<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dynamic]]></title>
    <link>http://securityratty.com/tag/dynamic</link>
    <description></description>
    <pubDate>Mon, 25 Aug 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Inside a Managed Spam Service]]></title>
      <link>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</link>
      <guid>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</guid>
      <description><![CDATA[A managed spam vendor always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary managed spamming...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/w97lHPkkz7o/s1600-h/managed_spamming_service_2008.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/iBd96sIzD2o/s200-R/managed_spamming_service_2008.jpg" /></a>A <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spam vendor</a> always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">managed spamming system</a>, and is able to provide better spamming rates at a cheaper prices?&nbsp; Market forces and unethical competition at its best.<br />
<br />
So, what is this market challenger using the monopolist's -- in respect to managed spamming services not spam in general -- proprietary system (<a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>) up to anyway? Promising and delivering, 1, 400,000 emails daily, 60,000 mails per hour, and 100 emails per minute. What we've got here are the spam metrics out of 5 already finished spam campaigns that has managed to sent out a million spam emails using only 2000 malware infected hosts. Also, CC-ing and BCC-ing made it possible to multiple the effect of the campaign and increase the total number of emails spammed. Talking about benchmarks, 789 emails per minute at a rate of 12/13 emails per second is a pretty good one, considering it's only 2k bots that they were using. What they also promise is automatic rotation of IPs upon automatically checking them against public blacklists, and a mix rotation of IPs from their own netblocks located in Russia and Germany with the fresh IPs coming from the newly infected hosts.<br />
<br />
Earlier this month, I discussed the market leader's <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming system</a>, access to which they also offer for rent :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/nSP61RrjgSg/s1600-h/spamming_appliance_stats.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/0eV8S8Gv3NA/s200-R/spamming_appliance_stats.jpg" /></a>"<i>An inside look of the system obtained on 2008-08-12 indicates that they are indeed capable of delivering what they promise - speed, simplicity and 5000 malware infected hosts. Moreover, the attached screenshot demonstrates that 20 different email databases can be simultaneously used resulting in 16,523,247 emails about to get spammed using 52 different macroses. Furthermore, what they refer to as a dynamic set of regional servers aiming to ensure that the central server never gets exposed, is in fact fast-flux which depending on how many bots they are willing to put into “rtsegional server mode” shapes the size of the fast-flux network at a later stage.</i>"<br />
<br />
With cutting edge managed spam services like the ones currently in circulation, it remains to be seen whether or not spammers would migrate to this outsourcing model, or continue coming up with adaptive ways to send out their scams and malware on their own.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1n6HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1n6HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=69CPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=69CPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JSXmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JSXmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UqH8m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UqH8m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rsD3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rsD3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=myLSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=myLSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PFEmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PFEmm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/410205990" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:20:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam services">spam services</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/market follower starts">market follower starts</category>
      <category domain="http://securityratty.com/tag/emails daily">emails daily</category>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/million spam emails">million spam emails</category>
      <category domain="http://securityratty.com/tag/market challenger">market challenger</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/410205990/inside-managed-spam-service.html">Inside a Managed Spam Service</source>
    </item>
    <item>
      <title><![CDATA[Plan-based Complex Event Detection across Distributed Sources]]></title>
      <link>http://securityratty.com/article/7f2d9ec37ddd235b47e10e69a8a18a32</link>
      <guid>http://securityratty.com/article/7f2d9ec37ddd235b47e10e69a8a18a32</guid>
      <description><![CDATA[Here is an interesting 2008 paper, Plan-based Complex Event Detection across Distributed Sources
Abstract
Complex Event Detection (CED) is emerging as a key capability for many monitoring applications...]]></description>
      <content:encoded><![CDATA[<p>Here is an interesting 2008 paper, <a class="l" onmousedown="return clk(this.href,'','','res','4','')" href="http://www.cs.brown.edu/%7Eugur/ced.pdf">Plan-based Complex Event Detection across Distributed Sources.</a></p>
<p><strong>Abstract</strong></p>
<blockquote><p><em>Complex Event Detection (CED) is emerging as a key capability for many monitoring applications such as intrusion detection, sensorbased activity &amp; phenomena tracking, and network monitoring. Existing CED solutions commonly assume centralized availability and processing of all relevant events, and thus incur significant overhead in distributed settings. In this paper, we present and evaluate communication efficient techniques that can efficiently perform CED across distributed event sources.</em></p>
<p><em>Our techniques are plan-based: we generate multi-step event acquisition and processing plans that leverage temporal relationships among events and event occurrence statistics to minimize event transmission costs, while meeting application-specific latency expectations. We present an optimal but exponential-time dynamic programming algorithm and two polynomial-time heuristic algorithms, as well as their extensions for detecting multiple complex events with common sub-expressions. We characterize the behavior and performance of our solutions via extensive experimentation on synthetic and real-world data sets using our prototype implementation.</em></p></blockquote>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:49:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/complex event detection">complex event detection</category>
