NewsWorld-Whats happening now

Loading...

Sunday, March 15, 2009

Mumbai Pune NH4 Highway

Mumbai Pune NH4 Highway

Thursday, January 08, 2009

Satyam Computers Fraud

Satyam means Truth in Sanskrit.

But Satyam computers chairman did shameful thing by using fake balance sheets for around 10 years.
This is very shameful for Indian information technology industry which maintained its clean image in global markets.

Shareholders has lost their money, employees might loss their jobs and many. many things will happen in coming days. He should get arrested and landed in jail.

He has done worst thing.. That’s it.

Microsoft Security Bulletin Advance Notification for January 2009

Source:- Microsoft Newsletters

Microsoft Security Bulletin Advance Notification for January 2009
Issued: January 8, 2009
********************************************************************

This is an advance notification of security bulletins that
Microsoft is intending to release on January 13, 2009.

The full version of the Microsoft Security Bulletin Advance
Notification for January 2009 can be found at
http://www.microsoft.com/technet/security/bulletin/ms09-jan.mspx.

This bulletin advance notification will be replaced with the
January bulletin summary on January 13, 2009. For more information
about the bulletin advance notification service, see
http://www.microsoft.com/technet/security/Bulletin/advance.mspx.

To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security
Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.

Microsoft will host a webcast to address customer questions on
these bulletins on Wednesday, January 14, 2009,
at 11:00 AM Pacific Time (US & Canada). Register for the January
Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.

Other Information
=================

Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft will release an updated version of the Microsoft Windows
Malicious Software Removal Tool on Windows Update, Microsoft Update,
Windows Server Update Services, and the Download Center.

Non-Security, High-Priority Updates on MU, WU, and WSUS:
========================================================
For information about non-security releases on Windows Update and Microsoft
update, please see:
* http://support.microsoft.com/kb/894199: Microsoft Knowledge Base
Article 894199, Description of Software Update Services and
Windows Server Update Services changes in content.
Includes all Windows content.
* http://technet.microsoft.com/en-us/wsus/bb466214.aspx: New,
Revised, and Released Updates for Microsoft Products Other Than
Microsoft Windows

Microsoft Active Protections Program (MAPP)
===========================================
To improve security protections for customers, Microsoft provides
vulnerability information to major security software providers in
advance of each monthly security update release. Security software
providers can then use this vulnerability information to provide
updated protections to customers via their security software or
devices, such as antivirus, network-based intrusion detection
systems, or host-based intrusion prevention systems. To determine
whether active protections are available from security software
providers, please visit the active protections Web sites provided by
program partners, listed at
http://www.microsoft.com/security/msrc/mapp/partners.mspx.

Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing
a Microsoft security update, it is a hoax that may contain
malware or pointers to malicious Web sites. Microsoft does
not distribute security updates via e-mail.

The Microsoft Security Response Center (MSRC) uses PGP to digitally
sign all security notifications. However, PGP is not required for
reading security notifications, reading security bulletins, or
installing security updates. You can obtain the MSRC public PGP key
at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.

To receive automatic notifications whenever
Microsoft Security Bulletins are issued, subscribe to Microsoft
Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.

Satyam will continue business, protect staff



Source:- Timesofindia



Satyam Computer Services is speaking to its top 100 clients individually, and has received expressions of support from key customers, its interim CEO said on Thursday.


The chairman of the outsourcing company resigned on Wednesday saying that profits had been falsely inflated for years, sending the company's shares plunging nearly 80 percent.


Ram Mynampati was appointed the interim CEO.


"Our only aim at this time is to ensure that the business continues," Mynampati told reporters at a news conference. Another top priority for the company was to protect employees' careers, said Mynampati.


He said the company would help investigating agencies and had launched a process to assess its financial position. The Satyam board relied on audited data on revenue and had no inkling about the fraud, said Satyam interim CEO Ram Mynampati.


The company is in the process of identifying new candidates for the board, said Mynampati. Mynampati said that the aim was to ensure complete transparency and smooth transition of leadership.

Satyam Chairman Ramalinga Raju goes missing

Source:- Yahoo

Where is B. Ramalinga Raju? Everyone is trying to find an answer to the question after the chairman of Satyam Computers resigned Wednesday confessing to a Rs.70 billion (Rs.700 crore) fraud.

A team of officials from market regulator SEBI (Securities and Exchange Board of India) arrives here Thursday to begin a probe amid speculation that police might arrest Raju, but nobody knows his whereabouts.

Raju became incommunicado after sending a letter to Satyam board Wednesday morning. There was utter confusion after a TV channel reported that he had left either for the US or Dubai.
Raju is believed to have met nobody in the last two days. It is also possible that he might have handed over his letter to company officials before becoming incommunicado.

