<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: black]]></title>
    <link>http://securityratty.com/tag/black</link>
    <description></description>
    <pubDate>Wed, 03 Sep 2008 03:18:08 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Of Planes and Ships]]></title>
      <link>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</link>
      <guid>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</guid>
      <description><![CDATA[Tom Barnett is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.thomaspmbarnett.com/weblog/2008/09/column_121.html">Tom Barnett</a> is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the &quot;nail it to the wall&quot; quote at the end):</p><p><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">One of the main problems in counterterrorism today is that there are so many people and vehicles, and so much data and material, moving through globalization&#39;s myriad networks that it seems virtually impossible to track it all effectively. Nowhere has this problem been more acute than on the high seas.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In 2006, Adm. Harry Ulrich, then U.S. commander of NATO Naval Forces Europe, decided to do something about it. Despite having virtually no resources, his dream was to transpose the global air-traffic control system onto sea traffic.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Worldwide, aircraft are transparent, because they&#39;re all required to carry an identification beacon that allows them to be tracked leaving and entering airports, and monitored between airports, by a global network of sensors. Act suspiciously and somebody&#39;s fighter aircraft will soon be on your tail.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">No such pervasive system currently exists globally for maritime traffic. While bigger ships carry an ID beacon similar to aircraft, without a shared monitoring network, that&#39;s like tracking only selected commercial jets and giving everyone else a pass.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">So Ulrich, upon taking command, asked a simple question: &quot;If we can do that in the air, why can&#39;t we do it on the sea?&quot; He made a point of pioneering his sea-traffic-control effort first inside the Mediterranean, where NATO&#39;s southern naval forces have historically been concentrated, but his real target was waters off Africa -- the most ungoverned maritime space in the world.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich knew the U. S. Navy couldn&#39;t do it alone, much less bring Africa&#39;s meager coast-guard-like navies up to snuff so they could do it on their own. So he quickly created a network of assets -- both public and private -- to manage that space, modeling his monitoring system on international air-traffic control.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich began stitching together a network of shore-based sensors ringing the Mediterranean. His naval command then began initial monitoring by tapping into the International Maritime Organization&#39;s existing Automated Identification System, transforming NATO&#39;s ability to track ship traffic in the Med.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Almost overnight, NATO went from tracking dozens of ships on the Mediterranean to thousands, and instead of getting the data sometimes up to 72 hours late, now the contacts were being tracked in one to five minutes -- to an accuracy within 50 feet on the earth&#39;s surface.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When the classic big-firm systems integrators told Ulrich it would be too costly to pull it off, the admiral turned to the Volpe Center in Cambridge, Massachusetts, a U.S. Department of Transportation research center. Instead of hundreds of millions of dollars, Ulrich&#39;s initial network cost $900,000. The shore-based receivers are small, roughly the size of a radar dish you might find on a pleasure craft.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The strength of the system is a function of its reach: the more countries join, the larger the shared operational picture. By the time Ulrich retired at the end of 2007, he had enlisted 32 countries throughout the Mediterranean, the North Atlantic, along the west coast of Africa, around the Black Sea, and in the Pacific. Today, the network continues to spread around the planet.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; font-size: 14px; line-height: 20px; "><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">With Ulrich&#39;s system in place, local police, coast guards, and border patrols catch most bad guys, obviating American military responses. As Harry told me for an article I wrote about his work in a fall 2007 issue of Esquire, </span><span style="font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;I don&#39;t do defense; I do security. When you talk defense, you talk containment and mutually assured destruction. When you talk security, you talk collaboration and networking. This is the future.&quot;</span></span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The admiral&#39;s legacy program, the Maritime Safety and Security Information System, earned the Volpe Center a prestigious &quot;Innovations in American Government&quot; award this month from Harvard University&#39;s Ash Institute for Democratic Governance and Innovation.</span></p></blockquote><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Security Collaboration + Networking &#160;= Federation. This is indeed the future - SAML came along just at the nick of time.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When you assume that to do access control you must have &quot;Complete Mediation&quot; in Saltzer and Schroeder&#39;s terms of the subject (users), the objects (data), the session, and the roles, then you are going to have an interesting life trying to deliver anything. And if you do it will mucho expensive.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">if you take the federated autonomous nodes approach, agree upon an attribute schema plus a protection model for same, and basic protocol, you are then free to move about the country. Security doesn&#39;t have to equal centralization or high cost. Get the attributes from point a to point b securely.</span></div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 19:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architect">security architect</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/identification system">identification system</category>
      <category domain="http://securityratty.com/tag/initial network cost">initial network cost</category>
      <category domain="http://securityratty.com/tag/initial">initial</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/ulrich">ulrich</category>
      <category domain="http://securityratty.com/tag/time ulrich">time ulrich</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/of-planes-and-ships.html">Of Planes and Ships</source>
    </item>
    <item>
      <title><![CDATA[Inc 500/5000 Conference Summary]]></title>
      <link>http://securityratty.com/article/9368d02fff1906cea272fe55093a6965</link>
      <guid>http://securityratty.com/article/9368d02fff1906cea272fe55093a6965</guid>
      <description><![CDATA[It didnt really sink in until after the final black-tie awards ceremony finished last Saturday night that I had a chance to comprehend how starting a company that achieves this list is a once in a...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/slinc5002.jpg" border="0" alt="slinc5002" width="240" height="181" align="left" /> It didn’t really sink in until after the final black-tie awards ceremony finished last Saturday night that I had a chance to comprehend how starting a company that achieves <a href="http://www.inc.com/inc5000/">this list</a> is a once in a lifetime experience.</p>
<p>When I walked up on stage and accepted the <a href="http://www.inc.com/inc5000/2008/company-profile.html?id=200803500" target="_blank">Inc 500 award</a>, it hit me square in the face that this is a rare accomplishment, and even more difficult for a product company that started without the benefit of VC funding.</p>
<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/slinc5003.jpg" border="0" alt="slinc5003" width="240" height="181" /><br />
<em>Dave with wife, Anne, at the awards ceremony</em><br />
Over <a href="http://blog.inc.com/inc5000/" target="_blank">the 2 day period</a>, I heard from some <a href="http://secure.lenos.com/lenos/inc/Inc500WashingtonDC/speakers.asp" target="_blank">great speakers with entrepreneurial passion</a>, many who never had accomplished making the list. It is so <a href="http://www.prospectmx.com/inc-500-conference-and-awards" target="_blank">highly competitive and just plain hard</a> to do.</p>
<p>I loved <a href="http://blog.sciencelogic.com/good-to-great-built-to-last-whats-next-for-creating-great-companies/09/2008" target="_blank">hearing</a> some of the <a href="http://www.business-opportunities.biz/2008/09/24/inside-small-biz-guru-michael-gerbers-dreaming-room/" target="_blank">speeches during the conference</a> and getting to know other <a href="http://www.johnwinsor.com/my_weblog/2008/09/inc-500.html" target="_blank">entrepreneurs that attended</a> the conference talk about how they created their niche and ultimately built a successful company from a good idea.</p>
<p>Because I enjoyed hearing some of what I like to call &#8220;golden nuggets of wisdom&#8221; so much, I thought in my conference wrap-up I would pass on a few to our blog readers:</p>
<p><strong></strong></p>
<p><strong><a href="http://www.tompeters.com/" target="_blank">Tom Peters – Author In Search of Excellence and The New World of WOW</a></strong></p>
<p>“Only 7% of our great nation works for Fortune 500 companies. Small businesses and the <a href="http://www.jonlowder.com/2008/09/why-i-havent-be.html" target="_blank">entrepreneurs are the jet fuel</a> that makes our country fly.”</p>
<p>“Brand is shorthand for a collection of experiences, memories of what it will be like the next time a customer deals with you. With the <a href="http://www.debbieweil.com/blog/tom-peters/" target="_blank">advent of blogs and consumer activism</a>, Brand is impossible to fake; it is like the temperature in the room… it is there… it exists.”</p>
<p><strong><a href="http://www.carrots.com/" target="_blank">Chester Elton – SVP Carrot Culture Group</a></strong></p>