      <category domain="http://securityratty.com/tag/sources">sources</category>
      <category domain="http://securityratty.com/tag/multiple complex events">multiple complex events</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/communication efficient techniques">communication efficient techniques</category>
      <category domain="http://securityratty.com/tag/efficiently perform ced">efficiently perform ced</category>
      <category domain="http://securityratty.com/tag/ced">ced</category>
      <category domain="http://securityratty.com/tag/techniques">techniques</category>
      <category domain="http://securityratty.com/tag/event sources">event sources</category>
      <source url="http://www.thecepblog.com/2008/09/25/plan-based-complex-event-detection-across-distributed-sources/">Plan-based Complex Event Detection across Distributed Sources</source>
    </item>
    <item>
      <title><![CDATA[Complex Event Processing Approach for Strategic Intelligence]]></title>
      <link>http://securityratty.com/article/4e21d0747b810dd832ec39a6f7f8bf1a</link>
      <guid>http://securityratty.com/article/4e21d0747b810dd832ec39a6f7f8bf1a</guid>
      <description><![CDATA[FUSION 2006 Technical Program , Paper Number: 200 , Tuesday, 11 July 2006
Special Session: Situation Management I
Paper: Complex Event Processing approach for strategic intelligence
Authors: Nicolas...]]></description>
      <content:encoded><![CDATA[<p><a href="http://fusion.carthel.com/technical_program/" target="_blank">FUSION 2006 Technical Program</a>, <a href="http://www.foi.se/upload/projects/fusion/FOI-R--2252--SE.pdf" target="_blank">Paper Number: 200</a>, Tuesday, 11 July 2006</p>
<p>Special Session: Situation Management I</p>
<p>Paper: Complex Event Processing approach for strategic intelligence</p>
<p>Authors: Nicolas Museux, Juliette Mattioli, Claire Laudy and Helene Soubaras</p>
<p>Abstract: One of the key issues of strategic intelligence within a crisis situation is to build an early assessment of the situation, based on a context sensitive information interpretation and through a well constructed situation representation. Our proposal is based on the conjunction of a conceptual modelling to represent situations out of document analysis and a reactive rule-based modelling to analyse them according to a domain knowledge and a goal. This paper focuses on this Situation Analysis process. But we present our global approach and sum-up the Situation Representation and its objectives. We introduce the Complex Event Processing formalism used for the analysis and dynamic recognition of such situations. We illustrate our approach through a case study taken from what happened during the energy crisis in California in 2001.</p>
<p>Presenter Biography: Dr. Nicolas Museux is a research scientist in the PLATON lab, at THALES Research and Technology. He had his engineering diploma in computer science in 1998. Then he started his Ph.D. in Applied Mathematics, Computer Science Systems and Control at the Computer Science Center of e&#8217;Ecole des Mines de Paris, and THALES Research and Technology. His Ph.D. focused on the application of constraint programming in distributing low-level digital signal processing programs onto multiprocessors architectures, to optimize data management and computing duration. After he obtained his Ph.D. in 2001, he worked until the end of 2004 on several projects in the PLATON lab linked with combinatorial optimization. Since 2005, Dr. Nicolas MUSEUX works on the Situation understanding research program. Its objectives are to identify, to specify and to design tools for situation model based reasoning in order to address situation analysis, risk assessment and situation projection.</p>
]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 01:37:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/situation management">situation management</category>
      <category domain="http://securityratty.com/tag/situation">situation</category>
      <category domain="http://securityratty.com/tag/situation projection">situation projection</category>
      <category domain="http://securityratty.com/tag/crisis situation">crisis situation</category>
      <category domain="http://securityratty.com/tag/situation representation">situation representation</category>
      <category domain="http://securityratty.com/tag/situation analysis process">situation analysis process</category>
      <category domain="http://securityratty.com/tag/address situation analysis">address situation analysis</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/strategic intelligence">strategic intelligence</category>
      <source url="http://www.thecepblog.com/2008/09/21/complex-event-processing-approach-for-strategic-intelligence/">Complex Event Processing Approach for Strategic Intelligence</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Keynotes: IBM]]></title>
      <link>http://securityratty.com/article/44ba0e9ad08b54462e9c92a6c54837a5</link>
      <guid>http://securityratty.com/article/44ba0e9ad08b54462e9c92a6c54837a5</guid>
      <description><![CDATA[Day one of Interop NY began with an introduction from Interop Manager Lenny Heymann, then Bob Picciano, General manager Lotus software and WebSpehere Portal IBM took the stage
IBMs presentation was...]]></description>
      <content:encoded><![CDATA[<p>Day one of Interop NY began with an introduction from Interop Manager Lenny Heymann, then Bob Picciano, General manager Lotus software and WebSpehere Portal IBM took the stage.</p>
<p>IBM&#8217;s presentation was cleverly titled <strong>2mor0@Wrk</strong> - Tomororow work and Web 2.0.</p>
<p><strong>Overview</strong></p>
<p>Web 2.0 is delivering a whole different paradigm of communication. The slide is Lotus Symphony - NOT PPT. Over 2 million downloads.</p>
<p>There is an information overload that impacts individual productivity in the workplace. It has a profound effect on organizational productivity. A more complex organization entity provides more pressure and more inefficiencies in workplace. Up to 70% of time can be used looking for the WRONG information.</p>
<p>Collaboration mitigates information overload. It allows you to identify experts and opinions.</p>
<p>The collaboration agenda. Enterprises are at the onset of exploring these features. Web 2.0 is giving us the capacity to do more. Collaboration optimizes business outcomes - global, secure and dynamic.The most progressive companies are looking at UNIFIED COMMUNICATIONS. Making sure that directories and profiles are fully mobile.</p>
