<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: completely]]></title>
    <link>http://securityratty.com/tag/completely</link>
    <description></description>
    <pubDate>Tue, 12 Aug 2008 18:43:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[This week in history - volcanos, hurricanes, and the risk of Black Swans]]></title>
      <link>http://securityratty.com/article/1c99044530f3bdcc78ac07456ab99c44</link>
      <guid>http://securityratty.com/article/1c99044530f3bdcc78ac07456ab99c44</guid>
      <description><![CDATA[Pouring over endless details of risks, regulations, taxonomies, and technologies can sometimes give us a narrow view of the world, so it seems worthwhile to take a minute to mark the 125th anniversary...]]></description>
      <content:encoded><![CDATA[<p><img title="Chris McClean" alt="Chris McClean" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Chris-McClean.gif" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></p>

<p>Pouring over endless details of risks, regulations, taxonomies, and technologies can sometimes give us a narrow view of the world, so it seems worthwhile to take a minute to mark the 125th anniversary of the <a href="http://www.wired.com/science/discoveries/news/2008/08/dayintech_0826">cataclysmic eruption of Krakatoa</a> this week. For those of us that want to think big but can’t remember that far back, this week is also the 3rd anniversary of <a href="http://www.hhs.gov/disasters/emergency/naturaldisasters/hurricanes/katrina/index.html">Hurricane Katrina’s devastating sweep</a> across a wide stretch of the US Gulf Coast. </p>

<p>By now, I expect that most of you have read or are familiar with the 2007 book, The Black Swan, by <a href="http://www.fooledbyrandomness.com/">Nassim Nicholas Taleb</a>, which argues that these kinds of unpredictable, outlying occurrences are the ones that really shape businesses, countries, economies, and people. Taleb argues that although these “Black Swan” events are almost completely unforeseeable, we mistakenly try to explain the circumstances at the time and make predictions about similar events in the future. </p>

<p>In my ERM work with clients, and especially in the context of research I’ve been doing with my colleague <a href="http://www.forrester.com/rb/analyst/stephanie_balaouras?internal=1">Stephanie Balaouras</a> on business continuity and resiliency, questions come up about how to plan for catastrophes... and they’re good questions. Were the CardSystems or TJX data breaches foreseeable? What about the Societe General debacle or the 2004 Indian Ocean tsunami? What’s next? Should these types of events be included in our risk assessments? </p>

<p>We’d like to get your opinion on these and other risks that may be on the very edge of the statistical tail. At what point do they belong in your risk register? </p>

<p>Of course, it’s possible to define mitigating controls for crises, disasters, or incidents without knowing for sure what they’re going to look like. That’s one of the hallmarks of a good crisis management plan. And that’s an important point, because trying to predict the next unforeseeable event can be a real challenge sometimes. </p>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 07:07:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/similar events">similar events</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/black swan events">black swan events</category>
      <category domain="http://securityratty.com/tag/black swan">black swan</category>
      <category domain="http://securityratty.com/tag/plan">plan</category>
      <category domain="http://securityratty.com/tag/crisis management plan">crisis management plan</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/colleague stephanie balaouras">colleague stephanie balaouras</category>
      <category domain="http://securityratty.com/tag/argues">argues</category>
      <source url="http://blogs.forrester.com/srm/2008/08/this-date-in-hi.html">This week in history - volcanos, hurricanes, and the risk of Black Swans</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</link>
      <guid>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3">Download the show here</a> (MP3, 19MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the hiatus</li>
	</ul>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/">Are your Skype username and password completely exposed if you use iSkoot?</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/chronology-of-the-blogosphere-and-iskoot-weekend-response-to-the-iskoot-security-issue/">Chronology</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/iskoot-disclosure-of-skype-credentials-resolved-new-version-by-wednesday/">iSkoot disclosure of Skype credentials resolved &#8211; new version by Wednesday</a></li>
<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a> &#8211; and Hannes Tschofenig points to <a href="http://www.emergency-services-coordination.info/esw4.html">4th Emergency Services Coordination Workshop</a> and <a href="http://www.tschofenig.priv.at/twiki/pub/EmergencyServices/EswAgenda2008/BT-ES_SDO_April_08.ppt">presentation about the UK</a></li>
<li>MarketingVOX: <a href="http://www.marketingvox.com/british-proposal-may-force-isps-to-fork-over-online-activity-emails-voip-calls-038702/">British Proposal May Force ISPs to Fork Over Online Activity, Emails, <span class="caps">VOIP </span>Calls</a> pointing to Reuters article: <a href="http://www.reuters.com/article/lifestyleMolt/idUSL2076461020080520">Britain mulls plan to store all email and calls</a></li>

