<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: bloggers]]></title>
    <link>http://securityratty.com/tag/bloggers</link>
    <description></description>
    <pubDate>Wed, 23 Jul 2008 03:58:05 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Qaida's Propaganda Sites, Smacked Down]]></title>
      <link>http://securityratty.com/article/35b2487d7628fa97495df483b9c3dcde</link>
      <guid>http://securityratty.com/article/35b2487d7628fa97495df483b9c3dcde</guid>
      <description><![CDATA[Al-Qaida's once-robust online propaganda network has taken a major hit. The release of a 9/11 anniversary video was delayed by nearly a week. And one of the most-popular video-distribution sites is...]]></description>
      <content:encoded><![CDATA[Al-Qaida's once-robust online propaganda network has taken a major
hit. The release of a 9/11 anniversary video was delayed by nearly a
week. And one of the most-popular video-distribution sites is
offline. One paper blames American bloggers. Online jihadists think
it was the CIA.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d233926e34c0879d23bad392564f0e4e" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d233926e34c0879d23bad392564f0e4e" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=FR0hL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=FR0hL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=hmzpl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=hmzpl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2P47l"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2P47l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zDjBL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zDjBL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=qRONL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qRONL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=a7b4l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=a7b4l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Du98l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Du98l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=8rtfL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=8rtfL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/395672669" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/395672670" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 18:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/online jihadists">online jihadists</category>
      <category domain="http://securityratty.com/tag/anniversary video">anniversary video</category>
      <category domain="http://securityratty.com/tag/major hit">major hit</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/cia">cia</category>
      <category domain="http://securityratty.com/tag/most-popular">most-popular</category>
      <category domain="http://securityratty.com/tag/release">release</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/395672670/al-qaedas-once.html">Qaida's Propaganda Sites, Smacked Down</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: Cloud Language: The Taxonomy of On-Demand Computing]]></title>
      <link>http://securityratty.com/article/69fa97ea284dec188b278c522ed18fd8</link>
      <guid>http://securityratty.com/article/69fa97ea284dec188b278c522ed18fd8</guid>
      <description><![CDATA[This session on cloud computing was presented by Peter Laird of Oracle Corporation. Peter is a lead architect for the WebCenter product family. He previously worked with BEA as an architect for SaaS...]]></description>
      <content:encoded><![CDATA[<p>This <a href="http://www.interop.com/newyork/conference/all-by-day.php?tag=Cloud+Computing" target="_blank">session on cloud computing</a> was presented by Peter Laird of Oracle Corporation. Peter is a lead architect for the WebCenter product family. He previously worked with BEA as an architect for SaaS efforts. He also blogs at <a href="http://peterlaird.blogspot.com/" target="_blank">Laird On Demand</a>.</p>
<p><strong>Defining Cloud Computing</strong></p>
<p>Cloud computing is a very active community. The <a href="http://groups.google.com/group/cloud-computing" target="_blank">Google Group</a> gets 600 posts per month and many bloggers are covering the space. However, &#8220;cloud computing&#8221; is impossible to define in a way that satisfies everyone (or even most). Cloud computing is not alone in this controversy, consider the definition and meaning of &#8220;Web 2.0&#8243;, &#8220;mashups&#8221; or &#8220;RESTful architecture&#8221;. All of these terms are relatively recent. According to Google Trends, these terms became popular to the general public sometime between 2005 and 2007:</p>
<ul>
<li>Web 2.0 - often confused with RIA, AKA Social Computing, Long-Tail Apps, Crowdware (2005 by O&#8217;Reilly Media)</li>
<li>Mashup - made popular by Google Maps, AKA Composite/Situational Apps. (2005)</li>
<li>REST - Has a strict definition, but many don&#8217;t understand it and abuse the term. (2006 by R. Fielding)</li>
<li>Cloud computing - collides with many other terms, such as SaaS, Grid, Utility, PaaS, etc. (2007)</li>
</ul>
<p>The definition of cloud computing is in progress:</p>
<blockquote><p>There&#8217;s a Darwinian evolution of the exact definition of cloud computing running around. We&#8217;re about a country mile away from &#8220;knowing when I see it&#8221;, which is excellent progress. The cloud to everyone&#8217;s silver-lining has enough material to write a 3 volume desktop reference at this point. - Michael Cote, June 2008</p></blockquote>