<p>Collaboration should be a contextual part of the workflow, going directly into applications.</p>
<p>IBM&#8217;s collaboration strategy is to deliver these services through online or offline services.</p>
<p><strong>Demonstration</strong></p>
<p>Executive IT architect Ron Sebastian provided a demonstration of IBM&#8217;s collaboration strategy. IBM&#8217;s Web 2.0 solutions span delivery platforms:</p>
<ul>
<li>Platform - web as&nbsp; platform</li>
<li>Application - development</li>
<li>People - social computing</li>
</ul>
<p><a href="http://www-01.ibm.com/software/lotus/products/connections/" target="_blank">Lotus Connections</a> - a family of social computing software that provides profile lookup and community capabilities. Think of Facebook, Yahoo Groups, and delicious combined in one portal.</p>
<p>Ron demonstrated these social services embedded into a healthcare provider application. Semantic tagging is available, contact information and commenting. Not only are we providing service to customers, you can integrate sync capability to directly call the person you want.</p>
<p>The biggest aspect of Lotus Connection? It&#8217;s all integrated.</p>
<p>A new service - <a href="https://www.bluehouse.lotus.com/" target="_blank">Project Bluehouse</a>. This is a SaaS delivery of these collaborated capabilities. The store and share can manage and share documents within and outside the company. Access control is no longer an issue.</p>
<p>Collaborative Web 2.0 services available as standalone products that also work in a mobile environment.</p>
<p><strong>Case Study: Natural Disaster Management Mashup</strong></p>
<p>Boeing came up with twenty different scenarios that they could handle through their systems. The problem was the one they didn&#8217;t count on. One example was Katrina - how to deliver supplies to the area: what airports were open? Where could they land? The problem was they could not find one list of public, private and military airports, nor what was open. The mashup took different feeds to allow the deacon maker to make a more rapid and intelligent decision based on information on where they could fly in the appropriate supplies. From open information sites like <a href="http://www.airnav.com/" target="_blank">AirNav.com</a> and personal contacts, users were able to mashup the information to make better decisions.</p>
<p><strong>Conclusion</strong></p>
<p><a href="http://www.eweek.com/c/a/Messaging-and-Collaboration/IBM-to-Unveil-Social-Software-Center-at-Interop/" target="_blank">IBM announced the IBM Center for Social Software</a>, proving their commitment to connect, collaborate, and innovate. Users and academics can work together to how these innovations can be applied to businesses and provide value to the market.</p>
<p>There has been <a href="http://teblog.typepad.com/david_tebbutt/2008/04/ibms-bluehouse.html" target="_blank">some question</a> of whether or not IBM can pull this off and move into the collaborative Web 2.0 market. Despite <a href="http://www.theappgap.com/ibm-bluehouse-organizes-online-meetings-and-the-before-and-after.html" target="_blank">some criticism</a>, it looks like IBM has really taken a step forward in advancing their products and services to meet market needs.</p>
<p>People drive better business outcomes. Connecting, collaboration, and innovation is key. Having the right tools and information to do that eases pressure that many organizations feel and brings Web 2.0 technologies to the heart of businesses.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 09:39:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <category domain="http://securityratty.com/tag/information sites">information sites</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/collaboration">collaboration</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/ibms collaboration strategy">ibms collaboration strategy</category>
      <category domain="http://securityratty.com/tag/social services">social services</category>
      <category domain="http://securityratty.com/tag/collaborative web">collaborative web</category>
      <source url="http://blog.sciencelogic.com/interop-ny-keynotes-ibm/09/2008">Interop NY Keynotes: IBM</source>
    </item>
    <item>
      <title><![CDATA[Making role management work for the enterprise]]></title>
      <link>http://securityratty.com/article/6b1014726c937d347a9abdc00b8b0565</link>
      <guid>http://securityratty.com/article/6b1014726c937d347a9abdc00b8b0565</guid>
      <description><![CDATA[Many IT security professionals still regard role-based access and identity management as hopelessly complex because the predominantly manual approach used to review and manage roles is not scalable...]]></description>
      <content:encoded><![CDATA[Many IT security professionals still regard role-based access and identity management as hopelessly complex because the predominantly manual approach used to review and manage roles is not scalable and the dynamic nature of roles themselves often get out of sync with reality.]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/roles">roles</category>
      <category domain="http://securityratty.com/tag/predominantly manual approach">predominantly manual approach</category>
      <category domain="http://securityratty.com/tag/manage roles">manage roles</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/dynamic nature">dynamic nature</category>
      <category domain="http://securityratty.com/tag/hopelessly complex">hopelessly complex</category>
      <category domain="http://securityratty.com/tag/identity management">identity management</category>
      <category domain="http://securityratty.com/tag/regard">regard</category>
      <category domain="http://securityratty.com/tag/sync">sync</category>
      <source url="http://www.networkworld.com/news/tech/2008/091708-tech-update.html?fsrc=rss-security">Making role management work for the enterprise</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-10 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2d1af0f676495f958d061ee0c5c8bf43</link>
      <guid>http://securityratty.com/article/2d1af0f676495f958d061ee0c5c8bf43</guid>
      <description><![CDATA[Paul Melson's Blog: ArcSight User Conference 2008 * Logger 3.0 has adopted a more-ESM-like boolean filter interface. Big improvement over the chained-regex search in 2.5 and earlier. * Demo of Logger...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://pmelson.blogspot.com/2008/09/arcsight-user-conference-2008.html">Paul Melson's Blog: ArcSight User Conference 2008</a><br/>
* Logger 3.0 has adopted a more-ESM-like boolean filter interface. Big improvement over the chained-regex search in 2.5 and earlier.
    * Demo of Logger 3.0 shows that searches of data (no details on data set) are roughly 80x faster than a similar sized search on 2.5. (The claim is 100x faster, but I counted. Still, that&#039;s a significant improvement.)
