<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: contemporary]]></title>
    <link>http://securityratty.com/tag/contemporary</link>
    <description></description>
    <pubDate>Sat, 29 Dec 2007 03:43:45 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Meet ratproxy, our passive web security assessment tool]]></title>
      <link>http://securityratty.com/article/bc78dd4116c64ea5b3a05fa82e188ff7</link>
      <guid>http://securityratty.com/article/bc78dd4116c64ea5b3a05fa82e188ff7</guid>
      <description><![CDATA[Posted by Michal Zalewski

We're happy to announce that we've just open-sourced ratproxy , a passive web application security assessment tool that we've been using internally at Google. This utility,...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Michal Zalewski</span><br /><br />We're happy to announce that we've just open-sourced <a href="http://code.google.com/p/ratproxy">ratproxy</a>, a passive web application security assessment tool that we've been using internally at Google. This utility, developed by our information security engineering team, is designed to transparently analyze legitimate, browser-driven interactions with a tested web property and automatically pinpoint, annotate, and prioritize potential flaws or areas of concern.  <br /><br />The proxy analyzes problems such as cross-site script inclusion threats, insufficient cross-site request forgery defenses, caching issues, cross-site scripting candidates, potentially unsafe cross-domain code inclusion schemes and information leakage scenarios, and much more. (A more-detailed discussion of these features and information on securing vulnerable applications is provided <a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc">here</a>.) Compared with more-traditional active crawlers, or with fully manual request inspection and modification frameworks, this approach offers several significant advantages in terms of minimized overhead; marginalized risk of site disruptions; high coverage of complex, client-driven application states in web 2.0 solutions; and insight into dynamic cross-domain trust models.<br /><br />We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies. We believe that responsible security research brings a net overall benefit to the safety of the Web as a whole, and have released this tool explicitly to support that kind of research.<br /><br />To download the proxy, please visit this <a href="http://ratproxy.googlecode.com/files/ratproxy-1.50.tar.gz">page</a>. Also, please keep in mind that the proxy is designed solely to highlight interesting patterns in web applications, and a further analysis by a security professional is often required to interpret the results and their significance for the tested platform.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=cTCU6J"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=cTCU6J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=K3C5fj"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=K3C5fj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/324447250" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 12:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information leakage scenarios">information leakage scenarios</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/contemporary web technologies">contemporary web technologies</category>
      <category domain="http://securityratty.com/tag/information security community">information security community</category>
      <category domain="http://securityratty.com/tag/web property">web property</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/324447250/meet-ratproxy-our-passive-web-security.html">Meet ratproxy, our passive web security assessment tool</source>
    </item>
    <item>
      <title><![CDATA[Meet ratproxy, our passive web security assessment tool]]></title>
      <link>http://securityratty.com/article/bdf72a712e886694b4644a9a0db12b4c</link>
      <guid>http://securityratty.com/article/bdf72a712e886694b4644a9a0db12b4c</guid>
      <description><![CDATA[Posted by Michal Zalewski

We're happy to announce that we've just open-sourced ratproxy , a passive web application security assessment tool that we've been using internally at Google. This utility,...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Michal Zalewski</span><br /><br />We're happy to announce that we've just open-sourced <a href="http://code.google.com/p/ratproxy">ratproxy</a>, a passive web application security assessment tool that we've been using internally at Google. This utility, developed by our information security engineering team, is designed to transparently analyze legitimate, browser-driven interactions with a tested web property and automatically pinpoint, annotate, and prioritize potential flaws or areas of concern.  <br /><br />The proxy analyzes problems such as cross-site script inclusion threats, insufficient cross-site request forgery defenses, caching issues, cross-site scripting candidates, potentially unsafe cross-domain code inclusion schemes and information leakage scenarios, and much more. (A more-detailed discussion of these features and information on securing vulnerable applications is provided <a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc">here</a>.) Compared with more-traditional active crawlers, or with fully manual request inspection and modification frameworks, this approach offers several significant advantages in terms of minimized overhead; marginalized risk of site disruptions; high coverage of complex, client-driven application states in web 2.0 solutions; and insight into dynamic cross-domain trust models.<br /><br />We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies. We believe that responsible security research brings a net overall benefit to the safety of the Web as a whole, and have released this tool explicitly to support that kind of research.<br /><br />To download the proxy, please visit this <a href="http://ratproxy.googlecode.com/files/ratproxy-1.50.tar.gz">page</a>. Also, please keep in mind that the proxy is designed solely to highlight interesting patterns in web applications, and a further analysis by a security professional is often required to interpret the results and their significance for the tested platform.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=5AvS6vw2"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=sIWTM6AF"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=sIWTM6AF" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/matIm4t6Uks" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 12:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information leakage scenarios">information leakage scenarios</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/contemporary web technologies">contemporary web technologies</category>
      <category domain="http://securityratty.com/tag/information security community">information security community</category>
      <category domain="http://securityratty.com/tag/web property">web property</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/matIm4t6Uks/meet-ratproxy-our-passive-web-security.html">Meet ratproxy, our passive web security assessment tool</source>
    </item>
    <item>
      <title><![CDATA[Trend Micro mulls VB100 test pull-out]]></title>
      <link>http://securityratty.com/article/d7b61dd66c84c1474a1a1747e17a784d</link>
      <guid>http://securityratty.com/article/d7b61dd66c84c1474a1a1747e17a784d</guid>
      <description><![CDATA[Security giant Trend Micro is considering pulling its antivirus software from the Virus Bulletin 100 (VB100) tests, claiming they no longer reflect contemporary...]]></description>
      <content:encoded><![CDATA[Security giant Trend Micro is considering pulling its antivirus software from the Virus Bulletin 100 (VB100) tests, claiming they no longer reflect contemporary malware.]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reflect contemporary malware">reflect contemporary malware</category>
      <category domain="http://securityratty.com/tag/vb100">vb100</category>
      <category domain="http://securityratty.com/tag/virus bulletin">virus bulletin</category>
      <category domain="http://securityratty.com/tag/antivirus software">antivirus software</category>
      <category domain="http://securityratty.com/tag/tests">tests</category>
      <source url="http://www.networkworld.com/news/2008/060508-trend-micro-mulls-vb100-test.html?fsrc=rss-security">Trend Micro mulls VB100 test pull-out</source>
    </item>
    <item>
      <title><![CDATA[The Real "Security 2.0"?]]></title>
      <link>http://securityratty.com/article/bacd88d359bef5faad5d771a70263a69</link>
      <guid>http://securityratty.com/article/bacd88d359bef5faad5d771a70263a69</guid>
      <description><![CDATA[Yes! YES! Y-E-S! You guessed right - a blogging frenzy; I am baaack from my vacation/speaking in first cold then warm places and I have a &quot;backblog&quot; of fun items

First is &quot; Why Hacking Changed &quot; from...]]></description>
      <content:encoded><![CDATA[Yes! YES! Y-E-S! You guessed right - a blogging frenzy; I am baaack from my vacation/speaking in first cold then warm places and I have a "backblog" of fun items.<br /><br />First is "<a href="http://www.0x000000.com/?i=536">Why Hacking Changed</a>" from <a href="http://www.0x000000.com">The Hacker Webzine</a>. Please read it; and see thru all the drama.<br /><br />Some quotes:<br /><br />"Old school hacking is dead, network hacking is dead, firewalls are useless and AV software is a mere redundant software package that underlines your frustration and ignorance about contemporary hacking."<br /><br />"If you can define hacking today, it no longer means telnetting into servers or blowing whistles, but exploiting the application layer. With the application layer, I also mean the scripting language beneath it, since it interacts with the applications that it's running and share memory, and thereby the hardware it's running on."