<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: deviant]]></title>
    <link>http://securityratty.com/tag/deviant</link>
    <description></description>
    <pubDate>Thu, 10 May 2007 03:00:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Fundamentals of Physical Security]]></title>
      <link>http://securityratty.com/article/fe96fea643ac95680617e2a06a8f16f0</link>
      <guid>http://securityratty.com/article/fe96fea643ac95680617e2a06a8f16f0</guid>
      <description><![CDATA[Deviant Ollam works as a network engineer and security consultant but his strongest love has always been teaching. A supporter of First Amendment rights who believes that the best way to increase...]]></description>
      <content:encoded><![CDATA[Deviant Ollam works as a network engineer and security consultant but his strongest love has always been teaching. A supporter of First Amendment rights who believes that the best way to increase secu...]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 21:46:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/amendment rights">amendment rights</category>
      <category domain="http://securityratty.com/tag/security consultant">security consultant</category>
      <category domain="http://securityratty.com/tag/increase secu">increase secu</category>
      <category domain="http://securityratty.com/tag/deviant ollam">deviant ollam</category>
      <category domain="http://securityratty.com/tag/network engineer">network engineer</category>
      <category domain="http://securityratty.com/tag/love">love</category>
      <category domain="http://securityratty.com/tag/supporter">supporter</category>
      <source url="http://www.net-security.org/article.php?id=1128">The Fundamentals of Physical Security</source>
    </item>
    <item>
      <title><![CDATA[Blended security threats on the rise, IBM says]]></title>
      <link>http://securityratty.com/article/e185a55a43aca5128fe2a64a4bcef538</link>
      <guid>http://securityratty.com/article/e185a55a43aca5128fe2a64a4bcef538</guid>
      <description><![CDATA[Malware was up in 2007, but reported software vulnerabilities down, while the United States has the dubious achievement of leading as the primary hosting source for criminal, pornographic and socially...]]></description>
      <content:encoded><![CDATA[Malware was up in 2007, but reported software vulnerabilities down, while the United States has the dubious achievement of leading as the primary hosting source for criminal, pornographic and socially deviant content on the Web, according to security researchers at IBM’s ISS division.
			
			<div style="margin-top:20" />
			<table border="1" BORDERCOLOR="#0033CC" cellspacing="0" cellpadding="2">
				<tr valign="top" align="left">
					<td>
						<table border="0" cellspacing="3" cellpadding="2" width="100%">
			
			
		  
		<tr> 
		<tr>
      <td width="*">
				<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1">
				<p>	
			
			<a href="http://rsslinks.industrybrains.com/click?sid=93&scid=10069&rqctid=589&lid=472196&cid=133720&pr=2&tstamp=20080213000000&url=http://www.apc.com/go/promo/whitepapers/form.cfm%3fpromo_num%3d11754%26thepromo%3d101%26tsk%3da127w" target=_blank><strong>Fundamental Principles of Network Security</strong></a></p>
				<td align="right">
					<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" COLOR="#0033CC" size="-1"><p>Advertisement</p></font>
				</td>
				</tr>
				<tr><td colspan="2"><font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1"><p>Protect the organization. Learn the 'Need To Know' aspects of network security. Free paper from APC.
			
				</p>
				</font>
		 	</td>
     </tr>
		 
		 
			
