<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: clinton]]></title>
    <link>http://securityratty.com/tag/clinton</link>
    <description></description>
    <pubDate>Sun, 30 Mar 2008 16:57:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Bush's exit to put new e-records system to the test]]></title>
      <link>http://securityratty.com/article/5136882ab474438d37a3010c7c02b7cb</link>
      <guid>http://securityratty.com/article/5136882ab474438d37a3010c7c02b7cb</guid>
      <description><![CDATA[The National Archives received only 32 million e-mails from the Clinton administration eight years ago, but in a few months, it expects to get hit with 50 times that from the Bush administration,...]]></description>
      <content:encoded><![CDATA[The National Archives received only 32 million e-mails from the Clinton administration eight years ago, but in a few months, it expects to get hit with 50 times that from the Bush administration, which has exacerbated the problem by dragging its feet in supplying the data.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e889bfb861b0728bfef7d260f090a058:diBBHUUrFFyErrj%2B%2BKgX1ahwdVzU4L3H6hB2XrUTFg680kI%2FEeBFtIPW7%2FsmXk6TnXG0Jcl19YIp'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6dc5566a1b9d46a6a42c1890a26ab6f9:lqkR6JP7fpNff1d3fHteBbf0KLF%2F8LrAyaCArSXp1eDqQAZydSSqtdqW0snQg%2Bog7uJkQpstzyDw0A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:dfa5facdde0aecd816123a7300487a3d:Zgucha0u0JmZ3UA7kY6%2B6%2BlAxyvCphjii5cIhjz3KZN31yEk7VQenZe5I%2B5I1GHGerp1IES1LJL5PA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:51286a4f343898890678765c7028ca67:Rw58e65mDSHXMIyCwPCibMX3mCCvq6OZltcMj2VvY6ip%2BQs8wbwXyfEgckk6zFuw0wIJ4YpbFyGCdQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=e7b60bc98cf75a8107026f8126bdf79b&amp;p=1"><img style="border:0;" src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=e7b60bc98cf75a8107026f8126bdf79b&amp;p=1" border="0" /></a>
]]></content:encoded>
      <pubDate>Fri, 21 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bush administration">bush administration</category>
      <category domain="http://securityratty.com/tag/national archives">national archives</category>
      <category domain="http://securityratty.com/tag/million e-mails">million e-mails</category>
      <category domain="http://securityratty.com/tag/clinton administration">clinton administration</category>
      <category domain="http://securityratty.com/tag/feet">feet</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/hit">hit</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/expects">expects</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e7b60bc98cf75a8107026f8126bdf79b">Bush's exit to put new e-records system to the test</source>
    </item>
    <item>
      <title><![CDATA[They didn't go away you know....]]></title>
      <link>http://securityratty.com/article/265b22f7a3a1ac42a1aa3d3c8f7bd79d</link>
      <guid>http://securityratty.com/article/265b22f7a3a1ac42a1aa3d3c8f7bd79d</guid>
      <description><![CDATA[Listening to a discussion on CNN the day after President elect Obama won the U.S. Presidential race, made me think about what the terrorists may be thinking

It really is fairly easy for the average...]]></description>
      <content:encoded><![CDATA[Listening to a discussion on CNN the day after President elect Obama won the U.S. Presidential race, made me think about what the terrorists may be thinking. <br /><span id="fullpost"><br />It really is fairly easy for the average citizen to push these thoughts out of their mind, but we should always keep it somewhere in our minds - close enough to recall it when necessary.<br /></span><br />Bill Clinton was "tested" early in his Presidency as was the U.K.'s new Prime Minister - Gordon Brown.  In PM Brown's case it came 72 hours after the Election in Britain.  How long may we wait to see something here..or overseas, but definitely aimed at inflciting U.S. casualties?<br /><br />Bottom line - we should always remian alert and open to the idea that something could happen and we can not afford to drop our guard and think "they have gone".  Terrorists have great amounts of patience.  They conduct surveillance right under the noses of their intended victims.  As the old saying goes; "we have to be successful every single time - they only have to be lucky once".<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 03:02:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/brown">brown</category>
      <category domain="http://securityratty.com/tag/gordon brown">gordon brown</category>
      <category domain="http://securityratty.com/tag/president elect obama">president elect obama</category>
      <category domain="http://securityratty.com/tag/single time">single time</category>