<p>“At the casino – they train the heck out of the Valet! Why do they spend 3 months on Valet training? Because he is the first and the last person to greet and interact with a visitor during their trip! Who is your company Valet?”</p>
<p><strong><a href="http://www.ideo.com/search/cluster/paul-bennett/" target="_blank">Paul Bennett – Chief Creative officer IDEO</a> – speaking on &#8212; Creating a culture of optimism:</strong></p>
<p>“You need to ditch B-B and B-C Need to become P-P Person to Person.”</p>
<p>“You don’t buy loyalty… you earn it… this is an interesting challenge, but small allows us to behave like human beings… Going off script and doing something human is a great place to start.”</p>
<p>“Stop obsessing about ROI and start obsessing about ROC! Return on Customer/Consumer is much more powerful than ROI!!!!”</p>
<p>“Happy people, unabashedly doing, happy things, makes for happy companies, which create happy businesses which enable happy cultures… IN WHICH THRIVE”</p>
<p><strong><a href="http://carlson.umn.edu/Page5365.aspx" target="_blank">Marilyn Carlson Nelson – Chairman and CEO Carlson Companies</a> – A family owned $40 Billion empire including TGI Fridays, Radisson Hotels…</strong></p>
<p>“My leadership was tested terribly - after 9/11 the travel industry was particularly harmed. It was an extraordinary time for Carlson. “</p>
<p>“Put tactics around these strategic initiatives”</p>
<ul>
<li>Whomever you serve, serve with caring</li>
<li>Whenever you dream – dream with your all</li>
<li>Wherever you go, go as a leader</li>
<li>And never, never give up</li>
<li>Whatever you do – do it with integrity</li>
</ul>
<p>“That builds trust, trust builds relationships and relationships build results.”</p>
<p>=============================================</p>
<p>Actually, I took about 40 pages of notes throughout the two days… So I can’t say that this will be my last summary post on the Inc 500/5000 conference, but I can say that the conference did leave a strong impression about how I can help shape the future of ScienceLogic in an even more positive way.</p>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 14:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/happy companies">happy companies</category>
      <category domain="http://securityratty.com/tag/happy">happy</category>
      <category domain="http://securityratty.com/tag/successful company">successful company</category>
      <category domain="http://securityratty.com/tag/happy businesses">happy businesses</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/product company">product company</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/ceo carlson companies">ceo carlson companies</category>
      <source url="http://blog.sciencelogic.com/inc-5005000-conference-summary/09/2008">Inc 500/5000 Conference Summary</source>
    </item>
    <item>
      <title><![CDATA[Two Copycat Web Malware Exploitation Kits in the Wild]]></title>
      <link>http://securityratty.com/article/59660edd6ee56561c03dbddbfcbaac92</link>
      <guid>http://securityratty.com/article/59660edd6ee56561c03dbddbfcbaac92</guid>
      <description><![CDATA[We're slowly entering into &quot;can you find the ten similarities&quot; stage in respect to web malware exploitation kits, and their coders continuous supply of copycat malware kits under different names,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNqBEcPBZZI/AAAAAAAACLA/AJVrNj6P8JE/s1600-h/zopa01.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNqBEcPBZZI/AAAAAAAACLA/of0mCvvFn4o/s200-R/zopa01.JPG" /></a>We're slowly entering into "can you find the ten similarities" stage in respect to web malware exploitation kits, and their coders continuous supply of copycat malware kits under different names, taking advantage of different exploits combination. <a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat web malware exploitation kits are faddish</a>, however, from a strategic perspective, releasing exploits kits like this one <a href="http://www.trustedsource.org/blog/153/Rise-Of-The-PDF-Exploits">covered by Trustedsource</a>, consisting entirely of PDF exploits, can greatly increase the exploitability level of Adobe vulnerabilities in general.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqC_oeGqgI/AAAAAAAACLI/tCvdE7XRFt4/s1600-h/zopa02.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqC_oeGqgI/AAAAAAAACLI/iSGUOgS9ZUg/s200-R/zopa02.JPG" /></a>A similar web malware exploitation kit, once again using only Adobe related exploits is Zopa. Have you seen this layout before? That's the very same layout <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack</a> and <a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">IcePack</a> were using, were in the sense of cybercriminals preferring to use much mode modular alternatives these days. Ironically, Zopa is more expensive than MPack and IcePack, with the coder trying to cash-in on its biased exclusiveness and introduction stage buzz generated around it.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqFtIcwL7I/AAAAAAAACLQ/ZTdoCdSNYbA/s1600-h/stats_copycat_kit.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="200" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqFtIcwL7I/AAAAAAAACLQ/aGd-dPNq3TY/s200-R/stats_copycat_kit.jpg" width="151" /></a>The second web malware exploitation kit is relying on a mix of exploits targeting patched vulnerabilities affecting IE, Firefox and Opera, with its authors asking for $50 for monthly updates, updates of what yet remains unknown. Both of these kits once again demonstrate the current&nbsp; mentality of the kit's coders having to do with -- thankfully -- zero innovation, fast cash and no long-term value.<br />
<br />
However, modularity, convergence with traffic management kits, vertical integration with cybercrime services and bullet proof hosting providers, advanced metrics, <a href="http://securitylabs.websense.com/content/Blogs/3183.aspx">evasive practices</a>, improved OPSEC (operational security), and dedicated cybercrime campaign optimizing staff, are all in the works.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web  Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY  Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch  Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The  Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware  in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The  FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack  and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The  Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The  FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The  FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The  WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The  Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The  Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google  Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The  IcePack Malware Kit in Action</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H3UxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H3UxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p3TZL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p3TZL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2h0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2h0l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LBCnl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LBCnl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ntatL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ntatL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AnrYL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AnrYL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0AlHl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0AlHl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402081047" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 10:28:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diy botnet kit">diy botnet kit</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear grabber kit">nuclear grabber kit</category>
      <category domain="http://securityratty.com/tag/apophis kit">apophis kit</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/control kit">control kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402081047/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: CSIRO Wins Patent Appeal; Zune-Fi in SF; Kodak ESP 9]]></title>
      <link>http://securityratty.com/article/95aa70e977b254cabeb9c3b2679b4b8d</link>
      <guid>http://securityratty.com/article/95aa70e977b254cabeb9c3b2679b4b8d</guid>
      <description><![CDATA[Australian tech office wins appeal: Buffalo sinks further into the hole as it loses its appeal against a judgement over its use of what the Australian CSIRO technical agency asserts is its patented...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.zdnet.com.au/news/hardware/soa/CSIRO-victorious-in-Wi-Fi-appeal/0,130061702,339292134,00.htm?omnRef=1337"><strong>Australian tech office wins appeal:</strong></a> Buffalo sinks further into the hole as it loses its appeal against a judgement over its use of what the Australian CSIRO technical agency asserts is its patented technology used in all 802.11 implementations. The case, in the patent-holder-friendly US Eastern District Court of Texas--a venue that may be dethroned as a <em>forum coveniens</em> for patentholders' suits in new legislation--prevents Buffalo from importing or selling gear in the US with Wi-Fi technology embedded. In Japan, the patent office threw out CSIRO's patent. While Cisco paid CSIRO as the result of an acquisition of an Australian company a few years ago, most US-based technology giants are involved in resisting the patent's continued validation and enforcement. I've read the patent and some of the suits, and as a non-patent expert, it's clear CSIRO original invention didn't cover what's at stake. However, CSIRO was allowed in a subsequent filing to extend its patent to cover already-in-use technology in a way that seems odd to me, but happens in patents all the time. Many millions of dollars and many more years may be expended before a resolution happens. CSIRO apparently isn't asking for insane fees, although anything paid to them would be passed along to consumers. If companies settled, this might result in an increase of 1 to 5 percent on retail prices. It may ultimately effect WiMax, too, though no suits in that area have been filed.</p>