<p><strong>Definition #1</strong> - &#8220;Cloud computing is the realisation of Internet (&#8221;Cloud&#8221;) based development and use of computer technology (&#8221;Computing&#8221;) delivered by an ecosystem of providers. - Sam Johnston, July 2008</p>
<p><strong>Definition #2</strong> - &#8220;Cloud computing = network computing. I love the idea of cloud computing, the next evolution of the most network intensive architecture possible, but one that if it works well, is transparent. It&#8217;s all about the transparency.&#8221; - Douglas Gourlay, Cisco, May 2008</p>
<p><strong>Definition #3</strong> - &#8220;There seems to be a group myopia around so-called &#8220;cloud computing&#8221; and its definitions. What we&#8217;re really talking about are &#8220;cloud services&#8221; of which, &#8220;computing&#8221; is only a subset&#8230;Cloud services are not SaaS. They are far more akin to web services&#8230;&#8221; - Randy Bias, neoTactics, May 2008</p>
<p><strong>(Anti-)Definition #4</strong> - &#8220;Note that I refer to cloud services, not to the could. I am not interested in defining cloud as a term, because I don&#8217;t think it&#8217;s very useful. For those of us in the distributed computing&#8217;s pace</p>
<p><strong>The Working Definition (Winner!):</strong></p>
<p>&#8220;&#8230;the notion of providing easily accessible compute and storage resources on a pay-as-you-go, on-demand basis, from a virtually infinite infrastructure managed by someone else. As a customer, you don&#8217;t know where the resources are, and for the most part, you don&#8217;t care. What&#8217;s really important is the capability to access your application anywhere, move it freely and easily, and inexpensively add resources for instant scalability.&#8221; - Mitchell Crandell, Rightscale, June 2008</p>
<p><strong>Taxonomies of the Cloud Space</strong></p>
<p>Taxonomies are useful to provide insight into a market. It classifies a multitude of players into a smaller bucket.</p>
<p><em>Andreessen&#8217;s Platforms - September 2007</em></p>
<p>Provided an early taxonomy model for emerging cloud platforms</p>
<p>Platform being a system that can be programmed</p>
<ul>
<li>Access API - platform that provides web service endpoints</li>
<li>Plug-In API - platform invokes your code, that you have deployed remotely</li>
<li>Runtime Environment - your code runs inside the platform&#8217;s process space.</li>
</ul>
<p><em>Mehta 11 Layer Stack, April 2008</em></p>
<ol>
<li>Facilities (space, power, cooling)</li>
<li>Network</li>
<li>Hardware (e.g. servers Amazon EC2 runs)</li>
<li>Hardware virtualization (e.g. Xen for EC2) - optional</li>
<li>O/S (e.g. Linux)</li>
<li>Systems Management (e.g., tools to manage EC2 instances)</li>
<li>Application Middleware (e.g., MySQL on EC2)</li>
<li>Application Code</li>
<li>Application APIs / Web Services</li>
<li>GUI for Application</li>
<li>GUI for Application Development / Customization</li>
</ol>
<p><em>Croll Cloud Stack, June 2008</em></p>
<p>7 layer stack within Turnkey app and Generic Platform.</p>
<p><em>Turnkey app</em></p>
<ul>
<li>SaaS</li>
<li>Extensible app</li>
<li>Generic IDE</li>
<li>Constrained APIs</li>
<li>App Cluster</li>
<li>Virtual Data Center</li>
<li>Virtual Servers</li>
</ul>
<p><em>Generic Platform</em></p>
<p>The bottom of Alistair&#8217;s stack includes &#8220;root access &#8220;style compute clouds.</p>
<p><em>Robert Anderson, July 2008</em></p>
<p>3 layer stack</p>
<ul>
<li>Software (SaaS)</li>
<li>Platform (PaaS)</li>
<li>Infrastructure (IaaS)</li>
</ul>
<p>This is the model taxonomy for this session.</p>
<p><strong>Related Concepts and Terms</strong></p>
<ul>
<li>Infrastructure as a Service (IaaS), Hardware as a Service (HaaS) are synonyms to cloud infrastructure.</li>
<li>Virtualization</li>
<li>Hosting</li>
<li>Autonomic computing</li>
<li>Distributed computing</li>
<li>Grid computing</li>
</ul>
<p>Cloud Applications</p>
<ul>
<li>SaaS</li>
<li>S+S (Software+Services)</li>
<li>Managed Service Provider (MSP)</li>
</ul>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 14:25:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud applications">cloud applications</category>
      <category domain="http://securityratty.com/tag/croll cloud stack">croll cloud stack</category>
      <category domain="http://securityratty.com/tag/cloud infrastructure">cloud infrastructure</category>
      <category domain="http://securityratty.com/tag/platforms process space">platforms process space</category>
      <category domain="http://securityratty.com/tag/space">space</category>
      <category domain="http://securityratty.com/tag/cloud space">cloud space</category>
      <category domain="http://securityratty.com/tag/cloud platforms">cloud platforms</category>
      <category domain="http://securityratty.com/tag/cloud services">cloud services</category>
      <source url="http://blog.sciencelogic.com/interop-ny-cloud-language-the-taxonomy-of-on-demand-computing/09/2008">Interop NY: Cloud Language: The Taxonomy of On-Demand Computing</source>
    </item>
    <item>
      <title><![CDATA[How To Become A Security Blogger?]]></title>
      <link>http://securityratty.com/article/566eb8d7c8113949794dbf6e4eead107</link>
      <guid>http://securityratty.com/article/566eb8d7c8113949794dbf6e4eead107</guid>
      <description><![CDATA[I know, I know. Some might say that it is a silly question since you rarely seek to become a blogger - you just become one
However, I got a few emails from my readers asking me something along these...]]></description>