    * Hugh has hinted that the slick, high-performance append-only storage stuff that Logger has is going to be integrated into ESM is some release beyond 4.5. That could mean the end of the Oracle / PartitionArchiver storage model.</li>
<li><a href="http://vmblog.com/archive/2008/09/09/splunk-tames-the-chaos-brought-on-by-virtualization.aspx">Splunk Tames the Chaos Brought on by Virtualization : VMblog.com - Virtualization Technology News and Information for Everyone</a><br/>
Existing system management tools were not designed to handle the dynamic nature of virtualization.  The Splunk for VMWare Management application includes a VMWare API for data input, over 25 pre-defined searches, alerts, and reports and dashboards specifically designed to monitor key metrics for the VMWare Virtual Infrastructure.</li>
<li><a href="http://eventlogs.blogspot.com/2008/08/why-your-hr-department-will-love.html">Dorian Software BLOG: Why Your HR Department Will Love Windows Vista, Even If Your IT Department Doesn't.</a><br/>
Event ID 4802 tracks whenever the screensaver is invoked after a group policy-determined idle time.

Event ID 4803 tracks whenever the screensaver is dismissed by the logged-on user.</li>
<li><a href="http://www.tditx.com/log-management.asp#hypervisor">Moderately Idiotic Competitor</a><br/>
But the clever inside criminal is taking all the payroll data from the system that is either off the network or is temporarily down. When the machine comes back up, there is no record of the intrusion and the traditional &quot;inside out&quot; log management system tells the user there is no problem.</li>
<li><a href="http://lastinfirstout.blogspot.com/2008/07/presumed-hostile-your-application-is.html">Last In - First Out: Presumed Hostile - Your Application is Out to Get You</a></li>
<li><a href="http://help.eclipse.org/help33/index.jsp?topic=/org.eclipse.tptp.monitoring.doc.user/samples/slog_analyzer.html">Help - Eclipse SDK - Working with the Log4J Logging sample</a></li>
<li><a href="http://www.datagovernance.com/cartoon_2.html">Cartoon 2 from The Data Governance Institute ROI</a></li>
<li><a href="http://gordonewasiuk.com/?p=967">Eccentric Engineer &raquo; Blog Archive &raquo; Conf Call Hem and Haw</a><br/>
It’s just a damned centralized-logging platform.  Unix sysadmins have been doing those for years.  This stuff is about as basic as tying your shoes.  All this fluff seems like overkill…but it’s IT…and we have policies.</li>
<li><a href="http://blog.isc2.org/isc2_blog/2008/08/security-metric.html">(ISC)2 Blog: Security metrics: more is not better</a></li>
<li><a href="http://www.roer.com/node/394">Are you Owned? | Roer.Com Information Security Blog</a><br/>
# list of all your profiles online, with your log in.
# list of all your IM/e-mail and other communication tools, with log in
# list of other sites/tools that requires you to log on.
# The lists above should also include each sites URL or contact information for changing passwords, or in worst case shutting them down.
# a friends-list who you trust, and who are willing to help you get back your own life online. The purpose is to have them help you rebuild your internet presence. Make sure you agree some way for them to be certain that they are communicating with you, and not someone else.</li>
<li><a href="http://www.csoonline.com/article/412163/Industry_View_Web_Application_Security_Today_Are_We_All_Insane_">Industry View: Web Application Security Today - Are We All Insane? - CSO Online - Security and Risk</a><br/>
The problem has gotten so bad that industry sources say most websites hosting malware have been hacked, Google says 1.3 percent of their search queries return malicious content, and Vint Cerf (father of the Internet) approximates that one quarter of all PCs are part of a botnet. Firewalls are not working. Antivirus/spyware is not working, nor are weekly patching, user education, SSL, or &quot;turning off the home computer&quot; as recommended by the FBI cyber-crime website. In what has become an inside joke, every authority says to use these &quot;best-practices&quot; despite their ineffectiveness.</li>
<li><a href="http://taosecurity.blogspot.com/2008/09/schneier-agrees-security-roi-is-mostly.html">TaoSecurity: Schneier Agrees: Security ROI is &quot;Mostly Bunk&quot;</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/389332419" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security blog">information security blog</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/web application security">web application security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/arcsight user conference">arcsight user conference</category>
      <category domain="http://securityratty.com/tag/security roi">security roi</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/389332419/anton18">Links for 2008-09-10 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Summarizing August's Threatscape]]></title>
      <link>http://securityratty.com/article/01c05fcd5f209b7515be2cee57a93c9b</link>
      <guid>http://securityratty.com/article/01c05fcd5f209b7515be2cee57a93c9b</guid>
      <description><![CDATA[Following the previous summaries of June's and July's threatscape based on all the research published during the month, it's time to summarize August's threatscape

August's threatscape was dominated...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SL_ZoXre4vI/AAAAAAAACJ0/LKtKpSt0igQ/s1600-h/ddanchev_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SL_ZoXre4vI/AAAAAAAACJ0/Phtgyl6rLXQ/s200-R/ddanchev_august.png" /></a>Following the previous summaries of <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's</a> and <a href="http://ddanchev.blogspot.com/2008/08/summarizing-julys-threatscape.html">July's threatscape</a> based on all the research published during the month, it's time to summarize August's threatscape.<br />
<br />
August's threatscape was dominated by a huge increase of rogue security software domains made possible due to the easily obtainable templates for the sites, several malware campaigns targeting popular social networking sites, Russian's organized cyberattack against Georgia with evidence on who's behind it pointing to "everyone" and a few botnets dedicated to the attack making the whole process easy to outsource and turn responsibility into an "open topic", several new web based botnet management kits and tools found in the wild, evidence that the 76service may in fact be going mainstream since the concept of cybercrime as a service is already emerging, and, of course, a peek at India's CAPTCHA solving economy, where the best comment I've received so far is that every site should embrace reCAPTCHA, so that while solving CAPTCHAs and participating in the abuse of these services in question, they would be also digitizing books. As usual, August was a pretty dynamic month for the middle of summer, with everyone excelling in their own malicious field.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/08/mcafees-site-advisor-blocking-nruns-ag.html">McAfee's Site Advisor Blocking n.runs AG - "for starters"</a><br />
