<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: effective]]></title>
    <link>http://securityratty.com/tag/effective</link>
    <description></description>
    <pubDate>Wed, 06 Aug 2008 20:30:41 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[8 quick ways to get your site blacklisted]]></title>
      <link>http://securityratty.com/article/4dfcd3d1fb0f6681ce9068057083b01a</link>
      <guid>http://securityratty.com/article/4dfcd3d1fb0f6681ce9068057083b01a</guid>
      <description><![CDATA[Effective online communication relies on your ability to reach customers. If your e-mail or newsletters are listed on a spam blacklist, the messages won't get through. Here are several common mistakes...]]></description>
      <content:encoded><![CDATA[Effective online communication relies on your ability to reach customers. If your e-mail or newsletters are listed on a spam blacklist, the messages won't get through. Here are several common mistakes that put business communication at risk.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=hAJY68"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=hAJY68" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/365660180" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam blacklist">spam blacklist</category>
      <category domain="http://securityratty.com/tag/common mistakes">common mistakes</category>
      <category domain="http://securityratty.com/tag/reach customers">reach customers</category>
      <category domain="http://securityratty.com/tag/business communication">business communication</category>
      <category domain="http://securityratty.com/tag/messages">messages</category>
      <category domain="http://securityratty.com/tag/newsletters">newsletters</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <category domain="http://securityratty.com/tag/ability">ability</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/365660180/article.do">8 quick ways to get your site blacklisted</source>
    </item>
    <item>
      <title><![CDATA[The Risk of Anthrax]]></title>
      <link>http://securityratty.com/article/96c08b49a95008d4904855cb113bf42e</link>
      <guid>http://securityratty.com/article/96c08b49a95008d4904855cb113bf42e</guid>
      <description><![CDATA[Some reality to counter the hype. The Bottom Line
While there has been much consternation and alarm-raising over the potential for widespread proliferation of biological weapons and the possible use...]]></description>
      <content:encoded><![CDATA[<p>Some <a href="http://www.stratfor.com/weekly/busting_anthrax_myth">reality</a> to counter the hype.</p>

<blockquote><strong>The Bottom Line</strong>

<p>While there has been much consternation and alarm-raising over the potential for widespread proliferation of biological weapons and the possible use of such weapons on a massive scale, there are significant constraints on such designs. The current dearth of substantial biological weapons programs and arsenals by governments worldwide, and the even smaller number of cases in which systems were actually used, seems to belie -- or at least bring into question -- the intense concern about such programs.</p>

<p>While we would like to believe that countries such as the United States, the United Kingdom and Russia have halted their biological warfare programs for some noble ideological or humanitarian reason, we simply can’t. If biological weapons were in practice as effective as some would lead us to believe, these states would surely maintain stockpiles of them, just as they have maintained their nuclear weapons programs. Biological weapons programs were abandoned because they proved to be not as effective as advertised and because conventional munitions proved to provide more bang for the buck. </blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=cDpkeK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=cDpkeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nHCblK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nHCblK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 10:29:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/weapons">weapons</category>
      <category domain="http://securityratty.com/tag/biological weapons programs">biological weapons programs</category>
      <category domain="http://securityratty.com/tag/programs">programs</category>
      <category domain="http://securityratty.com/tag/nuclear weapons programs">nuclear weapons programs</category>
      <category domain="http://securityratty.com/tag/biological weapons">biological weapons</category>
      <category domain="http://securityratty.com/tag/biological warfare programs">biological warfare programs</category>
      <category domain="http://securityratty.com/tag/surely maintain stockpiles">surely maintain stockpiles</category>