      <content:encoded><![CDATA[<p>I know, I know. Some might say that it is a silly question <strong>since you rarely <em>seek to become</em> a blogger - you just <em>become</em> one.</strong></p>  <p>However, I got a few emails from my readers asking me something along these line, thus this post. For example, I got asked &quot;Should I focus more on targeting security professionals or general IT users?&quot;, &quot;Any pitfalls I should be aware of?&quot; as well as general questions about how to start, what content is best, etc all the way to &quot;How did I profit from my blog?&quot;</p>  <p>&#160;</p>  <p><em>Q: Who should I blog to?</em></p>  <p>A: Blog to colleagues first i.e. infosecurity pros. Blogging to IT or general public is - in some sense - harder or - gasp! - will turn you into a journalist (someone who knows nothing about everything BUT writes about it as an &quot;expert&quot; :-)) Maybe you can broaden it later. <strong>Even better, write for YOU (!)</strong>     <br /></p>  <p><em>Q: What area of security I should focus my blogging on?</em></p>  <p>A: Focus on the area of security that you <strong>like the most or know them most</strong>: IDS? Patching? PIX administration? Linux? AD esoterica? Logs, maybe? :-) Then broaden if you feel like it or as you learn new areas</p>  <p>&#160;</p>  <p><em>Q: Any advice on site design, themes, etc?</em></p>  <p>A: Site design, themes, etc will all come later; just pick something basic and <strong>FOCUS on content</strong>, not on SEO, design, etc. MUST have RSS feed; make it highly visible (HTML is out, RSS is IN :-)) </p>  <p>&#160;</p>  <p><em>Q: Any security blogging pitfalls that I should avoid? Any other tips?</em></p>  <p><em>A:</em></p>  <ul>   <li>Don't stick to only long, deep posts? Unbelievably, people often prefer shorter posts or a mix of short/shallow and longer/deep posts (that came as a shock to me early on!)</li>    <li>Tips on how to do whatever useful work well; comments on hot issues (that you understand) works too for a shorter post.</li>    <li>Definitely comment on other bloggers posts (more often early on, later - as you wish...) </li>    <li>Avoid long breaks in blogging (&gt;7 days); it will&#160; lead to reader loss (you should only care about it later - focus on fun content first!)</li>    <li>Join Security Bloggers Network (drop an email to Alan Shimel for it) </li> </ul>  <p><em>Q:&#160; Has blogging in this niche generated any income for you? If so, how much?</em></p>  <p>A: Exactly $0. The reason is that I never wanted to &quot;monetize&quot; my blog;&#160; I don't have banners, etc. This is by design. </p>  <p><em>Q: How did it help your professional career in a significant way?</em></p>  <p>Yes, I think it helped my career and connected me to a lot of fun people! I sure hope I am not &quot;known only as as blogger&quot;, but blog can definitely make one much more known professionally, especially if you create fun and/or useful content.</p>  <p>Overall, blog is a time commitment, but it is also a passion. It does help your career, but &quot;forcing &quot; yourself to do it just for &quot;career benefits&quot; is,&#160; IMHO, a wrong approach.</p>  <p>Yo, my fellow bloggers; help the newbies out, will ya?! Let's start a series of posts on &quot;how to be a good security blogger!&quot;</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=HbVc3K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=HbVc3K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NtynTK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NtynTK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=iousXK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=iousXK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/378283723" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 07:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blogger">blogger</category>
      <category domain="http://securityratty.com/tag/security blogger">security blogger</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/bloggers posts">bloggers posts</category>
      <category domain="http://securityratty.com/tag/longerdeep posts">longerdeep posts</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/site design">site design</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/378283723/how-to-become-security-blogger.html">How To Become A Security Blogger?</source>
    </item>
    <item>
      <title><![CDATA[Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis]]></title>
      <link>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</link>
      <guid>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</guid>
      <description><![CDATA[Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned here , here ; SANS jumped in as well ), I decided to follow along and join the initiative. One of the bloggers called it...]]></description>