Sources in Satyam, however, said he was in Hyderabad and might address a press conference later in the day. The reporters who rushed to his house in upmarket Jubliee Hills were told by the security guards that he was attending a meeting in Satyam Infocity at Madhapur.

However, no senior official from Satyam could be reached to confirm this. A large group of reporters waited outside Satyam Infocity till late Wednesday but in vain.

The Hyderabad police were also reportedly trying to find the whereabouts of Raju. The Andhra Pradesh government has ordered a probe by crime branch. Police Commissioner B. Prasada Rao Wednesday said they would act only if a shareholder or regulator lodges a complaint against Raju.

Some police teams were also sent to Satyam offices in the city to find Raju's whereabouts but they were unsuccessful in tracing him as well.

Tuesday, January 06, 2009

Equities -Understanding Indian IT sector


Source:- Kotak

The technology sector offers a wide arrange of products and services for both customers and other businesses. Consumer goods like personal computers, stereos and televisions are continually improved and upgraded, offering the latest technology to all users. Businesses receive information and services from software and database systems, which allow the companies to make strategic business decisions.



The stocks in this sector…


A category of stocks relating to the research, development and/or distribution of technologically based goods and services. This sector contains businesses revolving around the manufacturing of electronics, creation of software, computers or products and services relating to information technology.



Factors affecting IT sector


· A major demand for Indian IT services companies comes from the developed markets of USA and Europe. Any impact on these economies is bound to affect the IT sector.


· The rising salary cost is also a major influence on IT sector. However with recession hitting the economy this factor is not very strong.


· The billing rates of the clients also have a strong influence on this sector. The clients with strong negotiation powers can mange to push the rates down. IT companies have not faced any major re-negotiation on rates till now.


· The foreign exchange rate determines the revenue of this sector. If the foreign exchange rate appreciates it is not beneficial for the sector.



Current scenario of IT sector


Macros not favourable…


About 80 – 85% of the demand for Indian IT services companies comes from the developed markets of USA and Europe. With both these geographies in recession, decision making process by clients has become slow. Clients in these geographies and other economies as well are either postponing decisions or putting IT spends on hold. This is because they themselves are not comfortable with their revenue and earnings outlook. Their visibility in their own businesses has reduced significantly. Specific issues of the clients going bankrupt or undergoing M&A have also led to temporary or permanent disruption in business.



Our recent interactions with leading IT services companies have indicated that, the velocity of business flow from clients has further reduced in the current quarter. IT budgets for the next calendar, which normally get finalized by November or December, are likely to be finalized only in 1QCY09. Also, Indian vendors expect discretionary spends and high end services like consulting to experience a relatively slower growth. Thus, the overall pace of deal flows is expected to slow down.


According to NASSCOM, the USD growth rate for the IT services and BPO exports in FY09 is expected to come down to 21% - 24% (expected to revised further) from about 29% in the previous fiscal.



though off-shoring is expected to gain increased traction


There is a general opinion that, off-shoring should see higher traction in times of economic recession. We opine that, once when there is some stability in the developed economies, companies there will have better visibility of the quarters ahead. It is at this point of time that, allocations for off-shoring of projects will see increased traction.


Cost rationalization and better value for money spent will be the driving forces, we believe. While it is difficult to arrive at an exact time-frame for this, we share the companies' optimism that, 1QFY10 should see better traction in off-shore project allocations.



Billing rates expected to moderate


As yet, IT companies have not faced any major re-negotiation on rates. However, we understand that smaller IT companies have already started working at lower price points to save volumes. We believe that, in the next few months, larger companies may have to either bring down price points or provide more value for the same price to existing as well as new clients.


Indian companies have acquired significant competencies over the past 4 – 5 years and are able to build in greater efficiencies in their delivery process so as to provide higher value. More and more companies are now undertaking fixed priced projects. These projects allow clients to freeze their IT spend while providing opportunities to vendors to maximize gains by improving productivity. This may allow vendor companies to restrict impact on margins to some extent.



Larger companies are better bets…


On a relative basis, we opine that, the larger companies have more ability and resources to overcome these growth challenges and restrict impact on their profitability.


We see advantages like deep client relationships, strategic nature of projects, better account management capabilities, a broader range of services, better geographic spread and better execution and technical capabilities on the revenue front. Better negotiation capabilities, easier access to quality man-power, flexibility in scaling up projects, a global delivery model etc are the levers for restricting impact on margins.



as are smaller players operating in focus segments


We believe that, it is desirable for a smaller company to focus on a few verticals or capabilities and move up the value chain in these areas. It is no use focusing on several verticals and providing vanilla services. They will be easily beaten by larger players.


There are several such companies which have moved up the value chain in focused sectors and have been able to develop deep relationships with clients because of their expertise. We believe that, these companies will be able to achieve better growth v/s comparable peers and should be seen as good investment candidates.