False positives are rather common, especially when you're aiming to protect the end user from himself and not let him gain access to "hacking tools", but you're flagging security tools as badware and missing over half the SQL injected domains currently in the wild due to the fact that SiteAdvisor's community still haven't reviewed them - that's not good<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/08/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</a><br />
Twitter, just like every Web 2.0 application, isn't and shouldn't be treated as a unique platform for dissemination of malware, since it's dissemination of malware "as usual". This particular malware campaign was not just executed by a lone gunman, but also, was taking advantage of a flaw allowing the author to add new followers potentially exposing them to the malicious links serving banker malware. For the the time being, MySpace, Facebook and Twitter accounts are the very last thing a malicious attacker is interesting in puchasing accounting data for, but how come? It's all due to the oversupply of automatically registered accounts at other popular services, whose ecosystem of Internet properties empower cybercriminals with the ability to launch, host and distribute malware in between abusing the very same company's services for the blackhat SEO campaign and redirection services. Theoretically, a distributed network build upon the services provided by a single company is faily easy to accomplish due to the single login authentication applied everywhere. A singly bogus Gmail account results in a blackhat SEO hosting blogspot account, flash based redirector hosted at Picasa, and a couple of thousands of spam emails sent automatically sent through Gmail in order to abuse it's trusted email reputation<br />
&nbsp; <br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/08/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</a><br />
If aggressiveness matter, this campaign consisting of remotely injected redirection scripts at legitimate sites next to on purposely introduced malware oriented domains, was perhaps the most aggressive one during the month. Fake flash players, fake windows media players and fake youtube players are prone to increase as a social engineering tactic of choice due to the template-ization of malware serving sites for the sake of efficiency<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
With Zeus vulnerable to a remotely exploitable flaw allowing cybercriminals to hijack other cybercriminal's Zeus botnet, private exploits targeting the still rather popular at least in respect to usefulness Pinch malware are leaking, allowing everyone including security researchers to take a peek at a particular campaign running unpatched Pinch gateway<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/08/phishers-backdooring-phishing-pages-to.html">Phishers Backdooring Phishing Pages to Scam One Another</a><br />
Backdooring phishing pages is perhaps the most minimalistic approach a cybercriminal wanting to scam another cybercriminal is going to take. The far more beneficial approach that I've encountered on a couple of occassions so far, would be to backdoor a proprietary web malware exploitation kit, release it in the wild, let them put the time and efforts into launching the campaigns, then hijack their botnet. In fact, the possibilities for backdooring copycat web malware exploitation kits in order to take advantage of the momentum while introducing a non-existent kit has always been there at the disposal of malicious attackers. One thing's for sure - there's no such thing as a free web malware exploitation kit, just like there isn't such thing as a free phishing page<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/08/email-hacking-going-commercial-part-two.html">Email Hacking Going Commercial - Part Two</a><br />
In between the scammers promising the Moon and asking for anything between $20 to $250 to hack into an email account, there are "legitimate" services taking advantage of web email hacking kits consisting of each and every known XSS vulnerability for a particular service in an attempt to increase the chances of the attacker. And given that the majority of these have been patched a long time ago, social engineering comes into play. Do these services have a future? Definitely as more and more people are in fact looking for and requesting such services, in fact, they're willing to pay a bonus considering how exotic it is for them to have any email that they provide hacked into and the accounting data sent back to them<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/08/russia-vs-georgia-cyber-attack.html">The Russia vs Georgia Cyber Attack</a><br />
Event of the month? Could be, but just like every "event of the moth" everyone seems to be once again restating their "selective retention" preferences. What is selective retention anyway? Selective retention is basically a situation where once Russian is attacking another country's infrastructure, you would automatically conclude that it's Russian FSB behind the attacks and consciously and subconsciously ignore all the research and articles telling you otherwise, namely that the FSB wouldn't even bother acknowledging Georgia's online presence, at least not directly. Moreover, talking about the FSB as the agency behind the cyberattacks indicates "selective retention", talking about FAPSI indicates better understanding of the subject.<br />
<br />
In times when cybercrime is getting ever easier to outsource, anyone following the news could basically orchestrate a large scale DDoS attack against a particular country in order to forward the responsibility to any country that they want to. In Russia vs Georgia, you have a combination of a collectivist society that's possessing the capabilities to launch DDoS attacks, knows where and how to order them, and that in times when your country is engaged in a war conflict drinking beer instead of DDoS-sing the major government sites of the adversary is not an option.<br />
<br />
Selective retention when combined with a typical mainstream media's mentality to "slice the threat on pieces" instead of turning the page as soon as possible, is perhaps the worst possible combination. Furthermore, coming up with <a href="http://intelfusion.net/wordpress/?p=398">Social Network analysis of the cyberattacks</a> would produce nothing more but a few fancy graphs of over enthusiastic Russian netizen's distributing the static list of the targets. The real conversations, as always, are <a href="http://blogs.nyu.edu/blogs/agc282/zia/2008/08/intelfusions_sna_of_russian_cy.html">happening in the "Dark Web" limiting the possibilities for open source intelligence</a> using a data mining software. Things changed, OPSEC is slowly emerging as a concept among malicious parties, whenever some of the "calls for action" in the DDoS attacks were posted at mainstream forums, they were immediately removed so that they don't show up in such academic initiatives<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</a><br />