<p><li>Enterprise VoIP Planet: <a href="http://www.voipplanet.com/solutions/article.php/3747161">VoIP Security: <span class="caps">SIP</span>-Versatile but Vulnerable</a></li><br />
		<li><span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/cip/?p=343">Pay Attention to VoIP Security Before The Storm</a></li></p>

<p><li>NetworkWorld: <a href="http://www.pcworld.com/businesscenter/article/145272/guide_to_voip_security.html">Business Guide to VoIP Security</a></li><br />
<li>Pocket-lint: <a href="http://www.pocket-lint.co.uk/news/news.phtml/14768/15792/Fraudsters-targeting-internet-phone-services.phtml">Fraudsters targeting VoIP Users</a> based on <a href="http://www.voip-news.co.uk/2008/05/21/newport-networks-highlights-voip-security/">report out of Newport Networks</a> (reported in VoIP News) &#8211; also covered at Fierce VoIP: <a href="http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18">Newport Networks riles up VoIP Security Fears</a> and Computeractive: <a href="http://www.computeractive.co.uk/personal-computer-world/news/2216851/phreak-voip">Phreak-out over VoIP</a> and <a href="http://www.thetechherald.com/article.php/200821/1017/Newport-Networks-raises-VoIP-identity-theft-concerns">TechHerald article</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2008/042808converge1.html">Security and management considerations when deploying <span class="caps">OCS</span></a></li><br />
<li>LXer: <a href="http://lxer.com/module/newswire/view/102328/">Secure Calling Initiative Reaches Second Milestone</a> pointing to <a href="http://www.gnutelephony.org/index.php/Secure_Call">Secure Calling Initiative</a></li><br />
	<br />
	<li>[H]Enthusiast: <a href="http://www.hardocp.com/news.html?news=MzI0NjMsLCxoZW50aHVzaWFzdCwsLDE">Mobile Phones, VoIP Not Secure, Experts Warn</a>=</li><br />
	<br />
	<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-privacy-042308/">The Essential Guide to VoIP Privacy</a></li><br />
	<br />
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/18/information-week-interviews-securelogix-about-voip-security/">Information Week interviews SecureLogix about VoIP security</a></li><br />
<li>eWeek: <a href="http://www.eweek.com/c/a/Knowledge-Center/VoIP-Security-through-Responsible-Software-Development/">VoIP Security through Responsible Software Development</a></li><br />
<li><a href="http://techdirt.com/articles/20080429/095514977.shtml">Microsoft gives back door keys to Vista to police</a></li><br />
<li>Comment (blog) from <a href="http://www.blueboxpodcast.com/2008/03/blue-box-77-sky.html#comment-108655562">Martyn Davies</a></li><br />
		<li>Comment (email) from Detlef</li><br />
		<li>Comment (email) from Dan McGinn-Combs</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>41:43 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=labVEA"><img src="http://feeds.feedburner.com/~a/BlueBox?i=labVEA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=PJqInK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=PJqInK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=DKnQRK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=DKnQRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=0ojlsK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=0ojlsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=zQkKxK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=zQkKxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=j1XWBk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=j1XWBk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=t89cyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=t89cyK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/375722849" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 16:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip users based">voip users based</category>
      <category domain="http://securityratty.com/tag/enterprise voip planet">enterprise voip planet</category>
      <category domain="http://securityratty.com/tag/voip calls">voip calls</category>
      <category domain="http://securityratty.com/tag/voip privacy">voip privacy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/375722849/blue-box-81-isk.html">Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Open Letter to Verizon Wireless]]></title>
      <link>http://securityratty.com/article/33861048df9fa12f13bd8d46690d0a5b</link>
      <guid>http://securityratty.com/article/33861048df9fa12f13bd8d46690d0a5b</guid>
      <description><![CDATA[After receiving no support from agents at the Verizon Wireless store or by agents on the phone, I decided to write them and make it an open letter. Its no secret that Verizon has a great network, but...]]></description>
      <content:encoded><![CDATA[<P><FONT size=2><FONT face=Verdana>After receiving no support from agents at the Verizon Wireless store or by agents on the phone, I decided to write them and make it an open letter.<SPAN>&nbsp; </SPAN>It&#8217;s no secret that Verizon has a great network, but it&#8217;s also no secret that their phone selection stinks.<SPAN>&nbsp; </SPAN>I don&#8217;t want to leave them and am hoping that whatever little bad press I can cause will encourage them to resolve the issue.<SPAN>&nbsp; </SPAN>If not, I&#8217;m tapping out.<SPAN>&nbsp; </SPAN>For 3 years I have hated my phone and loved their network.<SPAN>&nbsp; </SPAN>I&#8217;m ready to feel mediocre about both.<SPAN>&nbsp; </SPAN>Here it goes: </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>I am currently without a phone and would appreciate a speedy reply. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>I have been a Verizon Wireless customer for over 5 years and my monthly bill easily averages over $200 during that time frame.<SPAN>&nbsp; </SPAN>While I love your network, I have been completely unsatisfied by your selection of phones.<SPAN>&nbsp; </SPAN>It is a stretch to say that my last phone worked&#8212;it had a feature called a battery that allowed me to switch from the car charger to my office charger without dying.<SPAN>&nbsp; </SPAN>And I waited&#8212;under duress&#8212;until I was allowed to purchase a new phone with the discount. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>My current phone has a wonderful battery life, but this is the 4th time the charger has snapped off in the phone.<SPAN>&nbsp; </SPAN>The phone is fine, but I keep paying $30 for new chargers.<SPAN>&nbsp; </SPAN>I refuse to purchase another or wait until February when I will be eligible for a new phone.<SPAN>&nbsp; </SPAN>You sold a phone with a design flaw, and I&#8217;m not even asking for a refund or a free phone.<SPAN>&nbsp; </SPAN>Just allow me to take a chance on a new one at the 2 year contract renewal rate.<SPAN>&nbsp; </SPAN></FONT></FONT>
<P><FONT size=2><FONT face=Verdana><SPAN></SPAN></FONT></FONT><FONT size=2><FONT face=Verdana>If not, I will gladly pay the early termination fee and leave Verizon.<SPAN>&nbsp; </SPAN>On general principle, I will spend more money canceling my account with you than I would likely receive as a discount on a new phone.<SPAN>&nbsp; </SPAN>As a customer, I consider it unacceptable that you sell inferior phones and leave me with no recourse. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>The first time I waited haplessly to become eligible for a new phone.<SPAN>&nbsp; </SPAN>I will not suffer a second time.<SPAN>&nbsp; </SPAN>If you don&#8217;t like the fact that you will end up losing money by allowing me to purchase a new phone early, I suggest you take it up your vendors who supply you with awful products.<SPAN>&nbsp; </SPAN>I can promise you that we will both lose more money if you don&#8217;t. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>Sincerely, </FONT></FONT>
<P><FONT face=Verdana size=2>Eric Marvets</FONT></P><img src ="http://marvets.com/blog/aggbug/12205.aspx" width = "1" height = "1" />]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 11:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/phone workedit">phone workedit</category>
      <category domain="http://securityratty.com/tag/free phone">free phone</category>
      <category domain="http://securityratty.com/tag/current phone">current phone</category>
      <category domain="http://securityratty.com/tag/verizon">verizon</category>
      <category domain="http://securityratty.com/tag/phone selection stinks">phone selection stinks</category>
      <category domain="http://securityratty.com/tag/verizon wireless store">verizon wireless store</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/verizon wireless customer">verizon wireless customer</category>
      <source url="http://marvets.com/blog/archive/2008/08/25/12205.aspx">Open Letter to Verizon Wireless</source>
    </item>
    <item>
      <title><![CDATA[Red Light Cameras Don't Work]]></title>
      <link>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</link>
      <guid>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</guid>
      <description><![CDATA[Interesting : the solution to one problem causes another. &quot;The rigorous studies clearly show red-light cameras don't work,&quot; said lead author Barbara Langland-Orban, professor and chair of health...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.ridelust.com/red-light-cameras-just-dont-work/">Interesting</a>: the solution to one problem causes another.</p>

<blockquote>"The rigorous studies clearly show red-light cameras don't work," said lead author Barbara Langland-Orban, professor and chair of health policy and management at the USF College of Public Health. "Instead, they increase crashes and injuries as drivers attempt to abruptly stop at camera intersections."

<p>Comprehensive studies from North Carolina, Virginia, and Ontario have all reported cameras are associated with increases in crashes. The study by the Virginia Transportation Research Council also found that cameras were linked to increased crash costs. The only studies that conclude cameras reduced crashes or injuries contained "major research design flaws," such as incomplete data or inadequate analyses, and were always conducted by researchers with links to the Insurance Institute for Highway Safety. The IIHS, funded by automobile insurance companies, is the leading advocate for red-light cameras since insurance companies can profit from red-light cameras by way of higher premiums due to increased crashes and citations.</blockquote></p>

<p>And, of course, the agenda of the government is to increase revenue due to fines:</p>

<blockquote>A 2001 paper by the Office of the Majority Leader of the U.S. House of Representatives reported that red-light cameras are "a hidden tax levied on motorists." The report came to the same conclusions that all of the other valid studies have, that red-light cameras are associated with increased crashes and that the timings at yellow lights are often set too short to increase tickets for red-light running. That's right, the state actually tampers with the yellow light settings to make them shorter, and more likely to turn red as you're driving through them.