Google software pack

Information about Google Pack Software


    Google Chrome Web Browser
  • Make browsing the web faster, safer, and easier
  • Experience fewer browser crashes

    Google Toolbar for Internet Explorer
  • Search from any web page and autofill forms
  • Block annoying pop-ups

    Spyware Doctor Starter Edition
  • Detects and removes spyware, adware, trojans and keyloggers
  • Includes Smart Updates and scheduling to protect your PC

    Picasa
  • Find, edit and share your photos in seconds
  • Easily remove red eye and fix photos

    Adobe Reader
  • View, print, and search PDF files via a redesigned interface
  • Secure your documents and collaborate via online, real-time meetings

    Skype
  • Make free voice and video calls to anyone else on Skype
  • Call landlines and mobile phones at attractively low rates

    Google Earth
  • Zoom from space to street level — tour the world
  • Find maps, driving directions, hotels, restaurants and more

    Norton Security Scan
  • Detects and eliminates viruses and Internet worms
  • Free detection updates and scheduled scanning

    Google Desktop
  • Find all your email, files, web history and more
  • Get all your personalised info in one place with Sidebar

    Google Photos Screensaver
  • Display photos from your PC and photo-sharing sites
  • Watch cinematic slideshows

    Mozilla Firefox with Google Toolbar
  • Browse the web quickly and securely
  • Switch between pages quickly with tabbed browsing

    RealPlayer
  • Play popular media formats, organise music and videos
  • Transfer music to iPod and other portable media players
Learn more about Google Pack Software



Sunday, January 04, 2009

iPhone Competitors

Below are few iPhone competitors

1. Nokia N95 - The N95, the most powerful handset yet to be released, is equipped with a full-load of pretty nasty features like its fully-integrated GPS, 5 MP camera, HSDPA connection speed, including all the multimedia entertainment support today’s mobile crowd will likely need. Even without iPhone’s multi-touch technology, the N95 has a user interface that is too hot to ignore right now with iPhone still months away. With Nokia’s market leadership in place to help sell this juicy handset, the N95 is iPhone’s biggest threat. Recently Nokia announced an agreement with YouTube that will definitely make the yummy N95 that much easier to swallow.



2. Samsung F700 - Slim, touch-screen and HSDPA capable. The only weakness of this device is the Flash user interface. But this Samsung could easily turn around once they show us how the touch-screen actually works, if it does work like we imagine a Flash UI could work.






3. Sony Ericsson SO903iTV Bravia Phone - Soon to be released in Japan. Ask the Japanese how good this TV phone is then tell them how the iPhone compares to it and you will see a smile so smug you won’t need him to put it in words. This new Bravia Phone is not number one for only one reason: the Japanese doesn’t think releasing it to the U.S. is worth their while. But who knows.










4. LG Prada Phone - The most hyped iPhone rival, it boasts inferior touch-screen controls and UI compared to the iPhone, but not too inferior to make it a non-threat. Released months earlier than iPhone, it costs 200 dollars more, which goes against the LG Prada in a major way. Other specs of the LG Prada are no iPhone beater either.




Source:-http://www.cellphones.ca/

Microsoft may slash 15K jobs this month

Source:- Indian express

The world’s top software firm, Microsoft, is planning a massive reduction in its workforce where up to 15,000 jobs may be axed this month, says a media report. “Microsoft is preparing to announce the first wide scale layoffs in its 32-year history, with up to 15,000 jobs at risk, according to some predictions,” The Times said in a report published online.

Speculation about job cuts was triggered by a report by Fudzilla, a technology blog site, which said employees were told that the software group was preparing for major layoffs from its global operations on January 15, it added. Earlier, a brokerage firm Oppenheimer & Co's analyst Brad Reback had asked Microsoft to cut its workforce by 10 per cent or about 9,100 employees. Such a layoff exercise “would be a healthy move for the company”, Reback added. Microsoft had close to 91,000 employees on its payrolls at end of July-September quarter.

The report said the news of job losses came amid the company being forced to apologise for an embarrassing hiccup with its Zune digital music player. A bug in the device’s internal clock in the original 30-gigabyte version failed to cope with the last day of the leap year and thousands of owners were left with a frozen screen on December 31.

Alternative Fuel -Concept Green Cars

Source:- hybridcars.com
Toyota first demonstrated a futuristic hybrid concept vehicle at the Tokyo Auto Show in 1995. The car, which consisted of an electric motor connected to a regular gasoline engine, was called the Toyota Prius. Hybrid skeptics —both at the show and afterward—are now silent, as cumulative global sales continue to surpass all expectations. Which of today's wild and wacky hi-tech enviro car concepts will become tomorrow's practical fuel-efficient vehicles? Let's take a look at some contenders.
-----------------------------------------------------------------------------------------------
Volvo 3CC
The Volvo 3CC concept car, a rocket-shaped three-seater, can accommodate the full range of power systems, from traditional gasoline and alternative fuels such as ethanol, to hybrid and all electric. Three thousand lithium-ion batteries, just like those used in laptop computers, give it the equivalent of 105 horsepower. The 3CC has the aerodynamics of a two-seat sports car, but can slip a third passenger, or perhaps two children, in a single seat in the back.