      <content:encoded><![CDATA[<p>Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/08/pay_it_forward__1.html">here</a>, <a href="http://mcwresearch.com/archives/265">here </a>; <a href="http://isc.sans.org/diary.php?storyid=1530&amp;rss">SANS jumped in as well</a>), I decided to follow along and join the initiative. One of the bloggers called it <a href="http://mcwresearch.com/archives/255">&quot;pay it forward</a>&quot; to the community.</p>  <p>So, Anton Security Tip of the Day #16: <strong>Virtually Screwed - Journey Into VMWare ESX Log Analysis</strong></p>  <p>CISecurty guide for VMWare (<u><a href="http://www.cisecurity.org/bench_vm.html">here</a></u>) and DISA STIG for virtual machines (<u><a href="http://iase.disa.mil/stigs/stig/index.html">here</a></u>) both mandate collection and analysis of VM platform logs; none goes into enough details on what to look for in logs. Let's try to shed some light on security-focused log analysis of VMWare ESX v. 3.x logs. </p>  <p>First, at least until ESXi becomes the default choice, one needs to keep in mind that ESX as &quot;Linux-inside&quot; and thus diving into <em>/var/log</em> will not reveal any &quot;alien technology&quot; (well, not much :-)). However, one of the most useful logs is <em>/var/log/hostd.N </em>which is not a descendant of Linux standard logs. Extensive VM event records are written into this file. </p>  <p>Let's focus on various types of logins to the ESX platform and identify logs that indicate a successful and failed attempts to log in. Here are a few useful examples to analyze:</p>  <p><strong>Successful logins:</strong></p>  <ul>   <li><em>May 30 09:20:42 esx2 su(pam_unix)[9405]: session opened for user root by jhonny(uid=1626)</em> </li> </ul>  <p>This is a classic Linux root login message; you can watch for these by searching VMWare ESX logs for &quot;session AND opened AND user AND root.&quot;&#160; Notice the user name of the user who switched to root.</p>  <ul>   <li><em>May 30 09:20:34 esx2 sshd(pam_unix)[9364]: session opened for user jhonny by (uid=0)</em> </li> </ul>  <p>This is also a classic Linux message for a normal (non-root) user login.</p>  <ul>   <li><em>[2008-05-25 06:57:48.774 'ha-eventmgr' 111639472 info] Event 40645 : User jhonny@1.1.1.1 logged in</em> </li> </ul>  <p>This is a VMWare -specific application login to ESX. You can track such events by username, by event ID or by keywords &quot;event AND logged AND user&quot; (if you are using search)</p>  <p><strong>Failed logins:</strong></p>  <ul>   <li><em>May 30 09:20:31 esx2 sshd[9356]: Failed password for jhonny from 1.1.1.1 port 54773 ssh2</em> </li> </ul>  <p>Another classic Linux message from the ESX system; a failure to login due to incorrect password. </p>  <ul>   <li><em>May 27 12:06:59 esx2 sshd[4756]: Failed password for illegal user jonny from 1.1.1.1 port 30594 ssh2</em> </li> </ul>  <p>A message indicating a failure to login due to incorrect username (note a typo). </p>  <ul>   <li><em>May 25 07:03:48 esx1 sudo:&#160;&#160;&#160;&#160; jhonny : 3 incorrect password attempts ; TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/bin/bash</em> </li> </ul>  <p>This ESX Linux platform message should also be familiar to Linux/Unix admins: it indicates multiple sudo password failures; look for such messages in the logs.</p>  <p>BTW, do you <a href="http://chuvakin.blogspot.com/2006/09/anton-security-tip-of-day-3-watch-for.html">need to be reminded</a> to track NOT only failed, but also successful login events?!</p>  <p>Overall, you must prepare for the future by learning to analyze&#160; VMWare logs, just like you handled &quot;legacy OS&quot;, such as Linux/Unix and Windows.</p>  <p>As I said before, I am tagging all the tips on <a href="http://del.icio.us/anton18">my del.icio.us feed</a>; here is the link: <a href="http://del.icio.us/anton18/security+tips">All Security Tips of the Day</a>.</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:54499c21-dd11-4ff7-9221-4cf2ec0c95fe" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/tips" rel="tag">tips</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a></div> <script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");<br />document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var pageTracker = _gat._getTracker("UA-101395-5");<br />pageTracker._initData();<br />pageTracker._trackPageview();</script>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fhl1bK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fhl1bK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xW7PtK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xW7PtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=qHcDbK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=qHcDbK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/374532539" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware esx">vmware esx</category>
      <category domain="http://securityratty.com/tag/analyze vmware logs">analyze vmware logs</category>
      <category domain="http://securityratty.com/tag/analyze">analyze</category>
      <category domain="http://securityratty.com/tag/vmware esx logs">vmware esx logs</category>
      <category domain="http://securityratty.com/tag/esx">esx</category>
      <category domain="http://securityratty.com/tag/security tip">security tip</category>
      <category domain="http://securityratty.com/tag/anton security tip">anton security tip</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/374532539/anton-security-tip-of-day-16-virtually.html">Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis</source>
    </item>
    <item>
      <title><![CDATA[Black Hat wrap up - secure@microsoft, booth babes and bloggers]]></title>
      <link>http://securityratty.com/article/bd7d7b3698d05a16a10cc4d0a21e2bfd</link>
      <guid>http://securityratty.com/article/bd7d7b3698d05a16a10cc4d0a21e2bfd</guid>
      <description><![CDATA[You can read plenty of other blogs about some of the great presentations at Black Hat. So I thought I would take another angle and talk about some of the other stuff that may be important to you
1....]]></description>