<p>In fact, six U.S. cities have been found guilty of shortening the yellow light cycles below what is allowed by law on intersections equipped with cameras meant to catch red-light runners. Those local governments have completely ignored the safety benefit of increasing the yellow light time and decided to install red-light cameras, shorten the yellow light duration, and collect the profits instead.</p>

<p>The cities in question include Union City, CA, Dallas and Lubbock, TX, Nashville and Chattanooga, TN, and Springfield, MO, according to Motorists.org, which collected information from reports from around the country.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GkyduK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GkyduK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gARYoK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gARYoK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:19:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/red">red</category>
      <category domain="http://securityratty.com/tag/red-light">red-light</category>
      <category domain="http://securityratty.com/tag/red-light runners">red-light runners</category>
      <category domain="http://securityratty.com/tag/install red-light cameras">install red-light cameras</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/red-light cameras">red-light cameras</category>
      <category domain="http://securityratty.com/tag/conclude cameras">conclude cameras</category>
      <category domain="http://securityratty.com/tag/studies">studies</category>
      <category domain="http://securityratty.com/tag/rigorous studies">rigorous studies</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/red_light_camer.html">Red Light Cameras Don't Work</source>
    </item>
    <item>
      <title><![CDATA[Web Based Botnet Command and Control Kit 2.0]]></title>
      <link>http://securityratty.com/article/4f945955ba8a424fe6b9352583602062</link>
      <guid>http://securityratty.com/article/4f945955ba8a424fe6b9352583602062</guid>
      <description><![CDATA[The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/bFba_0dWvI4/s1600-h/web_botnet_cc_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/TqKIw6bxpjw/s200-R/web_botnet_cc_1.JPG" /></a>The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose features clearly indicate that the kit's coder know exactly which niches to fill - presumably based on his personal experience or market research into competing products.<br />
<br />
What are some its key differentiation factors? <b>Multitasking</b> at its best, for instance, the kits provides the botnet master with the opportunity to manage numerous different task such as several malware campaigns and DDoS attacks simultaneously, where each of these gets a separate metrics page.  <b>&nbsp;</b><br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/Yicbw9alvSs/s1600-h/web_botnet_cc_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/rzG7g1DxhQs/s200-R/web_botnet_cc_2.JPG" /></a><b>Automation</b> of malicious tasks, by setting up tasks, and issuing notices on the status of the task, when it was run and when it was ended. Just consider the possibilities for a scheduling malware and DDoS attacks for different quarters. <b>&nbsp;</b><br />
<br />
<b>Segmentation</b> in every aspect of the tasks, for instance, a DDoS attacks against a particular site can be scheduled to launched on a specific date from infected hosts based in chosen countries only. <b>&nbsp;</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/UMGxAh9uGF0/s1600-h/web_botnet_cc_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/ZlxV-mc44fM/s200-R/web_botnet_cc_3.JPG" /></a><b>Customized DDoS</b> in the sense of empowering the botnet master with point'n'click ability to dedicate a precise number of the bots to participate, which countries they should be based in, and for how long the attack should remain active. <b>Quality and assurance in DDoS attacks</b> based on the measurement of the bot's bandwidth against a particular country, in this case the object of the attack, so theoretically bots from neighboring countries would DDoS the country in question far more efficiently. <b>&nbsp;</b><br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/NKwLnKmmH44/s1600-h/web_botnet_cc_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/pVosEgAltxk/s200-R/web_botnet_cc_4.JPG" /></a><b>Historical malware campaign performance</b>, is perhaps the most quality assurance feature in the entire kit, presumably created in order to allow the person behind it to measure which were the most effective malware and DDoS campaigns that he executed in the past. From an OSINT perspective, sacrificing his operational security by maintaing detailed logs from previous attacks is a gold mine directly establishing his relationships with previous malware campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/BhFmeDoa8Lk/s1600-h/web_botnet_cc_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/vij9THb60ow/s200-R/web_botnet_cc_5.JPG" /></a><b>Bot Description</b>:  &nbsp; <br />
<div dir="ltr" id="result_box">1. Completely invisible Bot work in the system.  <br />
2. Not loads system.  <br />
3. Invisible in the process.  <br />
4. Workaround all firewall.  <br />
5. Bot implemented as a driver.  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/SzpE6NqryP8/s1600-h/web_botnet_cc_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/CptzW9_ji-k/s200-R/web_botnet_cc_6.JPG" /></a><b>Functions Bot</b> (constantly updated):&nbsp;</div><div dir="ltr" id="result_box">1. Downloading a file (many options). <br />
2. HTTP DDoS (many options, including http authentication).  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/LI52hSDJhpA/s1600-h/web_botnet_cc_7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/AIaGhGUL0Fk/s200-R/web_botnet_cc_7.JPG" /></a><b>The web interface</b>&nbsp;</div><div dir="ltr" id="result_box">-- Convenient manager tasks. <br />
