tfh
Volume 16, Number 40 -- October 15, 2007

'Viral' Marketing Campaign from Bytware Targets PHP-i5/OS Security

Published: October 15, 2007

by Alex Woodie

Is i5/OS susceptible to a PHP virus? According to i5/OS security software vendor Bytware, it very well could be. In any event, System i users should be aware of the security threats posed by enabling PHP on the server, the company says, and that's why it kicked off a "viral" marketing and educational campaign at the COMMON Focus show in Columbus, Ohio, yesterday.

Bytware's campaign, which will play out on the Web over the next several weeks, revolves around a story about a financial services company whose System i server is hacked by a crime syndicate in China. While the story is made up, the avenue into the server is a real PHP vulnerability.

The System i community is encouraged to participate as the story unfolds via videos posted to the campaign's main Web site, www.i5virus.com, as well as on videos posted to YouTube and advertisements run on System i-related Web sites. The campaign is organized as a scavenger hunt, where people must visit certain Web sites to find answers to questions on PHP and i5/OS security and ultimately be asked to solve the mystery. Buttons distributed at this week's COMMON show in Ohio are also the source of some clues. At the end of the saga, Bytware will select several winners in a drawing. Potential prizes include an Apple iPod, a Nintendo Wii game console, and iTunes gift cards.

The story about the PHP hack and the Chinese crime syndicate is fictional, but it does serve to highlight the very real threat posed by PHP on the System i, says Chris Jones, Bytware's marketing director and the guy who created the viral marketing campaign.

"The premise in the game is a real vulnerability. Whether it would be easy to exploit, I don't know," Jones says. "We want to raise some awareness about PHP security and vulnerabilities. You need to be aware about potential vulnerabilities and make sure that you've configured everything properly."

This is the second such campaign Jones has created for Bytware, a Reno, Nevada-based developer of systems management, security, and anti-virus tools for the i5/OS server. Several years ago, Jones, who lives in Japan, directed the "iSeries Security Caper" that played out in fictional newspapers. In that case, the company was highlighting its newest product, StandGuard Anti Virus, which detects and removes Windows viruses from the System i's Integrated File System (IFS).

While i5/OS itself is immune from Windows viruses, the IFS can serve as a repository for Windows viruses, and serve to infect and re-infect Windows PCs, even if they're running antivirus themselves.

The possibility of a PHP vulnerability leading to a virus that could infect i5/OS or the IFS is similar, in some respects, to the known problem of Windows virus infestations on the System i server. The security organization PHP.org lists some 480 known vulnerabilities in the PHP runtime, including the deep recursion stack overflow vulnerability that Bytware is using in its fictional account.

So what's the payoff for Bytware? While details are scarce at this point, it appears the company is developing some type of security product for the System i that will address the potential problem of PHP viruses infiltrating the system. Whether it's a new product, or an extension of StandGuard Anti Virus is not known at this point.

In the meantime, it should be fun watching Bytware's 'viral' marketing piece play out over the next few weeks.


RELATED STORIES

IBM Pays for System i5 Video Viral Marketing

Project Prometheus Unchained as iSociety

IBM Unveils iSeries.mySeries Marketing Campaign

An iSeries Whodunit: Bytware Unveils Great Security Caper of 2004



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
WORKSRIGHT SOFTWARE

Do you need area code information?
Do you need ZIP Code information?
Do you need ZIP+4 information?
Do you need city name information?
Do you need county information?
Do you need a nearest dealer locator system?

We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

Just call us and we'll arrange for 30 days FREE use of either
ZIP/CITY or PER/ZIP4.

WorksRight Software, Inc.
Phone: 601-856-8337
Fax: 601-856-9432
E-mail: software@worksright.com
Web site: www.worksright.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Computer Measurement Group:  CMG '07 International Conference, December 2-7, San Diego
Clearview Software International:  Mobilize your work force with CostarMobile 2.0
COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee

 

 

IT Jungle Store Top Book Picks

The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Linux Beacon
Novell Delivers openSUSE 10.3 Linux Development Release

IBM Tweaks BladeCenter S for the Office, Preps Power6 Blades

Novell Actually Ships Open Enterprise Server 2

Growing Businesses, Upgrades Drive IT Hiring in Q4

Four Hundred Stuff
looksoftware's Modernization Suite Resembling a Full IDE

Pat Townsend Normalizes i5/OS Log Data for Security Analyses

Linoma Boosts Surveyor/400's SQL Functionality

PowerTech Updates Compliance Manager

Big Iron
Growing Businesses, Upgrades Drive IT Hiring in Q4

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Controlling System i Shutdown Activities Using an Intelligent Power-Handling Program, Part I

Programmatically Import Excel Worksheets Using IBM's ActiveX Object Library

Admin Alert: Remotely Accessing an HMC System Console, Part 2

System i PTF Guide
October 6, 2007: Volume 10, Number 40

September 29, 2007: Volume 9, Number 39

September 22, 2007: Volume 9, Number 38

September 15, 2007: Volume 9, Number 37

September 8, 2007: Volume 9, Number 36

September 1, 2007: Volume 9, Number 35

The Windows Observer
Six Patches Issued by Microsoft, One Held Back Again

VMware Previews Future Hypervisor, Creates SMB Bundles

Akamai Debuts Service to Speed Any IP-Based Application

Microsoft Wants To Manage Your Health Records

The Unix Guardian
Niagara-2 Chips Double Entry Sparc Server Performance

Akamai Debuts Service to Speed Any IP-Based Application

IBM Tweaks BladeCenter S for the Office, Preps Power6 Blades

Growing Businesses, Upgrades Drive IT Hiring in Q4

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

New Generation Software
Tango/04
Computer Measurement Group
Krengeltech
WorksRight Software


Printer Friendly Version


TABLE OF CONTENTS
New System i 525 Solution Editions Debut, 570 Gets Tweaked

IBM Adds Web Services and SOA Tools to the System i

Zend Puts Out New Release of Commercial-Grade PHP

AS/400s Are From Rochester, RS/6000s Are From Austin

But Wait, There's More:

More Reader Feedback on EGL, State of System i, Pricing Disparities . . . Worldwide IT Spending to Top $3 Trillion in 2007 . . . RPG Enhancements for i5/OS V6R1 Revealed . . . IBM Adds Zend to Value Pak, Ships ESX Server Storage Support . . . 'Viral' Marketing Campaign from Bytware Targets PHP-i5/OS Security . . . Avnet Builds Out EMEA Business with ACAL, Magirus Acquisitions . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement