<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dancho]]></title>
    <link>http://securityratty.com/tag/dancho</link>
    <description></description>
    <pubDate>Mon, 21 Jan 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fun AV Cartoon]]></title>
      <link>http://securityratty.com/article/974d1eee21b3773241fe943fab156d44</link>
      <guid>http://securityratty.com/article/974d1eee21b3773241fe943fab156d44</guid>
      <description><![CDATA[Thanks to Dancho for the link . The cartoon is here
About me:...]]></description>
      <content:encoded><![CDATA[Thanks to <a href="http://ddanchev.blogspot.com/">Dancho </a>for the <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">link</a>. The cartoon is <a href="http://bp0.blogger.com/_wICHhTiQmrA/SG5J7KMsDwI/AAAAAAAAB3s/GJ5Zr7bymOU/s1600-h/antivirus_industry_10years.gif">here</a>.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PglloJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PglloJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=vO3vmJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=vO3vmJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xbIToJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xbIToJ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/332846897" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 11 Jul 2008 05:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cartoon">cartoon</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/dancho">dancho</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/332846897/fun-av-cartoon.html">Fun AV Cartoon</source>
    </item>
    <item>
      <title><![CDATA[ICANN And IANA Defaced]]></title>
      <link>http://securityratty.com/article/5887642d6261fd229fc5f260cd84c5ab</link>
      <guid>http://securityratty.com/article/5887642d6261fd229fc5f260cd84c5ab</guid>
      <description><![CDATA[Well, I have to admit I only just saw this one this morning. Since its a long weekend(ish) here in Canada I wasnt planning on updating the site until Wednesday. This one is something worth sharing. I...]]></description>
      <content:encoded><![CDATA[<p>Well, I have to admit I only just saw this one this morning. Since it&#8217;s a long weekend(ish) here in Canada I wasn&#8217;t planning on updating the site until Wednesday. This one is something worth sharing. I figured I&#8217;d pass it along. </p>
<p>A group calling itself &#8220;NetDevilz&#8221; defaced the homepages for ICANN &amp; IANA. </p>
<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2008/06/icanndefaced.jpg" alt="credit: Websense, Zone-H" /></center></p>
<p>Ouch.</p>
<p>From Websense:</p>
<blockquote><p>Websense® Security Labs™ has received reports that the official website of ICANN and IANA Domains have been hijacked by a Turkish group called “NetDevilz”. ICANN and IANA are responsible for the Internet Protocol (IP) address space allocation, protocol identifier assignment, generic (gTLD) and country code Top Level Domain Name System management, and root server system management functions.</p></blockquote>
<p>For the full advisory please read on.</p>
<p><a href="http://securitylabs.websense.com/content/Alerts/3119.aspx">Article Link</a></p>
<p>For more on this check out Dancho Danchev&#8217;s <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html">posting</a> on his site.</p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=hrECsk"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=hrECsk" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Vw07MI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Vw07MI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=IoWIki"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=IoWIki" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Iv4zyi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Iv4zyi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=4rciQi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=4rciQi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=iKXGgi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=iKXGgi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/323293837" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 10:49:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iana">iana</category>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/websense">websense</category>
      <category domain="http://securityratty.com/tag/websense security labs">websense security labs</category>
      <category domain="http://securityratty.com/tag/iana domains">iana domains</category>
      <category domain="http://securityratty.com/tag/protocol identifier assignment">protocol identifier assignment</category>
      <category domain="http://securityratty.com/tag/address space allocation">address space allocation</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/system management">system management</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/323293837/">ICANN And IANA Defaced</source>
    </item>
    <item>
      <title><![CDATA[FISMA Report Card News, Formulas, and 3 Myths]]></title>
      <link>http://securityratty.com/article/b5be8b7e91c58d0ef038594276f66108</link>
      <guid>http://securityratty.com/article/b5be8b7e91c58d0ef038594276f66108</guid>
      <description><![CDATA[Ever watch a marathon on TV? Theres the usual formula for how we lay out the day
History of the marathon and Pheidippides
Discussion of the race length and how it was changes so that the Queen could...]]></description>
      <content:encoded><![CDATA[<p>Ever watch a marathon on TV?  There&#8217;s the usual formula for how we lay out the day:</p>
<ul>
<li>History of the marathon and <a title="Pheidippides" href="http://en.wikipedia.org/wiki/Pheidippides" target="_blank">Pheidippides</a></li>
<li>Discussion of the race length and how it was changes so that the Queen could watch the finish</li>
<li>World records and what our chances are for making one today</li>
<li>Graphics of the race course showing the key hills and the &#8220;sprint to the finish&#8221;</li>
<li>Talk about the womens&#8217; marathon including Joan Benoit and Kathrine Switzer</li>
<li>Description of energy depletion and &#8220;The Wall&#8221;</li>
<li>Stats as the leaders hit the finsh line</li>
<li>Shots of &#8220;back-of-the-pack&#8221; runners and the race against yourself</li>
</ul>
<p>Well, I now present to you the formula for FISMA Report Cards:</p>
<ul>
<li>Paragraph about how agencies are failing to secure their data, the report card says so</li>
<li>History and trending of the report card</li>
<li>Discussion on changing FISMA</li>
<li>Quote from Karen Evans</li>
<li>Quote from Alan Paller about how FISMA is a failure and checklist-driven security</li>
<li>Wondering when the government will get their act together</li>
</ul>
<p>Have a read of <a href="http://blogs.zdnet.com/security/?p=1185" target="_blank">Dancho&#8217;s response </a>to the FISMA Report Card.  Pretty typical writing formula that you&#8217;ll see from journalists.  I won&#8217;t even comment on the &#8220;FISMA compliance&#8221; title.  Oh wait, I just did.  =)</p>
<p>Some myths about FISMA in particular that I need to dispell right now:</p>
<ol>
<li><strong>FISMA is a report card:</strong>  It&#8217;s a law, the grades are just an awareness campaign.  In fact, the whole series of NIST Special Publications are just implementation techniques&#8211;they are <em>guidance </em>after all.  Usually the media and bloggers talk about what FISMA measures and um, well, it doesn&#8217;t measure anything, it just requires that agencies have security programs based on a short list of criteria such as security planning, contingency planning, and security testing.  It just goes back to the adage that <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">nobody really knows what FISMA is</a>.</li>
<li><strong>FISMA needs to be changed:</strong>  As a law, FISMA is <em>exactly</em> where it needs to be.  Yes, Congress does have talks about modifying FISMA, but not much has come of it because what they eventually discover after much debate and sword-waving is that FISMA is the way to write the law about security, the problem is with the execution at all levels&#8211;OMB, GAO, and the agencies&#8211;and typically across organizational boundaries and competing master agendas.</li>
<li><strong>There is a viable alternative framework:</strong>  Dancho points out <a href="http://www.ignet.gov/pande/audit/fismaframework0906.pdf" target="_blank">this framework</a> in his post which is really an auditors&#8217; plugin to the existing NIST Framework for FISMA.  Thing is, nobody has a viable alternative framework because it&#8217;s still going to be the same people with the same training executing in the same environment.</li>
</ol>
<p style="text-align: center;"><em><img src="http://farm1.static.flickr.com/47/181917366_70c6423250.jpg?v=0" alt="Urban Myth: Cellular Phones Cause Gas Fires" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Urban Cell-Phone Fire Myth photo by </em><a href="http://www.flickr.com/photos/bike/" target="_blank"><em>richardmasoner</em></a><em>.  This myth is <a href="http://www.snopes.com/autos/hazards/gasvapor.asp" target="_blank">dispelled at snopes.com</a>.</em></p>
<p>Way back last year I wrote a blog post about <a href="http://www.guerilla-ciso.com/archives/96" target="_blank">indicator species and how we&#8217;re expecting the metrics to go up based on our continual measuring of them</a>.  Every couple of months I go back and review it to see if it&#8217;s still relevant.  And the answer this week is &#8220;yes&#8221;.</p>
<p>Now I&#8217;ve been thinking and talking probably too much about FISMA and the grades over the past couple of years, so occassionally I come to conclusions .  According to Mr Vlad the Impaler, the report card is a bad idea, but I&#8217;m slowly beginning to see the wisdom of it:  it&#8217;s an opportunity to have a debate and to raise some awareness of Government security outside of those of us who do it.  The only other time that we have a public debate about security is after a serious data breach, and that&#8217;s not a happy time.</p>
