<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: drop]]></title>
    <link>http://securityratty.com/tag/drop</link>
    <description></description>
    <pubDate>Tue, 07 Oct 2008 04:33:10 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Mamma.com: Insider trading and XSS]]></title>
      <link>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</link>
      <guid>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</guid>
      <description><![CDATA[Mamma.com 's got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked 4064 on Alexa as of today
I won't profess to following...]]></description>
      <content:encoded><![CDATA[<a href="http://mamma.com/" target="_blank">Mamma.com</a>'s got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked <a href="http://www.alexa.com/search?q=mamma.com" target="_blank">4064</a> on <a href="http://www.alexa.com" target="_blank">Alexa</a> as of today.<br />I won't profess to following Mr. Cuban's public life and the occasional antics. Obviously, he's a colorful and popular figure; certainly in Dallas, if not nationally. <br />What follows is not a judgment of Mr. Cuban or his pending legal challenges. I'm sure the process will play itself out accordingly.<br />A quick summary and some reference material:<br />The SEC has <a href="http://www.businessweek.com/the_thread/blogspotting/archives/2008/11/sec_hits_mark_c.html?chan=technology_technology+index+page_top+stories" target="_blank">filed</a> insider trading charges against Mr. Cuban. "According to the SEC, Cuban dumped 600,000 shares, or all of his 6.3% stake, in the search engine Mamma.com (The Mother of All Search Engines), in June 2004 after learning about private financing that the company was proposing. By selling, he avoided losing $750,000, the SEC alleges."<br />The whole issue for Mr. Cuban was <a href="http://blogmaverick.com/2008/11/17/the-sec/" target="_blank">PIPE</a> financing because it's "dilutive to existing shareholders’ stakes."<br />That's the long and the short of the current issue, and again, not my real interest here, with the exception of the bet I made with myself regarding the probable web application security posture of mamma.com. <br />All this talk about a popular site immediately sets off the little bell in my head (I hear it a lot). <span style="font-weight:bold;"><br />"What's wrong with the site?" is always the first question I ask myself.</span> <br /><br />I was not disappointed. <br /><br />Mamma.com exhibits the following issues:<br />1) XSS vulnerability in the <span style="font-style:italic;">utfout<span style="font-weight:bold;"><span style="font-style:italic;"></span></span></span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s1600-h/mamma1.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s320/mamma1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129685521075730" /></a><br /><br />2) XSS vulnerability in the <span style="font-style:italic;">qtype</span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s1600-h/mamma2.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 201px;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s320/mamma2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129978766677474" /></a><br /><br />3) XSS vulnerability in their Mammajobs site at the <span style="font-style:italic;">pid</span> variable. This one's weirder still; if you drop an IFRAME in, it simply redirects to any URL you include in the IFRAME string.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s1600-h/mamma3.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 99px;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s320/mamma3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270130171179660098" /></a><br /><br />4) The prospect of CSRF (rather pointless here given that its just a search engine, but but still defies best practices) appears likely given that mamma.com blindly accepts updates via GET and POST with no sign of a formkey (canary) in sight.<br /><br />I figured it best to stop there, and have submitted all these to Copernic (the Momma parent company). <br />I am however truly disappointed that an enterprise as ambitious and motivated as Momma/Copernic seems to have thrown the baby out with the bath water when it comes to web application security.<br />With regard to Mark Cuban dumping his shares: maybe he was afraid of getting pwned. ;-) All kidding aside, it's a shame that the whimsical and pessimistic thoughts regarding web site security that bounce around in my head inevitably bear themselves out.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html&title=Mamma.com:%20Insider%20trading%20and%20XSS " title="Mamma.com: Insider trading and XSS ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html" title="Mamma.com: Insider trading and XSS ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 06:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mamma">mamma</category>
      <category domain="http://securityratty.com/tag/mark cuban">mark cuban</category>
      <category domain="http://securityratty.com/tag/cuban">cuban</category>
      <category domain="http://securityratty.com/tag/engine">engine</category>
      <category domain="http://securityratty.com/tag/engine mamma">engine mamma</category>
      <category domain="http://securityratty.com/tag/xss vulnerability">xss vulnerability</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/insider">insider</category>
      <category domain="http://securityratty.com/tag/web site security">web site security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Mamma.com: Insider trading and XSS</source>
    </item>
    <item>
      <title><![CDATA[Most Spam Came from a Single Web Hosting Firm]]></title>
      <link>http://securityratty.com/article/894b4e87cb13c364abc659a7aab3070a</link>
      <guid>http://securityratty.com/article/894b4e87cb13c364abc659a7aab3070a</guid>
      <description><![CDATA[Really : Experts say the precipitous drop-off in spam comes from Internet providers unplugging McColo Corp., a hosting provider in Northern California that was the home base for machines responsible...]]></description>
      <content:encoded><![CDATA[<p><a href="http://voices.washingtonpost.com/securityfix/2008/11/spam_volumes_drop_by_23_after.html?nav=rss_blog">Really</a>:</p>

<blockquote>Experts say the precipitous drop-off in spam comes from Internet providers unplugging McColo Corp., a hosting provider in Northern California that was the home base for machines responsible for coordinating the sending of roughly 75 percent of all spam each day.</blockquote>

<p>Certainly this won't last:</p>

<blockquote>Bhandari said he expects the spam volume to recover to normal levels in about a week, as the spam operations that were previously hosted at McColo move to a new home.

<p>"We're seeing a slow recovery," Bhandari. "We fully expect this to recover completely, and to go into the highest ever spam period during the upcoming holiday season."</blockquote></p>

<p>But with all the talk of massive botnets sending spam, it's interesting that most of it still comes from hosting services.  You'd think this would make the job of detecting spam a lot easier.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dOYuN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dOYuN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=HEDZN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=HEDZN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:11:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam volume">spam volume</category>
      <category domain="http://securityratty.com/tag/spam period">spam period</category>
      <category domain="http://securityratty.com/tag/spam operations">spam operations</category>
      <category domain="http://securityratty.com/tag/recover">recover</category>
      <category domain="http://securityratty.com/tag/recover completely">recover completely</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/home base">home base</category>
      <category domain="http://securityratty.com/tag/machines responsible">machines responsible</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/most_spam_came.html">Most Spam Came from a Single Web Hosting Firm</source>
    </item>
    <item>
      <title><![CDATA[Spam drop could boost Trojan attacks]]></title>
      <link>http://securityratty.com/article/37e020c8882e10718719f34547ff84f3</link>
      <guid>http://securityratty.com/article/37e020c8882e10718719f34547ff84f3</guid>
      <description><![CDATA[The dramatic fall in spam traffic last week after alleged rogue ISP McColo was taken down will be only a temporary reprieve and could generate a new wave of Trojans, experts...]]></description>
      <content:encoded><![CDATA[The dramatic fall in spam traffic last week after alleged rogue ISP McColo was taken down will be only  a temporary reprieve and could generate a new wave of Trojans, experts warn.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c90c0e82cb49a490c389a351f970b88e:qG5hS2x%2BvBMxko6ckCL%2Bm9lIkLbOqQYrgcR7DUtbCwCYBASzPRsVnJnaOVLlHhcHBfjhiXcEQG9P'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:21f92acc3e939ae230ccfd53db7bc79f:dr5zQQz6mejlLlMKHXQA%2FxE3lgCPruIqIKjo%2B4oRzhINmYAWvJ4GMGDg3Tl4Ua1DDRqFjIx7gKBtGw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:29afd4cf8e78395aab8ec2b73593d2a7:OhsDZ6jNJDGFiLH8ja2DcvrPsy%2FlVy6xd7YvhZvr9n4XkDu769RlKcHBh%2BuKJEfdr6fiE%2BcYKZYLVQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7e4eaa1539df55c97e5bd6cdef66a719:cNzjvOtMqB2BZWmSGy7xSLJJwTJ3p%2B6fnIF%2FiWhqDzZeQcVOrfA7Yk8itYqqUiYVAMnyOd61sXWFaQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=396f1ec2a9ed56a2d5751f1637049450"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=396f1ec2a9ed56a2d5751f1637049450" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=396f1ec2a9ed56a2d5751f1637049450" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rogue isp mccolo">rogue isp mccolo</category>
      <category domain="http://securityratty.com/tag/spam traffic">spam traffic</category>
      <category domain="http://securityratty.com/tag/experts warn">experts warn</category>
      <category domain="http://securityratty.com/tag/temporary reprieve">temporary reprieve</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/dramatic">dramatic</category>
      <category domain="http://securityratty.com/tag/wave">wave</category>
      <category domain="http://securityratty.com/tag/trojans">trojans</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=396f1ec2a9ed56a2d5751f1637049450">Spam drop could boost Trojan attacks</source>
    </item>
    <item>
      <title><![CDATA[Spam drop could boost Trojan attacks]]></title>
      <link>http://securityratty.com/article/72bfea02112e57e9d6b1474f8f1d568e</link>
      <guid>http://securityratty.com/article/72bfea02112e57e9d6b1474f8f1d568e</guid>
      <description><![CDATA[The dramatic fall in spam traffic reported last week after alleged rogue ISP McColo was taken offline will only be a temporary reprieve and could actually generate a new wave of Trojans, experts have...]]></description>
      <content:encoded><![CDATA[The dramatic fall in spam traffic reported last week after alleged rogue ISP McColo was taken offline will only be a temporary reprieve and could actually generate a new wave of Trojans, experts have warned.]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rogue isp mccolo">rogue isp mccolo</category>
      <category domain="http://securityratty.com/tag/spam traffic">spam traffic</category>
      <category domain="http://securityratty.com/tag/temporary reprieve">temporary reprieve</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <category domain="http://securityratty.com/tag/offline">offline</category>
      <category domain="http://securityratty.com/tag/dramatic">dramatic</category>
      <category domain="http://securityratty.com/tag/wave">wave</category>
      <category domain="http://securityratty.com/tag/trojans">trojans</category>
      <source url="http://www.networkworld.com/news/2008/111708-spam-drop-could-boost-trojan.html?fsrc=rss-security">Spam drop could boost Trojan attacks</source>
    </item>
    <item>
      <title><![CDATA[They didn't go away you know....]]></title>
      <link>http://securityratty.com/article/265b22f7a3a1ac42a1aa3d3c8f7bd79d</link>
      <guid>http://securityratty.com/article/265b22f7a3a1ac42a1aa3d3c8f7bd79d</guid>
      <description><![CDATA[Listening to a discussion on CNN the day after President elect Obama won the U.S. Presidential race, made me think about what the terrorists may be thinking