      <category domain="http://securityratty.com/tag/conduct surveillance">conduct surveillance</category>
      <category domain="http://securityratty.com/tag/bill clinton">bill clinton</category>
      <category domain="http://securityratty.com/tag/remian alert">remian alert</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/presidential race">presidential race</category>
      <source url="http://www.thebulletproofblog.com/2008/11/they-didnt-go-away-you-know.html">They didn't go away you know....</source>
    </item>
    <item>
      <title><![CDATA[Clinton Urges Party Unity In Powerful Convention Address]]></title>
      <link>http://securityratty.com/article/a954988d4421ade0a174e500f7a8538f</link>
      <guid>http://securityratty.com/article/a954988d4421ade0a174e500f7a8538f</guid>
      <description><![CDATA[Hillary Clinton exhorts the members of her party to unite and rally behind former Democratic presidential nominee Barack Obama, saying that the nation can't afford to elect another Republican to the...]]></description>
      <content:encoded><![CDATA[Hillary Clinton exhorts the members of her party to unite and rally behind former Democratic presidential nominee Barack Obama, saying that the nation can't afford to elect another Republican to the White House.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=badb1c80222bb54a485706f6a82ddf24"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=badb1c80222bb54a485706f6a82ddf24"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=badb1c80222bb54a485706f6a82ddf24" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=S8osMK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=S8osMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=LocPTk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=LocPTk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=RgYGCk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=RgYGCk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=SDKqbK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=SDKqbK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=diwLbK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=diwLbK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xK84Jk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xK84Jk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=0Ccfak"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0Ccfak" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=V5s7dK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=V5s7dK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/376167404" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/376167408" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 00:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hillary clinton exhorts">hillary clinton exhorts</category>
      <category domain="http://securityratty.com/tag/white house">white house</category>
      <category domain="http://securityratty.com/tag/party">party</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <category domain="http://securityratty.com/tag/unite">unite</category>
      <category domain="http://securityratty.com/tag/afford">afford</category>
      <category domain="http://securityratty.com/tag/rally">rally</category>
      <category domain="http://securityratty.com/tag/republican">republican</category>
      <category domain="http://securityratty.com/tag/elect">elect</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/376167408/clinton-urges-p.html">Clinton Urges Party Unity In Powerful Convention Address</source>
    </item>
    <item>
      <title><![CDATA[Obama Campaign Seeks Web-Site Security Help]]></title>
      <link>http://securityratty.com/article/d21012924388e580f0c8dc8e7a3c18a5</link>
      <guid>http://securityratty.com/article/d21012924388e580f0c8dc8e7a3c18a5</guid>
      <description><![CDATA[Barack Obama's presidential campaign is seeking a security expert to help lock down its Web site, which was hacked two months ago by a Hillary Clinton supporter taking advantage of a programming...]]></description>
      <content:encoded><![CDATA[Barack Obama's presidential campaign is seeking a security expert to help lock down its Web site, which was hacked two months ago by a Hillary Clinton supporter taking advantage of a programming error.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=nkGjLr"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=nkGjLr" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/312756046" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 16 Jun 2008 02:26:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hillary clinton supporter">hillary clinton supporter</category>
