Don’t have one of those stylish iPhone alarm clocks that wake you up every morning playing your favorite song? You don’t need one! There’s a great alternative, simply grab the Windows 7 Alarm Clock Gadget that can do the same.
You can set the alarm by clicking on the gadget. Click on the little options icon to choose a MP3 file that you want to hear as a wake-up song. You can also change the color of the skin and customize the display. Overall a pretty handy gadget.
Tip: Use a time switch to boot your PC in the morning (automatically) and you can save a lot of energy.
If you are not looking for a Windows 7 sidebar gadget, but for a real desktop solution, I suggest that you read this post over at our sister site VistaDesktopThemes.com:
Microsoft released a record number of 13 bulletins for 34 vulnerabilities on Patch Tuesday--and the first critical update for Windows 7--as well as fixes for zero-day flaws involving Server Message Block (SMB) and Internet Information Services (IIS).
The most severe of the three SMB flaws, which were first reported last month, could allow an attacker to take control of a computer remotely by sending a specially crafted SMB packet to a computer running the Server service. Exploit code for one of the SMB holes has been posted to the Web, Microsoft said.
Windows 7 is affected by two critical patches intended to mend vulnerabilities that could allow remote code execution if a malicious Web page were viewed, one part of a cumulative security update for Internet Explorer and the other in .Net Framework and Silverlight.
Other critical patches in the security bulletin for October fix a vulnerability in Windows Media Runtime that could be exploited if a user opened a malicious media file or received malicious streaming content from a Web site or application, and if a specially crafted ASF (Advanced Systems Format) file is played using Windows Media Player 6.4.
Among the critical updates: a cumulative security update of ActiveX Kill Bits that is being exploited and that affects ActiveX controls compiled using Active Template Library (ATL); and another patch resolving several vulnerabilities in ATL ActiveX Controls that could allow remote code execution if a user loaded a malicious component or control. ActiveX and ATLs were the subject of an emergency patch Microsoft released in July.
The final critical bulletin fixes a hole in Windows GDI+ (Graphics Device Interface) that could allow an attacker to take control of a computer if the user viewed a malicious image file using affected software or browsed a malicious Web page.
"Microsoft has repeatedly had to fix problems related to the Graphics Device Interface in Windows, and vulnerabilities in the component have been exploited broadly in the past. We can expect that security researchers will be looking to reverse-engineer today's patches, which may very well lead to exploits being created," said Dave Marcus, director of security research and communications at McAfee Labs.
Related "For the Record" podcast, with Symantec's Ben Greenbaum Listen now:Download today's podcast
Nine of the vulnerabilities were previously disclosed, which meant that attackers had time to come up with so-called "zero-day" exploits before the patches were available, Marcus noted.
The most alarming vulnerability in the mix is the SMB flaw, which was introduced by the patch for a different vulnerability, according to Josh Phillips, virus researcher at Kaspersky Lab.
Andrew Storms, director of security operations at nCircle, said the bug that is likely to have the biggest impact will be the critical one that affects Windows Media Runtime and involves a speech codec bug that has limited exploits in the wild. "This is a typical file-parsing issue and similar to vulnerabilities that have allowed attackers to create drive-by attacks that infect unsuspecting video viewers," he said.
Meanwhile, the critical SMB vulnerability is relatively difficult to exploit given default firewall conditions, but the IIS bugs are easy to exploit, Storms added.
"The sheer volume of the bulletins and patches is extreme," said Jason Miller, senior data team leader for Shavlik Technologies. "This is really going to affect administrators. It's going to be very challenging because of the time and research that's going to be needed" to patch systems.
Also released were five bulletins rated "important" to fix vulnerabilities in IIS, for which exploit code has been publicly released and for which there have been limited attacks, along with Windows CryptoAPI, Windows Indexing Service, Windows Kernel, and Local Security Authority Subsystem Service.
The update for Windows CryptoAPI relates to flaws in the way domain names are verified on the Internet, which could allow attackers to impersonate a site and steal information from unsuspecting Web surfers. The holes were revealed by researchers Dan Kaminsky and Moxie Marlinspike at Defcon in August.
Affected software includes Windows 7; Windows 2000; Windows XP; Windows Vista; Server 2003 and 2008; Office XP, 2003, and 2007; Microsoft Office System; SQL Server 2000 and 2005; Silverlight; Visual Studio .Net 2003; Visual Studio 2005 and 2008; Visual FoxPro 8.0 and 9.0; Microsoft Report Viewer 2005 and 2008; Forefront Client Security 1.0; and Office software including Visio, Project, Word Viewer, and Works.
The installation also removes the Win/FakeScanti Trojan, which displays fake malware warnings and then asks computer users to pay for fake antivirus software.
(For more information and analysis from Symantec, listen to my colleague Larry Magid's podcast.)
Update:This story was updated at 2:15 p.m. PDT with additional comment and at 11:47 a.m. PDT with more details and reaction from experts.