      <category domain="http://securityratty.com/tag/noble ideological">noble ideological</category>
      <category domain="http://securityratty.com/tag/humanitarian reason">humanitarian reason</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/the_risk_of_ant.html">The Risk of Anthrax</source>
    </item>
    <item>
      <title><![CDATA[BlackHat Recap]]></title>
      <link>http://securityratty.com/article/bec2ea65daab94e0e7001ef1ba7b1b9a</link>
      <guid>http://securityratty.com/article/bec2ea65daab94e0e7001ef1ba7b1b9a</guid>
      <description><![CDATA[Another BlackHat has come and gone. As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations. I had...]]></description>
      <content:encoded><![CDATA[<p>Another BlackHat has come and gone.  As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations.  I had a fantastic time catching up with old friends and finally getting the opportunity to meet more of the <a href="http://n0where.org/security-twits/">Security Twits</a> and others in the security community.  I didn&#8217;t submit a talk this year, but nevertheless, fake Dan Kaminsky was still excited to see me.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b.jpg"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b-300x225.jpg" alt="" title="chris_2742966251_1b47297b33_b" width="300" height="225" class="aligncenter size-medium wp-image-215 photoborder" /></center></a></p>
<p>My favorite talk, as expected, was the Sotirov/Dowd talk on <a href="http://taossa.com/archive/bh08sotirovdowd.pdf">How To Impress Girls With Browser Memory Protection Bypasses</a>.  The attack is a conceptually simple, yet completely reliable technique for exploiting vulnerabilities in web browsers.  Of course, the media has <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html">sensationalized </a> the impact of their findings, but ultimately, this is still significant as far as browser-based exploits are concerned.  It&#8217;s worth mentioning that part of the technique allowing them to load a .NET DLL at an arbitrary location under Vista was reliant on an implementation bug wherein the OS disables ASLR if the version in the .NET COR header was below a certain value.  However, the address space spraying and stack spraying techniques are likely to be extended to other platforms utilizing similar memory protection mechanisms.  </p>
<p>As for the girls?  I can report first-hand that the ladies at TAO on Wednesday night were hanging on <a href="http://twitter.com/alexsotirov">Alex</a>&#8217;s every word.  They were particularly impressed when he whipped out the laptop for a live demo.  Unfortunately, none of the dozen iPhone owners in the immediate vicinity thought to snap a picture (too busy Twittering).  Oh well.  </p>
<p>I also enjoyed Hovav Shacham&#8217;s talk on return-oriented programming.  Simply put, he described a generalization of the return-to-libc shellcode approach with the intent to demonstrate that one could achieve Turing-complete computation using &#8220;found code&#8221; in process images.  By chaining together series of mini-computations ending in return (RET) instructions, it was possible to build higher-level programming constructs such as branches and loops.  The nature of the x86 instruction set provides some flexibility because instructions are interpreted differently depending on how you align the instruction pointer (i.e. the old shellcode trick of searching the process image for any JMP EBX instruction and using that as your EIP).  In RISC architectures such as SPARC, however, you don&#8217;t have that luxury; if your %pc isn&#8217;t aligned properly you get a bus error.  So it was quite interesting to see that they were able to extend the concept to RISC.  The practicality of the attack technique is limited by the fact that the shellcode is tuned to a particular binary image &#8212; if the shellcode was built using instructions extrapolated from glibc 2.3.5, it won&#8217;t work for a system running glibc 2.4.  </p>
<p>I thought Scott Stender&#8217;s talk on <a href="http://isecpartners.com/files/iSEC%20Partners%20-%20Concurrency%20Attacks%20in%20Web%20Applications.pdf">Concurrency Attacks in Web Applications</a> was interesting as well.  In a nutshell, spewing thousands of simultaneous requests at web application transactions that are not thread-safe can create interesting problems.  In the presentation, Scott ran his demo against a VM running on the attack machine.  I found myself wondering how effective the same attack would be over the Internet &#8212; would it be significantly less reliable (or not at all)?  Race conditions are generally easier to exploit locally than remotely due to more predictable execution conditions.  Certainly this is an under-tested vulnerability class though.</p>