      <category domain="http://securityratty.com/tag/months ago">months ago</category>
      <category domain="http://securityratty.com/tag/barack obama">barack obama</category>
      <category domain="http://securityratty.com/tag/presidential campaign">presidential campaign</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/advantage">advantage</category>
      <category domain="http://securityratty.com/tag/lock">lock</category>
      <category domain="http://securityratty.com/tag/error">error</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/312756046/article.do">Obama Campaign Seeks Web-Site Security Help</source>
    </item>
    <item>
      <title><![CDATA[Parents can't afford to let their guard down when it comes to their children's safety]]></title>
      <link>http://securityratty.com/article/f4271355521860175541d0aa7fa6d4c5</link>
      <guid>http://securityratty.com/article/f4271355521860175541d0aa7fa6d4c5</guid>
      <description><![CDATA[I was very fortunate last night to have been able to attend a presentation in Richmond by the well known Criminal and Behavioral Profiler, Dr. Clinton Van Zandt
Dr. Van Zandt adressed a dinner which...]]></description>
      <content:encoded><![CDATA[I was very fortunate last night to have been able to attend a presentation in Richmond by the well known Criminal and Behavioral Profiler, Dr. Clinton Van Zandt.<br />Dr. Van Zandt adressed a dinner which was organized by the <a href="http://piava.wordpress.com/">Private Investigators Association of Virgina.</a>  Attendees were kept spell bound by inside sories involving the Jon Bennet Ramsey murder, The Unibomber, The Beltway Snipers and more. <br /><br /></span><br />Last month I was also fortunate to have been able to hear Col. Dave Grossman speak eloquently and passionately about the tragic school shootings in which he has been called in to assist educators and parents understand.  One thing is clear from listening to both men, parents need to be ever mindful of the fact that they are their children's protectors.  They are the sheepdogs, ever on the lookout for marauding wolves.<br /><br />If you are a parent, or an educator or a security professional, I strongly urge you to read up on the teachings of these learned men and jump at the opportunity to hear them live if at all possible.  I personally guarantee you that you will not be disappointed.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 23 May 2008 00:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/clinton van zandt">clinton van zandt</category>
      <category domain="http://securityratty.com/tag/van zandt">van zandt</category>
      <category domain="http://securityratty.com/tag/parents">parents</category>
      <category domain="http://securityratty.com/tag/tragic school shootings">tragic school shootings</category>
      <category domain="http://securityratty.com/tag/strongly urge">strongly urge</category>
      <category domain="http://securityratty.com/tag/behavioral profiler">behavioral profiler</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/inside sories">inside sories</category>
      <category domain="http://securityratty.com/tag/investigators association">investigators association</category>
      <source url="http://www.thebulletproofblog.com/2008/05/parents-cant-afford-to-let-their-guard.html">Parents can't afford to let their guard down when it comes to their children's safety</source>
    </item>
    <item>
      <title><![CDATA[Are current vulnerability and compliance testing tools like answering the phone at 3am?]]></title>
      <link>http://securityratty.com/article/6654f6456677a336f8a4941afb4009d8</link>
      <guid>http://securityratty.com/article/6654f6456677a336f8a4941afb4009d8</guid>
      <description><![CDATA[I was at a meeting for a potentially large customer engagement for vulnerability assessment and compliance testing last week. The requirements for this customer was not unusual. They wanted to test...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p></p> <p>I was at a meeting for a potentially large customer engagement for vulnerability assessment and compliance testing last week.&nbsp; The requirements for this customer was not unusual. They wanted to test for conventional CVE type vulnerabilities. Additionally, they also wanted to test for configuration compliance. Hotfixes, patch level, AV, etc.&nbsp; This direction is where a lot of the traditional vulnerability management solutions have been heading.&nbsp; Whether adding a separate compliance module or audit and local check capability, most of the traditional vulnerability scanning solutions offer some coverage in this area.