						</table>
					</td>
				</tr>
			</table>
			<div style="margin-top:20" />
			
			]]></content:encoded>
      <pubDate>Mon, 11 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/ibms iss division">ibms iss division</category>
      <category domain="http://securityratty.com/tag/software vulnerabilities">software vulnerabilities</category>
      <category domain="http://securityratty.com/tag/dubious achievement">dubious achievement</category>
      <category domain="http://securityratty.com/tag/free paper">free paper</category>
      <category domain="http://securityratty.com/tag/fundamental principles">fundamental principles</category>
      <category domain="http://securityratty.com/tag/deviant content">deviant content</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/advertisement">advertisement</category>
      <source url="http://www.networkworld.com/news/2008/021208-blended-security-threats.html?fsrc=rss-security">Blended security threats on the rise, IBM says</source>
    </item>
    <item>
      <title><![CDATA[Catch not-so-smart hackers to send message to smart hackers]]></title>
      <link>http://securityratty.com/article/f9cbec4e00c145ad6789f7e3399d6e11</link>
      <guid>http://securityratty.com/article/f9cbec4e00c145ad6789f7e3399d6e11</guid>
      <description><![CDATA[Hackers interact with software/hardware in order to compromise Confidenitality, Integrity and Availability of software/hardware. The adjective &quot;smart&quot; in the phrase &quot;smart hackers&quot; distinguishes those...]]></description>
      <content:encoded><![CDATA[<P>Hackers interact with software/hardware in&nbsp;order to&nbsp;compromise Confidenitality, Integrity and Availability of software/hardware. The adjective "smart" in the&nbsp;phrase "smart hackers"&nbsp;distinguishes those hackers who can compromise Confidentialy, Integrity and Availability in such a way that they leave minimal or no audit&nbsp;trail.</P>
<P>There are technical controls [tools such as <A href="https://www.blogware.com/www.vontu.com">Vontu</A>] available to monitor deviant&nbsp;computer usage&nbsp;of employees of a company.&nbsp;It is&nbsp;extremely difficult to catch a smart-deviant&nbsp;employee. An intelligent alternative is to catch not-so-smart-deviant employee to trigger a warning&nbsp;message to smart-deviant employee - [smart-deviant employee could either become smarter or they could just shut up!].&nbsp;Typical examples of not-so-smart-deviant employee behaviour are: 1. Sending confidential document to a competitior through an&nbsp;email attachment. 2. FTP'ing confidential document outside of the company. 3. Using webmail to send confidential document.</P>
<P><A href="http://securityincite.com/blog/mike-rothman/the-daily-incite-may-8-2007">Mike Rothman's</A> blog post about <A href="http://news.yahoo.com/s/pcworld/20070503/tc_pcworld/131523">spammer's using encrypted zip files</A> to tunnel thro' filters demonstrates the brilliance of smart hackers. It is&nbsp;well known&nbsp;truth that HTTP is known as UFBP (Universal Firewall Bypass Protocol). What if a hacker&nbsp;tunnels&nbsp;encrypted data thro' a SOAP container which uses HTTP? It would be extremely hard to catch those extreme cases with technical controls. </P>
<P>Jeremiah's thoughtful&nbsp; <A href="http://jeremiahgrossman.blogspot.com/2007/05/how-to-check-if-your-webmail-account.html">blog post</A> about &nbsp;"How to check if your WebMail account has been hacked".&nbsp;A smart hacker who has hacked say your gmail account would not be dumb enough to open a spurious looking email in the first place, moreover they would get around by&nbsp;choosing the option of not displaying images!</P>
<P>Smart hackers get away most of the time. There is no point in spending cycles to catch them. Hope for the good by catching&nbsp;not-so-smart hackers! Do make sure when you catch&nbsp;not-so-smart, it leads to widespread educational opportunity.</P>
<P>&nbsp;</P>]]></content:encoded>
      <pubDate>Thu, 10 May 2007 03:00:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/not-so-smart hackers">not-so-smart hackers</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/not-so-smart">not-so-smart</category>
      <category domain="http://securityratty.com/tag/smart">smart</category>
      <category domain="http://securityratty.com/tag/smart hackers">smart hackers</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/smart-deviant employee">smart-deviant employee</category>
      <category domain="http://securityratty.com/tag/hackers interact">hackers interact</category>
      <category domain="http://securityratty.com/tag/smart hacker">smart hacker</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2007/5/10/2939873.html">Catch not-so-smart hackers to send message to smart hackers</source>
    </item>
  </channel>
</rss>