      <content:encoded><![CDATA[<p></p>  <p>You can read plenty of other blogs about some of the great presentations at Black Hat.  So I thought I would take another angle and talk about some of the other stuff that may be important to you.</p>  <p>1.  <a href="mailto:secure@microsoft.com"><font face="Courier"><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/Picture%20049.jpg"><img title="Picture 049" style="border-right: 0px; border-top: 0px; margin: 5px 10px 5px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="Picture 049" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/Picture%20049_thumb.jpg" width="244" align="left" border="0"></img></a></font><font face="Courier New">secure@microsoft.com</font></a> – This years hottest party was again the Microsoft party.  This year it was at the LAX club in the Luxor.  As usual there were quite a number of people at the door who thought they could talk their way in or worse yet were told they “were one the list”.  I was happy to be able to go and saw many of the usual suspects there as well. I had to leave the party early to go catch my red eye flight home, so went right to the airport from the party.  As I wrote earlier, Microsoft is trying really hard on security.  But I couldn’t help but notice the irony of this grainy, lousy picture of the DJ booth at the party.  If you can, notice the computers that the <a href="mailto:secure@microsoft.com">secure@microsoft.com</a> DJs are using. That’s right they are Macs!</p>  <p>2. A new low for booth babes – What would a Shimel review of a trade show be without a booth babe rant.  Hey I recognize it is Vegas and all, but EdgeOS went way over the line this year.  A booth babe dressed as a Las Vegas showgirl or some other type of costume makes a statement.  I personally don’t like exploiting woman to make that statement, but I understand.  However, these guys had woman who were dressed so raunchy and classless, that I could not bring myself to post a picture of them.  Come on guys!  You want to resort to the booth babe thing (and BTW I think the Black Hat crowd does not respond to that), at least have a little class.  These girls looked like street walkers and do you and your company no favors.  Is that really the image you want to promote?  Grow up!</p>  <p>3.  The Security Bloggers Network – We are back!  With the end of the Black Hat show, the SBN is going back to being the<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/securitybloggers.gif"><img title="securitybloggers" style="margin: 5px 5px 5px 10px" height="147" alt="securitybloggers" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/securitybloggers_thumb.gif" width="112" align="right" border="0"></img></a> SBN.  The old logo is back and our promotion with Black Hat is at an end.  However, I want to personally thank so many of you SBN members who blogged about Black Hat.  The Black Hat marketing folks made it a point to come over to me and thank us for the overwhelming support and help of the community.  Our network delivered big time with them and they are already thinking about ways we can work together next year.  I will keep you all posted on that.</p>  <p>We have several new promotions we are working on with the SBN and will have more on that soon. Also, we learned some valuable lessons.  Next time we will work with the network members more closely in doing these affiliations.  Also, for any show like this we need to have an official bloggers get together.  Not because we don’t want to buy our own drinks (thanks to Chris Hoff for doing more than his share in picking up a big bar tab), but frankly we need to reserve a place that has enough space for us.  Security bloggers are big time. We have a great community of people who get together. Lets make it better.</p>  <p>I have some other ideas around the SBN I am working on too and want to form a committee to help. If you are a member and want to get involved, please drop me a line or comment.</p>  <p>Anyway, another year of Black Hat is in the books. It was a good one and I can’t wait until next year!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=mqB9CC"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=mqB9CC" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=rP6xlK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=rP6xlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=fhzqOK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=fhzqOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=roBQzK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=roBQzK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=yW5ceK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=yW5ceK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=zosCbk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=zosCbk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=XDP8lk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=XDP8lk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/359668026" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:46:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/booth">booth</category>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/booth babes">booth babes</category>
      <category domain="http://securityratty.com/tag/booth babe rant">booth babe rant</category>
      <category domain="http://securityratty.com/tag/black hat crowd">black hat crowd</category>
      <category domain="http://securityratty.com/tag/security bloggers network">security bloggers network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/security bloggers">security bloggers</category>
      <category domain="http://securityratty.com/tag/booth babe">booth babe</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/359668026/black-hat-wrap.html">Black Hat wrap up - secure@microsoft, booth babes and bloggers</source>