<p>I just wish the media would stop with the story line that FISMA is failing because the grades provide recursive evidence of it.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths&amp;url=http://www.guerilla-ciso.com/archives/404&amp;version=0.7" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/404&amp;t=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=CeAzjI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=CeAzjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=ZGK9zi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=ZGK9zi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/299192207" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 May 2008 12:36:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/report card">report card</category>
      <category domain="http://securityratty.com/tag/fisma report card">fisma report card</category>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma measures">fisma measures</category>
      <category domain="http://securityratty.com/tag/fisma compliance title">fisma compliance title</category>
      <category domain="http://securityratty.com/tag/fisma report cards">fisma report cards</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security programs based">security programs based</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/299192207/404">FISMA Report Card News, Formulas, and 3 Myths</source>
    </item>
    <item>
      <title><![CDATA[Redmondmag...I told you so!]]></title>
      <link>http://securityratty.com/article/86c5246bb43764de7badda595a9e2b02</link>
      <guid>http://securityratty.com/article/86c5246bb43764de7badda595a9e2b02</guid>
      <description><![CDATA[There is no more egregious an act of negligence committed by online vendors and businesses than ignoring notifications of vulnerabilities found in their applications
So when Dancho Danchev pointed out...]]></description>
      <content:encoded><![CDATA[There is no more egregious an act of negligence committed by online vendors and businesses than ignoring notifications of vulnerabilities found in their applications. <br />So when <a href="http://ddanchev.blogspot.com/">Dancho Danchev</a> <a href="http://blogs.zdnet.com/security/?p=1118">pointed out</a> that <a href="http://redmondmag.com/">Redmond Magazine</a> had been SQL injected by Chinese Hacktivists, I was both appalled, yet not surprised.<br />On <span style="font-weight:bold;">January 29th, 2008</span> I informed <a href="http://www.1105media.com/">1105 Media</a>, the parent company of the <a href="http://redmondmediagroup.com/">Redmond Media Group</a>, of multiple XSS vulnerabilities in various properties they maintain, including EntMag.com and AdtMag.com, as well as Redmondmag.com.<br /><br />From my email:<br /><span style="font-style:italic;">"I’d like to advise you of XSS vulnerabilities in the search code used by all Redmond Media Group websites.<br />This is most easily validated by pasting a simple script alert generator in the search form. <br />These vulnerabilities were disclosed by XSSed.com in February and July of 2007.<br /><a href="http://www.xssed.com/mirror/20073/">http://www.xssed.com/mirror/20073/</a><br /><a href="http://www.xssed.com/mirror/13305/">http://www.xssed.com/mirror/13305/</a><br />These vulnerability be exploited by malicious people to conduct XSS attacks and it could further lead to reputation and PR issues for the Redmond Media Group."</span><br /><br />Not only did they flatly ignore me, and they guys from <a href="http://www.xssed.com/">XSSed.com</a> who'd notified then in <span style="font-weight:bold;">FEBRUARY and JULY 2007!</span>, but all these vulnerabilities still exist, including Redmondmag.com. You could definitely say that these issues have led to "reputation and PR issues for the Redmond Media Group." <br />Doh! I told you so!<br />It goes without saying that if you are vulnerable to XSS, you have a significantly higher likelihood of being vulnerable to SQLi.<br />Redmondmag.com was also victimized by the 2nd wave of mass SQL injection attacks that dropped in <span style="font-style:italic;">nihaorr1.com/1.js</span>. <br /><br />Regarding current vulnerabilities, observe the following:<br /><a href="http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://search.redmondmag.com/search.asp&cmd=search&SearchForm=%%SearchForm%%&index=C:\dtSearch\rmg\red_all&sort=Date&srcrequest=%22%3E%3CSCRIPT%3Ealert('XSS_Alert')%3C/SCRIPT%3E&submit1=Search"><span style="font-style:italic;">http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://search.redmondmag.com/search.asp&cmd=search&SearchForm=%%SearchForm%%&index=C:\dtSearch\rmg\red_all&sort=Date&srcrequest=%22%3E%3CSCRIPT%3Ealert('XSS_Alert')%3C/SCRIPT%3E&submit1=Search">http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=<br />http://search.redmondmag.com/search.asp&cmd=search&SearchForm=%%SearchForm%%&<br />index=C:\dtSearch\rmg\red_all&sort=Date&<br />srcrequest=(Insert JavaScript here)&submit1=Search</span></a><br /><br />Props, as always, to Whiteacid's XSS Assistant and POST forwarder.<br />But behold, what do we see, but <span style="font-style:italic;">index=C:\dtSearch\rmg\red_all</span>.<br />Well, now we know you use <a href="http://www.dtsearch.com/">dtSearch</a> on the C: of your Windows server (no surprise there ;-)).<br /><br />Common people, fix your sites!<br />You have been found guilty of the following charges:<br />1) Vulnerable to SQLi<br />2) Vulnerable to XSS<br />3) Internal file disclosure<br />4) Flagrant negligence with regard to secure coding best practices<br />50 Flagrant disregard fo information submitted to you by the information security community.<br /><span style="font-weight:bold;">1105 Media and the Redmond Media Group, you have failed your readers, your visitors, your customers, and yourselves, and you should be ashamed.</span><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/05/redmondmagi-told-you-so.html&title=Redmondmag%20...%20I%20told%20you%20so! " title="Redmondmag...I told you so! del.icio.us">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/05/redmondmagi-told-you-so.html" title="Redmondmag...I told you so! ">digg</a>]]></content:encoded>