-----------------------------------------------------------------------------------------------
Daihatsu UFE III
Daihatsu, the Japanese car company known for compacts, is on the third generation of the UFE (which stand for Ultra Fuel Economy). This mini-hybrid vehicle can transport three people?one upfront, and two in the back. The hybrid system comprises a 660-cubic centimeter direct-injection gasoline engine, two motors, and a nickel-metal hydride battery. Its estimated fuel economy is 169 miles per gallon.


-----------------------------------------------------------------------------------------------
Nissan Pivo
Nissan has developed a bubble-shaped, three-seater electric car called the Pivo—short for pivot. It runs exclusively on electricity. The cabin sits atop a wheeled platform that can swivel 360 degrees, doing away with the need to reverse when emerging from narrow spaces.
-----------------------------------------------------------------------------------------------
Ford Mercury Meta One
The Mercury Meta One combines a hybrid transmission with a twin-turbocharged V-6 diesel engine calibrated to run on a bio-diesel blend (fuel made from natural, renewable sources such as vegetable oils). The combination is designed to produce the power of a V-10, with emission levels clean enough to meet California's Partial Zero Emissions Vehicle (PZEV) requirement.

-----------------------------------------------------------------------------------------------
BMW X3
The X3 combines a next-generation direct-injection inline six-cylinder engine with an electric motor—and a supercapacitor instead of the rechargeable batteries most hybrids use. A supercapacitor discharges all of its energy in a quick burst of power. Then, the gasoline engine takes over until the regenerative braking can recharge the supercapacitor for another quick burst. The system provides a modest 20% improvement in fuel economy over current models.


-----------------------------------------------------------------------------------------------
Toyota Volta
The Volta's 3.3-liter V-6 gas engine is located behind the rear axle and isn't connected directly to the wheels. Instead, movement is provided by two electric engines, one per axle, offering the safety benefits of all-wheel drive. But the real gain of packaging a large internal-combustion engine with two electric motors is rip-roaring speed: The 408-horsepower hybrid drive can go from 0 to 60 in 4 seconds.

-----------------------------------------------------------------------------------------------
The Honda FCX Concept
The Honda FCX Concept uses a secret weapon to deliver more power than its predecessor fuel cell vehicles: gravity. Honda calls it a "3V" system: "Vertical gas flow, vertebral layout, and volume-efficient packaging." In the 3V schema, oxygen and hydrogen flow from the top to the bottom of the fuel cell stack and the fuel cells are arranged vertically in the center tunnel for more efficient packaging of the fuel cells. With these improvements, the FCX fuel-cell car now has a driving range of 354 miles—a 30 percent improvement from the 2005 model—and a maximum speed of 100 miles per hour. The vehicle can driven in temperatures as low as minus 86 degrees Fahrenheit. The super-slick Honda FCX Concept has a long and ultra-low profile that is anything but vertical.


for more go to source website mention at top

Thursday, January 01, 2009

NEW YEAR WISHES

Happy New Year 2009


Tuesday, December 30, 2008

TechTree.com - Chandrayaan's MIP Images Soon

The Chandrayaan saga continues even after two months of its launch. Post the successful launch, it is now the turn of the onboard equipments to daze us earthlings.ISRO (Indian Space Research Organization) is all set to release a set of pictures taken from the Moon Impact Probe (MIP), which crash landed on the lunar surface. The images were taken while the probe was on its 25-minute descent towards the lunar surface. The MIP had detached from the orbiting Chandrayaan and landed on the moon at 8:31 IST on November 14, 2008. While two images were released soon after the landing, no more were released after that.

Read Full article on below link

http://www.techtree.com/India/News/Chandrayaans_MIP_Images_Soon/551-97167-643.html

Microsoft Security Advisory Notification

Title: Microsoft Security Advisory Notification
Issued: December 30, 2008

Click here to Read this

Sunday, December 28, 2008

State bank of india - SBI Hacked ?