<p><a href="http://news.cnet.com/8301-10805_3-10046542-75.html"><strong>Finding Zune-Fi:</strong></a> Ina Fried of News.com wanders the polite streets of San Francisco in search of Zune connections over Wi-Fi. She finds a few, and has a good experience. One cafe owner sees the ease with which she can stream music and calls it cool. She can't connect at the long-running Google-sponsored free Wi-Fi at Union Square, however, which means the Wi-Fi likely has an accept button that must be pressed. Surely Microsoft could insert a little technology that would allow a browser-free acceptance of terms? Probably involves Yet Another Protocol: the Wi-Fi Terms Browser-Free Presentation Protocol (WTBFPP).</p>

<p><img src="http://wifinetnews.com//images/2008/kodakesp9.jpg" alt="kodakesp9.jpg" border="0" width="150" height="120" align="right" /><a href="http://www.kodak.com/eknec/PageQuerier.jhtml?pq-path=13572&pq-locale=en_US"><strong>Kodak adds interesting Wi-Fi enabled all-in-one:</strong></a> The new Kodak ESP 9 is a multi-function printer (fax, scan, print, copy) that connects to a network via Wi-Fi or Ethernet. The $300 device spits out 30 pages per minutes in color, 32 ppm in black only. Kodak claims that the model line to which the ESP belongs uses ink in a vastly more efficient manner than the "average of comparable consumer inkjet printers." </p>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 05:53:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csiro">csiro</category>
      <category domain="http://securityratty.com/tag/patent">patent</category>
      <category domain="http://securityratty.com/tag/cover">cover</category>
      <category domain="http://securityratty.com/tag/cover already-in-use technology">cover already-in-use technology</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/kodak">kodak</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wi-fi technology">wi-fi technology</category>
      <source url="http://wifinetnews.com/archives/008452.html">Wee-Fi: CSIRO Wins Patent Appeal; Zune-Fi in SF; Kodak ESP 9</source>
    </item>
    <item>
      <title><![CDATA[Wakeup Call for Risk Management]]></title>
      <link>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</link>
      <guid>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</guid>
      <description><![CDATA[Blogger: Dan Blum
With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of risk management, it’s important to understand more about what happened, and then draw some parallels to our business risk management and&nbsp; IT risk management situations.</p>