-- Every task can be stopped, put on pause, etc. ... <br />
-- Interest and visual scale of the task.&nbsp;&nbsp;</div><div dir="ltr" id="result_box">-- A task manager for DDoS and Loader <br />
&nbsp;&nbsp;&nbsp;&nbsp;</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/Zqcrn6XWYEw/s1600-h/web_botnet_cc_8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/0PQgE_timh4/s200-R/web_botnet_cc_8.JPG" /></a>-- <b>For DDoS tasks</b> </div><div dir="ltr" id="result_box">Bots involved in DDoS 'f. <br />
Condition of the victim (works, fell).  <br />
</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/HNHO_ar0MgA/s1600-h/web_botnet_cc_9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/Y1z0VIR3B9k/s200-R/web_botnet_cc_9.JPG" /></a>2. <b>Bots manager  </b><br />
-- Displays a list of bots (postranichno). <br />
-- Obratseniya date of the first and last. <br />
-- ID Bot. <br />
-- Country Bot. <br />
-- Type Bot. <br />
-- The status Bot (online / offline). <br />
-- Bot bandwidth to different parts of the world (europe, asia). <br />
-- The possibility of removing bots</div><div dir="ltr" id="result_box">-- When you click on ID Bot loadable still a wealth of information about it</div><div dir="ltr" id="result_box"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/BM5pm1_Rtag/s1600-h/web_botnet_cc_11.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/mQEa7wVxDNc/s200-R/web_botnet_cc_11.JPG" /></a>3. <b>Statistics botneta  </b><br />
-- Statistics both common and build Bot. <br />
-- Information on the growth and decline botneta dates (and build). <br />
-- Bots online <br />
-- All bots</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/JTOJS-ZHQek/s1600-h/web_botnet_cc_12.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/ujbOfFEX9TA/s200-R/web_botnet_cc_12.JPG" /></a>-- Dead bots. <br />
<br />
4. <b>Statistics botneta country</b></div><div dir="ltr" id="result_box">-- All countries to work on&nbsp;</div><div dir="ltr" id="result_box">-- New work by country&nbsp;</div><div dir="ltr" id="result_box">-- Online work from country to country</div><div dir="ltr" id="result_box">-- Dead bots by country</div><div dir="ltr" id="result_box"></div><div dir="ltr" id="result_box">5. <b>Detailed history botneta</b>&nbsp;</div><div dir="ltr" id="result_box">6. <b>Convenient user-friendly interface adding teams</b> <br />
8. <b>Admin minimal server loads</b>  <br />
-- Use php5/mysql  <br />
</div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/3oulo2cgTtM/s1600-h/web_botnet_cc_13.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/xEI9xAwNGNM/s200-R/web_botnet_cc_13.JPG" /></a><b>Upcoming features : </b><br />
1. Form grabber (price increase substantially), for old customers will be charged as an upgrade <br />
2. Public key cryptography<br />
3. Clustering campaigns and DDoS attacks<br />
<br />
Despite it's proprietary nature, it's quality and innovative features will sooner or later leak out for everyone to take advantage of, a rather common lifecycle for the majority of proprietary malware kits in general.</div><div dir="ltr" id="result_box"><br />
<b>Related posts:</b></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy DDoS Bot Web Based<br />
</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot - Web Based Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot - Web Based Malware</a> </div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html">Custom DDoS Capabilities Within a Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">Loads.cc - DDoS for Hire Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a>&nbsp;</div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html">Botnet Communication Platforms</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html">A Botnet Master's To-Do List</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/05/ddos-on-demand-vs-ddos-extortion.html">DDoS on Demand VS DDoS Extortion</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/how-does-botnet-with-100k-infected-pcs.html">How Does a Botnet with 100k Infected PCs Look Like?</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y5dBtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y5dBtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WsNccK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WsNccK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ToV4Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ToV4Pk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=I6a7ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=I6a7ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2S7WNK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2S7WNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qk66sK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qk66sK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8S5ask"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8S5ask" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/372102101" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:02:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos attacks based">ddos attacks based</category>
      <category domain="http://securityratty.com/tag/ddos attacks">ddos attacks</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/previous malware campaigns">previous malware campaigns</category>
      <category domain="http://securityratty.com/tag/ddos attacks simultaneously">ddos attacks simultaneously</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/country bot">country bot</category>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/372102101/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</source>
    </item>
    <item>
      <title><![CDATA[Securing Your Gmail With Just a Click]]></title>
      <link>http://securityratty.com/article/607ed5a24c0b50b25a2cbe170ddda454</link>
      <guid>http://securityratty.com/article/607ed5a24c0b50b25a2cbe170ddda454</guid>