<p>One presentation I wasn&#8217;t able to attend but want to follow up on is <a href="http://twitter.com/nate_mcfeters">Nate McFeters</a>, John Heasman, and Rob Carter&#8217;s talk which discussed the GIFAR attack I&#8217;ve been hearing so much about lately.  The gist is that you can create a file that is both a valid GIF and a valid JAR, then use some Java applet tricks to initiate HTTP requests on behalf of the victim.  </p>
<p>Finally, the <a href="http://pwnie-awards.org/2008/">Pwnie Awards</a> didn&#8217;t fail to disappoint.  Drama ensued over the Most Overhyped award, but at least this year some of the winners showed up to claim their awards!  <a href="http://twitter.com/halvarflake">Halvar</a> rapping Symantec lyrics was also quite memorable.</p>
<p>All in all, a fun and informative week, but as usual, I was relieved to get the hell out of Vegas and head home on Friday morning. </p>
<p>P.S. For a much more entertaining BlackHat/Defcon Recap, read <a href="http://securityuncorked.net/2008/08/anecdotes-blackhat-defcon/">Jennifer Jabbusch&#8217;s account</a> of the week&#8217;s events.  It&#8217;s my favorite one so far!</p>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 18:43:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/favorite">favorite</category>
      <category domain="http://securityratty.com/tag/favorite talk">favorite talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/sotirovdowd talk">sotirovdowd talk</category>
      <category domain="http://securityratty.com/tag/scott stenders talk">scott stenders talk</category>
      <category domain="http://securityratty.com/tag/completely reliable technique">completely reliable technique</category>
      <category domain="http://securityratty.com/tag/reliable">reliable</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/technique">technique</category>
      <source url="http://www.veracode.com/blog/?p=202">BlackHat Recap</source>
    </item>
    <item>
      <title><![CDATA[BlackHat Recap]]></title>
      <link>http://securityratty.com/article/6b779e65a6ad790dd8e631057208ff77</link>
      <guid>http://securityratty.com/article/6b779e65a6ad790dd8e631057208ff77</guid>
      <description><![CDATA[Another BlackHat has come and gone. As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations. I had...]]></description>
      <content:encoded><![CDATA[<p>Another BlackHat has come and gone.  As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations.  I had a fantastic time catching up with old friends and finally getting the opportunity to meet more of the <a href="http://n0where.org/security-twits/">Security Twits</a> and others in the security community.  I didn&#8217;t submit a talk this year, but nevertheless, <a href="http://flickr.com/photos/fakedankaminsky/">fake Dan Kaminsky</a> was still excited to see me.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b.jpg"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b-300x225.jpg" alt="" title="chris_2742966251_1b47297b33_b" width="300" height="225" class="aligncenter size-medium wp-image-215 photoborder" /></center></a></p>
<p>My favorite talk, as expected, was the Sotirov/Dowd talk on <a href="http://taossa.com/archive/bh08sotirovdowd.pdf">How To Impress Girls With Browser Memory Protection Bypasses</a>.  The attack is a conceptually simple, yet completely reliable technique for exploiting vulnerabilities in web browsers.  Of course, the media has <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html">sensationalized</a> the impact of their findings, but ultimately, this is still significant as far as browser-based exploits are concerned (here is a <a href="http://blogs.zdnet.com/Bott/?p=513">more accurate report</a>).  It&#8217;s worth mentioning that part of the technique allowing them to load a .NET DLL at an arbitrary location under Vista was reliant on an implementation bug wherein the OS disables ASLR if the version in the .NET COR header was below a certain value.  However, the address space spraying and stack spraying techniques are likely to be extended to other platforms utilizing similar memory protection mechanisms.  </p>
<p>As for the girls?  I can report first-hand that the ladies at TAO on Wednesday night were hanging on <a href="http://twitter.com/alexsotirov">Alex</a>&#8217;s every word.  They were particularly impressed when he whipped out the laptop for a live demo.  Unfortunately, none of the dozen iPhone owners in the immediate vicinity thought to snap a picture (too busy Twittering).  Oh well.  </p>