    </item>
    <item>
      <title><![CDATA[My excellent adventure at Black Hat]]></title>
      <link>http://securityratty.com/article/4911547e5865f4f749dca83e6e765ab4</link>
      <guid>http://securityratty.com/article/4911547e5865f4f749dca83e6e765ab4</guid>
      <description><![CDATA[Yesterday was a great day at Black Hat. I would tell you all about it, but it seems Mitchell thinks that it best that we don't talk about what goes on here at Black Hat . Now, far be it from me to...]]></description>
      <content:encoded><![CDATA[<p>Yesterday was a great day at Black Hat. I would tell you all about it, but it <a href="http://www.theconvergingnetwork.com/2008/08/shimel-violates.html">seems Mitchell thinks that it best that we don't talk about what goes on here at Black Hat</a>. Now, far be it from me to break "Cardinal Rules" (has anyone ever really thought about what exactly is a "cardinal rule"? Why not a Blue Jay or Falcon rule?) but if we can't talk about it, what good is it. I think Mitchell is confusing divulging the really juicy Vegas stuff, from just the mundane. So let me tell you about my excellent adventure yesterday at Black Hat.<br><br>I was one of the multitude standing in the back listening to Dan's DNS report. You probably have already heard that it is bigger and worse than originally reported. I than spent a lot of time with the Microsoft people talking to them about their security stuff. I will tell you that despite many who rail against Microsoft, these guys actually are doing a great job on security and in dealing with the security community. Much better than a certain company named for a fruit whose marketing people killed the presentation of their own security research team. After lunch I took a front row seat to watch Hoff present on virtual security. He has some very pretty slides, but the message was clear. Great presentation by Hoff. I spent most of the rest of the afternoon catching up with lots of security bloggers here. I am amazed by the number of us here at Black Hat. <br><br>Had a quiet dinner with Mitchell (I would tell you about it but you know about what happens in Vegas with Mitchell) and than went to the Breach party at the Shadow Bar (I love that place, but it was too hot last night). We than went over to the Fuente cigar bar and next thing you know we were joined by about 30 of our closest security blogger buddies. It was a great time and their are pictures floating around twitter somewhere of it. We talked and laughed into the late hours, winding up at the Augustus cafe again for an early breakfast.<br><br>Well it is back to the show today and another round of parties tonight. Ah, it is tough living the life ;-)</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/ccf323f7-07c7-4094-9f72-65644a0714a6/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=ccf323f7-07c7-4094-9f72-65644a0714a6" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"></img></a></div>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=j0KXcs"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=j0KXcs" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=46dXIK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=46dXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LcowtK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LcowtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ciyhoK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ciyhoK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=597hOK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=597hOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=KEMtMk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=KEMtMk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TXQNRk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TXQNRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/358568409" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 07:52:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security bloggers">security bloggers</category>
      <category domain="http://securityratty.com/tag/security research team">security research team</category>
      <category domain="http://securityratty.com/tag/virtual security">virtual security</category>
      <category domain="http://securityratty.com/tag/security community">security community</category>
      <category domain="http://securityratty.com/tag/security stuff">security stuff</category>
      <category domain="http://securityratty.com/tag/security blogger buddies">security blogger buddies</category>
      <category domain="http://securityratty.com/tag/juicy vegas stuff">juicy vegas stuff</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/358568409/my-excellent-ad.html">My excellent adventure at Black Hat</source>
    </item>
    <item>
      <title><![CDATA[Another off to Black Hat post]]></title>
      <link>http://securityratty.com/article/f621f239eb76c9b9bbc2b885b0d218b0</link>
      <guid>http://securityratty.com/article/f621f239eb76c9b9bbc2b885b0d218b0</guid>
      <description><![CDATA[Let me run with the pack and put up my own &quot;off to Black Hat &quot; post. I leave Tuesday actually and won't get there until Tuesday evening. I will be on a red eye home Thursday night/Friday morning. In...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Let me run with the pack and put up my own &quot;off to <a class="zem_slink" title="Black Hat Briefings" href="http://en.wikipedia.org/wiki/Black_Hat_Briefings" rel="wikipedia">Black Hat</a>&quot; post.&nbsp; I leave Tuesday actually and won't get there until Tuesday evening.&nbsp; I will be on a red eye home Thursday night/Friday morning.&nbsp; In this way I don't break my own three day rule on Vegas.&nbsp; What is my three day rule?&nbsp; Suffice to say that it prevents me from spiraling down into the bowels of degeneracy.</p>

