<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: defense]]></title>
    <link>http://securityratty.com/tag/defense</link>
    <description></description>
    <pubDate>Mon, 11 Aug 2008 02:00:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Best Western forced to play defense on data breach disclosure]]></title>
      <link>http://securityratty.com/article/6a5ccb0e491837bbdd64c37c284656ca</link>
      <guid>http://securityratty.com/article/6a5ccb0e491837bbdd64c37c284656ca</guid>
      <description><![CDATA[A dispute between Best Western and a Scottish newspaper over the scope of a data breach highlights the need for companies to get out in front on disclosures of data...]]></description>
      <content:encoded><![CDATA[A dispute between Best Western and a Scottish newspaper over the scope of a data breach highlights the need for companies to get out in front on disclosures of data breaches.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=4cyEAu"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=4cyEAu" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/377427991" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data breach highlights">data breach highlights</category>
      <category domain="http://securityratty.com/tag/scottish newspaper">scottish newspaper</category>
      <category domain="http://securityratty.com/tag/western">western</category>
      <category domain="http://securityratty.com/tag/data breaches">data breaches</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/dispute">dispute</category>
      <category domain="http://securityratty.com/tag/disclosures">disclosures</category>
      <category domain="http://securityratty.com/tag/scope">scope</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/377427991/article.do">Best Western forced to play defense on data breach disclosure</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</link>
      <guid>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel® to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=lWcQZE"><img src="http://feeds.feedburner.com/~a/BlueBox?i=lWcQZE" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=pYLEpK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pYLEpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=rcmyeK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=rcmyeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=FcteyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=FcteyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=g4KpjK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=g4KpjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=XvHGuk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=XvHGuk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=WQc3oK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=WQc3oK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/376657116" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 15:53:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/376657116/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[SDL and the XSS Filter]]></title>
      <link>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</link>
      <guid>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</guid>
      <description><![CDATA[Steve Lipner here. When the Internet Explorer team posted the announcement about the XSS Filter feature in IE8 I asked some other members of the SDL blog team why arent we talking about the new XSS...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Steve Lipner here.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>When the Internet Explorer team posted the announcement about the </FONT><A href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"><FONT face=Calibri color=#0000ff size=3>XSS Filter feature in IE8</FONT></A><FONT size=3><FONT face=Calibri> <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>I asked some other members of the SDL blog team “why aren’t we talking about the new XSS Filter feature on the SDL blog?” &nbsp;Bryan and Jeremy said something like “that’s a mitigation that only applies to specific clients and a subset of attacks”.&nbsp; So we didn’t cross-reference IE’s XSS Filter post on the SDL blog at the time.&nbsp; Instead, I agreed to write a subsequent post about the relationship of XSS Filter to the SDL and to the ways that our SDL and security science teams think about improving product security.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>For those of you who aren’t familiar with XSS Filter, a brief summary is that it is a client-side defense against reflected cross-site scripting (XSS) attacks.&nbsp; It works by recognizing that reflected XSS attacks inject script into the string that the browser sends to the targeted web server.&nbsp; If the server doesn’t neuter or strip out the injected script, it gets sent back to the browser and executed in the context of the target web page.&nbsp; Bad things then happen.&nbsp; At a high level, XSS Filter remembers the string that the browser sent to the server, and looks at the server’s response to see if any of the script was actually in that string.&nbsp; If it was, then XSS Filter decides that it got there because it was injected by an XSS attack and blocks the script from executing.&nbsp; The rest of the web page renders as usual.&nbsp; This is a vastly oversimplified sketch of XSS Filter – for details, see the post by David Ross, inventor of XSS Filter on the </FONT><A href="http://blogs.technet.com/swi/archive/2008/08/19/ie-8-xss-filter-architecture-implementation.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>So what does XSS Filter have to do with the SDL?&nbsp; Well, for almost nine years, since XSS was first discovered at Microsoft, we’ve been trying to figure out effective ways to reduce vulnerability to XSS attacks.&nbsp; Our focus has been on improving the ways that web page developers code their pages, and we’ve developed a lot of tools and techniques for making web content safer from XSS attacks and for detecting XSS vulnerabilities in live pages.&nbsp; The SDL requires the use of many of these tools and techniques, and we’re sure we’ve prevented a lot of XSS vulnerabilities from being introduced into Microsoft web pages as a result.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>But while we identify (and the SDL requires) measures that allow developers to avoid classes of vulnerabilities, we also look to identify more sweeping solutions that can either 1) eliminate classes of vulnerabilities, 2) reduce their severity, or 3) reduce the likelihood of attacks being successful.&nbsp; The process usually starts from deep understanding of a class of vulnerabilities and attacks, and then we broaden defenses from there.&nbsp; In the case of XSS Filter, David’s years of work researching XSS led him to come up with an approach that blocks many of the most common vulnerabilities to reflected attacks found on the web today.&nbsp; The solution is compatible with existing web pages (doesn’t “break the web”) and thus we were able to enable it by default for users of Internet Explorer 8.&nbsp; Because it’s a client-side mitigation, it will help protect users from attacks even though the sites they visit may be vulnerable to XSS.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Our work on buffer overrun defenses follows a somewhat similar pattern – we started by prescribing coding techniques, banning the use of some APIs, and building tools that detect coding constructs that look like buffer overruns.&nbsp; As we gained a deeper understanding of how buffer overruns can be exploited, we enhanced the </FONT><A href="http://msdn.microsoft.com/en-us/library/8dbf701c(VS.80).aspx"><FONT face=Calibri size=3>/GS compiler flag</FONT></A><FONT face=Calibri size=3> and added </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2006/05/26/address-space-layout-randomization-in-windows-vista.aspx"><FONT face=Calibri color=#0000ff size=3>ASLR</FONT></A><FONT size=3><FONT face=Calibri> in a quest to cause classes of exploits to fail even if a buffer overrun remains.&nbsp; We’re not yet close to eliminating the SDL requirements for use of tools and coding techniques, but the SDL also requires the use of the mitigations to reduce the severity of vulnerabilities that slip past.&nbsp; Will we ever get to the point where the mitigating technologies are so strong that we can relax the coding requirements?&nbsp; Maybe not, but we will continue to introduce technologies that reduce the chances of a successful attack.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Similarly, in the case of XSS, even after IE8 ships, the SDL will continue to require the use of safe web site coding practices and tools such as the </FONT><A href="http://msdn.microsoft.com/en-us/library/aa973813.aspx"><FONT face=Calibri color=#0000ff size=3>Anti-XSS library</FONT></A><FONT size=3><FONT face=Calibri> both to protect users of browsers other than IE8 and to provide protection in recognition of the fact that XSS Filter is a mitigation or defense in depth rather than a complete solution.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>But we’ll also be keeping our eyes open (and doing active research) in the quest for an even more effective defense – whether client or server side – that eliminates XSS for good.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>This post is a little far afield from the normal content of the SDL blog, but I thought it was important to provide a picture of the role of security science and security research in defining SDL requirements and in making major improvements in software security.&nbsp; You can read more about our work in security science in the </FONT><A href="http://blogs.technet.com/swi/default.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.</FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8900490" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 11:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss filter">xss filter</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/xss led">xss led</category>
      <category domain="http://securityratty.com/tag/anti-xss library">anti-xss library</category>
      <category domain="http://securityratty.com/tag/xss attack">xss attack</category>
      <category domain="http://securityratty.com/tag/xss attacks">xss attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/xss filter remembers">xss filter remembers</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/08/27/sdl-and-the-xss-filter.aspx">SDL and the XSS Filter</source>
    </item>
    <item>
      <title><![CDATA[TSA Follies]]></title>
      <link>http://securityratty.com/article/f014b8f845713a3e6bc73c172d773b7c</link>
      <guid>http://securityratty.com/article/f014b8f845713a3e6bc73c172d773b7c</guid>
      <description><![CDATA[They break planes : Citing sources within the aviation industry, ABC News reports an overzealous TSA employee attempted to gain access to the parked aircraft by climbing up the fuselage... reportedly...]]></description>
      <content:encoded><![CDATA[<p>They <a href="http://www.aero-news.net/index.cfm?ContentBlockID=340a79d6-839a-470d-b662-944325cea23d">break planes</a>:</p>

<blockquote>Citing sources within the aviation industry, ABC News reports an overzealous TSA employee attempted to gain access to the parked aircraft by climbing up the fuselage... reportedly using the Total Air Temperature (TAT) probes mounted to the planes' noses as handholds.

<p>"The brilliant employees used an instrument located just below the cockpit window that is critical to the operation of the onboard computers," one pilot wrote on an American Eagle internet forum. "They decided this instrument, the TAT probe, would be adequate to use as a ladder."</blockquote></p>

<p>They <a href="http://www.cnn.com/2008/US/08/19/tsa.watch.list/index.html?iref=mpstoryview">harass innocents</a>:</p>

<blockquote>James Robinson is a retired Air National Guard brigadier general and a commercial pilot for a major airline who flies passenger planes around the country.

<p>He has even been certified by the Transportation Security Administration to carry a weapon into the cockpit as part of the government's defense program should a terrorist try to commandeer a plane.</p>

<p>But there's one problem: James Robinson, the pilot, has difficulty even getting to his plane because his name is on the government's terrorist "watch list."</blockquote></p>

<p>It's easy to <a href="http://edition.cnn.com/2008/US/08/19/tsa.watch.list/index.html">sneak by them</a>:</p>

<blockquote>The third-grader has been on the watch list since he was 5 years old. Asked whether he is a terrorist, he said, "I don't know."

<p>Though he doesn't even know what a terrorist is, he is embarrassed that trips to the airport cause a ruckus, said his mother, Denise Robinson.</p>

<p>[...]</p>

<p>Denise Robinson says she tells the skycaps her son is on the list, tips heavily and is given boarding passes. And booking her son as "J. Pierce Robinson" also has let the family bypass the watch list hassle.</blockquote></p>

<p>And <a href="http://www.i-hacked.com/content/view/267/48/">here's</a> how to sneak lockpicks past them.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8fHJ7K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8fHJ7K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LcgXdK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LcgXdK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 05:12:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flies passenger planes">flies passenger planes</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/planes">planes</category>
      <category domain="http://securityratty.com/tag/list hassle">list hassle</category>
      <category domain="http://securityratty.com/tag/sneak lockpicks past">sneak lockpicks past</category>
      <category domain="http://securityratty.com/tag/james robinson">james robinson</category>
      <category domain="http://securityratty.com/tag/denise robinson">denise robinson</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <category domain="http://securityratty.com/tag/pilot">pilot</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/tsa_follies.html">TSA Follies</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Two]]></title>
      <link>http://securityratty.com/article/9d3454e7551fca2a11e4a5ee55704677</link>
      <guid>http://securityratty.com/article/9d3454e7551fca2a11e4a5ee55704677</guid>
      <description><![CDATA[With scammers continuing to introduce new typosquatted domains promoting well known brands of rogue security software that is most often found at the far end of a malware campaign, exposing yet...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKphU3YsSbI/AAAAAAAACDk/28wApKSrbYA/s1600-h/fake_security_software.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="76" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKphU3YsSbI/AAAAAAAACDk/bPxU6HdrxA8/s200-R/fake_security_software.JPG" width="200" /></a>With scammers continuing to introduce new typosquatted domains promoting well known brands of rogue security software that is most often found at the far end of a malware campaign, exposing yet another diverse portfolio of last week's introduced domains is what follows.<br />
<br />
Naturally, in between taking advantage of the usual hosting services, most of the domains remain parked at the same IPs, this centralization makes it easier to locate them all, then having to go through several misconfigured malicious doorways that will anyway expose the portfolio.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpjp46fg4I/AAAAAAAACDs/hW-zlDsLSIg/s1600-h/antivirus_pro_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpjp46fg4I/AAAAAAAACDs/mjJJ2yUIcsE/s200-R/antivirus_pro_2008.png" width="200" /></a><b>antivirus2008t-pro .com</b> - (91.203.92.64; 78.157.142.7)<br />
<b>antivirus2008pro-download1 .com<br />
antivirus2008pro-download2 .com<br />
scanner.antivir64 .com<br />
antivirus2008t-pro .com<br />
antivirus-2008y-pro .com</b><br />
<br />
<b>&nbsp;systemscanner2009 .com</b> - (89.18.189.44; 208.88.53.114)<br />
<b>xpdownloadserver .com&nbsp;&nbsp;&nbsp; <br />
global-advers .com<br />
xpantivirus .com&nbsp;&nbsp;&nbsp; <br />
updatesantivirus .com<br />
windows-scannernv .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpkn-kX73I/AAAAAAAACD0/GOsFiicPQXs/s1600-h/xp_anti_virus.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpkn-kX73I/AAAAAAAACD0/AekOVq9ibn0/s200-R/xp_anti_virus.png" width="200" /></a><b>ratemyblog1 .com</b> - 208.88.53.114<br />
<b>windows-scanner2009 .com<br />
systemscanner2009 .com<br />
antivirus-database .com<br />
antivirus2009professional .com<br />
antivirus-2009pro .com<br />
antivirus2009-scanner .com<br />
global-advers .com<br />
drivemedirect .com<br />