The reappearance of the 76Service allowing everyone to log into a web based interface and collect all the accounting and financial data coming from malware infected hosts across the globe for the period of time for which they've bought access, indicates that what used to be proprietary services which were supposedly no longer available, are now being operated in a do-it-yourself fashion. Goods and products mature into services, so from a cost-benefit analysis perspective, outsourcing is naturally most beneficial even when it comes to cybercrime <br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</a><br />
If it's the botnets used in the attacks, they are known, if it's about who's providing the hosting for the command and control, it's the "usual suspects", but just like previous discussion of the Russian Business Network, it remains questionable on whether or not they work on a revenue-sharing basis, are simply providing the anti-abuse hosting, or are the shady conspirators that every newly born RBN expert is positioning them to be.<br />
<br />
Cheap conversation regarding the RBN ultimately serves the RBN, and just for the record, there's a RBN alternative in every country, but the only thing that remains the same are the customers, tracking the customers means exposing the RBN and the international franchises of their services, making it harder to identify their international operations. And given that the "tip of the iceberg", namely RBN's U.S operations remain in tact, talking about taking actions against their international operations in countries where cybercrime law is still pending, is yet another quality research into the topic building up the pile of research into the very same segments of the very same ISPs.<br />
<br />
Just for the record - these "very same ISPs" are regular readers of my blog, and if you analyze their activities, they're definitely reading yours too, ironically, surfing through gateways residing within their netblock that are so heavily blacklisted due to the guestbook and forum spamming activities that their bad reputation usually ends up in another massive blackhat SEO campaign exposed.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/08/guerilla-marketing-for-conspiracy-site.html">Guerilla Marketing for a Conspiracy Site</a><br />
Conspiracy theorists may in fact have a new wallpaper to show off with<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/08/banker-malware-targetting-brazilian.html">Banker Malware Targeting Brazilian Banks in the Wild</a><br />
When misinformed and not knowing anything about a particular underground segment, a potential cybercriminal would stick to using such primitive compared to the sophisticated banker malware kits currently in the wild. These sophisticated banker malware kits are often coming in a customer-tailored proposition, with their price increasing or decreasing based on the specific module to be included or excluded. For instance, a module targeting all the U.S banks that has been put in a "learning mode" long before it was made available to the customers can be requested and is often available with the business model build around the customer's wants&nbsp; <br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/08/compromised-cpanel-accounts-for-sale.html">Compromised Cpanel Accounts For Sale</a><br />
Despite the massive SQL injection attacks, accounting data for Cpanel accounts coming from malware infected hosts seems to be once again coming into play, which isn't surprising given the filtering capabilities and log parsing tools today's botnet masters are empowered with. These very same compromised Cpanel accounts and the associated domains often end up so heavility abused that it's tactics like these that are driving the underground multitasking mentality, namely, abusing a single compromised account for each and every malicious online activity you can think of - even hosting banners for their blackhat SEO services <br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</a><br />
In August we saw a peek of fake security software, neatly typosquatted domains whose authors earn revenue each and every time someone installs the software. The vendors behind this software are forwarding the entire process of driving traffic to those excelling in aggregating traffic and abusing it. As anticipated, underground multitasking started taking place within the fake security software domains, with the people behind them introducing client-side exploits in order to improve the monetization of the traffic coming to the sites<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
There's no such thing as a (quality) free botnet kit. What's for free is often the leftovers from a single feature of a more sophisticated proprietary botnet kit. This one in particular is however trying to demonstrate that even a plain simple GUI botnet command and control software can achieve the results desired by an average script kiddie, and not necessarily satisfy the needs of the experienced botnet master<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A Diverse Portfolio of Fake Security Software - Part Three</a><br />
As far as trends and fads are concerned, the majority of the domains are currently parked at up to four different IPs, with most of them going into a stand by mode once they get detected and reappear back couple of weeks later<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/08/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware - Part Two</a><br />
Due to the template-ization of fake celebrity video sites, and simple traffic management tools combined with blackhat SEO tactics, these sites are also prone to increase in the next couple of months<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
It's releases like these that remind us of the amount of time, efforts and personal touch that a malicious attacker would put into such a management kit, currently acting as a personal benchmark as far as complexity and features indicating the coder's experience with botnets is concerned. What's he's failing to anticipate is that this kit is sooner or later going to turn into the "MPack of botnet management"<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A Diverse Portfolio of Fake Security Software - Part Four</a><br />
Keep it coming, we'll keep it exposing until we end up getting down to the "fake software vendor" itself<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/08/automatic-email-harvesting-20.html">Automatic Email Harvesting 2.0</a><br />
Email harvesting is slowly maturing into a vertically integrated service provided by vendors of managed spamming services. This email harvesting module is aiming to close the page on text obfuscation in respect to fighting spam, and is successfully recognizing and collecting such publicly available emails. From a psychological perspective though, the end users who bothered to obfuscate their emails are less likely to fall victims into phishing scams, with the obfuscation speaking for a relatively decent situational awareness on how they emails end up in a spammer's campaign<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</a><br />
