customers viewed. Netflix denies that it has done anything wrong.

What does the Settlement provide?

Netflix has agreed to change its data retention practices so that it separates (known as “decoupling”) Entertainment Content Viewing History (that is, movies and TV shows that someone watched) from identification information for those subscribers who have not been aNetflix subscriber for at least 365 days, with some exceptions.

In addition, Netflix will pay $9 million into a Settlement Fund to:
• Make donations to Court-approved not-for-profit organizations, institutions, or programs.
• Pay notice and settlement administration expenses.
• Pay attorneys’ fees of up to 25% or $2.25 million of the Settlement Fund, plus up to $25,000 in expenses.
• Pay a total incentive award of $30,000 to the Named Plaintiffs.

Proposals from potential donation recipients will be sought, and, after consideration, recommendations will be made to the Court. A list of the proposed donation recipients will be posted on the website.

Your Options

If you do nothing, you will remain in the Settlement and your rights will be affected. If you do not want to be included, you must exclude yourself by November 14, 2012. If you exclude yourself you will keep your right to sue Netflix about the claims in this lawsuit. If you remain in the Settlement, you can object to it by November 14, 2012.

The Court will hold a hearing on December 5, 2012 to consider any objections, whether to approve the Settlement, award attorneys’ fees, and incentive award. You can appear at the hearing, but you don’t have to. You can hire your own attorney, at your own expense, to appear or speak for you at the hearing.

For more information: 1-866-898-5088    www.VideoPrivacyClass.com
PO Box 2750 Faribault, MN 55021-9750

This email and any attachments thereto may contain private, confidential, and privileged material for the sole use of the intended recipient. Any review, copying, or distribution of this email (or any attachments thereto) by others is strictly prohibited. If you are not the intended recipient, please contact the sender immediately and permanently delete the original and any copies of this email and any attachments thereto.

SCCM 2012 wsus sync fails unknown SQL error

After moving the System Center 2012 Configuration Manager (SCCM2012) SQL Site Database to another drive, creating a new Software Update package or a new application fail

Symptoms

After moving the System Center 2012 Configuration Manager SQL Site Database to another drive, creating a new Software Update group, Software Update package, or creating a new application fails and errors similar to the following are logged in the SMSProv.log file:

*** *** Unknown SQL Error! SMS Provider 14-03-2012 07:56:47 2016 (0x07E0)
*~*~*** Unknown SQL Error! ThreadID : 2016 , DbError: 50000 , Sev: 16~*~* SMS Provider 14-03-2012 07:56:47 2016 (0x07E0)
*** [24000][0][Microsoft][SQL Server Native Client 10.0]Invalid cursor state SMS Provider 14-03-2012 07:56:48 2016 (0x07E0)
*~*~[24000][0][Microsoft][SQL Server Native Client 10.0]Invalid cursor state *** Unknown SQL Error! ThreadID : 2016 , DbError: 0 , Sev: 0~*~* SMS Provider 14-03-2012 07:56:48 2016 (0x07E0)
 
SQL Profiler provides the following additional details:

An error occurred in the Microsoft .NET Framework while trying to load assembly id 65539. The server may be running out of resources, or the assembly may not be trusted with PERMISSION_SET = EXTERNAL_ACCESS or UNSAFE. Run the query again, or check documentation to see how to solve the assembly trust issues. For more information about this error:

System.IO.FileLoadException: Could not load file or assembly ‘cryptoutility, Version=5.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35′ or one of its dependencies. An error relating to security occurred. (Exception from HRESULT: 0x8013150A)

System.IO.FileLoadException:

   at System.Reflection.Assembly._nLoad(AssemblyName fileName, String codeBase, Evidence assemblySecurity, Assembly locationHint, StackCrawlMark& stackMark, Boolean throwOnFileNotFound, Boolean forIntrospection)

   at System.Reflection.Assembly.InternalLoad(AssemblyName assemblyRef, Evidence assemblySecurity, StackCrawlMark& stackMark, Boolean forIntrospection)

   at System.Reflection.Assembly.InternalLoad(String assemblyString, Evidence assemblySecurity, StackCrawlMark& stackMark, Boolean forIntrospection)

   at System.Reflection.Assembly.Load(String assemblyString)

Cause

This can occur if the SQL Site Database MDF and LDF files are moved to a different drive. For example, if originally the Configuration Manager Site Database was created on C:\Program files\MSSQL server\data but then later the MDF and LDF files were moved to different drive to save space (e.g. D:\CM2012DB), you may see the issue above.

Note that this is a supported SQL operation. For more information see the following:

How to move SQL Server databases to a new location by using Detach and Attach functions in SQL Server – http://support.microsoft.com/kb/224071

How to Move SQL Server Data File(s) (.mdf) and Log File(s) (.ldf) Files From One Location to Another – http://support.microsoft.com/kb/965095

This occurs with System Center 2012 Configuration Manager because by default, the SQL Site Database has the SQL TRUSTWORTHY property set to ON, however when you detach and reattach the database it gets set to OFF.  When the database is not configured with this setting ON, <ConfigMgr_Install>\bin\x64\CryptoUtility.dll fails to load into SQL and you get an ’invalid cursor state’ message.

Resolution

To resolve this issue complete the following steps:

1. Manually set the property back to ON by running the following command against your CM database:

ALTER DATABASE CM_SAG SET TRUSTWORTHY ON

2. Ensure that the database that was moved is owned by SA.

Mac Apps That Need Retina Support

I was listening to This Week In Tech – http://twit.tv/ and one of the issues they spoke about was the Mac Retina display and how people have issues with the display and app support.  So I decided to do some research.