It really is fairly easy for the average...]]></description>
      <content:encoded><![CDATA[Listening to a discussion on CNN the day after President elect Obama won the U.S. Presidential race, made me think about what the terrorists may be thinking. <br /><span id="fullpost"><br />It really is fairly easy for the average citizen to push these thoughts out of their mind, but we should always keep it somewhere in our minds - close enough to recall it when necessary.<br /></span><br />Bill Clinton was "tested" early in his Presidency as was the U.K.'s new Prime Minister - Gordon Brown.  In PM Brown's case it came 72 hours after the Election in Britain.  How long may we wait to see something here..or overseas, but definitely aimed at inflciting U.S. casualties?<br /><br />Bottom line - we should always remian alert and open to the idea that something could happen and we can not afford to drop our guard and think "they have gone".  Terrorists have great amounts of patience.  They conduct surveillance right under the noses of their intended victims.  As the old saying goes; "we have to be successful every single time - they only have to be lucky once".<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 03:02:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/brown">brown</category>
      <category domain="http://securityratty.com/tag/gordon brown">gordon brown</category>
      <category domain="http://securityratty.com/tag/president elect obama">president elect obama</category>
      <category domain="http://securityratty.com/tag/single time">single time</category>
      <category domain="http://securityratty.com/tag/conduct surveillance">conduct surveillance</category>
      <category domain="http://securityratty.com/tag/bill clinton">bill clinton</category>
      <category domain="http://securityratty.com/tag/remian alert">remian alert</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/presidential race">presidential race</category>
      <source url="http://www.thebulletproofblog.com/2008/11/they-didnt-go-away-you-know.html">They didn't go away you know....</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security AND Compliance 9]]></title>
      <link>http://securityratty.com/article/8c92a5eb0e9512d04ed455c88f9d493d</link>
      <guid>http://securityratty.com/article/8c92a5eb0e9512d04ed455c88f9d493d</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #9, dated October 30th, 2008....]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #9, dated October 30th, 2008. BTW, I am renaming it into “Fun Reading on Security AND Compliance”</p>  <ol>   <li>“A Gartnergate?” What happened after Mr Pescatore <a href="http://blogs.gartner.com/john_pescatore/2008/10/28/twelve-word-tuesday-measuring-security-program-effectiveness/">uttered his now famous 12 words</a>: “The best security program is at the business with the happiest customers.” <a href="http://1raindrop.typepad.com/1_raindrop/2008/10/whats-happiness-got-to-do-with-it-1.html">This</a> (complete with Gunnar’s famous “firewalls+SSL” chart), <a href="http://rationalsecurity.typepad.com/blog/2008/10/gunnar-peterson-channels-tina-turner-sort-of-whats-happiness-got-to-do-with-it.html">this</a> – will add more as this snowballs. </li>    <li>Do you have an “ignorable” security policy? If yours is BOTH “ignorable” and “unfair”, then fuggedaboutit. <a href="http://www.networkworld.com/news/2008/102808-cisco-security-policies.html?nlhtsecstrat=rn_102808&amp;nladname=102808securitystrategiesal">Cisco survey kinda proves it</a>. A few fun comments are <a href="http://www.computerweekly.com/blogs/stuart_king/2008/10/security-policies.html">here</a> (“If people can't get their jobs done without having to find a way to circumvent policy then the policy is wrong.”)</li>    <li>Risk and clouds – <a href="http://riskmanagementinsight.com/riskanalysis/?p=496">here</a>, <a href="http://techbuddha.wordpress.com/2008/10/26/cloud-computing-the-good-the-bad-and-the-cloudy/">here</a>, <a href="http://rationalsecurity.typepad.com/blog/2008/10/will-you-all-please-shut-up-about-securing-the-cloudno-such-thing.html">here</a> and <a href="http://rationalsecurity.typepad.com/blog/2008/10/cloud-computing-security-in-poetic-review.html">here in poetic form</a> (!). Fun reading, but you know what? For many, many organization, what they have today is LESS secure than any future cloud computing advance… </li>    <li>Richard Bejtlich <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back.html">drop-kicks SIEM</a>&#160;<a href="http://chuvakin.blogspot.com/search/label/SIEM">too</a>, then <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_25.html">kicks it in the balls</a>. Then <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">kicks the dead