<br /><br />and<br /><br />"We can even prove that we can own your network with only seven characters typed into your query string: 1' OR 1=1 is far more dangerous than any shellcode I've ever seen in my life."<br /><br />"What works today works also tomorrow. And what will work in two or 5 years from now is software and application hacking."<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uhMZOIG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uhMZOIG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=28tJsXG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=28tJsXG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/263523198" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Apr 2008 08:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application layer">application layer</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/share memory">share memory</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/characters typed">characters typed</category>
      <category domain="http://securityratty.com/tag/hacker webzine">hacker webzine</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/language beneath">language beneath</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/263523198/real-security-20.html">The Real "Security 2.0"?</source>
    </item>
    <item>
      <title><![CDATA[Intellectual Property- what is it and how do we secure it?]]></title>
      <link>http://securityratty.com/article/f736baed0ea94e12b52e2216eb76b8d9</link>
      <guid>http://securityratty.com/article/f736baed0ea94e12b52e2216eb76b8d9</guid>
      <description><![CDATA[Intellectual Property
Intellectual property, a major component of Intellectual Capital, is described in Chapter 4 of IT Governance: Guidelines for Directors . Intellectual property (IP) is a term used...]]></description>
      <content:encoded><![CDATA[<h2>Intellectual Property</h2>
<p>Intellectual property, a major component of Intellectual Capital, is described in Chapter 4 of <strong><a href="http://www.itgovernance.co.uk/products/19" target="_self">IT Governance: Guidelines for Directors</a></strong>. Intellectual property (IP) is a term used to describe certain legal entitlements which are concerned with the protection and usage of recorded media (TV programmes/films/music), written works, names and inventions. IP is usually in the form of:</p>
<ul>
<li>a patent,</li>
<li>a copyright,</li>
<li>a trademark or</li>
<li>a design</li>
</ul>
<p>Every country has its own form of copyright legislation. In the UK, the <strong><a href="http://www.ipo.gov.uk/home.htm" target="_new">UK Patent Office</a></strong> provides substantial information about UK intellectual property rights (&#8217;IPR&#8217;), the <strong><a href="http://www.cla.co.uk/">Copyright Licensing Agency</a></strong> is a critical resource, and the <strong><a href="http://www.wipo.int/portal/index.html.en" target="_new">World Intellectual Property Organization</a></strong> (&#8217;WIPO&#8217;) &#8220;promotes intellectual property throughout the world.&#8221; The <strong><a href="http://www.itgovernance.co.uk/products/44" target="_self">Handbook of Intellectual Property Management</a></strong> is an excellent reference book on the subject.</p>
<p>Further insights into the many different types of IP and the laws governing them are detailed in the <strong><a href="http://www.itgovernance.co.uk/products/1401">Handbook of European Intellectual Property Management</a></strong> which predominantly covers the world of IP from a European perspective or, if you are looking for a specifically legal manual, then <strong><a href="http://www.itgovernance.co.uk/products/1409">Intellectual Property Law, Fourth Edition</a></strong> provides a worldwide perspective and introduction to the subjects.</p>
<p>Both the books mentioned above are available for immediate despatch from the IT Governance online store. IT Governance have searched the book publishing world exhaustively for the most interesting and highly authoritative books on the many different aspects of IP; these are now readily available in one place for you to purchase. Please read on for more information on IP and the books associated with specific aspects of IP.</p>
<h2>Copyright</h2>
<p>Copyright is primarily concerned with the right to use a certain piece of information or a particular expression. Its main principle is that it allows the copyright holder to regulate the use of the item protected by copyright.</p>
<p>The most visible sign that an item is protected by copyright is the symbol © which is usually clearly featured on the item in question. However, this symbol has never been legally recognised.</p>
<p>Copyright can be described in simple terms as the ‘the right to copy the item in question’. If you are looking to understand the ins and outs of copyright, then the best book for you to read is <strong><a href="http://www.itgovernance.co.uk/products/1412">A User&#8217;s Guide to Copyright, Sixth Edition</a></strong>. This cuts through the jargon to provide both legal and non-legal professionals with a guide to the world of copyright.</p>