      <description><![CDATA[Im learning lessons on security this week, because Ive just brought a new kitten home and she is exploring every nook and cranny in my home. Chewing on my cacti, playing with the blinds, and naturally...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;m learning lessons on security this week, because I&#8217;ve just brought <a rel="nofollow" target="_blank" href="http://flickr.com/photos/sylphbranching/2778845191/">a new kitten </a>home and she is exploring every nook and cranny in my home. Chewing on my cacti, playing with the blinds, and naturally clawing up the couch. I wish there was a way to press a button and kitty-proof my house!</p>
<p>Luckily there now is a way to press a button and get secure gmail with SSL, at least. Thanks to <span class="entry-author-name"><a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~r/Security-Bloggers-Network/~3/370004218/">Martin McKeay</a> for the tip </span>&#8211; the big Goog has enabled HTTPS in the Gmail options settings&#8211;</p>
<blockquote><p>Gmail has been capable of running on SSL for quite some time, but it’s not something that’s enabled by default. I always typed the https in by hand, but I don’t completely trust that method. I’ve used Better Gmail2 in the past, but that doesn’t like FireFox 3 for some reason. There are also a number of <a rel="nofollow" target="_blank" href="http://userscripts.org/scripts/show/1404">scripts</a> for <a rel="nofollow" target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/748">GreaseMonkey</a> that force Gmail to use SSL, but now Gmail has made it an <a rel="nofollow" target="_blank" href="http://googlesystem.blogspot.com/2008/07/force-gmail-to-use-secure-connection.html">option on the settings page</a>. It’s on the bottom of the page and easy to miss if you’re not looking closely.</p></blockquote>
<p>Good, now I can stop worrying about my email and get to the tough task of securing my apartment instead.</p>
<p><span class="entry-author-name">Go read the full article about this new feature <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~r/Security-Bloggers-Network/~3/370004218/">here.</a><br />
</span></p>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 11:51:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gmail">gmail</category>
      <category domain="http://securityratty.com/tag/force gmail">force gmail</category>
      <category domain="http://securityratty.com/tag/secure gmail">secure gmail</category>
      <category domain="http://securityratty.com/tag/gmail options settings">gmail options settings</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/settings page">settings page</category>
      <category domain="http://securityratty.com/tag/ssl">ssl</category>
      <category domain="http://securityratty.com/tag/completely trust">completely trust</category>
      <category domain="http://securityratty.com/tag/martin mckeay">martin mckeay</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/371376583/">Securing Your Gmail With Just a Click</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[Opinion: Encryption compliance still the Wild West]]></title>
      <link>http://securityratty.com/article/515cd2dfc3a309002722c001aa023901</link>
      <guid>http://securityratty.com/article/515cd2dfc3a309002722c001aa023901</guid>
      <description><![CDATA[Some states do not consider encryption alone sufficient to ensure that the data is unrecoverable, and at this stage in the game, companies cannot assume that just because they have encrypted data or...]]></description>
      <content:encoded><![CDATA[Some states do not consider encryption alone sufficient to ensure that the data is unrecoverable, and at this stage in the game, companies cannot assume that just because they have encrypted data or implemented encryption key management that they are either completely protected from future legal liabilities or have complied with the law.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=wTX6O7"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=wTX6O7" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/368453695" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/encryption">encryption</category>
      <category domain="http://securityratty.com/tag/encryption key management">encryption key management</category>
      <category domain="http://securityratty.com/tag/future legal liabilities">future legal liabilities</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/completely">completely</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/assume">assume</category>
      <category domain="http://securityratty.com/tag/stage">stage</category>
      <category domain="http://securityratty.com/tag/ensure">ensure</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/368453695/article.do">Opinion: Encryption compliance still the Wild West</source>
    </item>
    <item>
      <title><![CDATA[BlackHat Recap]]></title>
      <link>http://securityratty.com/article/bec2ea65daab94e0e7001ef1ba7b1b9a</link>
      <guid>http://securityratty.com/article/bec2ea65daab94e0e7001ef1ba7b1b9a</guid>
      <description><![CDATA[Another BlackHat has come and gone. As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations. I had...]]></description>
      <content:encoded><![CDATA[<p>Another BlackHat has come and gone.  As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations.  I had a fantastic time catching up with old friends and finally getting the opportunity to meet more of the <a href="http://n0where.org/security-twits/">Security Twits</a> and others in the security community.  I didn&#8217;t submit a talk this year, but nevertheless, fake Dan Kaminsky was still excited to see me.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b.jpg"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b-300x225.jpg" alt="" title="chris_2742966251_1b47297b33_b" width="300" height="225" class="aligncenter size-medium wp-image-215 photoborder" /></center></a></p>