windows-scannernv .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpmSONqTJI/AAAAAAAACEE/4Cukn7sK9ek/s1600-h/fake_IE_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpmSONqTJI/AAAAAAAACEE/iHExDhLb0z4/s200-R/fake_IE_7.png" width="200" /></a><b>webscweb-scannerfree .com</b> - (58.65.238.106; 208.88.53.180)<br />
<b>freebmwx3 .com<br />
mytube4 .com<br />
beginner2009 .com<br />
webscweb-scannerfree .com<br />
antivirus2009-software .com<br />
antivirus-database .com<br />
purchase-anti .com</b><br />
<br />
<b><br />
onlinescannerxp .com<br />
virus-onlinescanner .com<br />
spywareonlinescanner .com<br />
xponlinescanner .com<br />
virus-securityscanner .com<br />
virus-securityscanner .com<br />
webscannerfreever .com<br />
blazervips .com<br />
global-advers .com<br />
xpantivirus .com&nbsp;&nbsp;&nbsp; <br />
drivemedirect .com<br />
windows-scannernv .com</b><br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKplujVb0XI/AAAAAAAACD8/laUP6HFKiPc/s1600-h/xp_anti_virus2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKplujVb0XI/AAAAAAAACD8/vH2l1Xo0k0Y/s200-R/xp_anti_virus2.png" /></a><b>mytube4 .com</b> - 58.65.238.106<br />
<b>beginner2009 .com<br />
webscweb-scannerfree .com<br />
securityscannerfree .com<br />
xpcleaner-online .com<br />
streamhotvideo .com<br />
xpcleanerpro .com<br />
onlinescannerxp .com<br />
online-xpcleaner .com<br />
antispyguard-scanner .com<br />
virus-onlinescanner .com<br />
microsoft.browsersecuritycenter .com<br />
fastupdateserver .com<br />
blazervips .com<br />
xpantivirus .com<br />
drivemedirect .com<br />
fastwebway .com<br />
xpantivirussecurity .com<br />
wordpress.firm .in<br />
megacodec .biz<br />
mcprivate .biz</b><br />
<br />
<b>internet-defense2009 .com </b>- 84.16.252.73<b><br />
myfreespace3 .com<br />
greatvideo3 .com<br />
internet-defense2009 .com<br />
windows-defense .com<br />
3gigabytes .com<br />
teledisons .com<br />
updatesantivirus .com<br />
update-direct .com<br />
xp-protectsoft .com</b><br />
<br />
<b>top-pc-scanner .com - </b>(91.203.92.50; 92.62.101.43)<b><br />
nortonsoft .com - </b>(91.186.11.5)<b><br />
powerantivirus-2009 .com - (</b>91.208.0.233)<b><br />
powerantivirus2009 .com - </b>(91.208.0.233)<b><br />
pwrantivirus .com - </b>(91.208.0.231)<b><br />
xp-guard .com - </b>(92.62.101.35)<b><br />
xpertantivirus .com - </b>(91.208.0.230)<b><br />
internetscanner2009 .com - </b>(89.149.229.168)<br />
<br />
Where's the business model here? Where it's always been, upon installation of the rogue security software, the malware campaigner earns up to 40% revenue from the rogue security software's vendor.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://http//ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<br />
<b></b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h33YSK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h33YSK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVrJfK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVrJfK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FyAb7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FyAb7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wEuVk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wEuVk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zeV8HK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zeV8HK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Xb2U2K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Xb2U2K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1JfUGk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1JfUGk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/368786894" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 21:51:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/portfolio">portfolio</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/rogue security software">rogue security software</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/domains remain">domains remain</category>
      <category domain="http://securityratty.com/tag/drivemedirect">drivemedirect</category>
      <category domain="http://securityratty.com/tag/global-advers">global-advers</category>
      <category domain="http://securityratty.com/tag/lazy summer days">lazy summer days</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/368786894/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Defense Spooks: Let's Control Enemy Minds]]></title>
      <link>http://securityratty.com/article/2405600bcfe670aac40e16295c673819</link>
      <guid>http://securityratty.com/article/2405600bcfe670aac40e16295c673819</guid>
      <description><![CDATA[Rather than developing performance-enhancing drugs for soldiers, defense agents want to study performance-degrading drugs for our enemies. A report recommends investment in neuroscience research that...]]></description>