&nbsp; However, in speaking to this potential customer and in thinking about their needs, an inherent problem with this solution is that it is only as good as the devices that are available on the network when the scan takes place.</p> <p>In traditional vulnerability scanning, <u>when</u> the scan takes place was not as much of an issue, usually you are scanning servers and other devices that are on the network 24/7. In fact doing the scans during off hours was usually preferred. Too many of the network based vulnerability scanners took up too much bandwidth and other resources to accomplish during the prime time hours of the day. In compliance scanning though, you need the status of laptops, desktops and other devices that may not be connected to the network 24/7.&nbsp; Therefore it is important to reach and test these devices when they are on the network.&nbsp; That is the rub.&nbsp; How do you really make sure the devices connecting to your network are compliant if you are only testing them at a point in time and that usually at an off hour?</p> <p>This problem reminded me of the Clinton-Obama flap over who answers the phone at the White House at 3am.&nbsp; That is an important question for who is president, but for compliance answering the phone when someone is there to talk to is more important.&nbsp; I think this is where NAC provides an advantage.&nbsp; By utilizing NAC to detect devices coming on the network and than using a low impact compliance test as well as traditional vulnerability scanning, you get a picture of vulnerability posture and compliance status as of the last time they accessed the network. You can still do follow on tests at any time you desire, but at least when a device is logging on you are sure of a test.</p> <p>Will NAC supplement vulnerability testing in this manner? I think so.&nbsp; Many customers we have spoken to about this like the idea of "scan on connect" and we have already enabled our own NAC product Safe Access and vulnerability management platform VAM to do this.&nbsp; What do you think?</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=atl0PH"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=atl0PH" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JgJVaH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JgJVaH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=kjoSqH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=kjoSqH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=OqhPXH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=OqhPXH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=pS6W5H"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=pS6W5H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YCq7Eh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YCq7Eh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qHBwth"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qHBwth" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/293979749" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 19 May 2008 19:16:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/configuration compliance">configuration compliance</category>
      <category domain="http://securityratty.com/tag/compliance status">compliance status</category>
      <category domain="http://securityratty.com/tag/status">status</category>
      <category domain="http://securityratty.com/tag/prime time hours">prime time hours</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/detect devices">detect devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/293979749/are-current-vul.html">Are current vulnerability and compliance testing tools like answering the phone at 3am?</source>
    </item>
    <item>
      <title><![CDATA[Democratic Campaign Hacking Picks Up]]></title>
      <link>http://securityratty.com/article/69da973682312c9089a492f46f00f5a5</link>
      <guid>http://securityratty.com/article/69da973682312c9089a492f46f00f5a5</guid>
      <description><![CDATA[Following last week's hack against BarackObama.com , Netcraft is reporting a research exploit against VoteHillary.Org . VoteHillary.org is owned by a PAC, not the Clinton campaign, whose site is...]]></description>
      <content:encoded><![CDATA[Following <a href="http://blogs.pcmag.com/securitywatch/2008/04/a_hack_we_can_believe_in.php">last week's hack against BarackObama.com</a>, Netcraft is reporting <a href="http://news.netcraft.com/archives/2008/04/24/clinton_and_obama_xss_battle_develops.html">a research exploit against VoteHillary.Org</a>. 

VoteHillary.org is owned by a PAC, not the Clinton campaign, whose site is <A href="http://www.hillaryclinton.com">www.HillaryClinton.com</A>.  Harry Sintonen, the Finnish security researcher who found the bug in VoteHillary.org, first tried to attack HillaryClinton.com, but found no cross-site scripting errors there.