As a firm believer in sampling in order to draw conclusions on the big picture, an approach that has proven highly accurate in modeling historical and upcoming tactics and behavior, a single fake porn site serving malware campaign usually exposes a dozen of misconfigured redirectors, which thanks to their misconfiguration despite the evasive features available within the kits, expose another dozen of malware campaigns<br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/08/facebook-malware-campaigns-rotating.html">Facebook Malware Campaigns Rotating Tactics</a><br />
With no particular flaw exploited other than the social engineering tactic of using already compromised Facebook accounts who would automatically spam all their friends with links to flash files hosted at legitimate services, the more persistent the campaign is, the higher the chance that it will scale enough. This campaign in particular is mainly relying on rotation of tactics, namely different messages, different services and file extensions used in order to trick someone's friend into visiting the URL. With the number of users increasing, the most popular social networking sites are naturally going to be permanently under attacks from cybercriminals<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</a><br />
Despite that it's a single brand, namely the International Virus Research Lab that's introducing client-side exploits within it's portfolio of domains, the opportunity for abuse may be noticed by the rest of the brands pretty fast<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/08/exposing-indias-captcha-solving-economy.html">Exposing India’s CAPTCHA Solving Economy</a><br />
Taking into consideration the mentality surrounding a particular country's cybercriminals, how they think, how they operate, what do they define as an opportunity, and how much personal efforts are they willing to put into their campaigns, I wouldn't be surpised if a Russian vendor offering 100,000 bogus Gmail accounts for sale has in fact outsourcing the account registration process to Indian workers, paid them pocket change and is then reselling them ten to twenty times higher than the price he originally paid for them. <br />
<br />
The text based CAPTCHAs used at the major Internet portals and services, are so efficiently abused by this approach that continuing to use is directly undermining the trust these email providers and services often come with as granted<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VdcSL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VdcSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2dvxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2dvxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hYvml"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hYvml" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YfcJl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YfcJl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WUVJL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WUVJL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jRCTL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jRCTL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KYkll"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KYkll" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/388609194" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 02:57:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/facebook malware campaigns">facebook malware campaigns</category>
      <category domain="http://securityratty.com/tag/usefulness pinch malware">usefulness pinch malware</category>
      <category domain="http://securityratty.com/tag/banker malware kits">banker malware kits</category>
      <category domain="http://securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/diy botnet kit">diy botnet kit</category>
      <category domain="http://securityratty.com/tag/distribute malware">distribute malware</category>
      <category domain="http://securityratty.com/tag/banker malware">banker malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/388609194/summarizing-augusts-threatscape.html">Summarizing August's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[A tip on using ASP.NET validation controls]]></title>
      <link>http://securityratty.com/article/20fc43ecdf7ca60d64f9285d0e374a62</link>
      <guid>http://securityratty.com/article/20fc43ecdf7ca60d64f9285d0e374a62</guid>
      <description><![CDATA[Executive summary
ValidationSummary controls look at the ErrorMessage field to figure out what to display, so always use ErrorMessage in a verbose enough way that it will be helpful from a...]]></description>
      <content:encoded><![CDATA[<p>Executive summary:</p> <ul> <li>ValidationSummary controls look at the ErrorMessage field to figure out what to display, so always use ErrorMessage in a verbose enough way that it will be helpful from a ValidationSummary control.</li> <li>If you need a shorter message to display inline (i.e., where the validation control is on the form, as opposed to the ValidationSummary) use the body of the control to define it.</li></ul> <p>In the past, I&#39;ve used RequiredFieldValidator controls on my web forms to remind users that certain fields are required. I would set the ErrorMessage to something vanilla like, &quot;This field is required&quot;, or even something simpler like &quot;*&quot; (an asterisk) if I didn&#39;t have much room on the form to display more prose for an error.</p> <p>A friend was recently testing a new feature that I&#39;d built for our sales team and she had a hard time seeing the little red asterisks that were showing up next to required fields. It felt to her as though she was pushing the submit button on the form but nothing was happening. It was clear that a ValidationSummary control would be helpful, especially if placed close to the submit button for the form.</p> <p>I&#39;ve been a bit lazy in the past about using ValidationSummary controls, partially because most of my forms are simple enough that they feel a bit redundant. But on a more complicated form, they can be very helpful to guide users back to the places on the form where there&#39;s problems.</p> <p>So I threw one of those puppies on the form and immediately saw that there was a problem - my error message was set to &quot;*&quot;, which meant that my validation summary was pretty useless - it just displayed a bunch of red asterisks! And in places where I&#39;d used the prose, &quot;This field is required&quot;, well that was pretty useless as an error message in the summary.</p> <p>After a bit of research and experimentation, I discovered that the ValidationSummary control looks at the ErrorMessage property on each validation control in order to figure out what to display in the summary. So it&#39;s important to use ErrorMessage with a summary in mind! Don&#39;t use text like &quot;*&quot; or &quot;This field is required&quot;. Be more specific so the user can find her way up to the problem field, as in, &quot;PostalCode is required&quot;.</p> <p>But if you make ErrorMessage verbose so that it&#39;s helpful in a summary, it may make your form really ugly when displayed inline next to the control being validated. The trick is to use the body of the validation control element to specify the inline error message. Then you end up with two messages: a verbose one that&#39;s used in your summary, and a more localized, brief message that shows up right next to the control being validated. Note the asterisk that&#39;s in the body of the RequiredFieldValidator below:</p><pre class="csharpcode"><span class="kwrd">&lt;</span><span class="html">asp:RequiredFieldValidator</span>