      <content:encoded><![CDATA[Rather than developing performance-enhancing drugs for soldiers, defense agents want to study performance-degrading drugs for our enemies. A report recommends investment in neuroscience research that could reveal ways to eliminate our enemies' motivation to fight and get them to obey our commands.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=7127b04e7a3ee74a1b439337f828c65f"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=7127b04e7a3ee74a1b439337f828c65f"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=7127b04e7a3ee74a1b439337f828c65f" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=m0AhRK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=m0AhRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jTL4ck"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jTL4ck" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=m3QDyk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=m3QDyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=6tfZGK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=6tfZGK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=HpqFOK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=HpqFOK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Nqg9pk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Nqg9pk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=hTLxsk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=hTLxsk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=6PNshK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=6PNshK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/366716889" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/366716890" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 09:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/report recommends investment">report recommends investment</category>
      <category domain="http://securityratty.com/tag/enemies">enemies</category>
      <category domain="http://securityratty.com/tag/drugs">drugs</category>
      <category domain="http://securityratty.com/tag/defense agents">defense agents</category>
      <category domain="http://securityratty.com/tag/neuroscience research">neuroscience research</category>
      <category domain="http://securityratty.com/tag/fight">fight</category>
      <category domain="http://securityratty.com/tag/soldiers">soldiers</category>
      <category domain="http://securityratty.com/tag/commands">commands</category>
      <category domain="http://securityratty.com/tag/reveal">reveal</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/366716890/the-dia-looks-i.html">Defense Spooks: Let's Control Enemy Minds</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.15.08]]></title>
      <link>http://securityratty.com/article/803e2f6db1563e98882d0a71faf66398</link>
      <guid>http://securityratty.com/article/803e2f6db1563e98882d0a71faf66398</guid>
      <description><![CDATA[Cloud Computing will also cure the common cold! Not really. But amidst all the hype and overly-used marketing speak its hard to tell the difference. Researchers from the University of Michigan...]]></description>
      <content:encoded><![CDATA[<p>Cloud Computing will also cure the common cold! Not really. But amidst all the hype and overly-used marketing speak it&#8217;s hard to tell the difference. Researchers from the University of Michigan announced CloudAV, a network service using the <a href="http://www.infoworld.com/article/08/08/08/Researchers_look_to_cloud_computing_to_fight_malware_1.html?source=NLC-TB&amp;cgd=2008-08-08">&#8220;cloud-computing&#8221; concept to fight malware</a>. Please stop the insanity! I&#8217;m just waiting for someone to put &#8220;my&#8221; and &#8220;cloud computing&#8221; together&#8230;</p>
<p>Here&#8217;s an interesting post on High Earth Orbit about the usage and promotion of <a href="http://highearthorbit.com/open-source-in-defense/">open source software for defense</a> contracts. As a developer of open source tools, Andrew Turner of course brings up some &#8220;pros&#8221; for the government to push open source, but it&#8217;s the &#8220;cons&#8221; that are really interesting. A big &#8220;con&#8221; &#8211; the US government having something called &#8220;<a href="http://tech.slashdot.org/article.pl?sid=08/08/04/2253246">sovereign immunity</a>&#8221; which apparently means something like it can&#8217;t be sued unless it consents to be sued. Hunh &#8211; the Republic of ScienceLogic-Land? Closing the loop here, a federal appeals court just boosted open-source software licenses by saying that any infringements can now get more <a href="http://weblog.infoworld.com/openresource/archives/2008/08/court_rules_tha.html?source=rss">severe remedies under copyright law</a> (instead of contract law); here&#8217;s the case, <a href="http://blawgletter.typepad.com/bbarnett/2008/08/can-you-copyrig.html">Jacobsen v Katzer</a>. But apparently not if it&#8217;s the <a href="http://arstechnica.com/news.ars/post/20080804-air-force-cracks-software-carpet-bombs-dmca.html">US government</a>?? Who knows more?</p>
<p>Does Linus Torvalds hate everyone except for developers? You have to check out this article on an email exchange he had with Network World this week, talking about how fed up he is with the &#8220;<a href="http://www.infoworld.com/article/08/08/14/Torvalds_Fed_up_with_the_security_circus_1.html">security circus</a>&#8221;. Over the course of the exchange and some other comments from last month, he manages to blast security folk, OpenBSD (on security) in particular, vendors and PR people (of course). In the midst of the barrage of colorful language, it&#8217;s difficult to really get his point &#8211; which if you can dig it out, ends up being surprisingly sensible.</p>
<p>Sharon Taylor, Chief Architect of ITIL V3, recently wrote that with the release of the latest version of ITIL<a href="http://itmanagersinbox.com/345/itil-v3-and-business-service-management/">, BSM is now an &#8216;ITIL best practice</a>.&#8217; You say potato&#8230; &#8220;The distinction between IT and the business has blurred, and the language of IT has been replaced with the language of the business.&#8221;</p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:04:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <category domain="http://securityratty.com/tag/open-source software licenses">open-source software licenses</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blast security folk">blast security folk</category>