      <pubDate>Sun, 18 May 2008 08:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/current vulnerabilities">current vulnerabilities</category>
      <category domain="http://securityratty.com/tag/multiple xss vulnerabilities">multiple xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss target">xss target</category>
      <category domain="http://securityratty.com/tag/xss assistant">xss assistant</category>
      <category domain="http://securityratty.com/tag/redmond media">redmond media</category>
      <category domain="http://securityratty.com/tag/xss alert">xss alert</category>
      <source url="http://holisticinfosec.blogspot.com/2008/05/redmondmagi-told-you-so.html">Redmondmag...I told you so!</source>
    </item>
    <item>
      <title><![CDATA[Dancho on Security Industry and Media]]></title>
      <link>http://securityratty.com/article/420da9c215574cc3320676052e4092c1</link>
      <guid>http://securityratty.com/article/420da9c215574cc3320676052e4092c1</guid>
      <description><![CDATA[Dancho Danchev makes this astute observation about the coverage of security by the media
You know it's a slow news week when you come across
1. Articles starting that malware increased 450% during the...]]></description>
      <content:encoded><![CDATA[<a href="http://ddanchev.blogspot.com">Dancho Danchev</a> makes this astute observation about the coverage of security by the media:<br />"You know it's a slow news week when you come across :<br />1. Articles starting that malware increased 450% during the last quarter - of course it's supposed to increase given the automated polymorphism they've achieved thereby having anti virus vendors spend more money on infrastructure to analyze it" + <a href="http://ddanchev.blogspot.com/2008/04/ten-signs-its-slow-news-week.html">9 more items</a>.<br /><br />It would be funny .. if it weren't sad :-)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=GnRWVfG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=GnRWVfG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YyM4KUG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YyM4KUG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/276575517" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 14:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/slow news week">slow news week</category>
      <category domain="http://securityratty.com/tag/anti virus vendors">anti virus vendors</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/astute observation">astute observation</category>
      <category domain="http://securityratty.com/tag/dancho danchev">dancho danchev</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/funny">funny</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/polymorphism">polymorphism</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/276575517/dancho-on-security-industry-and-media.html">Dancho on Security Industry and Media</source>
    </item>
    <item>
      <title><![CDATA[What? You Are Releasing Untested Malware?]]></title>
      <link>http://securityratty.com/article/6de9bcb42cc280f49cf9bf18f137755f</link>
      <guid>http://securityratty.com/article/6de9bcb42cc280f49cf9bf18f137755f</guid>
      <description><![CDATA[What are you, some kind of amateur

Dancho Danchev reminds people how modern malware is tested here . A quote: &quot;And when a popular piece of malware known as Shark introduced a built-in VirusTotal...]]></description>
      <content:encoded><![CDATA[... What are you, some kind of amateur? :-)<br /><br />Dancho Danchev reminds people how modern malware is tested <a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">here</a>. A quote:  "And when a popular piece of malware known as<a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html"> Shark introduced a built-in VirusTotal submission</a> to verify the low detecting rate of the newly generated server, something really had to change - like it did."<br /><br />So, imagine a  malicious "clone" of VirusTotal that is launched by an enterprising criminal to provide "a valuable service" of malware testing to a cybercrime community? :-) : "A small fee for testing please.  What, you are releasing an untested malware? Phooo... What are you, some kind of amateur? :-)"<br /><br />Dancho then predicts: "One thing's for sure - <span style="font-weight: bold;">malware will start getting benchmarked against each and every antivirus solution and firewall before the campaign gets launched</span>, in a much more efficient and Q&amp;A structured approach than it is for the time being."<br /><br />Please tell me if this happens, it won't be the final nail in the "legacy"/"blacklist-only" AV coffin?<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=aPzNysG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=aPzNysG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=1cK5wGG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=1cK5wGG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/265977995" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 07 Apr 2008 12:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/modern malware">modern malware</category>