horse</a> (<a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back.html">1</a>,<a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_25.html">2</a>,<a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">3</a>) </li>    <li><a href="http://securosis.com/2008/10/29/the-good-enoughwoe-is-me-dissociation-postulate/">Excellent reminder</a> about why people don’t care about security with a fabled quote from MJR (yes, it is my fave too!) Overall, Rich “reassures” with: “Don’t worry. When things get bad enough, we’ll get the call. If you’ve kept your documentation and communications up, you won’t get shafted with the proverbial short end.” </li>    <li>A few essays on risk, from <a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=211600785">ANSI</a>, from <a href="http://www.schneier.com/blog/archives/2008/10/does_risk_manag.html">Schneier</a> and from BlogInfoSec (<a href="http://www.bloginfosec.com/2008/09/04/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-1/">part 1</a> and <a href="http://www.bloginfosec.com/2008/10/29/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-2/">part 2</a>, especially read <a href="http://www.bloginfosec.com/2008/10/29/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-2/">part 2</a>) </li>    <li>So, what do CTOs really do every day? Interesting summary <a href="http://www.emergentchaos.com/archives/2008/10/ctos_product_management_a.html">here</a> and <a href="http://startuplessonslearned.blogspot.com/2008/09/what-does-startup-cto-actually-do.html">here</a>. </li>    <li><a href="http://layer8.itsecuritygeek.com/layer8/why-security-privacy-and-compliance-dont-mix/">Fun exploration of <em>security x privacy x compliance</em></a>. </li>    <li><a href="http://srmsblog.burtongroup.com/2008/10/it-security-meets-the-crash-of-2008.html">Burton Group opines</a> on which security technologies will fare better/worse during &quot;The crisis”</li>    <li>A really fun interview with our CEO Philippe Courtot <a href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;taxonomyName=Management&amp;articleId=9117939&amp;taxonomyId=14">here</a>. </li>    <li>More on <a href="http://taosecurity.blogspot.com/2008/09/security-vs-it-at-computerworld.html">IT vs IT security</a>, this time from Richard.</li>    <li>Do you want <a href="http://consumerist.com/5069018/how-outsourced-call-centers-are-costing-millions-in-identity-theft">people like that</a> doing “security”? A normal call center employee recognizes fraud, but their so-called “outsource security dept” authorizes the scam. Niiice.</li>    <li>Finally, “<a href="http://blog.wired.com/defense/2008/10/robot-packs-hun.html">Robots Hunt 'Non-Cooperative Humans' in Army Plan</a>” No comment :-)</li> </ol>  <p>Enjoy!</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OZKuM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OZKuM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Qv4oM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Qv4oM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0COrM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0COrM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/438357287" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 09:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/outsource security dept">outsource security dept</category>
      <category domain="http://securityratty.com/tag/security technologies">security technologies</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/circumvent policy">circumvent policy</category>
      <category domain="http://securityratty.com/tag/ignorable security policy">ignorable security policy</category>
      <category domain="http://securityratty.com/tag/security program">security program</category>
      <category domain="http://securityratty.com/tag/ignorable">ignorable</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/438357287/fun-reading-on-security-and-compliance.html">Fun Reading on Security AND Compliance 9</source>
    </item>
    <item>
      <title><![CDATA[The Skein Hash Function]]></title>
      <link>http://securityratty.com/article/c65ce3834e7790e113fa9e1fd1504568</link>
      <guid>http://securityratty.com/article/c65ce3834e7790e113fa9e1fd1504568</guid>
      <description><![CDATA[NIST is holding a competition to replace the SHA family of hash functions, which have been increasingly under attack . (I wrote about an early NIST hash workshop here
Skein is our submission (myself...]]></description>
      <content:encoded><![CDATA[<p>NIST is <a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html">holding a competition</a> to replace the SHA family of hash functions, which have been <a href="http://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html">increasingly under attack</a>.  (I wrote about an early NIST hash workshop <a href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_1.html">here</a>.)</p>