<p>I also enjoyed Hovav Shacham&#8217;s talk on return-oriented programming.  Simply put, he described a generalization of the return-to-libc shellcode approach with the intent to demonstrate that one could achieve Turing-complete computation using &#8220;found code&#8221; in process images.  By chaining together series of mini-computations ending in return (RET) instructions, it was possible to build higher-level programming constructs such as branches and loops.  The nature of the x86 instruction set provides some flexibility because instructions are interpreted differently depending on how you align the instruction pointer (i.e. the old shellcode trick of searching the process image for any JMP EBX instruction and using that as your EIP).  In RISC architectures such as SPARC, however, you don&#8217;t have that luxury; if your %pc isn&#8217;t aligned properly you get a bus error.  So it was quite interesting to see that they were able to extend the concept to RISC.  The practicality of the attack technique is limited by the fact that the shellcode is tuned to a particular binary image &#8212; if the shellcode was built using instructions extrapolated from glibc 2.3.5, it won&#8217;t work for a system running glibc 2.4.  </p>
<p>I thought Scott Stender&#8217;s talk on <a href="http://isecpartners.com/files/iSEC%20Partners%20-%20Concurrency%20Attacks%20in%20Web%20Applications.pdf">Concurrency Attacks in Web Applications</a> was interesting as well.  In a nutshell, spewing thousands of simultaneous requests at web application transactions that are not thread-safe can create interesting problems.  In the presentation, Scott ran his demo against a VM running on the attack machine.  I found myself wondering how effective the same attack would be over the Internet &#8212; would it be significantly less reliable (or not at all)?  Race conditions are generally easier to exploit locally than remotely due to more predictable execution conditions.  Certainly this is an under-tested vulnerability class though.</p>
<p>One presentation I wasn&#8217;t able to attend but want to follow up on is <a href="http://twitter.com/nate_mcfeters">Nate McFeters</a>, John Heasman, and Rob Carter&#8217;s talk which discussed the GIFAR attack I&#8217;ve been hearing so much about lately.  The gist is that you can create a file that is both a valid GIF and a valid JAR, then use some Java applet tricks to initiate HTTP requests on behalf of the victim.  </p>
<p>Finally, the <a href="http://pwnie-awards.org/2008/">Pwnie Awards</a> didn&#8217;t fail to disappoint.  Drama ensued over the Most Overhyped award, but at least this year some of the winners showed up to claim their awards!  <a href="http://twitter.com/halvarflake">Halvar</a> rapping Symantec lyrics was also quite memorable.</p>
<p>All in all, a fun and informative week, but as usual, I was relieved to get the hell out of Vegas and head home on Friday morning. </p>
<p>P.S. For a much more entertaining BlackHat/Defcon Recap, read <a href="http://securityuncorked.net/2008/08/anecdotes-blackhat-defcon/">Jennifer Jabbusch&#8217;s account</a> of the week&#8217;s events.  It&#8217;s my favorite one so far!</p>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 18:43:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/favorite">favorite</category>
      <category domain="http://securityratty.com/tag/favorite talk">favorite talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/sotirovdowd talk">sotirovdowd talk</category>
      <category domain="http://securityratty.com/tag/scott stenders talk">scott stenders talk</category>
      <category domain="http://securityratty.com/tag/completely reliable technique">completely reliable technique</category>
      <category domain="http://securityratty.com/tag/reliable">reliable</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/technique">technique</category>
      <source url="http://www.veracode.com/blog/2008/08/blackhat-recap/">BlackHat Recap</source>
    </item>
    <item>
      <title><![CDATA[Deploying effective service delivery platforms for next-gen networks]]></title>
      <link>http://securityratty.com/article/56a0000f691122152d14780cd1024816</link>
      <guid>http://securityratty.com/article/56a0000f691122152d14780cd1024816</guid>
      <description><![CDATA[Next-generation networks can make legacy networks look simple because all services, applications, billing and operations systems, as well as customer data for fixed and mobile devices must work...]]></description>
      <content:encoded><![CDATA[Next-generation networks can make legacy networks look simple because all services, applications, billing and operations systems, as well as customer data for fixed and mobile devices must work seamlessly on one network.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/363096932" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 09:04:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/operations systems">operations systems</category>
      <category domain="http://securityratty.com/tag/customer data">customer data</category>