      <category domain="http://securityratty.com/tag/built-in virustotal submission">built-in virustotal submission</category>
      <category domain="http://securityratty.com/tag/virustotal">virustotal</category>
      <category domain="http://securityratty.com/tag/antivirus solution">antivirus solution</category>
      <category domain="http://securityratty.com/tag/popular piece">popular piece</category>
      <category domain="http://securityratty.com/tag/amateur">amateur</category>
      <category domain="http://securityratty.com/tag/final nail">final nail</category>
      <category domain="http://securityratty.com/tag/valuable service">valuable service</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/265977995/what-you-are-releasing-untested-malware.html">What? You Are Releasing Untested Malware?</source>
    </item>
    <item>
      <title><![CDATA[Major Web sites hit with growing Web attack]]></title>
      <link>http://securityratty.com/article/665769d794549027e7fb34479ed6e75c</link>
      <guid>http://securityratty.com/article/665769d794549027e7fb34479ed6e75c</guid>
      <description><![CDATA[A blossoming Web attack, first reported by security researcher Dancho Danchev earlier this month, has expanded to hit over a million Web pages, including many well-known...]]></description>
      <content:encoded><![CDATA[A blossoming Web attack, first reported by security researcher Dancho Danchev earlier this month, has expanded to hit over a million Web pages, including many well-known sites.]]></content:encoded>
      <pubDate>Thu, 27 Mar 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web attack">web attack</category>
      <category domain="http://securityratty.com/tag/million web pages">million web pages</category>
      <category domain="http://securityratty.com/tag/hit">hit</category>
      <category domain="http://securityratty.com/tag/well-known sites">well-known sites</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <source url="http://www.networkworld.com/news/2008/032808-major-web-sites-hit-with.html?fsrc=rss-security">Major Web sites hit with growing Web attack</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-01-21 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/08d05094e6308fc457aa2aae733da92b</link>
      <guid>http://securityratty.com/article/08d05094e6308fc457aa2aae733da92b</guid>
      <description><![CDATA[Dancho Danchev's Blog - Mind Streams of Information Security Knowledge: E-crime and Socioeconomic Factors
High Tower Software Announces Cinxi SOA @ SOA WORLD MAGAZINE...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">Dancho Danchev's Blog - Mind Streams of Information Security Knowledge: E-crime and Socioeconomic Factors</a></li>
<li><a href="http://soa.sys-con.com/read/488089.htm">High Tower Software Announces Cinxi SOA @ SOA WORLD MAGAZINE</a></li>
<li><a href="http://geer.tinho.net/geer.housetestimony.070423.txt">http://geer.tinho.net/geer.housetestimony.070423.txt</a><br/>
re:     Hearing, Wednesday 25 April 07, entitled
                  Addressing the Nation's Cybersecurity Challenges:
                  Reducing Vulnerabilities Requires Strategic Investment
                  and Immediate Action</li>
<li><a href="http://www.redmonk.com/cote/2008/01/19/what-one-msp-needs-barcampesm-session/">People Over Process &raquo; What One MSP Needs - barcampESM session</a></li>
<li><a href="http://www.ffiec.gov/ffiecinfobase/booklets/information_security/05_sec_monitoring.htm">FFIEC InfoSec  Handbook on Security Monitoring and Logging</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/220787445" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security knowledge">information security knowledge</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ffiec infosec handbook">ffiec infosec handbook</category>
      <category domain="http://securityratty.com/tag/soa world magazine">soa world magazine</category>
      <category domain="http://securityratty.com/tag/barcampesm session">barcampesm session</category>
      <category domain="http://securityratty.com/tag/socioeconomic factors">socioeconomic factors</category>
      <category domain="http://securityratty.com/tag/dancho danchev">dancho danchev</category>
      <category domain="http://securityratty.com/tag/mind streams">mind streams</category>
      <category domain="http://securityratty.com/tag/cybersecurity challenges">cybersecurity challenges</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/220787445/anton18">Links for 2008-01-21 [del.icio.us]</source>
    </item>
  </channel>
</rss>