      <category domain="http://securityratty.com/tag/colorful language">colorful language</category>
      <category domain="http://securityratty.com/tag/language">language</category>
      <category domain="http://securityratty.com/tag/itil">itil</category>
      <category domain="http://securityratty.com/tag/email exchange">email exchange</category>
      <source url="http://blog.sciencelogic.com/links-list-81508/08/2008">Links List 8.15.08</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the Georgia Cyber Attacks?]]></title>
      <link>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</link>
      <guid>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</guid>
      <description><![CDATA[Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate most, it's lowering down the quality of the...]]></description>
      <content:encoded><![CDATA[<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/WYu9dc61zMQ/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="51" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/1TazKONjKVw/s200-R/georgia_ddos8.JPG" style="border: 0pt none ;" width="200" /></a>Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate&nbsp; most, it's lowering down the quality of the discussion I hate the most. Even if you're excluding all the factual evidence (<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>), common sense must prevail.<br />
<br />
Sometimes, the degree of incompetence can in fact be pretty entertaining, and greatly explains why certain countries are lacking behind others with years in their inability to understand the rules of information warfare, or the basic premise of unrestricted warfare, that there are no rules on how to achieve your objectives.<br />
<br />
So who's behind the Georgia cyber attacks, encompassing of plain simple ping floods, web site defacements, to sustained DDoS attacks, which no matter the fact that Geogia has switched hosting location to the U.S remain ongoing? It's <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's self-mobilizing cyber militia, the product of a collectivist society</a> having the capacity to wage cyber wars and literally dictating the rhythm in this space. What is militia anyway : <br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/hxG1PZAcltY/s1600-h/information_warfare.1.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/B0-V902UtRA/s200-R/information_warfare.1.gif" style="border: 0pt none ;" /></a>"<i>civilians trained as soldiers but not part of the regular army; the entire body of physically fit civilians eligible by law for military service; a military force composed of ordinary citizens to provide defense, emergency law enforcement, or paramilitary service, in times of emergency; without being paid a regular salary or committed to a fixed term of service; an army of trained civilians, which may be an official reserve army, called upon in time of need; the national police force of a country; the entire able-bodied population of a state; or a private force, not under government control; An army or paramilitary group comprised of citizens to serve in times of emergency</i>"<br />
<br />
Next to the "blame the Russian Business Network for the lack of large scale implementation of DNSSEC" mentality, certain news articles also try to wrongly imply that <a href="http://arstechnica.com/news.ars/post/20080813-georgian-attacks-might-not-be-russians-after-all.html%20">there's no Russian connection in these attacks</a>, and that the attacks are not "state-sponsored", making it look like that there should be a considerable amount of investment made into these attacks, and that the Russian government has the final word on whether or not its DDoS capabilities empowered citizens should launch any attacks or not. In reality, the only thing the Russian government was asking itself during these attacks was "why didn't they start the attacks earlier?!".<br />
<br />
Thankfully, there are some visionary folks out there understanding the situation. Last year, I asked the following question - <a href="http://www.imedialearn.com/imediapoll/poll.php?code=f1156c39d3c972139c62bc91c17e2c53">What is the most realistic scenario on what exactly happened in the recent DDoS attacks aimed at Estonia, from your point of view?</a> and some of the possible answers still fully apply in this situation :<br />
<br />
- It was a Russian government-sponsored hacktivism, or shall we say a government-tolerated one<br />
<br />
- Too much media hype over a sustained ICMP flood, given the publicly obtained statistics of the network traffic<br />
<br />
- Certain individuals of the collectivist Russian society, botnet masters for instance, were automatically recruited based on a nationalism sentiments so that they basically forwarded some of their bandwidth to key web servers<br />
<br />
- In order to generate more noise, DIY DoS tools were distributed to the masses so that no one would ever know who's really behind the attacks<br />
<br />
- Don't know who did it, but I can assure you my kid was playing !synflood at that time<br />
<br />