<p>Skein is our submission (myself and seven others: <a href="http://en.wikipedia.org/wiki/Niels_Ferguson">Niels Ferguson</a>, <a href="http://th.informatik.uni-mannheim.de/People/Lucks/">Stefan Lucks</a>, <a href="http://www.hifn.com/executiveTeam.aspx?id=182">Doug Whiting</a>, <a href="http://www-cse.ucsd.edu/~mihir/">Mihir Bellare</a>, <a href="http://www.cs.washington.edu/homes/yoshi/">Tadayoshi Kohno</a>, <a href="http://www.pgp.com/about_pgp_corporation/management.html">Jon Callas</a>, and Jesse Walker).  <a href="http://www.schneier.com/skein.pdf">Here's</a> the paper:</p>

<blockquote><strong>Executive Summary</strong>

<p>Skein is a new family of cryptographic hash functions.  Its design combines speed, security, simplicity, and a great deal of flexibility in a modular package that is easy to analyze.</p>

<p>Skein is fast.  Skein-512 -- our primary proposal -- hashes data at 6.1 clock cycles per byte on a 64-bit CPU.  This means that on a 3.1 GHz x64 Core 2 Duo CPU, Skein hashes data at 500 MBytes/second per core -- almost twice as fast as SHA-512 and three times faster than SHA-256.  An optional hash-tree mode speeds up parallelizable implementations even more.  Skein is fast for short messages, too; Skein-512 hashes short messages in about 1000 clock cycles.</p>

<p>Skein is secure.  Its conservative design is based on the Threefish block cipher.  Our current best attack on Threefish-512 is on 25 of 72 rounds, for a safety factor of 2.9. For comparison, at a similar stage in the standardization process, the AES encryption algorithm had an attack on 6 of 10 rounds, for a safety factor of only 1.7.  Additionally, Skein has a number of provably secure properties, greatly increasing confidence in the algorithm.</p>

<p>Skein is simple.  Using only three primitive operations, the Skein compression function can be easily understood and remembered.  The rest of the algorithm is a straightforward iteration of this function.</p>

<p>Skein is flexible.  Skein is defined for three different internal state sizes -- 256 bits, 512 bits, and 1024 bits -- and any output size.  This allows Skein to be a drop-in replacement for the entire SHA family of hash functions.  A completely optional and extendable argument system makes Skein an efficient tool to use for a very large number of functions: a PRNG, a stream cipher, a key derivation function, authentication without the overhead of HMAC, and a personalization capability.  All these features can be implemented with very low overhead.  Together with the Threefish large-block cipher at Skein core, this design provides a full set of symmetric cryptographic primitives suitable for most modern applications.</p>

<p>Skein is efficient on a variety of platforms, both hardware and software.  Skein-512 can be implemented in about 200 bytes of state.  Small devices, such as 8-bit smart cards, can implement Skein-256 using about 100 bytes of memory.  Larger devices can implement the larger versions of Skein to achieve faster speeds.</p>