<p>The risk management failure in the housing market and on Wall Street had multiple interdependent dimensions:</p>

<ul><li><strong>Mortgage lenders abandoned long standing prudent loan practices</strong>. They made too many loans that buyers might not be able to repay. Exotic instruments like ARMs, option ARMs, and interest only loans proliferated. In many cases, all pretense of lending standards were abandoned, so-called “liar loans” approved.</li>

<li><strong>Capital was grossly over-leveraged</strong>. Mortgage lenders and other financial services packaged loans into securities, which they sold to raise capital to support more lending. Real capital reserve requirements to back loans were reduced. Of course, if borrowers could not repay loans, all or parts of the derivative securities would become worthless.</li>

<li><strong>Risk was aggregated at Fannie Mae, Freddie Mac, and mortgage loan insurance companies</strong>. These companies bought or insured some mortgage loans, providing something of a backstop should loans fail. Government sponsored enterprises (GSEs) Fannie and Freddie in turn became over-leveraged and securities that they sold were in turn repackaged in the murky brew of mortgage-backed securities called collateralized debt obligations (CDOs) and other exotic instruments returning generous yields. </li>

<li><strong>Non-Caveat Emptor.</strong> Institutional wealth funds and financial services firms who should have known better bought securities that had been deliberately structured to obfuscate risk. They bought securities they didn’t understand with buried tranches of toxic subprime loans..</li></ul>

<p>It was a great Ponzi scheme – one that kept working as long as housing prices were going up; the recipients of subprime loans could always flip that house to the next buyer. Everyone made money. As Chuck Prince of Citigroup famously put it during <a href="http://search.ft.com/ftArticle?sortBy=gadatearticle&amp;queryText=chuck+prince+dancing&amp;y=0&amp;aje=true&amp;x=0&amp;id=070710000610&amp;ct=0&amp;page=6&amp;nclick_check=1">a July, 2007 interview</a>: “So long as the music is playing, you’ve got to keep dancing. We’re still dancing.” But one month later, the music stopped. Since then, Citigroup and other financial institutions have taken massive writeoffs with more to come. Wall Street titans like Bear Sterns, Lehman Brothers, Merrill Lynch, and AIG have fallen or been bought out.</p>

<p>What can we learn from this risk management debacle?</p>

<p>As business risk managers and investors, we should ask questions like these:</p>

<ul><li><strong>Does the executive incentive structure of the company encourage managers to dance around risk?</strong> Many Wall Street firms paid senior managers 5 times their salary in bonuses tied to annual growth alone.</li>

<li><strong>Is the company over-leveraged?</strong> Is it borrowing too much money and betting it on ventures with uncertain outcomes?</li>