Article updated at 5:00 pm to correct mIQ media sharing details.
Best Buy Mobile's mIQ dashboard is easier on the eye.
(Credit: Screenshot by Jessica Dolcourt/CNET)
Microsoft introduced its My Phone service last week, an online dashboard for managing and sharing the contents of your mobile phone. We liked some aspects, and critiqued some others. Ultimately, we wished that Microsoft had teamed up with its Seattle neighbor, connected services startup Dashwire, whose legacy dashboard did much of the same thing as My Phone does now, but did it better. Dashwire has since turned its standalone product into a platform. Best Buy Mobile snapped up a license and is now offering its own sync-and-share service, called mIQ (short for mobile IQ).
I know what you're thinking: The T-Mobile Sidekick backup service just failed, and the blame is Microsoft's. Why trust its My Phone service at all? But backup isn't the point of these services. They're about management. Moreover, comfortably managing the contents of your smartphone from a screen and keypad that's larger than anything you can get on your smartphone. And if you delete a number or photo from the Web or phone, it's gone. Neither of these services intends to save it, but they do intend to make it available online.
So now that that's clear, it's time for a throwdown.
My Phone and mIQ both download small clients to the mobile phone. From there, they bidirectionally sync the phone's contents to an online dashboard. My Phone is limited to Windows phones, but mIQ is free for anyone with a BlackBerry, Symbian, or Windows phone.
Features
We'll say right off the bat that Microsoft's My Phone is richer in feature types overall compared with Best Buy Mobile's mIQ. Where mIQ syncs contacts, calendar, messages, calls, photos, and videos, My Phone also adds music, documents, favorites, tasks, and notes (it never found our music, though.) You can add new contacts, calendar items, and tasks with My Phone, and upload music, photos, and videos to transfer directly to the phone on your next sync.
My Phone also supports multiple phones on a single dashboard and can share your photos on Facebook, Flickr, and MySpace (but why can't it e-mail them to a friend?) A premium My Phone service, which you can try free until the end of November, can help you find your phone in various ways, as long as it's turned on, and the service can also lock it down or erase it if lost.
How Microsoft's My Phone shares photos.
(Credit: Screenshot by Jessica Dolcourt/CNET)
mIQ lacks My Phone's multiple phone support and phone location features. It does, however, let you update your status on Twitter and Facebook and can share pictures on Twitter, Facebook, Friend Finder, and Flickr. mIQ also integrates Skype and CallWave visual voice mail, so that registered members of those services can place calls and listen to voice mail in any order from their PCs. You can also generate text messages from mIQ, as long as the cell phone and the mIQ app are up and running. mIQ stores outgoing messages until you turn the service on. You can also add new calendar items and can download photos and videos to the computer.
Interface design
From the standpoint of user experience, Microsoft's My Phone is the pits. It's not the in-box theme and ads that bother us most, but more how the small type and boring layout make it forgettable, and easy to overlook tools. Best Buy Mobile's mIQ is better, with both navigational icons and snippets of each feature on the main page, so they're easier to find. But mIQ's interface is a tad cluttered and misses some of the visual edge of Dashwire's original.
Winner: My Phone, sort of
If you've got a Windows Mobile phone, go with Microsoft's My Phone service. Do it for the find-my-phone feature, if not for genuine engagement. BlackBerry and Symbian users will gain a lot of benefit from mIQ's brand of online mobile management, but it, too, has areas of growth. Luckily, both services will develop, keeping the competition alive.
Adobe on Tuesday released a security bulletin that includes fixes for 28 vulnerabilities in Adobe Reader and Acrobat, including a critical hole that has reportedly been exploited in the wild in limited attacks.
Affected software includes version 9.1.3 of Reader and Acrobat; Acrobat 8.1.6 for Windows, Macintosh, and Unix; and version 7.1.3 of Reader and Acrobat for Windows and Macintosh. The vulnerabilities could cause the applications to crash and could allow an attacker to take control of a user's computer.
Adobe recommends that people update to Adobe Reader 9.2 and Acrobat 9.2, or Acrobat 8.1.7 or Acrobat 7.1.4. For Adobe Reader users who cannot update to Adobe Reader 9.2, Adobe has provided the Adobe Reader 8.1.7 and Adobe Reader 7.1.4 updates.
One of the updates addresses a hole that Trend Micro says has been exploited by a Trojan horse that arrives as a PDF file containing malicious JavaScript. That exploit affects Microsoft Windows 98, ME, NT, 2000, XP, and Server 2003, according to Trend Micro.
"All users of Adobe Reader or Acrobat will need to update their software with today's release because these updates include fixes for the most critical kind of bugs," said Andrew Storms, director of security operations at nCircle.
This is Adobe's second quarterly security update for Adobe Reader and Acrobat.
Also on Tuesday, Microsoft issued a security advisory with a record number of bulletins, including the first fixes for critical holes in Windows 7.