<p>Skein was designed by a team of highly experienced cryptographic experts from academia and industry, with expertise in cryptography, security analysis, software, chip design, and implementation of real-world cryptographic systems.  This breadth of knowledge allowed them to create a balanced design that works well in all environments.</blockquote></p>

<p><a href="http://www.schneier.com/code/skein_NIST_CD_101308.zip">Here's</a> source code, text vectors, and the like for Skein.  Watch the <a href="http://www.schneier.com/skein.html">Skein website</a> for any updates -- new code, new results, new implementations, the proofs.</p>

<p>NIST's deadline is Friday.  It seems as if everyone -- including many amateurs -- is working on a hash function, and I predict that NIST will receive at least 80 submissions.  (Compare this to the 21 submissions NIST received -- five were rejected as not being complete --  for the AES competition in 1998.)  I expect people to start posting their submissions over the weekend.  (Ron Rivest already <a href="http://people.csail.mit.edu/rivest/Rivest-TheMD6HashFunction.ppt">presented</a> MD6 at Crypto in August.)  Probably the best place to watch for new hash functions is <a href="http://planeta.terra.com.br/informatica/paulobarreto/hflounge.html">here</a>; I'll try to keep a listing of the submissions myself.</p>

<p>The selection process will take around four years.  I've previously called this sort of thing a cryptographic demolition derby -- last one left standing wins -- but that's only half true.  Certainly all the groups will spend the next couple of years trying to cryptanalyze each other, but in the end there will be a bunch of unbroken algorithms; NIST will select one based on performance and features.</p>

<p>NIST has stated that the goal of this process is not to choose the best standard but to choose a good standard.  I think that's smart of them; in this process, "best" is the enemy of "good."  My advice is this: immediately sort them based on performance and features.  Ask the cryptographic community to focus its attention on the top dozen, rather than spread its attention across all 80 -- although I also expect that most of the amateur submissions will be rejected by NIST for not being "complete and proper."  Otherwise, people will break the easy ones and the better ones will go unanalyzed.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RsFiM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RsFiM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=VuObM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=VuObM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 01:35:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skein">skein</category>
      <category domain="http://securityratty.com/tag/hash function">hash function</category>
      <category domain="http://securityratty.com/tag/function">function</category>
      <category domain="http://securityratty.com/tag/implement skein-256">implement skein-256</category>
      <category domain="http://securityratty.com/tag/implement">implement</category>
      <category domain="http://securityratty.com/tag/skein hashes data">skein hashes data</category>
      <category domain="http://securityratty.com/tag/skein website">skein website</category>
      <category domain="http://securityratty.com/tag/hashes data">hashes data</category>
      <category domain="http://securityratty.com/tag/key derivation function">key derivation function</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_skein_hash.html">The Skein Hash Function</source>
    </item>
    <item>
      <title><![CDATA[NBA Preview and Flashback]]></title>
      <link>http://securityratty.com/article/b7a6f4985a46dfec8a0d683b7d11b6f9</link>
      <guid>http://securityratty.com/article/b7a6f4985a46dfec8a0d683b7d11b6f9</guid>
      <description><![CDATA[NBA starts today, it is always good to have something to look forward to once the weather gets cold in Minnie. I follow two teams. The Celtics who have a decent chance at repeating as champs. KG and...]]></description>
      <content:encoded><![CDATA[<p>NBA starts today, it is always good to have something to look forward to once the weather gets cold in Minnie. I follow two teams. The Celtics who have a decent chance at repeating as champs. KG and Pierce should be back in full force, hopefully Ray Allen holds up. Perkins and Rondo may get a little better with experience. Biggest loss is Posey and we will miss him a lot more than people think. A real glue guy, defense, passing, rebounding, makes the smart plays and as a middleware guy myself I can relate. He will make CP3 even more dangerous.</p><div><br /><div>The other team I follow is the Timberwolves. I think they will be pretty good this year. Al Jefferson is a beast down low. Only four players averaged 20 and 10 last year and he is one. He is the best big man in the post after Duncan. Getting Love and Miller for OJ Mayo was a smart deal by McHale. I think McCants can be a decent instant offense 6th man. Would be good to see Foye step up this year. Weakness looks to be defense</div><br />