      <category domain="http://securityratty.com/tag/next-generation networks">next-generation networks</category>
      <category domain="http://securityratty.com/tag/mobile devices">mobile devices</category>
      <category domain="http://securityratty.com/tag/legacy networks">legacy networks</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/seamlessly">seamlessly</category>
      <category domain="http://securityratty.com/tag/fixed">fixed</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/363096932/0,289483,sid103_gci1325006,00.html">Deploying effective service delivery platforms for next-gen networks</source>
    </item>
    <item>
      <title><![CDATA[CNN Custom Alerts Spam]]></title>
      <link>http://securityratty.com/article/f544d5e769f123f7cc5f3036bac72fdd</link>
      <guid>http://securityratty.com/article/f544d5e769f123f7cc5f3036bac72fdd</guid>
      <description><![CDATA[In general, my anti-spam filters and tools are pretty effective. So when I start to see something like this







it's obvious that a huge spam wave is underway. These are, of course, related to the...]]></description>
      <content:encoded><![CDATA[
        In general, my anti-spam filters and tools are pretty effective. So when I start to see something like this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="cn1.jpg" src="http://blog.spywareguide.com/images/cn1.jpg" class="mt-image-none" style="" height="137" width="193" /></span></div><br /> <div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="cn2.jpg" src="http://blog.spywareguide.com/images/cn2.jpg" class="mt-image-none" style="" height="247" width="214" /></span></div>
<br />....it's obvious that a huge spam wave is underway. These are, of course, related to the <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">fake CNN Spam</a> from a few days ago. Here, the emails take the form of "custom alerts":<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/cn32.html" onclick="window.open('http://blog.spywareguide.com/images/cn32.html','popup','width=613,height=352,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/cn3-thumb-313x179.jpg" alt="cn3.jpg" class="mt-image-none" style="" height="179" width="313" /></a></span><br /><br />Click to Enlarge<br /></div><br />I've seen two types of this mail - one links to a genuine CNN article from the headline text (with the smaller link underneath leading to an infection site), the other simply links to the infection site from both clickable links. As before, deleting these Emails is the best course of action. Interestingly, the format of these mails might not be working to the spammers advantage. Lots of people I've talked to who had one of these mails sent through simply deleted them without a second thought, thinking it was merely something on the real CNN they thought they'd signed up to and didn't actually want.<br /><br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Sun, 10 Aug 2008 13:28:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/links">links</category>
      <category domain="http://securityratty.com/tag/clickable links">clickable links</category>
      <category domain="http://securityratty.com/tag/simply links">simply links</category>
      <category domain="http://securityratty.com/tag/simply">simply</category>
      <category domain="http://securityratty.com/tag/custom alerts">custom alerts</category>
      <category domain="http://securityratty.com/tag/infection site">infection site</category>
      <category domain="http://securityratty.com/tag/fake cnn spam">fake cnn spam</category>
      <category domain="http://securityratty.com/tag/genuine cnn article">genuine cnn article</category>
      <category domain="http://securityratty.com/tag/huge spam wave">huge spam wave</category>
      <source url="http://blog.spywareguide.com/2008/08/cnn-custom-alerts.html">CNN Custom Alerts Spam</source>
    </item>
    <item>
      <title><![CDATA[Listening to the evidence]]></title>
      <link>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</link>
      <guid>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</guid>
      <description><![CDATA[Last week the House of Commons Culture, Media and Sport Select Committee published a report of their inquiry into Harmful content on the Internet and in video games . They make a number of...]]></description>