- Offended by the not so well coordinated removal of the Soviet statue, Russian oligarchs felt the need to send back a signal but naturally lacking any DDoS capabilities, basically outsourced the DDoS attacks<br />
<br />
- A foreign intelligence agency twisting the reality and engineering cyber warfare tensions did it, while taking advantage of the momentum and the overall public perception that noone else but the affected Russia could be behind the attacks<br />
<br />
- I hate scenario building, reminds me of my academic years, however, yours are pretty good which doesn't necessarily mean I actually care who did it, and pssst - it's not cyberwar, as in cyberwar you have two parties with virtual engagement points, in this case it was bandwidth domination by whoever did it over the other. A virtual shock and awe<br />
<br />
- I stopped following the news story by the time every reporter dubbed it the first cyber war, and started following it again when the word hacktivism started gaining popularity. So, hacktivists did it to virtually state their political preferences <br />
<br />
Departamental cyber warfare would never reach the flexibity state of people's information warfare where everyone is a cyber warrior given he's empowered with access to the right tools at a particular moment in time.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">People's Information Warfare Concept</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Combating Unrestricted Warfare</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html">The Cyber Storm II Cyber Exercise</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attacks Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html">North Korea's Cyber Warfare Unit 121</a><br />
<div><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><div><a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">Empowering the Script Kiddies</a></div><div><a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">Malware Infected Hosts as Stepping Stones</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html">The Current, Emerging, and Future State of Hacktivism</a></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Tcck1K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Tcck1K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X9Eb0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X9Eb0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sJIFNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sJIFNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dY7m7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dY7m7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rRiYlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rRiYlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCeTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCeTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IYEN6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IYEN6k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/364867192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:16:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/departamental cyber warfare">departamental cyber warfare</category>
      <category domain="http://securityratty.com/tag/cyber warfare tensions">cyber warfare tensions</category>
      <category domain="http://securityratty.com/tag/information warfare concept">information warfare concept</category>
      <category domain="http://securityratty.com/tag/information warfare">information warfare</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian oligarchs">russian oligarchs</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/364867192/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</source>
    </item>
    <item>
      <title><![CDATA[Experts: Passwords May Not Be a Good Online Defense]]></title>
      <link>http://securityratty.com/article/280bac440f99e1ea6da852e1a0accd91</link>
      <guid>http://securityratty.com/article/280bac440f99e1ea6da852e1a0accd91</guid>
      <description><![CDATA[Tired of creating and changing website passwords? Many experts propose dropping passwords entirely for a security system based on cryptography. For example, machines have a cryptographically encoded...]]></description>
      <content:encoded><![CDATA[Tired of creating and changing website passwords? Many experts propose dropping passwords entirely for a security system based on cryptography. For example, machines have a cryptographically encoded conversation to establish both parties’ authenticity, using digital keys that we, as users, have no need to see.]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 02:00:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/security system based">security system based</category>
      <category domain="http://securityratty.com/tag/website passwords">website passwords</category>
      <category domain="http://securityratty.com/tag/parties authenticity">parties authenticity</category>
      <category domain="http://securityratty.com/tag/experts propose">experts propose</category>
      <category domain="http://securityratty.com/tag/digital keys">digital keys</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/cryptography">cryptography</category>
      <category domain="http://securityratty.com/tag/conversation">conversation</category>
      <source url="http://digg.com/security/Experts_Passwords_May_Not_Be_a_Good_Online_Defense">Experts: Passwords May Not Be a Good Online Defense</source>
    </item>
  </channel>
</rss>