Read Reports about State bank of india website problem
Business standard
Economic Times

Tips for safe internet banking

Click here to Read Article on MSN

Section 49–O of the Indian Constitution VOTE NOBODY

A must read for all responsible Indian citizens.
Section 49–O of the Constitution
Did you know that there is a system in our constitution, as per the 1969 act, in section "49–O" that a person can go to the polling booth, confirm his identity, get his finger marked and convey the presiding election officer that he doesn't want to vote anyone!
Yes such a feature is available, but obviously these seemingly notorious leaders have never disclosed it. This is called "49–O".
Why should you go and say "I VOTE NOBODY"... because, in a ward, if a candidate wins, say by 123 votes, and that particular ward has received "49–O" votes more than 123, then that polling will be canceled and will have to be re–polled. Not only that, but the candidature of the contestants will be removed and they cannot contest the re–polling, since people had already expressed their decision on them. This would bring fear into parties and hence look for genuine candidates for their parties for election. This would change the way; of our whole political system... it is seemingly surprising why the election commission has not revealed such a feature to the public....
Please spread this news to as many as you know...Seems to be a wonderful weapon against corrupt parties in India... show your power, expressing your desire not to vote for anybody, is even more powerful than vote.

ONLINE BLOOD AVAILABILITY

There is a Website: www.friendstosupport.org Where u can search for a Particular blood group, you will get thousand's of donor addresses. Pass this msg 2 all u know. It will help many. Please don't delete it without Forwarding. U will really help some1 without Ur Knowledge. If you can't! then who can?

Monday, December 22, 2008

India.s First Scientific Mission to Moon



















Chandrayaan-1

Chandrayaan-1, India.s first scientific mission to Moon is slated
for launch during 2007. The primary objectives of the mission
are to expand the scientific knowledge about the origin and
evolution of moon, upgrade India.s technological capabilities and
provide challenging opportunities to the young scientists working
in planetary sciences.




Pursuit of space science is one of the important objectives of the
Indian Space Programme. The Thumba Equatorial Rocket
Launching Station (TERLS) was established near
Thiruvananthapuram in 1963 for studying the ionospheric
electrojet and related phenomenon, which paved the way for space
research activities in the country. Also, the first Indian satellite,
Aryabhata, launched in 1975, carried scientific experiments to
investigate X-ray astronomy, Solar neutrons and supra thermal
electron density. Since then, several instruments for scientific
research have been flown on board high altitude balloons, sounding
rockets and satellites. Several ground based facilities have also
been set up for conducting research by scientists from universities
and research institutions in astrophysical, solar and atmospheric
research programmes.








Click here to Read more




Sony Ericsson XPERIA X1







Sony Ericsson XPERIA X1


Features
2G Network -GSM 850 / 900 / 1800 / 1900
3G Network -HSDPA 850 / 1900 / 2100
Status Available. Released 2008, October
Dimensions -110.5 x 52.6 x 17 mm
Weight -145 gType
TFT touchscreen, 65K colorsSize -800 x 480 pixels, 3.0 inches
Full QWERTY keyboard
Optical trackpadType
Polyphonic, MP3Vibration -Yes
Phonebook -Practically unlimited entries and fields,
PhotocallCall records -Practically unlimited
Card slot -microSD (TransFlash),
memory -400 MB internal memory -256 MB RAM, 512 MB storage memory
GPRS -Class 10 (4+1/3+2 slots), 32 - 48 kbps
EDGE -Yes3G -
HSDPA, 7.2 Mbps
WLAN -Wi-Fi 802.11b/g
Bluetooth -Yes, v2.0 with A2DP
Infrared port -No
USB -Yes, v2.0 miniUSB
OS -Microsoft Windows Mobile 6.1 Professional
Messaging -SMS, MMS, Email, Push email, IMBrowser -WAP 2.0/HTML (IE), RSS feeds
Colors -Solid Black, Steel Silver
Camera -3.15 MP, 2048x1536 pixels, autofocus, video, flash; secondary videocall
-Built-in GPS receiver -A-GPS function
-FM radio with RDS -MP3/AAC/MPEG4 player -3.5 mm audio jack
-Pocket Office (Word, Excel, PowerPoint, OneNote, PDF viewer) -Picture editor/blogging -Organiser
-Built-in handsfree -Voice memo/dial
Standard battery-Li-Po 1500 mAh (BST-41)
Stand-by -Up to 833 hTalk time -Up to 10 h

Monday, December 15, 2008

Cisco certifications

Cisco certifications
The widely respected IT certification programs available through Cisco Career Certifications bring valuable, measurable rewards to network professionals, their managers, and the organizations that employ them.

Three Levels of IT Certification
We offer three levels of general IT certification: Associate, Professional, and Expert (CCIE representing the highest level of achievement).

Seven Different Paths
Various tracks—such as Routing and Switching, Network Security, and Service Provider—are available, so that you can match your certification path to your job role or industry.

IT Certification in Focused Areas
In addition to general certifications, network professionals can enhance their core networking knowledge by achieving specialist certification in technologies such as security, IP telephony, and wireless.