<p>The law governing copyright is standardised across the world by treaties such as the Berne Convention. If you are looking to grasp the fundamentals of these copyright treaties and gain interpretive guidance, then the doubly authoritative manual, <strong><a href="http://www.itgovernance.co.uk/products/1416">International Copyright and Neighbouring Rights: The Berne Convention and Beyond, Second Edition</a>,</strong> is highly recommended. This is a two book set from Oxford University Press (OUP) which offers highly intelligent insights and guidance into the complex issue of copyright law. Additionally, copies of the most of the major copyright agreements and treaties, such as the Berne and Rome Conventions, are included.</p>
<h2>Patents</h2>
<p>Patents are generally a set of rights granted to an inventor, or to a person or organisation associated with the inventor, for a fixed period of time. These rights are granted in exchange for disclosure of an invention or idea.</p>
<p>Patents usually grant a period of exclusivity in which the inventor, or associated individuals/organisations, can prevent others from making, using, selling, offering to sell or importing the invention. However, these rights are not the same in all countries.</p>
<p>If you are looking to ascertain the ins and outs of UK and EU patent law then <strong><a href="http://www.itgovernance.co.uk/products/1410">A User’s Guide to Patents, Second Edition</a></strong> provides a thorough understanding of these articles. It also addresses many of the wider public policy issues of patents.</p>
<p>There are many different international agreements and treaties governing how patents are enforced. However, these agreements or treaties are usually enshrined in local laws. The main agreements and treaties governing the use of patents are the Trade Related Aspects of Intellectual Property (TRIPS) Agreement and the Paris Convention for the Protection of Industrial Property. Further information on the TRIPS Agreement in particular can be found in a book called <strong><a href="http://www.itgovernance.co.uk/products/1417">Trade Related Aspects of Intellectual Property Rights: A Commentary on the TRIPS Agreement</a></strong>. This book distils the essence of the TRIPS Agreement making it easily interpretable by the layman as well as the legal professional.</p>
<p>For a more thorough country-by-country approach to the legal aspects of patents and which treaties or agreements are, in effect, within a particular country then <strong><a href="http://www.itgovernance.co.uk/products/1415">International Patent Treaties with Commentary</a></strong> is essential reading. It provides country-by-country information of the particular patent laws operating in that country, as well as providing information on how to maximise your patent rights in that country.</p>
<p>Patent searching can often be a difficult task: you can pay third party organisations to undertake searches for you, or you can do it yourself on websites such as <strong><a href="http://www.google.com/patents">Google Patent Search</a></strong>, the <strong><a href="http://www.ipo.gov.uk/home.htm" target="_new">UK Patent Office</a></strong> or the <strong><a href="http://www.uspto.gov/">United States Patent and Trademark Office</a></strong>’s website.</p>
<p>If you are looking for tried and tested methods of searching for patents, and don’t want to pay a third party service provider to do searches for you, then the methods conveyed in <strong><a href="http://www.itgovernance.co.uk/products/1418">Patent Searching: Tool &amp; Techniques</a></strong> are essential. Make sure before filing your patent, that one does not exist for an invention similar to your own, and save time and money on third party services by using the methods in this book.</p>
<h2>Trademarks</h2>
<p>A trademark is a unique and distinctive sign, or indicator of some type, which is used to distinguish a company’s, person’s or legal entity’s products or services from other entities products or services.</p>
<p>Trademarks are usually names, logos, designs, symbols or words. They can also be a combination of all of the previous elements put together.</p>
<p>Trademark rights confer exclusive rights of usage of the trademark within a certain market to licensors. More than one organisation can have rights to use a certain trademark, however the market they can use it in is limited. An example of this would be Apple Music and Apple Computers; the trademark here being an apple symbol.</p>
<p>Further information on the correct usage of trademarks can be found in a highly authoritative manual called <strong><a href="http://www.itgovernance.co.uk/products/1420">Trade Mark Use,</a></strong> which is published by Oxford University Press. This manual clearly describes the correct usage of trademarks and the laws that cover the many different aspects of trademarking.</p>