<p>So what am I looking forward to at Black Hat?&nbsp; The Dan K / DNS stuff should be fun.&nbsp; I will be cheering on my boy Hoff and I always sit in on Jeremiah.&nbsp; But lets face it, I am there for the party and catching up.&nbsp; I am looking forward to throwing a few back with Rothman.&nbsp; Seeing Martin, Mogul and the rest of the bunch.&nbsp; There are always good parties of course and free drinks and food never hurts.</p>

<p>Of course I will also spend some time at the StillSecure booth shaking hands and kissing babies.&nbsp; If you would like to say hello feel free to stop on by.</p>

<p>Also, a quick thanks to all of the members of the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed">SBN</a> for their support on our Black Hat affiliation.&nbsp; The last few weeks have seen a bunch of blogs raising the buzz on the conference.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/black-hat-blogg.html">Black Hat Bloggers Network topic of interest #2</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/abf654e0-e626-4943-b843-8364744d2d4e/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=abf654e0-e626-4943-b843-8364744d2d4e" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 06:54:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/black hat affiliation">black hat affiliation</category>
      <category domain="http://securityratty.com/tag/day rule">day rule</category>
      <category domain="http://securityratty.com/tag/forward">forward</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/stillsecure booth">stillsecure booth</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/bunch">bunch</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/another-off-to.html">Another off to Black Hat post</source>
    </item>
    <item>
      <title><![CDATA[Another off to Black Hat post]]></title>
      <link>http://securityratty.com/article/7749634a01752754f16cf28eac045607</link>
      <guid>http://securityratty.com/article/7749634a01752754f16cf28eac045607</guid>
      <description><![CDATA[Let me run with the pack and put up my own &quot;off to Black Hat &quot; post. I leave Tuesday actually and won't get there until Tuesday evening. I will be on a red eye home Thursday night/Friday morning. In...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Let me run with the pack and put up my own &quot;off to <a class="zem_slink" title="Black Hat Briefings" href="http://en.wikipedia.org/wiki/Black_Hat_Briefings" rel="wikipedia">Black Hat</a>&quot; post.&nbsp; I leave Tuesday actually and won't get there until Tuesday evening.&nbsp; I will be on a red eye home Thursday night/Friday morning.&nbsp; In this way I don't break my own three day rule on Vegas.&nbsp; What is my three day rule?&nbsp; Suffice to say that it prevents me from spiraling down into the bowels of degeneracy.</p>

<p>So what am I looking forward to at Black Hat?&nbsp; The Dan K / DNS stuff should be fun.&nbsp; I will be cheering on my boy Hoff and I always sit in on Jeremiah.&nbsp; But lets face it, I am there for the party and catching up.&nbsp; I am looking forward to throwing a few back with Rothman.&nbsp; Seeing Martin, Mogul and the rest of the bunch.&nbsp; There are always good parties of course and free drinks and food never hurts.</p>

<p>Of course I will also spend some time at the StillSecure booth shaking hands and kissing babies.&nbsp; If you would like to say hello feel free to stop on by.</p>

<p>Also, a quick thanks to all of the members of the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed">SBN</a> for their support on our Black Hat affiliation.&nbsp; The last few weeks have seen a bunch of blogs raising the buzz on the conference.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/black-hat-blogg.html">Black Hat Bloggers Network topic of interest #2</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/abf654e0-e626-4943-b843-8364744d2d4e/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=abf654e0-e626-4943-b843-8364744d2d4e" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=EhvRZc"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=EhvRZc" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cbROXK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cbROXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=5ToXTK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=5ToXTK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TrWrBK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TrWrBK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HlqY2K"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HlqY2K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=frbdkk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=frbdkk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=X3DXJk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=X3DXJk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/355394751" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 05:54:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/black hat affiliation">black hat affiliation</category>
      <category domain="http://securityratty.com/tag/day rule">day rule</category>