Monday, October 20, 2008

future is yours

Whenever you are facing any setback in life be patient..
i feel sorry for whatever i done wrong ...
There is one phrase which says " sorry can't make dead man alive"

But still i am sorry for whatever i had done ..."Which was not right?"

We have to learn from life...

Everybody should face the past without regret..

Do the karma ..And get the fruit..

Sunday, September 28, 2008

टीवी website

indianpentiumv2: http://shop.ebay.co.uk/merchant/thesiew_W0QQ_nkwZQQ_armrsZ1QQ_fromZQQ_mdoZ
indianpentiumv2: www.idesitv.com
indianpentiumv2: http://www.apalimarathi.com/

Thursday, September 13, 2007

CISSP Info

Are you game for CISSP?
A large number of security professionals around the world are pursuing CISSP certification. Here are some valuable tips to help you prepare for the examination. by Avinash Kadam
Mention 'CISSP' (Certified Information Systems Security Professional) to any information security professional and most likely, he/she will be already considering the examination to acquire certification. The number of CISSPs has grown from around 3,000 in the year 2000 to 23,000 in 2003. So just what is it that has attracted security professionals all over the world towards this certification?
The CISSP exam is conducted by International Information Systems Security Certification Consortium, abbreviated as (ISC)2, chartered in 1989. The basis of this examination is understanding of the Common Body of Knowledge (CBK), which is a compendium of information security knowledge. The certification process itself requires fulfillment of the following conditions:
1. Subscribe to the (ISC)2 Code of Ethics.2. Pass the CISSP Certification examination.3. Endorsement by a CISSP or equivalent qualified professional 4. Minimum professional experience of four years; graduates require three years of experience.
If you are already working in the information security field, the conditions are not formidable. The challenge is to go through the entire Common Body of Knowledge, which is very comprehensive. No topic on information security is left out.
I have mapped the CISSP domains with BS7799 domains. CISSP certifies an individual, whereas BS7799 certifies an organization; the body of security knowledge remains the same, which is not surprising. So, if you are concerned about information security, you need professionals who have a thorough understanding of all the security domains. CISSP endorses this knowledge, hence the surge in its popularity.
Details of the main topics for each domain are given in the CISSP Study Guide, which can be downloaded from the (ISC)2 website. In brief these are:
Security Management Practices: This domain requires knowledge about security policies, organization structure, risk assessment, roles and responsibilities, information classification, personnel security and so on. This may seem routine to a technical person. However, you would be more open to understanding these topics if you acknowledged the fact that security is not just the domain of technical personnel alone—it's also a responsibility of the entire organization. And you will be responsible for convincing everyone (from top management to end-user) about its importance.
Security Architecture and Models: This is the domain where candidates get a test of security beyond network security. Lots of security models and standards are involved. You will need to understand the theoretical basis of the Orange Book, Common Criteria standards and also models like Bell LaPadula. This is an interesting yet conceptually challenging module.
Access Control Systems & Methodo-logy: Here, we are again on familiar terrain. Various access control methods are required to be studied including biometrics, pap, chap, radius, single sign on, methods of attacks, penetration testing and intrusion detection.
Application Development Security: This is another slippery domain for networking professionals, but a very essential component of security. We have to study the application security issues like Java, ActiveX controls, database security, data warehousing and data mining security, malicious code and methods of attack, and various application development security issues.
Operations Security: This is one of those deceptively simple domains, where, like the security management practices domain, everything looks like common sense. The areas covered here are documenting operating procedures, segregation of duties, media management, administrative management, operations controls like input control, output control, auditing and so on. If you try to answer the questions based on your experience of operations alone, your answers may be limited in scope. So, be careful about this domain.
Physical Security: Physical security is very obvious. But this is the domain where most of the candidates fail. The reason again is overconfidence about answering questions using common sense. Are you sure you know enough about adequate lighting for a premises, or the appropriate height of a fence? Do spend sufficient time preparing for this domain.
Cryptography: This is another domain where a lot of unfamiliar theory has to be covered, especially in the area of symmetric key cryptography.
Telecommunications, Network, & Internet Security: Here we are back to familiar territory. You will have to brush up your concepts on the seven layers of the OSI Model and then study the security issues posed by each layer, as well as the solutions.
Business Continuity Planning: Availability is one of the major requirements for security, the other two being confidentiality and integrity. This domain covers BCP/DRP (Business Continuity Planning/ Disaster Recovery Planning), and requires one to study the traditional steps of Business Continuity, from risk assessment, impact analysis, recovery strategy planning—to implementation, restoration and testing. Most of us do not have much experience of an elaborate BCP, so we have to be careful about this domain.
Law, Investigations, & Ethics: This model is not about US laws but universally applicable principles of protection of intellectual property, copyright, evidence gathering, investigation methods and incidence handling. You should carefully read the (ISC)2 code of ethics to answer the questions pertaining to ethics.