Both attacks essentially bring you to the other campaign's site surreptitiously. They are essentially benign, but that could change in the coming months.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=90a8a624163e49c4bb2d0a28d713fb17" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=90a8a624163e49c4bb2d0a28d713fb17" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/277015663" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Apr 2008 06:54:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/votehillary">votehillary</category>
      <category domain="http://securityratty.com/tag/site surreptitiously">site surreptitiously</category>
      <category domain="http://securityratty.com/tag/attack hillaryclinton">attack hillaryclinton</category>
      <category domain="http://securityratty.com/tag/finnish security researcher">finnish security researcher</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/clinton campaign">clinton campaign</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/277015663/democratic_campaign_hacking_picks_up_1.html">Democratic Campaign Hacking Picks Up</source>
    </item>
    <item>
      <title><![CDATA[Obama XSS Silliness]]></title>
      <link>http://securityratty.com/article/deecccbd143566ad85ba011e74dd76a7</link>
      <guid>http://securityratty.com/article/deecccbd143566ad85ba011e74dd76a7</guid>
      <description><![CDATA[Apparently the security blunder of the weekend goes to the Barack Obama campaign for having XSS vulnerabilities throughout their website. Theres no need for me to rehash the story, you can read other...]]></description>
      <content:encoded><![CDATA[<p>Apparently the security blunder of the weekend goes to the Barack Obama campaign for having <a href="http://xssed.com/news/65/Barack_Obamas_official_site_hacked/">XSS vulnerabilities</a> throughout their website.  There&#8217;s no need for me to rehash the story, you can read <a href="http://www.webpronews.com/topnews/2008/04/21/obamas-site-hacked-change-comes-from-xss">other articles</a> that describe <a href="http://blog.internetnews.com/skerner/2008/04/hackers-take-from-barack-obama.html">what happened</a>.   My thoughts on the matter are as follows: </p>
<ul>
<li>I wish the media wouldn&#8217;t refer to this as &#8220;hacking Obama&#8217;s website&#8221; because it&#8217;s not quite accurate; XSS attacks end users, not the web site itself.  Clearly one makes a better headline.</li>
<li>Can people (that&#8217;s you, security bloggers) stop saying things like &#8220;they should have been filtering inputs?&#8221;  The most effective way to <a href="http://www.owasp.org/index.php/XSS">protect against XSS</a> is HTML entity encoding, NOT input validation.  Input validation is great and all &#8212; and please continue to use it in general &#8212; but you&#8217;re <a href="http://ha.ckers.org/xss.html">going to miss something</a>.</li>
<li>Why is anybody surprised about this?  Did anybody really think that the Obama (or Clinton, or McCain) campaigns would be spending money on web security testing?  I guess they might be from now on&#8230;</li>
<p>
</ul>
<p>All quite amusing nonetheless.</p>
]]></content:encoded>
      <pubDate>Tue, 22 Apr 2008 11:04:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/obama">obama</category>
      <category domain="http://securityratty.com/tag/xss attacks">xss attacks</category>
      <category domain="http://securityratty.com/tag/barack obama campaign">barack obama campaign</category>
      <category domain="http://securityratty.com/tag/input validation">input validation</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/obamas website">obamas website</category>
      <category domain="http://securityratty.com/tag/web security">web security</category>
      <source url="http://www.veracode.com/blog/?p=89">Obama XSS Silliness</source>
    </item>
    <item>
      <title><![CDATA[Obama site hacked, redirects clicks to Clinton's site]]></title>
      <link>http://securityratty.com/article/121748d8daca55bdac7bb05e4574b826</link>
      <guid>http://securityratty.com/article/121748d8daca55bdac7bb05e4574b826</guid>
      <description><![CDATA[A cross-site scripting flaw in the social networking section of Sen. Barack Obama's campaign site was exploited over the weekend to redirect users to the URL of rival Sen. Hillary...]]></description>
      <content:encoded><![CDATA[A cross-site scripting flaw in the social networking section of Sen. Barack Obama's campaign site was exploited over the weekend to redirect users to the URL of rival Sen. Hillary Clinton.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=ZybpOi"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=ZybpOi" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/274841993" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/campaign site">campaign site</category>