      <content:encoded><![CDATA[<p>Last week the <a href="http://www.parliament.uk/parliamentary_committees/culture__media_and_sport.cfm">House of Commons Culture, Media and Sport Select Committee</a> published a report of their inquiry into &#8220;<a href="http://www.publications.parliament.uk/pa/cm200708/cmselect/cmcumeds/353/353.pdf">Harmful content on the Internet and in video games</a>&#8220;. They make a number of recommendations including a self-regulatory body to set rules for Internet companies to force them to protect users; that sites should provide a &#8220;watershed&#8221; so that grown-up material cannot be viewed before 9pm; that YouTube should screen material for forbidden content; that &#8220;<a href="http://www.spiked-online.com/index.php?/site/article/4633/">suicide websites</a>&#8221; should be blocked; that ISPs should be forced to block child sexual abuse image websites whatever the cost, and that blocking of bad content was generally desirable.</p>
<p>You will discern a certain amount of enthusiasm for blocking, and for a &#8220;<a href="http://www.yes-minister.com/polterms.htm#Politicians">something must be done</a>&#8221; approach. However, in coming to their conclusions, they do not, in my view, seem to have listened too hard to the evidence, or sought out expertise elsewhere in the world&#8230;<br />
<span id="more-351"></span><br />
Google/YouTube told them that 10 hours of video was posted every minute, and the amount is increasing. In the oral evidence session an MP helpfully suggested: &#8220;That video content is tagged. You do not need to look at every single minute of video content. Surely you could have people who would look at the video content which is tagged with labels which suggest it could be inappropriate.&#8221; Of course &#8220;<a href="http://lostria.blogspot.com/2008/01/fertility-slaps.html">happy_slapping.wmv</a>&#8221; or &#8220;<a href="http://www.phrases.org.uk/meanings/bunny-boiler.html">fluffy_bunnies.avi</a>&#8221; must always contain exactly what it says on the tin (<a href="http://en.wikipedia.org/wiki/Not%21">not!</a>) but unaccountably Google said it was a &#8220;fair suggestion&#8221;, so perhaps my cynicism is misplaced.</p>
<p>However, back to blocking.</p>
<p>I submitted <a href="http://www.cl.cam.ac.uk/~rnc1/080129-cms.pdf">some evidence of my own</a>, which the committee summarised, reasonably accurately:</p>
<blockquote><p>Dr Richard Clayton, a researcher in the Security Group of the Computer Laboratory at Cambridge University and author of several academic papers on methods for blocking access to Internet content, pointed out that there was no single blocking method which was both inexpensive and discerning enough to block access to only one part of a large website (such as FaceBook). In his view, the fatal flaw of all network-level blocking schemes was the ease with which they could be overcome, either by encrypting content or by the use of proxy services hosted outside the UK.</p></blockquote>
<p>The committee&#8217;s conclusion, having read this was:</p>
<blockquote><p>At a time of rapid technological change, it is difficult to judge whether blocking access to Internet content at network level by Internet service providers is likely to become ineffective in the near future. However, this is not a reason for not doing so while it is still effective for the overwhelming majority of users.</p></blockquote>
<p>which I suppose logically means that the committee thinks that blocking should now be discarded as a policy option &#8212; but somehow I think that isn&#8217;t their intended meaning.</p>
<p>The Committee should perhaps have a look at <a href="http://www.acma.gov.au/webwr/_assets/main/lib310554/isp-level_internet_content_filtering_trial-report.pdf">this Australian report</a>, which found that ISP level content filtering (and in Australia the politicians want to use ISP level filtering to provide a child-friendly Internet) did work (up to a point) at Tier 3 (the smallest) ISPs. The <a href="http://en.wikiquote.org/wiki/Evelyn_Waugh#Scoop_.281938.29">up-to-a-point</a> is that unlike previous tests the systems didn&#8217;t completely wreck the browsing experience by slowing it down. However, the systems blocked only 85-98% of illegal material and similar percentages of material suitable for adults but not for younger children. Interestingly some products were better at different categories.</p>
<p>Getting that many sites wrong is really quite significant, so it&#8217;s difficult to see this as a ringing endorsement for blocking the web. Additionally, the Australian report found that the blocking was useless on &#8220;non-web&#8221; protocols (such as peer-to-peer) and their report specifically didn&#8217;t consider cost, or ease of circumvention &#8212; so it&#8217;s not just UK politicians not wanting to consider evidence on that topic!</p>