Examination structure
The total time allotted for CISSP examination is six hours. The examination consists of 250 objective type questions. For each, you have to select the correct answer from four options. In answering each question, you'll be able to eliminate two options, which are obviously incorrect ones or 'distracters'. Your real test will be to choose the correct answer from the remaining two options, which will be closely related. At times both may seem to be the correct answers. This is where your conceptual clarity will help you make the right choice.
No domain-wise distribution of questions has been specified. So we do not know the weightage given to individual domains. Your result does not contain the marks obtained by you. You are simply declared 'passed'. But if you are unsuccessful, you get domain-wise details, and know which domain(s) you failed. Essentially, it means that you cannot leave a domain as an option. You have to study everything.
Preparation for the CISSP examination
With the requirement of minimum four years experience, we can safely assume that you have the basic understanding of the information security field, and expertise in a few domains. Most likely, you would be a networking professional with good understanding of security requirement for networking. But you may not have same level of knowledge about the other areas. Where does one begin?
Reference books
The CISSP study guide from (ISC)2 website gives a list of excellent books. Eventually, many of them will form part of your personal library. Some of these books are available as Indian editions. The following books are my favorites. These are affordable and authoritative.
1. Computer Networks, Fourth Edition Andrew S. Tannenbaum2. Cryptography and Network Security William Stalling3. Building Internet Firewalls Elizabeth Zwicky4. Practical Unix & Internet Security Garfinkel & Spafford 5. TCP/IP Illustrated Volume 1 W. Richard Stevens6. Security Engineering Ross Anderson7. Inside Network Security Perimeter Stephan Northcutt8. Information Systems Control & Audit Ron Weber
Another excellent source of study material is the National Institute of Standards and Technology (NIST) publications. The Special Publication (SP800) series covers almost every topic in the world of security, from physical security to Web security, and wireless security—and these are available as free downloads.
Yet another free source is the SANS reading room.
Finally, use the popular 'Google' search site. Just specify the word that you are looking for and you'll get a million references.
Just don't get lost in the sea of knowledge.
Popularity of CISSP has also given rise to 'Preparation Guides'. These are condensed knowledge capsules. These give an overview of all the topics, but not an in-depth explanation. You must supplement these books with good technical books.
Question banks
There are a number of Internet sites giving tips about the examination and question banks. The preparation guides also give sample questions. Do take the help of these for your preparation. Make sure to keep track of those questions where your answers were wrong. Attempt these questions after a gap to see whether you are still giving wrong answers. This will mean that you need to reset your memory and refresh your understanding.
The questions here do not reflect the actual difficulty level of the CISSP examination. The questions in the exam may be more difficult. So do not get over confident if you're scoring good marks in these sample questions.
CISSP Seminars
(ISC)2 conducts official CISSP CBK review seminars worldwide. These seminars are now held in India at a special price for Indian nationals, working in India. The instructors for these seminars are selected and trained by (ISC)2. The five-day seminars review the entire CBK material and also give a sample test. This is a good opportunity for those who find it difficult to go through self-study mode and prefer the interactive atmosphere of a seminar. Check the (ISC)2 website for seminar announcements.
Group discussions / Study circles
Form a study group. This will keep you motivated and you will be able to discuss your doubts with others. You may even allocate topics to different group members and ensure that they teach others. I personally found that teaching is the best way to understand a subject. So, volunteer for the most difficult topic. Others may tear you apart in this encounter with a barrage of questions, but you will definitely emerge more knowledgeable. It would help if you're able to rope in a CISSP in these groups. You may boost his ego by calling him 'mentor'. Of course, the mentor should be able to spare his time for this purpose.
Study period
Allocate at least six months for preparation, with about 10 to 15 hours of study every week. You may not be able to adequately cover all the topics in less than this period. There's a lot of theory, for which you may not have had hands-on experience. Take this opportunity to bring yourself up-to-date on all the security related subjects. You will have to maintain the habit of studying, even after getting the CISSP certification, by earning 40 CPE (Continued Professional Education) points each year.
Examination schedule
(ISC)2 conducts examinations in all metros in India with regular frequency. Keep an eye on the website announcement. You should be able to plan the target examination date well in advance.
Examination Fee
Currently the examination fee is $450 but it is revised to $499 from 1st Jan. 2004. After passing the examination, you have to pay an annual maintenance fee of $65 along with the statement of having clocked in the 40 CPE hours.
The US dollar price for these certifications is a major deterrent, but the global recognition is the reason why people still want to pursue CISSP examination and certification.
Avinash Kadam is Director, Miel e-Security, Pvt. Ltd. He can be reached at awkadam@mielesecurity.com

WINNERS VERSUS LOSERS

¨ The Winner is always part of the answer;
The Loser is always part of the problem.