Every one who purchased the Next Generation Mac Book Pro have had apps that don’t use Apple’s system fonts or haven’t had their graphical assets super-sized look terrible.  The Retina Pro’s issues are with up scaling graphics across a compact 15-inch display area that’s harboring well over five million pixels.

Words jumbled into Images

Still Frames on Websites from bad Slash Animations

Applications and Web Pages are fuzzy

The issue is Apple has a great product so far ahead of its time that there is no design support for it yet.  Applications are suffering from this as well just to name the few I found from my research

Microsoft Office 2011 (This is the product I have heard most of the complaints about)

Spotify

Winamp

Adobe Products

AutoCad Products

Skype

Dropbox

AntiVirus Programs

Mozilla Firefox

Google Chrome

Facebook Children Charity Scam

Cybercriminals have developed a custom piece of malware that injects itself into your Facebook session and prompts you to donate to a charity for sick children. The scammers’ goal is to make off with your personal data, especially your credit card number. 

Security researchers have discovered a new variant of the Citadel malware that injects itself into your Facebook webpages and demands that you make a donation to a fake charity for sick children. Please be warned: there are no children charities that will ask you for a donation via Facebook. There are, however, individuals very interested in stealing your credit card number and other personal information (note: this is not the first time Facebook users are specifically being targeted, and it certainly won’t be the last), ZDnet reported.

http://www.zdnet.com/facebook-virus-warning-massive-children-charity-scam-7000001509/

Once your computer is infected with the malware, it quickly adds itself into your Facebook session.  After you log into your Facebook account, the Citadel injection mechanism displays a pop up that encourages you to donate $1 to children who “desperately” need humanitarian aid. Next, it asks you for your name, credit card number, expiration date, CVV, and security password.

DO NOT BE FOOLED BY THIS SCAM!

Conficker Still Affected Millions Of Computers And Businesses

Microsoft released a forth quarter security report stating that the worm Conficker is still infecting 1.7 million computers and work stations.   This news comes more than three years after the worm was first detected.  The rate of infection has increased despite widespread availability of tools to fight it.

Conficker has many different versions which make it hard to fight on large scale networks.  Although Microsoft had patches out way before a lot of companies were not patched.  Conficker can also turn off Automatic updates and BITS (Background Intelligent Transfer Service).  Despite Microsoft’s security patches and updates for Windows XP and Vista companies and end-users are still vulnerable due to Conficker’s ability to self-update by automatically connecting to hundreds of attacker-controlled domains.

Microsoft recommends two things

1. Adopting Better AV (Anti-Virus Solutions) and Malware Protection

2. Strong and Better passwords

Podcast 2

Podcast Topics:

Benefits of Single Sign On SSO Benefits and Negatives

LinkedIn Password Hashes Leaked Online

Google Warning Gmail Users About State-Sponsored Attacks

Flame Malware Hijacks Windows Update

Microsoft Certificate Was Used To Sign Flame Malware

Podcast 3

Podcast Topics:

Apples World Wide Developers Conference WWDC

System Center Configuration Manager 2012

Forefront Endpoint Protection

MySQL Patch CVE-2012-2122

Last.fm Hack

Red Hat Patch For AMD

Much More

Podcast 1

Our first podcast Talking about Apple iTunes

Browser Security

Safari

Firefox

Chrome

Opera

Fedora 17 and more

Podcast 4

We are back with our 4th podcast after along hiatus we are going to talk about security and technology news from the last 4 weeks.

Password Hashing

Google Keynote Jellybean, Tablet, Google TV, Cloud Drive, Offline Google Docs

Microsoft Patch Tuesday 3 Critical vulnerabilities Patched

Microsoft Windows 8 Release date October 26, 2012

Microsoft Tablet Features

Microsoft Office 2012 Release

iOS 6 Beta Jail Broken

Dell Offering Ubuntu Laptops Again

DropBox and UPS Spam Scams

Skype Patches a Security Bug that allows third party messaging

Nvidia Developer Forums Hacked 400,000 Hashed Passwords Compromised

Yahoo Voice Hacked 400,000 Clear Text Passwords Stolen

28 million Formspring Passwords Leaked

WikiLeaks excepts donations again

Internet Dooms Day

Yahoo appoints new CEO Marissa Ann Mayer

Marissa Ann Mayer Tweets her Pregnancy and gets nasty feedback

Cisco Hit With Backlash Over Home Router Cloud Service on models EA4500 and the EA2700

Oracle Zero Day Vulnerability Still Not Patched

Oracle Zero Day Vulnerability Still Not Patched after April’s patch release with had 88 patches.  The vulnerability allows an attacker to perform a man in the middle attack and capture information exchanged between clients and databases.  The vulnerability was reported in 2008 and has believed to been around since 1999 when the TNS Listener feature was added to Oracles product line.  Oracle has workarounds for the zero-day flaw which was found in there database server products.  Oracle has gone as far to release a security alert:

Oracle Security Alert for CVE-2012-1675

http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html

The vulnerability is in the TNS listener which has been recently disclosed as “TNS Listener Poison Attack” affecting the Oracle Database Server.  The products affected are Oracle Database 11g Release 2, versions 11.2.0.2, 11.2.0.3, Oracle Database 11g Release 1, version 11.1.0.7, Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, 10.2.0.5, Fusion Middleware, Enterprise Manager and E-Business Suite.  Oracle has released work arounds which can be found at My Oracle Support Note 1340831.1 and My Oracle Support Note 1453883.1.

This site is protected by Comment SPAM Wiper.