<li><strong>Are financial models used for risk management realistic?</strong> Earlier, I described the mortgage market of the past few years as a Ponzi scheme, where risk management models must have assumed prices would keep rising. Unlike the dotcom boom whose demise many predicted, very few in the industry foresaw the sharp declines to come in housing prices and sales volumes. Historically, the U.S. housing market has been a steadily rising one, but on the other hand the 2000s saw unprecedented rates of price increases. In reality, what goes up must come down. </li>

<li><strong>Has your company’s risk council ever performed worst case scenario analysis and built adequate reserves?</strong> In the days before economics emerged as a would-be “hard” deterministic science, business leaders may have been more cautious, more aware of and more accepting of uncertainty. Events like the Great Tulip Bubble came once in decades or centuries – not every few years. Note that legendary investor George Soros has proposed a Theory of Reflexivity that, if true, helps explain the recent extremes of boom and bust cycles. This theory holds that market participants model market behaviors based on self-interest, and for a time, their manipulations change the reality of the market – until gravitational forces bring it back to earth. Has the music of ephemeral success played to the backbeat of deterministic-sounding economic models gone to your heads and infected your risk management models? </li>

<li><strong>Are cost cutting efforts pursued blindly?</strong> Outsourcing and other forays into treacherous global waters may be giving away the crown jewels. Smart companies cut costs, but they do it in smart ways. Smart companies think like intelligence agencies as they parcel out work to different partners with varying levels of dependability, and they check on those partners.</li></ul>

<p>Risk management failures can also occur at the more technical level of IT security. As IT risk managers, we might ask questions like these:</p>

<ul><li><strong>Are the accounting and financial systems your IT department supports under adequate control?</strong> As Fred Cohen wrote in <a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=750">one of our documents</a>: “Many companies use computers to manage financial systems, and despite the Sarbanes-Oxley Act (SOX) claims about accounts being properly kept, there are many attacks on financial systems that remain. For example, most of the largest financial systems in the world running on common financial databases do not use <a href="http://en.wikipedia.org/wiki/Double-entry_bookkeeping">double-entry bookkeeping</a> and are thus susceptible to all manner of frauds by insiders.” We find it troubling that a prudent control dating back to the 12th century is going out of style in the name of convenience and cost cutting. Kind of like credit checking became anachronistic during the housing bubble, eh?</li>

<li><strong>Is the “separation” in your “separation of duty” (SoD) for real?</strong> Sure the SOX auditors are looking for SoD, and maybe you have different administrators with different accounts maintaining different systems or functions. But when they say Western civilization may be but one weak password from collapse they’re not lying. Look what happened to Sarah Palin’s email account! Weak and straggly SoD is a problem across all critical IT systems where deperimiterization and server consolidation may be bringing down protective barriers, identity management is weak, and strong process controls (e.g., where two people must sign on, one perform a critical operation such as backbone router reconfiguration, and the second observe) abandoned in the name of expediency. </li>

<li><strong>Are risks being aggregated to unacceptable levels in centralized control systems?</strong> There are many ways that risks aggregate within enterprise IT infrastructures as we pursue automation and cost cutting. Network risks aggregate when centralized domain name system control is implemented. Application risks aggregate when common infrastructure is shared among applications. And enterprises aggregate platform risks when they use low-assurance endpoints, authentication, and directory systems with single sign-on to access large numbers of resources and don’t separate high consequence systems. </li>

<li><strong>Non-caveat emptor:</strong> Has IT security really done the worst case consequence analysis, attack graphs, and vulnerability analysis to know when putting more eggs in a supposedly stronger basket aggregates risks to an unacceptable level? Or are you depending only on vendor claims about some black box appliance equivalent of a risk-obfuscated CDO security? Caveat emptor (buyer beware) again! (The good news is we’ll keep talking about promoting vendor and product rating systems so you don’t have to do all the detailed product analysis yourself, but that’s another post.)</li></ul>