<p>My favorite talk, as expected, was the Sotirov/Dowd talk on <a href="http://taossa.com/archive/bh08sotirovdowd.pdf">How To Impress Girls With Browser Memory Protection Bypasses</a>.  The attack is a conceptually simple, yet completely reliable technique for exploiting vulnerabilities in web browsers.  Of course, the media has <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html">sensationalized </a> the impact of their findings, but ultimately, this is still significant as far as browser-based exploits are concerned.  It&#8217;s worth mentioning that part of the technique allowing them to load a .NET DLL at an arbitrary location under Vista was reliant on an implementation bug wherein the OS disables ASLR if the version in the .NET COR header was below a certain value.  However, the address space spraying and stack spraying techniques are likely to be extended to other platforms utilizing similar memory protection mechanisms.  </p>
<p>As for the girls?  I can report first-hand that the ladies at TAO on Wednesday night were hanging on <a href="http://twitter.com/alexsotirov">Alex</a>&#8217;s every word.  They were particularly impressed when he whipped out the laptop for a live demo.  Unfortunately, none of the dozen iPhone owners in the immediate vicinity thought to snap a picture (too busy Twittering).  Oh well.  </p>
<p>I also enjoyed Hovav Shacham&#8217;s talk on return-oriented programming.  Simply put, he described a generalization of the return-to-libc shellcode approach with the intent to demonstrate that one could achieve Turing-complete computation using &#8220;found code&#8221; in process images.  By chaining together series of mini-computations ending in return (RET) instructions, it was possible to build higher-level programming constructs such as branches and loops.  The nature of the x86 instruction set provides some flexibility because instructions are interpreted differently depending on how you align the instruction pointer (i.e. the old shellcode trick of searching the process image for any JMP EBX instruction and using that as your EIP).  In RISC architectures such as SPARC, however, you don&#8217;t have that luxury; if your %pc isn&#8217;t aligned properly you get a bus error.  So it was quite interesting to see that they were able to extend the concept to RISC.  The practicality of the attack technique is limited by the fact that the shellcode is tuned to a particular binary image &#8212; if the shellcode was built using instructions extrapolated from glibc 2.3.5, it won&#8217;t work for a system running glibc 2.4.  </p>
<p>I thought Scott Stender&#8217;s talk on <a href="http://isecpartners.com/files/iSEC%20Partners%20-%20Concurrency%20Attacks%20in%20Web%20Applications.pdf">Concurrency Attacks in Web Applications</a> was interesting as well.  In a nutshell, spewing thousands of simultaneous requests at web application transactions that are not thread-safe can create interesting problems.  In the presentation, Scott ran his demo against a VM running on the attack machine.  I found myself wondering how effective the same attack would be over the Internet &#8212; would it be significantly less reliable (or not at all)?  Race conditions are generally easier to exploit locally than remotely due to more predictable execution conditions.  Certainly this is an under-tested vulnerability class though.</p>
<p>One presentation I wasn&#8217;t able to attend but want to follow up on is <a href="http://twitter.com/nate_mcfeters">Nate McFeters</a>, John Heasman, and Rob Carter&#8217;s talk which discussed the GIFAR attack I&#8217;ve been hearing so much about lately.  The gist is that you can create a file that is both a valid GIF and a valid JAR, then use some Java applet tricks to initiate HTTP requests on behalf of the victim.  </p>
<p>Finally, the <a href="http://pwnie-awards.org/2008/">Pwnie Awards</a> didn&#8217;t fail to disappoint.  Drama ensued over the Most Overhyped award, but at least this year some of the winners showed up to claim their awards!  <a href="http://twitter.com/halvarflake">Halvar</a> rapping Symantec lyrics was also quite memorable.</p>
<p>All in all, a fun and informative week, but as usual, I was relieved to get the hell out of Vegas and head home on Friday morning. </p>
<p>P.S. For a much more entertaining BlackHat/Defcon Recap, read <a href="http://securityuncorked.net/2008/08/anecdotes-blackhat-defcon/">Jennifer Jabbusch&#8217;s account</a> of the week&#8217;s events.  It&#8217;s my favorite one so far!</p>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 18:43:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/favorite">favorite</category>
      <category domain="http://securityratty.com/tag/favorite talk">favorite talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/sotirovdowd talk">sotirovdowd talk</category>
      <category domain="http://securityratty.com/tag/scott stenders talk">scott stenders talk</category>
      <category domain="http://securityratty.com/tag/completely reliable technique">completely reliable technique</category>
      <category domain="http://securityratty.com/tag/reliable">reliable</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/technique">technique</category>
      <source url="http://www.veracode.com/blog/?p=202">BlackHat Recap</source>
    </item>
    <item>
      <title><![CDATA[BlackHat Recap]]></title>
      <link>http://securityratty.com/article/6b779e65a6ad790dd8e631057208ff77</link>
      <guid>http://securityratty.com/article/6b779e65a6ad790dd8e631057208ff77</guid>
      <description><![CDATA[Another BlackHat has come and gone. As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations. I had...]]></description>