*Flashback*&#0160;
</div><div>I am biased but I think the 1980s was the most fun time to watch NBA. Everyone talks about Bird and Magic, but there were a lot of great players back then. Here is my all underrated 1980s team (no Celtics included due to conflict of interest and unobjectivity)</div><br /><div>C: <a href="http://www.youtube.com/results?search_query=moses+malone&amp;search_type=">Moses Malone</a> - beast of a big man, immovable force under the hoop with fantastic foot work for a big man. It is too bad he was traded by Portland because he and Bill Walton would have been the best big man combo of all time. &#0160;&#0160;</div><br /><div>PF: <a href="http://www.youtube.com/watch?v=CO1UvhQMnRk">Bobby Jones</a> - great defender, good rebounder, good passer for a big man. Typical Tar Heel -fundamentally sound. He would be the James Posey of this team. (Runner up: Calvin Natt)</div><br /><div>SF: <a href="http://www.youtube.com/results?search_query=bernard+king&amp;search_type=">Bernard King</a> - what a renaissance. Watch his moves on youtube, he was not that tall like say Alex English but he could go in the lane and score on anybody. Jordan of course is an all around better player but I think King was a better scorer and that is saying something. The playoffs when he was putting up 50 and 60 a night he was a terrifying force.&#0160;

</div><br /><div>SG: <a href="http://www.youtube.com/results?search_query=andrew+toney&amp;search_type=">Andrew Toney</a> - they called him the Boston strangler and as Celtics fan there was no one I was more afraid of. Its a real shame his career got cut short. (Runner up: George Gervin) &#0160;</div><br /><div>PG: <a href="http://www.youtube.com/results?search_query=tiny+archibald&amp;search_type=">Tiny Archibald</a> - Ok, one Celtic, but he is seriously underrated - would go flying into the lane, disappear in the trees, Tiny would fly out the bottom of the pile, and the ball would pop out the top and drop in. Probably the last great player to come out of NYC. (Runner up: Mo Cheeks)</div><br /><div>Sixth Man - <a href="http://www.youtube.com/watch?v=sxpu6cFF2B0">World B. Free</a> - no doubt about this one, he was great as a sixth man. And this guy was plain fun to watch. He would bomb it from 30 feet, when he was on he was a force. He would kick his leg into the defender when he was shooting a j to draw the foul. (Runner up: Michael Cooper)</div>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 20:42:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/real glue guy">real glue guy</category>
      <category domain="http://securityratty.com/tag/nba">nba</category>
      <category domain="http://securityratty.com/tag/1980s team">1980s team</category>
      <category domain="http://securityratty.com/tag/immovable force">immovable force</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/force">force</category>
      <category domain="http://securityratty.com/tag/celtics fan">celtics fan</category>
      <category domain="http://securityratty.com/tag/celtics">celtics</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/nba-preview-and-flashback.html">NBA Preview and Flashback</source>
    </item>
    <item>
      <title><![CDATA[Money Mules Syndicate Actively Recruiting Since 2002]]></title>
      <link>http://securityratty.com/article/a33470c5ef01ff61333511853f9e63cc</link>
      <guid>http://securityratty.com/article/a33470c5ef01ff61333511853f9e63cc</guid>
      <description><![CDATA[Money mules have already been an inseparable part of the underground ecosystem. And while others try to hide their activities by outsourcing their hosting needs to botnet masters partitioning their...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQcPr1E8aJI/AAAAAAAACYE/NAdxaAzEnw8/s1600-h/money_mules_syndicate_U.S_U.K.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQcPr1E8aJI/AAAAAAAACYE/6noTDuaSIow/s320-R/money_mules_syndicate_U.S_U.K.bmp" /></a>Money mules have already been an inseparable part of the underground ecosystem. And while others try to hide their activities by <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">outsourcing their hosting needs to botnet masters partitioning their botnets</a>, the experienced ones apply a decent level of OPSEC (operational security) by establishing a trust based model based on recommendations in order to even consider letting you register for their services. Their geographical location not only reflects the average time it would take to take action against their activities and expose yet another extensive network of fraudulent operations, but also, has the potential to increase or decrease the commissions that the mules take based on the risk factor of getting caught.<br />
<br />
There are several different types of money mules, those serving themselves, and those offering their services to others, in this particular case, we have a money mules syndicate that's been operating since 2002, and is only serving the high profile customers. What happens when such a money mule syndicate (naturally) starts vertically integrating by offering value-added services like credit card balance checking and date of birth lookups? Profits apparently increase, since the syndicate is actively recruiting and is currently looking for 20 to 30 mules -- their current staff is said to be approximately 100 people -- to cash out anything from bank account logins, Paypal accounts, to stolen credit card data. Here's a translated description of the service :<br />
<br />