<p>If you are looking to correctly classify your trademarks in accordance with the Nice Treaty, which is one of the main treaties governing the world trademark system, then <strong>International Trademark Classification: A Guide to the Nice Agreement</strong> is the essential manual you need. The advice included in this handy desk reference is fully in line with the ninth edition of the Nice Classification.</p>
<p>The above manual is written by a high authoritative author, Jesse N. Roberts who is the administrator of trademark classification at the United States Patent and Trademark Office.</p>
<h2>Licensing Intellectual Property</h2>
<p>Many organisations choose to license their trademarks, patents and copyrights to third parties for economic and other purposes. However, if you don’t understand the fundamentals of doing so, you can soon find yourself bogged down in a legal mire.</p>
<p><strong><a href="http://www.itgovernance.co.uk/products/1408">Essentials of Licensing Intellectual Property</a></strong> distils the key information you need to know if your organisation is considering licensing its IP to third party organisations. It demystifies the entire process of IP licensing by providing best-practice processes for every key stage of IP licensing.</p>
<h2>Intellectual Property Law</h2>
<p>There are many different agreements and treaties governing the many different types of intellectual property. IT Governance have scoured the world of publishing to assemble the best selection of both practical and authoritative books on the subject. Whether you are looking for a book covering the TRIPS Agreement or the Nice Treaty, then you will find it here:</p>
<ul>
<li><strong><a href="http://www.itgovernance.co.uk/products/1409">Intellectual Property Law, 4th Edition</a></strong></li>
<li><strong><a href="http://www.itgovernance.co.uk/products/1399">Holyoak and Torremans: Intellectual Property Law, Fourth Edition</a></strong></li>
<li><strong><a href="http://www.itgovernance.co.uk/products/1414">Contemporary Intellectual Property: Law and Policy</a></strong></li>
<li><strong><a href="http://www.itgovernance.co.uk/products/1415">International Patent Treaties with Commentary</a></strong></li>
<li><strong><a href="http://www.itgovernance.co.uk/products/1417">Trade Related Aspects of Intellectual Property Rights: A Commentary on the TRIPS Agreement</a></strong></li>
<li><strong><a href="http://www.itgovernance.co.uk/products/1416">International Copyright and Neighbouring Rights: The Berne Convention and Beyond, Second Edition</a></strong> (two books)</li>
</ul>
<h2>Creating, Managing and Measuring Intellectual Property</h2>
<p>For those who want to go about creating a portfolio of IP, knowing where to start can be very confusing and frustrating. Knowing how to protect IP, which treaties and agreements apply, and understanding the IP management process from creation to fruition are key requirements.</p>
<p>The <strong><a href="http://www.itgovernance.co.uk/products/44">Handbook of Intellectual Property</a></strong> provides a one-stop resource covering the main aspects of IP. Whichever aspect you are looking for, the information in this book is bound to be of interest to you.</p>
<p>It is often not appreciated how much value the effective management of IP can bring to an organisation. However, this is understandable, as IP is, in itself, intangible. In <strong><a href="http://www.itgovernance.co.uk/products/1413">Tangible Strategies for Intangible Assets</a></strong>, the author provides methods for measuring, realising and managing an organisation’s intellectual property. The methods covered include the Balanced Scorecard approach amongst many others. Sample case studies are given of how the methods in the book have been used successfully, including eBay and Amazon amongst many others.</p>
<p><a href="http://www.itgovernance.co.uk/ip.aspx">Source</a></p>
]]></content:encoded>
      <pubDate>Sat, 29 Dec 2007 03:43:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intellectual property">intellectual property</category>
      <category domain="http://securityratty.com/tag/treaties">treaties</category>
      <category domain="http://securityratty.com/tag/international patent treaties">international patent treaties</category>
      <category domain="http://securityratty.com/tag/major copyright agreements">major copyright agreements</category>
      <category domain="http://securityratty.com/tag/agreements">agreements</category>
      <category domain="http://securityratty.com/tag/copyright">copyright</category>
      <category domain="http://securityratty.com/tag/rights">rights</category>
      <category domain="http://securityratty.com/tag/intellectual property rights">intellectual property rights</category>
      <category domain="http://securityratty.com/tag/copyright legislation">copyright legislation</category>
      <source url="http://securityratty.com/blog/?p=7">Intellectual Property- what is it and how do we secure it?</source>
    </item>
  </channel>
</rss>