      <category domain="http://securityratty.com/tag/barack obama">barack obama</category>
      <category domain="http://securityratty.com/tag/redirect users">redirect users</category>
      <category domain="http://securityratty.com/tag/hillary clinton">hillary clinton</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/rival">rival</category>
      <category domain="http://securityratty.com/tag/section">section</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/274841993/article.do">Obama site hacked, redirects clicks to Clinton's site</source>
    </item>
    <item>
      <title><![CDATA[From warzones to strip clubs, the truth comes out for a former First Lady and a Pastor.]]></title>
      <link>http://securityratty.com/article/4644a2739d9bbdd4b4a3b5d2c22ca326</link>
      <guid>http://securityratty.com/article/4644a2739d9bbdd4b4a3b5d2c22ca326</guid>
      <description><![CDATA[Last week in the Washington Post, &quot;The Fact Checker&quot; awarded former first lady, Hillary Clinton, four &quot;Pinocchios&quot; (real whoppers)for claiming to have come under sniper fire during a photo op. in...]]></description>
      <content:encoded><![CDATA[Last week in the Washington Post, "The Fact Checker" awarded former first lady, Hillary Clinton, four "Pinocchios" (real whoppers)for claiming to have come under sniper fire during a photo op. in Bosnia.  On Thursday, Michael Dobbs once again awarded Senator Clinton another "poker" of Pinocchios.  <br /><span id="fullpost"><br /><br />This time she took heat for claiming that her trip to Bosnia was the first visit to a "war zone" by a first lady since World War II.  Her claim is considered completly inaccurate, since Pat Nixon made a trip to Saigon in July 1969.  At the time, South Vietnam was an actual, not a "potential" war zone in the aftermath of the 1968 Tet offensive.<br /><br />The article also made mention of Barbara Bush's visit to Saudi Arabia in 1990, two months before the Persian Gulf war began.  Speaking about Senator Clinton's claim that her aircraft made a tactical landing back in 1996, the pilot of the aircraft had a different memory.  Retired Air Force Col. William Changose said that it was not true that they took evasive measures to avoid sniper fire.  The Colonel went on to say that: "not only were there no bullets flying, there wasn't even a bumblebee flying around".          <br /></span><br />It seems that Senator Clinton is not the only one in the public eye to suffer from Pinocchioitis.  Apparently the Police in Riverside, Ohio found a Pastor who had gone missing from his home in western New York, since Wednesday the 26th of March, after telling his wife that he was going to Best Buy to have his computer fixed. Officers found the Pastor at a strip club called the "K.C. Lounge", partying like a New York Govenor.<br /><br />We often hear people in the media complaining about the negative effects that Rap music has on our youth.  One wonders why we are now not hearing more complaining about the so-called role models getting caught with their pants down, so to speak.  At least with the likes of rappers and other "bad boy" entertainers, what you see, is what you get.  It's little wonder that so many people are comfortable telling lies during interviews and embellishing resumes in order to get hired and get ahead.  <br /><br />When I was going to school, the "dog ate my homework" excuse was used but not believed.  Also, it tended to get used by children who had not yet reached their teens.  I think that even children of that age these days will be able to see through these poorly constructed falsehoods that our "role models" would have us believe.<br /><br />Unbelievable.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 30 Mar 2008 16:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/senator clinton">senator clinton</category>
      <category domain="http://securityratty.com/tag/sniper fire">sniper fire</category>
      <category domain="http://securityratty.com/tag/avoid sniper fire">avoid sniper fire</category>
      <category domain="http://securityratty.com/tag/role models">role models</category>
      <category domain="http://securityratty.com/tag/war zone">war zone</category>
      <category domain="http://securityratty.com/tag/lady">lady</category>
      <category domain="http://securityratty.com/tag/pastor">pastor</category>
      <category domain="http://securityratty.com/tag/air force col">air force col</category>
      <category domain="http://securityratty.com/tag/persian gulf war">persian gulf war</category>
      <source url="http://www.thebulletproofblog.com/2008/03/from-warzones-to-strip-clubs-truth.html">From warzones to strip clubs, the truth comes out for a former First Lady and a Pastor.</source>
    </item>
  </channel>
</rss>