<b>"<i>Who we are?</i></b><i><br />
</i><br />
<i>- First place at (cyber crime community) top list of trusted service providers for 2008</i><br />
<i>- We serve the big guys only since 2002</i><br />
<i>- We never scam, in business since 2002 without a single scam complaint</i><br />
<i>- We look for you, you don't look for us</i><br />
<i>- We offer outstanding working conditions and high commissions<b>&nbsp;</b></i><br />
<br />
<i><b>Who you should be?</b></i><br />
<i>- Dedicated person with experience in the field</i><br />
<i>- Have been in the business for at least 6 months</i><br />
<i>- Have been recommended by at least 1 person from (cybercrime community) and from (cybercrime community)</i><br />
<i>- You take 45% commission of the processed check, minimal amount is $3000</i><br />
<i>- You pay a membership fee</i><br />
<br />
<i>In the next two months we draw the command of 20-30 people who will most satisfy our requirements. For the selected team will be Paradise conditions:</i><br />
<br />
<i>- Instant payment (a few hours after delivered)  <br />
- Large numbers to drop service in the USA and the UK (30)  <br />
- Individual drop in the number of large islands  <br />
- 3-5 fresh weekly drop<br />
- Round-the-clock support</i>"  <br />
<br />
In case some of their customers get scammed -- appreciate the irony here as scammers compensate the scammers getting scammed by the scammer's outsourced personnel -- by some of their money mules, the service is offering compensation for the stolen goods/amount of money, clearly speaking for the revenues it is to prone to be generating. OPSEC (Operational Security) has been taking place across high-profile cybercrime communities during the last quarter, mostly in response to their increasing awareness that in the very same way they keep track of the major anti-fraud features implemented across their services of (ab)use, those implementing them could be monitoring them as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fGWOM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fGWOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f3mhM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f3mhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Wr9Sm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Wr9Sm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f0Zkm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f0Zkm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i6KYM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i6KYM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7W3IM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7W3IM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sc0Km"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sc0Km" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/434724736" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 05:44:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/money mules">money mules</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/mules">mules</category>
      <category domain="http://securityratty.com/tag/drop service">drop service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/scam">scam</category>
      <category domain="http://securityratty.com/tag/cybercrime community">cybercrime community</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/434724736/money-mules-syndicate-actively.html">Money Mules Syndicate Actively Recruiting Since 2002</source>
    </item>
    <item>
      <title><![CDATA[Sniffers presentation at 2008 Louisville Metro InfoSec Conference Thursday, October 9th, 2008]]></title>
      <link>http://securityratty.com/article/d5bb825be9a4d3baf860dee3dae49909</link>
      <guid>http://securityratty.com/article/d5bb825be9a4d3baf860dee3dae49909</guid>
      <description><![CDATA[Update: Sniffers presentation at 2008 Louisville Metro InfoSec Conference Thursday, October 9th, 2008 Looks like I will be presenting at the upcoming Louisville InfoSec Conference put on by the ISSA,...]]></description>
      <content:encoded><![CDATA[Update:<a href="http://www.louisvilleinfosec.com/">Sniffers presentation at 2008 Louisville Metro InfoSec Conference Thursday, October 9th, 2008</a><br/>Looks like I will be presenting at the upcoming <a href="http://www.louisvilleinfosec.com/">Louisville InfoSec Conference</a> put on by the ISSA, Thursday, October 9th, 2008 at Churchhill Downs. The person they had set do do the live hacking demo had to drop out, so they asked me to fill in on short notice.]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:33:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/october 9th">october 9th</category>
      <category domain="http://securityratty.com/tag/sniffers presentation">sniffers presentation</category>
      <category domain="http://securityratty.com/tag/louisville infosec conference">louisville infosec conference</category>
      <category domain="http://securityratty.com/tag/short notice">short notice</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <category domain="http://securityratty.com/tag/issa">issa</category>
      <category domain="http://securityratty.com/tag/demo">demo</category>
      <category domain="http://securityratty.com/tag/churchhill">churchhill</category>
      <category domain="http://securityratty.com/tag/drop">drop</category>
      <source url="http://www.louisvilleinfosec.com/">Sniffers presentation at 2008 Louisville Metro InfoSec Conference Thursday, October 9th, 2008</source>
    </item>
  </channel>
</rss>