<p>There are many parallels between the monumental risk management failure in the financial markets, and the probable weaknesses in our day to day business risk management and IT risk management. Abandonment of prudent practices for profit; excessive leverage and centralization; ill-constructed risk analysis models; risk obfuscation; and a failure of caveat emptor seem to be common problems. Please take this as a wakeup call to sharpen up the risk management thinking, process, and execution.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/397240912" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management debacle">risk management debacle</category>
      <category domain="http://securityratty.com/tag/risk management failure">risk management failure</category>
      <category domain="http://securityratty.com/tag/failure">failure</category>
      <category domain="http://securityratty.com/tag/risk management realistic">risk management realistic</category>
      <category domain="http://securityratty.com/tag/business risk management">business risk management</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management situations">risk management situations</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/397240912/wakeup-call-for.html">Wakeup Call for Risk Management</source>
    </item>
    <item>
      <title><![CDATA[VMworld 2008 Keynote with Paul Maritz]]></title>
      <link>http://securityratty.com/article/27088f9fffd4d9e8619b6768dd0513fa</link>
      <guid>http://securityratty.com/article/27088f9fffd4d9e8619b6768dd0513fa</guid>
      <description><![CDATA[Traveling towards VMworld 2008
I, along with thousands of others, wended my way through a vast dimly lit cavern of a place helped along by the strangely surreal sight of ushers in black waving wispy...]]></description>
      <content:encoded><![CDATA[<p><em><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px; border-right-width: 0px" height="160" alt="paulmaritzvmware" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/paulmaritzvmware.jpg" width="240" align="left" border="0" /> Traveling towards VMworld 2008</em></p>
<p>I, along with thousands of others, wended my way through a vast dimly lit cavern of a place helped along by the strangely surreal sight of ushers in black waving wispy red flags to guide us not to the empty seats in front of us, but to the ones 50 yards on. (Ah Vegas, my feet hurt already.) Perhaps the point was to live in the moment, soak in the pre-rock concert atmosphere complete with a hip and cool soundtrack ripped off from Apple commercials. (Do they all use the same ad firm?) A better way to build the anticipation for, yes, the kickoff keynote session at <a href="http://www.vmworld.com/conferences/2008/" target="_blank">VMworld 2008</a>. (<em><a href="http://www.flickr.com/photos/jumpingshark/2862470725/" target="_blank">photo credit: lodev</a>)</em></p>
<p>To the sounds of <a href="http://www.youtube.com/watch?v=PEinqCHPY08" target="_blank">Hey Ya</a> (Shake it like a Polaroid picture), we shifted forward in our uncomfortable temporary seating placed, as at all tech conferences, too close for all but the skinny girls. The moment was here &#8211; one of those videos started playing on the dozen or so huge monitors floating above the convention crowd. You know this video; you&#8217;ve probably seen it before from HP or someone like that. One of those videos with instrumental Coldplay music in the background with time <a href="http://www.hp.com/hpinfo/newsroom/hpads/" target="_blank">lapse/speeded-up video</a> of people in motion and floating captions dropping into the images that leave you with a slight smile on your face as you &#8220;get&#8221; the relationship between image and text. (Do they all use the same ad firm?)</p>
<p>And here he is, announced like a Vegas headliner, <a href="http://vmblog.com/archive/2008/07/23/forbes-interviews-vmware-ceo-paul-maritz-after-financial-analyst-call.aspx" target="_blank">Paul Maritz, the new CEO of VMware</a>. Hmm. After all that hype, I rather expected someone in a black turtleneck and jeans to come out. Instead here&#8217;s this guy with pleat-front pants and an admittedly cool accent (New Zealand?) who looks a little like Al from Home Improvement. Not that there&#8217;s anything wrong with that &#8211; everyone likes Al.</p>
<p><em>And then the real fun begins.</em></p>
<ul>
<li>30 years ago, Paul Maritz started off his business career as a developer </li>
<li>10 years ago, VMware was founded by <a href="http://blog.sciencelogic.com/diane-greene-ousted-from-vmware/07/2008" target="_blank">Diane</a> <a href="http://virtualization.com/news/2008/07/08/diane-greene-vmware-paul-maritz/" target="_blank">Greene</a> and <a href="http://www.cio-weblog.com/50226711/found_rosenblum_leaves_vmware.php" target="_blank">Mendel</a> <a href="http://blog.sciencelogic.com/another-vmware-founder-leaves/09/2008" target="_blank">Rosenblum</a> (BTW, 10 seconds spent showing a slide with cartoon-ized images of the founders, &#8220;thanks for what you did for the company for the past 10 years&#8221;. 10 seconds after 10 years&#8230;but maybe more would have been hypocritical&#8230;) </li>
<li>a retrospective of centralized vs. decentralized computing initiatives from the 1960&#8217;s to today </li>
<li>of course VMware milestones from 1998 to today </li>
<li>and then an analyst-ready diagram showing the product roadmap (to be delivered in 2009) with, you guessed it, finally a connection between <a href="http://advice.cio.com/laurianne_mclaughlin/vmworld_ceo_maritz_outlines_broad_plans_for_cloud_and_client" target="_blank">VMware and cloud computing</a> (remember Maritz&#8217;s cloud-computing company was bought by EMC just a couple of years ago and that&#8217;s the section he headed up at EMC before being brought into VMware). </li>
</ul>
<p><em>Forward Looking</em></p>
<p>2008 (and probably much of 2009) will be a very busy year for VMware. If you believe the roadmap, <a href="http://www.uberpulse.com/us/2008/09/vmwares_ambitious_expansion_plan.php" target="_blank">VMware seems to be taking on the management of everything</a> &#8211; from chargeback and capacity planning to virtual storage and virtual networking (more to come on just what the planned vStorage and vNetwork will deliver) &#8211; but all of it VMware-centric. As <a href="http://blog.sciencelogic.com/vmware-is-better-than-microsoft/09/2008" target="_blank">we said in an earlier post,</a> they&#8217;ve moved away from &#8220;defending&#8221; the hypervisor business proposition to focusing on management services on top of their own hypervisor platform. Revenue pressures must be excruciating &#8211; who wants to be a public company these days?</p>