      <category domain="http://securityratty.com/tag/forward">forward</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/stillsecure booth">stillsecure booth</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/bunch">bunch</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/355394751/another-off-to.html">Another off to Black Hat post</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Is there any reason to go to Black Hat still?]]></title>
      <link>http://securityratty.com/article/48dccc0384334ebae07a6e1e34cb280b</link>
      <guid>http://securityratty.com/article/48dccc0384334ebae07a6e1e34cb280b</guid>
      <description><![CDATA[I was reading the Security Bloggers Network feed this morning. I had missed a day or so and had a lot of articles to go through. I was also thinking of what could be the next topic suggested for...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=200,height=177,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/07/23/blackhatbloggers.gif"><img title="Blackhatbloggers" height="132" alt="Blackhatbloggers" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/07/23/blackhatbloggers.gif" width="150" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></a> I was reading the <a href="http://networks.feedburner.com/Security-Bloggers-Network">Security Bloggers Network</a> feed this morning. I had missed a day or so and had a lot of articles to go through. I was also thinking of what could be the next topic suggested for members to blog about as part of our cross-promotion with Black Hat.&nbsp; Than I realized there really was not any need.&nbsp; The topic was obvious, DNS. I didn't do an actual count of how many times it was mentioned (as <a href="http://www.bumpinthewire.com/?p=234">Mr Bump did with NAC vendors mentioned in the Information Week NAC survey</a>), but there had to be at least a dozen and half, if not more articles on the great DNS leak of 2008.&nbsp; </p>

<p>Dan Kaminsky's research was exemplary, but his naivete about people keeping the exploit under thier hat was not.&nbsp; While <a href="http://www.matasano.com/log/1105/regarding-the-post-on-chargen-earlier-today/#comments">Thomas Matasano apologized for his mistake</a>, frankly from the moment Havlar Flake begain speculating on it, it was just a matter of time.&nbsp; </p>

<p>Anyway, the cat is out of that bag, but something tells me that Dan K's presentation will still be a standing room only crowd in just a few weeks in Vegas.&nbsp; But beyond that there are still a bunch of good topics to be discovered at Black Hat.&nbsp; Not to mention lots of social activities brewing for both BH and DefCon.&nbsp; I amreally looking forward to it. I would hope that no one is feeling the air out of the ballon on this one!</p><br /><br /><fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html">Details of DNS Flaw Leaked; Exploit Expected by End of Today</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/07/22/Details_of_major_Internet_flaw_posted_by_accident_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/07/22/Details_of_major_Internet_flaw_posted_by_accident_1.html">Details of major Internet flaw posted by accident</a></li>

<li class="zemanta-article-ul-li"><a href="http://gigaom.com/2008/07/22/the-kaminsky-hack-dns-exploits-in-the-wild/">The Kaminsky Hack: DNS Exploits in the Wild</a></li>

<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1009_3-9996316-83.html?hhTest=1&amp;part=rss&amp;subj=news">Is Kaminsky's DNS flaw public?</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.boingboing.net/2008/07/22/kaminsky-on-the-nets.html">Kaminsky on the net-shaking DNS bug</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9110418&amp;source=rss_topic82">Details of major Internet flaw posted by accident</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/a94ce1a9-f719-4533-9603-beb582d33313/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=a94ce1a9-f719-4533-9603-beb582d33313" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=mPLh0z"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=mPLh0z" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=iDfnaJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=iDfnaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=sAYmLJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=sAYmLJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CaWUSJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CaWUSJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Gh4sLJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Gh4sLJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Z6tX2j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Z6tX2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=7rsO8j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=7rsO8j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/343474506" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 03:58:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dns flaw">dns flaw</category>
      <category domain="http://securityratty.com/tag/dns flaw public">dns flaw public</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/dns bug">dns bug</category>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/dns leak">dns leak</category>
      <category domain="http://securityratty.com/tag/kaminsky">kaminsky</category>
      <category domain="http://securityratty.com/tag/kaminsky hack">kaminsky hack</category>
      <category domain="http://securityratty.com/tag/major internet flaw">major internet flaw</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/343474506/is-there-any-re.html">Is there any reason to go to Black Hat still?</source>
    </item>
  </channel>
</rss>