      <content:encoded><![CDATA[<p>Another BlackHat has come and gone.  As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations.  I had a fantastic time catching up with old friends and finally getting the opportunity to meet more of the <a href="http://n0where.org/security-twits/">Security Twits</a> and others in the security community.  I didn&#8217;t submit a talk this year, but nevertheless, <a href="http://flickr.com/photos/fakedankaminsky/">fake Dan Kaminsky</a> was still excited to see me.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b.jpg"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b-300x225.jpg" alt="" title="chris_2742966251_1b47297b33_b" width="300" height="225" class="aligncenter size-medium wp-image-215 photoborder" /></center></a></p>
<p>My favorite talk, as expected, was the Sotirov/Dowd talk on <a href="http://taossa.com/archive/bh08sotirovdowd.pdf">How To Impress Girls With Browser Memory Protection Bypasses</a>.  The attack is a conceptually simple, yet completely reliable technique for exploiting vulnerabilities in web browsers.  Of course, the media has <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html">sensationalized</a> the impact of their findings, but ultimately, this is still significant as far as browser-based exploits are concerned (here is a <a href="http://blogs.zdnet.com/Bott/?p=513">more accurate report</a>).  It&#8217;s worth mentioning that part of the technique allowing them to load a .NET DLL at an arbitrary location under Vista was reliant on an implementation bug wherein the OS disables ASLR if the version in the .NET COR header was below a certain value.  However, the address space spraying and stack spraying techniques are likely to be extended to other platforms utilizing similar memory protection mechanisms.  </p>
<p>As for the girls?  I can report first-hand that the ladies at TAO on Wednesday night were hanging on <a href="http://twitter.com/alexsotirov">Alex</a>&#8217;s every word.  They were particularly impressed when he whipped out the laptop for a live demo.  Unfortunately, none of the dozen iPhone owners in the immediate vicinity thought to snap a picture (too busy Twittering).  Oh well.  </p>
<p>I also enjoyed Hovav Shacham&#8217;s talk on return-oriented programming.  Simply put, he described a generalization of the return-to-libc shellcode approach with the intent to demonstrate that one could achieve Turing-complete computation using &#8220;found code&#8221; in process images.  By chaining together series of mini-computations ending in return (RET) instructions, it was possible to build higher-level programming constructs such as branches and loops.  The nature of the x86 instruction set provides some flexibility because instructions are interpreted differently depending on how you align the instruction pointer (i.e. the old shellcode trick of searching the process image for any JMP EBX instruction and using that as your EIP).  In RISC architectures such as SPARC, however, you don&#8217;t have that luxury; if your %pc isn&#8217;t aligned properly you get a bus error.  So it was quite interesting to see that they were able to extend the concept to RISC.  The practicality of the attack technique is limited by the fact that the shellcode is tuned to a particular binary image &#8212; if the shellcode was built using instructions extrapolated from glibc 2.3.5, it won&#8217;t work for a system running glibc 2.4.  </p>
<p>I thought Scott Stender&#8217;s talk on <a href="http://isecpartners.com/files/iSEC%20Partners%20-%20Concurrency%20Attacks%20in%20Web%20Applications.pdf">Concurrency Attacks in Web Applications</a> was interesting as well.  In a nutshell, spewing thousands of simultaneous requests at web application transactions that are not thread-safe can create interesting problems.  In the presentation, Scott ran his demo against a VM running on the attack machine.  I found myself wondering how effective the same attack would be over the Internet &#8212; would it be significantly less reliable (or not at all)?  Race conditions are generally easier to exploit locally than remotely due to more predictable execution conditions.  Certainly this is an under-tested vulnerability class though.</p>
<p>One presentation I wasn&#8217;t able to attend but want to follow up on is <a href="http://twitter.com/nate_mcfeters">Nate McFeters</a>, John Heasman, and Rob Carter&#8217;s talk which discussed the GIFAR attack I&#8217;ve been hearing so much about lately.  The gist is that you can create a file that is both a valid GIF and a valid JAR, then use some Java applet tricks to initiate HTTP requests on behalf of the victim.  </p>
<p>Finally, the <a href="http://pwnie-awards.org/2008/">Pwnie Awards</a> didn&#8217;t fail to disappoint.  Drama ensued over the Most Overhyped award, but at least this year some of the winners showed up to claim their awards!  <a href="http://twitter.com/halvarflake">Halvar</a> rapping Symantec lyrics was also quite memorable.</p>
<p>All in all, a fun and informative week, but as usual, I was relieved to get the hell out of Vegas and head home on Friday morning. </p>
<p>P.S. For a much more entertaining BlackHat/Defcon Recap, read <a href="http://securityuncorked.net/2008/08/anecdotes-blackhat-defcon/">Jennifer Jabbusch&#8217;s account</a> of the week&#8217;s events.  It&#8217;s my favorite one so far!</p>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 18:43:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/favorite">favorite</category>
      <category domain="http://securityratty.com/tag/favorite talk">favorite talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/sotirovdowd talk">sotirovdowd talk</category>
      <category domain="http://securityratty.com/tag/scott stenders talk">scott stenders talk</category>
      <category domain="http://securityratty.com/tag/completely reliable technique">completely reliable technique</category>
      <category domain="http://securityratty.com/tag/reliable">reliable</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/technique">technique</category>
      <source url="http://www.veracode.com/blog/2008/08/blackhat-recap/">BlackHat Recap</source>
    </item>
  </channel>
</rss>