<p>The best part of that new &#8220;Virtual Data Center Operating System&#8221; <a href="http://www.vmware.com/technology/virtual-datacenter-os/" target="_blank">diagram/roadmap</a> was the addition (and I mean addition) of something called <a href="http://vmetc.com/2008/09/16/vmwares-vcloud-iniatives-the-vision-for-the-next-10-years/" target="_blank">Cloud vServices</a>. (Did anyone else find it odd that <a href="http://virtualization.com/news/2008/09/15/vcloud-vmware-to-be-cloud-computing-provider-too-but-inside-your-private-dc-and-not-tomorrow/" target="_blank">Cloud vServices</a> is kind of on its own in the Infrastructure vServices area? AND, I&#8217;ll have to get the other version of the diagram/roadmap I actually saw at the show because that one shows an inexplicable 4<sup>th</sup> box in the Application vServices area titled &#8220;&#8230;&#8221;. Really. Maybe to balance out the addition of <a href="http://www.itpro.co.uk/606237/vmwares-paul-maritz-goes-on-offence" target="_blank">Cloud vServices?</a>)</p>
<p>What was clear is that the move from VirtualCenter to vCenter &#8211;and the new vServices for rolled-up management of <a href="http://www.virtualization.info/2008/09/live-from-vmworld-2008-day-2-vmware.html" target="_blank">virtualization components</a>/capability to span multiple <a href="http://blogs.zdnet.com/virtualization/?p=542" target="_blank">VirtualCenters</a> (or future vCenters) for reporting, monitoring and management at scale &#8211; has been in the works for a bit (but in tech time, that could mean 6 months), but the cloud stuff&#8230;not so much.</p>
<p>Beyond the very high-level speak appropriate to a keynote (100+ service provider partners for off-premise cloud&#8230;suspended VM&#8217;s that you don&#8217;t have to pay for until you need it), the details are uber-fuzzy. There was a session that Dave went to which was supposed to shed more light, but when questions were asked about how it really works, the answers seemed to be TBD. Does anyone know more? If VMware really has figured out practical cloud computing for enterprises, kudos to them. But I fear they&#8217;re <a href="http://news.cnet.com/8301-13505_3-10042463-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">like everyone else</a> (except maybe AT&amp;T) and are still working out the details.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 15:00:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vservices">vservices</category>
      <category domain="http://securityratty.com/tag/infrastructure vservices">infrastructure vservices</category>
      <category domain="http://securityratty.com/tag/cloud vservices">cloud vservices</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware milestones">vmware milestones</category>
      <category domain="http://securityratty.com/tag/keynote">keynote</category>
      <category domain="http://securityratty.com/tag/vmware-centric">vmware-centric</category>
      <category domain="http://securityratty.com/tag/paul maritz">paul maritz</category>
      <source url="http://blog.sciencelogic.com/vmworld-2008-keynote-with-paul-maritz/09/2008">VMworld 2008 Keynote with Paul Maritz</source>
    </item>
    <item>
      <title><![CDATA[Adi Shamir's Cube Attack Paper is Online]]></title>
      <link>http://securityratty.com/article/b3b1de1d61f9f3721cb08be50933a666</link>
      <guid>http://securityratty.com/article/b3b1de1d61f9f3721cb08be50933a666</guid>
      <description><![CDATA[The cube attack paper, discussed here , is online: I. Dinur and A. Shamir, &quot; Cube Attacks on Tweakable Black Box Polynomials ,&quot; Cryptology ePrint Archive: Report...]]></description>
      <content:encoded><![CDATA[<p>The cube attack paper, discussed <a href="http://www.schneier.com/blog/archives/2008/08/adi_shamirs_cub.html">here</a>, is online:  I. Dinur and A. Shamir, "<a href="http://eprint.iacr.org/2008/385">Cube Attacks on Tweakable Black Box Polynomials</a>," Cryptology ePrint Archive: Report 2008/385.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FlLlL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FlLlL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BhkCL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BhkCL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Sun, 14 Sep 2008 13:21:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cube attack paper">cube attack paper</category>
      <category domain="http://securityratty.com/tag/cryptology eprint archive">cryptology eprint archive</category>
      <category domain="http://securityratty.com/tag/cube attacks">cube attacks</category>
      <category domain="http://securityratty.com/tag/shamir">shamir</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/dinur">dinur</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/adi_shamirs_cub_1.html">Adi Shamir's Cube Attack Paper is Online</source>
    </item>
    <item>
      <title><![CDATA[Adapting to Shelf Life]]></title>
      <link>http://securityratty.com/article/ea6547aa3e5e239ba69d1907590564e9</link>
      <guid>http://securityratty.com/article/ea6547aa3e5e239ba69d1907590564e9</guid>
      <description><![CDATA[Dan Pritchett blogged about Architectural Shelf Life - &quot;The duration that a collection of patterns and technology are applicable when starting a new system design.&quot; He argues that this changes about...]]></description>
      <content:encoded><![CDATA[<p>Dan Pritchett blogged about <a href="http://www.addsimplicity.com/adding_simplicity_an_engi/2008/08/architectural-s.html">Architectural Shelf Life</a> - &quot;The duration that a collection of patterns and technology are applicable when starting a new system design.&quot; He argues that this changes about every 5 years which is pretty fast when you think about it. Our story on the security is measured in decades not years. Kerberos, certificates, RSA, and other workhorse technologies are relatively unchanged since the 70s and 80s. So we security folk are multiple iterations behind developers.</p><div><br />