¨ The Winner always has a program;
The Loser always has an excuse.

¨ The Winner says, "Let me do it for you";
The Loser says, "That is not my job."

¨ The Winner sees an answer for every problem;
The Loser sees a problem for every answer.

¨ The Winner says, "It may be difficult but it is possible";
The Loser says, "It may be possible but it is too difficult."

¨ When a Winner makes a mistake, he says, "I was wrong";
When a Loser makes a mistake, he says, "It wasn't my fault."

¨ A Winner makes commitments;
A Loser makes promises.

¨ Winners have dreams;
Losers have schemes.

¨ Winners say, "I must do something";
Losers say, "Something must be done."

¨ Winners are a part of the team;
Losers are apart from the team.

¨ Winners see the gain;
Losers see the pain.

¨ Winners see possibilities;
Losers see problems.

¨ Winners believe in win-win;
Losers believe for them to win someone has to lose.

¨ Winners see the potential;
Losers see the past.

¨ Winners are like a thermostat;
Losers are like thermometers.

¨ Winners choose what they say;
Losers say what they choose.

¨ Winners use hard arguments but soft words;
Losers use soft arguments but hard words.

¨ Winners stand firm on values but compromise on petty things;
Losers stand firm on petty things but compromise on values.

¨ Winners follow the philosophy of empathy: "Don't do to others what you would not want them to do to you";
Losers follow the philosophy, "Do it to others before they do it to you."

¨ Winners make it happen;
Losers let it happen.

¨ Winners plan and prepare to win.
The key word is preparation.

Wednesday, September 12, 2007

Linux and Windows security compared

http://www.linux.com/articles/36273

sysadmin interview questions

http://www.devbistro.com/tech-interview-questions/Unix.jsp

http://www.geekinterview.com/question_details/17293

http://www.geekinterview.com/Interview-Questions/Operating-System/Solaris-Admin

Sunday, October 08, 2006

RAM viewer

Operator is a complete Linux (Debian) distribution that runs from a single bootable CD and runs entirely in RAM. The Operator contains an extensive set of Open Source network security tools that can be used for monitoring and discovering networks. This virtually can turn any PC into a network security pen-testing device without having to install any software. Operator also contains a set of computer forensic and data recovery tools that can be used to assist you in data retrieval on the local system.

http://www.ussysadmin.com/operator/

Overview: Software to monitor and free unused RAM. RAM Optimizer speeds up your computer system and helps prevent crashes by freeing unused RAM. If you use a computer on a regular basis and run more than one program at a sitting, it's very likely that you will benefit from the use of a RAM optimizer, especially if you experience slowdowns or crashes. Version 1.1 may include unspecified updates, enhancements, or bug fixes.

http://downloads.zdnet.com/download.aspx?&kw=RAM&docid=216719

get TOP 15 security tools

get TOP 15 security tools from below website

http://www.darknet.org.uk/2006/04/top-15-securityhacking-tools-utilities/

Tuesday, July 25, 2006

Mind management

Why do we need mind management?

Unless we control or manage our mind, it is difficult to achieve success and peace. Psychologists say every interest is first born in the mind as a seed. Then it continues to grow. Later it takes its real form which everybody can see. The interest that first appears in the mind remains weak for the first three minutes and it becomes strong within the next five minutes. All the negative aspects should be deleted within the first three minutes. If not taken out, they would become stronger later and you can never throw them out. After taking control over the mind, we can control passion, interest and unrest. Mind management is essential for a peaceful, successful and healthy life.

The age of computers has thrown us on the escalator of aspirations but has robbed us of simple charms like falling asleep. The compulsions of hectic schedules burden the mind and cause stress. However, the joys that elude us can be regained by practising power meditation. It creates tranquillity, simplifies life and cleanses the mind. It helps control indolence, ego and anger, and builds confidence and patience. With power meditation, negative thoughts get dissipated and a sense of happiness is achieved. With happiness and spiritual knowledge, one can relearn the meaning of life. The picture of life’s journey also becomes clearer. Osho said, “As science is not based on orthodox and blind beliefs and functions only on the principle of cause and effect, similarly power meditation doesn’t function on age-old theories or communal thoughts but originates from rational and divine experience. It strives to make an individual free from the confining pressures of daily life’’. The beauty of meditation is that it is independent of religion. According to modern medical science, combinations of factors like pollutants, imbalanced diet and high aspirations have rendered the human mind restless, thereby making the body perpetually ill. Here is a meditation method, which will enable you to control stress. Sit in the padmasan or sukhasan, cross-legged and erect. Keep your back, spine and neck straight. Keep your eyes closed. Sit in this position for 10 minutes. The method has two stages: for the first five minutes, breathe in slowly, hold it and then release it very slowly. Again, for the next five minutes, breathe and release your breath slowly.