      <span class="attr">ErrorMessage</span><span class="kwrd">=&quot;Zip/postal code is required&quot;</span>
      <span class="attr">ControlToValidate</span><span class="kwrd">=&#39;txtPostalCode&#39;</span>
      <span class="attr">ValidationGroup</span><span class="kwrd">=&#39;BasicInfo&#39;</span>
      <span class="attr">Display</span><span class="kwrd">=&quot;Dynamic&quot;</span>
      <span class="attr">runat</span><span class="kwrd">=&#39;server&#39;</span><span class="kwrd">&gt;</span>*<span class="kwrd">&lt;/</span><span class="html">asp:RequiredFieldValidator</span><span class="kwrd">&gt;</span></pre>
<p>I&#39;ve learned a lesson from all of this. In the future when I use validation controls I&#39;ll always provide a summary-friendly message in the ErrorMessage field, and if I need something different (typically shorter) to display inline, I&#39;ll put it in the body of the validation control element.</p>
<p>Hope this helps!</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=52816" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 13:16:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shorter message">shorter message</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/inline error message">inline error message</category>
      <category domain="http://securityratty.com/tag/validation control element">validation control element</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/inline">inline</category>
      <category domain="http://securityratty.com/tag/display inline">display inline</category>
      <category domain="http://securityratty.com/tag/errormessage">errormessage</category>
      <category domain="http://securityratty.com/tag/errormessage property">errormessage property</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/09/03/a-tip-on-using-asp-net-validation-controls.aspx">A tip on using ASP.NET validation controls</source>
    </item>
    <item>
      <title><![CDATA[HP Hires 140,000 to Get Rid of Your Job]]></title>
      <link>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</link>
      <guid>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</guid>
      <description><![CDATA[HP completed its $13.25 billion acquisition of EDS today
Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined...]]></description>
      <content:encoded><![CDATA[<p>HP completed its $13.25 billion acquisition of EDS today. </p>
<p>Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined outsourcing unit, expects to leverage HP automation tools to cut costs and improve that margin.</p>
<p>But Rod Bourgeois, an analyst at Sanford Bernstein says, &#8220;It&#8217;s not like HP has automation tools that weren&#8217;t at <a href="http://online.wsj.com/article/SB121971997812971951.html?mod=hps_us_whats_news">EDS&#8217;s disposal before</a>.&#8221;</p>
<p>But this brings up a good point. EDS and 140,000 new bodies notwithstanding, HP seems to be positioning itself to do a big <a href="http://blogs.wsj.com/biztech/2008/08/26/the-key-to-h-p-eds-automation/?mod=djemTECH">automation push in the marketplace</a>. </p>
<p><a href="http://www.infoworld.com/article/08/05/13/What-does-the-HP-EDS-deal-really-mean_1.html?source=fssr">Of course this makes sense</a> &#8211; we&#8217;ve talked before about what a critical role automation is going to have in managing the rapidly evolving &#8220;dynamic&#8221; data center. Technologies like virtualization and cloud computing needs are pushing out the limits of real-time resources management in the data center; management tools must perform faster, integrate with more solutions across the spectrum of IT infrastructure and be smart enough to do much of this on their own.</p>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:47:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eds">eds</category>
      <category domain="http://securityratty.com/tag/hp-eds">hp-eds</category>
      <category domain="http://securityratty.com/tag/eds ceo">eds ceo</category>
      <category domain="http://securityratty.com/tag/eds profit margin">eds profit margin</category>
      <category domain="http://securityratty.com/tag/margin">margin</category>
      <category domain="http://securityratty.com/tag/dynamic data center">dynamic data center</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/automation tools">automation tools</category>
      <category domain="http://securityratty.com/tag/real-time resources management">real-time resources management</category>
      <source url="http://blog.sciencelogic.com/hp-hires-140000-to-get-rid-of-your-job/08/2008">HP Hires 140,000 to Get Rid of Your Job</source>
    </item>
    <item>
      <title><![CDATA[The case for Java modularity]]></title>
      <link>http://securityratty.com/article/da1e0e743886572b9745e0aa127ce781</link>
      <guid>http://securityratty.com/article/da1e0e743886572b9745e0aa127ce781</guid>
      <description><![CDATA[It never rains but it pours! Get some background on the long and winding road to Java modularity, then compare the two specification requests vying for inclusion in Java 7: JSR 291: Dynamic Component...]]></description>
      <content:encoded><![CDATA[It never rains but it pours! Get some background on the long and winding road to Java modularity, then compare the two specification requests vying for inclusion in Java 7:  JSR 291: Dynamic Component Support for Java SE and JSR 277: (Sun's) Java Module System.]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/java">java</category>
      <category domain="http://securityratty.com/tag/java modularity">java modularity</category>
      <category domain="http://securityratty.com/tag/java module system">java module system</category>
      <category domain="http://securityratty.com/tag/dynamic component support">dynamic component support</category>
      <category domain="http://securityratty.com/tag/jsr">jsr</category>
      <category domain="http://securityratty.com/tag/specification requests">specification requests</category>
      <category domain="http://securityratty.com/tag/compare">compare</category>
      <category domain="http://securityratty.com/tag/pours">pours</category>
      <category domain="http://securityratty.com/tag/background">background</category>
      <source url="http://www.networkworld.com/news/2008/jw-08-java-modularity.html?fsrc=rss-security">The case for Java modularity</source>
    </item>
  </channel>
</rss>