<p>Finally, I should note that the Culture Media and Sport Committee has also ignored some rather more recent academic work. The MPs have put into their report that they were horrified to discover that child sexual abuse images took 24 hours to remove in the UK. What (should they ever learn of it) will they make of the recent discovery by <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and myself that shows that if the website is hosted abroad then <a href="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">a month is more to be expected</a>?</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 20:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/isp level content">isp level content</category>
      <category domain="http://securityratty.com/tag/video games">video games</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/bad content">bad content</category>
      <category domain="http://securityratty.com/tag/video content">video content</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/evidence">evidence</category>
      <category domain="http://securityratty.com/tag/child-friendly internet">child-friendly internet</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/08/listening-to-the-evidence/">Listening to the evidence</source>
    </item>
    <item>
      <title><![CDATA[Nikon Adds Wi-Fi with S610c with Wayport Uploads, WPS Security]]></title>
      <link>http://securityratty.com/article/80e982b2d2ee8f86f98456b1d7e568ea</link>
      <guid>http://securityratty.com/article/80e982b2d2ee8f86f98456b1d7e568ea</guid>
      <description><![CDATA[Nikon announces new Wi-Fi camera with Wayport hotspot link, WPS: The S610c with Wi-Fi inside, shipping in September for $330 (MSRP), supports Wi-Fi Protected Setup (WPS) for single button connections...]]></description>
      <content:encoded><![CDATA[<p><a href="http://press.nikonusa.com/2008/08/nikon_continues_leadership_in.php"><strong>Nikon announces new Wi-Fi camera with Wayport hotspot link, WPS:</strong></a> The S610c with Wi-Fi inside, shipping in September for $330 (MSRP), supports Wi-Fi Protected Setup (WPS) for single button connections to home networks, and a two year subscription to Wayport's hotspot network for uploading photos. This is nearly 10,000 McDonald's and 1,000 hotels, and doesn't include the Starbucks locations Wayport is building out for AT&T. The camera has a 10-megapixel sensor, 3.6x zoom lens, and 3-inch LCD screen, as well as vibration reduction, and up to an effective 3200 ISO.</p>

<p><img src="http://wifinetnews.com//images/2008/s610c.jpg" alt="s610c.jpg" border="0" width="250" height="188" /></p>

<p>Oddly, Nikon also announced the <a href="http://www.nikonusa.com/Find-Your-Nikon/Product/Digital-Camera/26135/COOLPIX-P6000.html"><strong>$500 P6000</strong></a> with a built-in GPS receiver, 13.5 MP sensor, 4x zoom, and effective 6400 ISO--and a built-in Ethernet jack. Which is a very weird choice. I know Wi-Fi adds cost and reduces battery life-span, but I would think that GPS plus Wi-Fi would allow assisted GPS for faster coordinated lookups (if the Wi-Fi tapped into Skyhook's system and cached some location information), as well as offering automated uploads, and Wi-Fi positioning when GPS signals couldn't be reached.</p>

<p>Seems like a missed ship here.</p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 07:13:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wayport">wayport</category>
      <category domain="http://securityratty.com/tag/camera">camera</category>
      <category domain="http://securityratty.com/tag/wi-fi camera">wi-fi camera</category>
      <category domain="http://securityratty.com/tag/wi-fi inside">wi-fi inside</category>
      <category domain="http://securityratty.com/tag/gps">gps</category>
      <category domain="http://securityratty.com/tag/wayport hotspot link">wayport hotspot link</category>
      <category domain="http://securityratty.com/tag/built-in gps receiver">built-in gps receiver</category>
      <category domain="http://securityratty.com/tag/supports wi-fi">supports wi-fi</category>
      <source url="http://wifinetnews.com/archives/008413.html">Nikon Adds Wi-Fi with S610c with Wayport Uploads, WPS Security</source>
    </item>
    <item>
      <title><![CDATA[Eight Steps to Responsible Surfing]]></title>
      <link>http://securityratty.com/article/a72ad36f246a9ff490930a87868f7ede</link>
      <guid>http://securityratty.com/article/a72ad36f246a9ff490930a87868f7ede</guid>
      <description><![CDATA[Web threats and attacks will continue to evolve, but surfers can protect themselves against the majority of malicious code by following eight different steps. To provide the greatest degree of...]]></description>
      <content:encoded><![CDATA[<div><strong></strong>Web threats and attacks will continue to evolve, but surfers can protect themselves against the majority of malicious code by following eight different steps. To provide the greatest degree of security, surfers cannot rely entirely on technology, and should also address the behavioral issues that are most likely to create risky situations.</div>
<p><strong>Changing Behavior</strong></p>