<a href="http://1raindrop.typepad.com/photos/uncategorized/2008/05/19/innovatecompare_2.png"><img alt="Innovatecompare_2" border="0" height="167" src="http://1raindrop.typepad.com/1_raindrop/images/2008/05/19/innovatecompare_2.png" title="Innovatecompare_2" width="300" /></a><p></p>
</div><div>Out of this comes the need for two things - one we need to innovate at a much higher rate, but equally important, we need better deployment models. The primitives we have that actually work need to be engineered better to form fit to the rapidly changing software side. Its not good enough to say &quot;<a href="http://1raindrop.typepad.com/1_raindrop/2007/10/sacred-cow-gore.html">we have it all figured out</a>&quot;, we have to apply the stuff that works to real software architectures. Why is the a dab of firewalls and SSL still our answer after all these years?</div><br /><div>Two case studies of where security technologies were adapted to technical realities to provide effective security mechanisms in the real world are SAML, which learned a lot from Kerberos and then applied it to the Web and XML; WS-Trust/STS, which owes a lot to SDSI/SPKI and applied it to Web services/XML plumbing.</div><br /><div>Software security is starting to grow as an industry. But a lot of the answers I hear and see in the field are predicated on &quot;we want to reengineer the entire SDLC&quot;, etc. sometimes what is really needed is evolution not revolution, and an easy to use adapter that ships in a few weeks...I remember <a href="http://1raindrop.typepad.com/1_raindrop/2005/12/the_road_to_ass.html">Brian Snow&#39;s</a> talk at black hat several years ago when he talked about how the NSA putting certificate checks in all calls to the Solaris kernel. Its not all about new primitives, its also about finding the art of the possible of what we can do with what we already have. Chief among these is adapting to technical realities.</div>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 06:22:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security technologies">security technologies</category>
      <category domain="http://securityratty.com/tag/real software architectures">real software architectures</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/security folk">security folk</category>
      <category domain="http://securityratty.com/tag/technical realities">technical realities</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/web servicesxml">web servicesxml</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/adapting-to-shelf-life.html">Adapting to Shelf Life</source>
    </item>
    <item>
      <title><![CDATA[In the News: Cloudburst, Black Hat Hack, Sex Drugs and Software]]></title>
      <link>http://securityratty.com/article/b824c0b40977a0631cff5e27a56d12b5</link>
      <guid>http://securityratty.com/article/b824c0b40977a0631cff5e27a56d12b5</guid>
      <description><![CDATA[Forget Your Password! Think your online passwords are secure? Think again. Not long ago, author Herbert H. Thompson asked some of his friends for their permission to let him break into their...]]></description>
      <content:encoded><![CDATA[Forget Your Password!&nbsp;Think your online passwords are secure? Think again. Not long ago, author Herbert H. Thompson asked some of his friends for their permission to let him break into their onli...]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 10:06:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online passwords">online passwords</category>
      <category domain="http://securityratty.com/tag/author herbert">author herbert</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/permission">permission</category>
      <category domain="http://securityratty.com/tag/thompson">thompson</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/onli">onli</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382697978/">In the News: Cloudburst, Black Hat Hack, Sex Drugs and Software</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kits are Faddish]]></title>
      <link>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</link>
      <guid>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</guid>
      <description><![CDATA[For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/u4h7TuozLDI/s1600-h/copycat_web_malware_exploitation_kit.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/H8HQ-QzSBfg/s200-R/copycat_web_malware_exploitation_kit.gif" /></a>For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained several moths later -- with all the related and royalty free updates coming with it, there are always the copycat malware kits like this one offered for $100.<br />
<br />
Taking into consideration the proprietary nature of some of the kits, the business model of malware kits was mostly relying on their exclusive nature next to the number, and diversity of the exploits included in order to improve the infection rate. This simplistic assumption on behalf of the coders totally <a href="http://blogs.zdnet.com/security/?p=1598">ignored the possibility of their kits leaking to the general public</a>, or copies of the kits ending up as a bargain in particular underground deal where the once highly exclusive kit was offered as a bonus.<br />
<br />
"Me too" web malware kits were a faddish way to enjoy the popularity of web malware kits like MPack and Icepack and try to cash in on that popularity by coming up average kits lacking any significant differentiation factors in the process. But just like the original and proprietary kits, whose authors didn't envision the long term growth strategy of integrating different services into their propositions or the kits themselves, the authors of copycat malware kits didn't bother considering the lack of long-term growth strategy for their releases. Branding in respect to releasing a Firepack malware kit to compete with Icepack which was originally released to compete with Mpack, has failed to achieve the desired results as well.<br />
<br />
And with malware kits now a commodity, and underground vendors excelling in a particular practice with the long term objective to vertically integrate in their area of expertise -- think spammers offering localization of messages into different languages and segmented email databases from a specific country -- would we witness the emergence of <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">managed cybercrime services</a> charging a premium for providing fresh dumps of credit card numbers, PayPal, Ebay accounts or whatever the buyer is requesting?<br />
<br />
That may well be the case in the long term.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The IcePack Malware Kit in Action</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jUilFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jUilFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LiAKxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LiAKxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GnpH1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GnpH1l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bjjwel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bjjwel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NAlZrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NAlZrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ybk3ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ybk3ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0j6X0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0j6X0l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382290326" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:18:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware kits">malware kits</category>
      <category domain="http://securityratty.com/tag/web malware kits">web malware kits</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/copycat malware kits">copycat malware kits</category>
      <category domain="http://securityratty.com/tag/proprietary kits">proprietary kits</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/long-term growth strategy">long-term growth strategy</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382290326/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</source>
    </item>
  </channel>
</rss>