<div>The safest way to deal with a danger is avoidance. By surfing safely and adapting offline sensibilities online, surfers can greatly reduce their danger of exposure to malware.</div>
<p><strong>1. Educate yourself.</strong><br />
At least every 6 to 12 months, surfers should browse the educational information provided by their operating system and security vendors and subscribe to any security-related newsletters they might offer. According to David Perry, familiarity with the latest threats, dangers, and recommended safety tips will allow surfers to make safe choices. &#8220;Until you know what&#8217;s out there, you&#8217;re just flying blind. Without an education, you&#8217;re wide open&#8221;.<br />
<strong>2. Avoid suspect sites.</strong><br />
While criminals can infect even mainstream Web sites, sites such as gambling sites, adult Internet sites, and illegal file-sharing sites are far more likely to carry malicious code. Web sites that offer &#8220;something for nothing&#8221; frequently recoup their losses by infecting visitors&#8217; PCs.<br />
<strong>3. Lose Your Comfort Zone.</strong></p>
<div>Web surfers should migrate their offline precautions to their online experience. By beginning with an attitude of healthy skepticism and only doing business with trusted Web sites, surfers can bypass a good deal of risk.</div>
<p><strong>Recommended Technology</strong></p>
<div>Despite the best precautions, every user will encounter Web-based malware. While no technology can guarantee protection against all attacks, a combination of preventive technologies provides the most comprehensive protection possible.</div>
<p><strong>4. Use an updated virus scanning suite.</strong><br />
The most important component of any threat mitigation system is a virus scanning suite. In addition to detecting and removing known viruses and malware, modern virus scanning suites provide additional protections against new attacks by disabling their known protocols. For example, Trend Micro™ Internet Security encrypts keyboard traffic, protecting personal data from keyboard logging programs that might go unnoticed. Users should update their scanner and virus definitions as frequently as possible to ensure the best possible coverage.<br />
<strong>5. Upgrade your OS and browser.</strong><br />
In addition to offering more features, Microsoft&#8217;s Internet Explorer version 7 and the latest Mozilla Firefox are both substantially more secure than previous-generation browsers. Users of older browsers should upgrade immediately to take advantage of increased security. Similarly, Windows Vista and Mac OS X are more secure than their predecessors, and users of older operating systems should consider upgrading, as well.<br />
<strong>6. Disable scripting and &#8220;widgets.&#8221;</strong><br />
Many Web-based attacks use various scripting languages to run infectious programs in a browser or use downloadable &#8220;widgets&#8221; to execute infections locally. By disabling scripting and avoiding downloadable widgets wherever possible, surfers disable these common attack vectors.<br />
<strong>7. Rate your Web pages.</strong><br />
Some available services rate the risk of Web pages in search results, allowing surfers to avoid unwanted content and hidden threats before viewing the pages. Rating applications (e.g., Trend Micro TrendProtect™) consume few system resources and run unobtrusively, so they are suitable for any Web-enabled personal computer.<br />
<strong>8. Ask your provider.</strong><br />
Commerce companies, banks, and credit card associations are all interested in computer security, and many offer additional features. For example, Visa&#8217;s Verified By Visa program requires cardholders to enter a second password to identify themselves during a transaction, while businesses in Poland require cell-phone confirmation of credit card purchases. While nothing will be 100 percent effective, any additional security measure provided by a trusted source will increase protection, and surfers should adopt as many as possible.</p>
<p>This article provided for your reading pleasure by Trend Micro.</p>
]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 20:30:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mainstream web sites">mainstream web sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/adult internet sites">adult internet sites</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web surfers">web surfers</category>
      <category domain="http://securityratty.com/tag/surfers">surfers</category>
      <category domain="http://securityratty.com/tag/surfers disable">surfers disable</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=536">Eight Steps to Responsible Surfing</source>
    </item>
  </channel>
</rss>
