<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: endless]]></title>
    <link>http://securityratty.com/tag/endless</link>
    <description></description>
    <pubDate>Thu, 03 Jul 2008 15:13:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hype Alert: Internet Shopping Carts Are Secure]]></title>
      <link>http://securityratty.com/article/6f0706e64d78d354492017803497a079</link>
      <guid>http://securityratty.com/article/6f0706e64d78d354492017803497a079</guid>
      <description><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled Internet Shopping Carts are Secure
OMG...really
To be fair, I realize the author is speaking from the...]]></description>
      <content:encoded><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled <a href="http://hubpages.com/hub/Internet-Shopping-Carts-Are-Secure" taget="_blank">Internet Shopping Carts are Secure</a>. <br />OMG...really?<br />To be fair, I realize the author is speaking from the eCommerce perspective, rather than that of an information security practitioner, but here's where the trouble begins:<br /><span style="font-style:italic;">"Shopping cart service providers have developed secure ecommerce shopping cart solutions for any business owner looking to enhance their current online store, or create a new one. Some ecommerce shopping cart solution providers are even receiving PABP (Payment Application Best Practice) certification which supports PCI compliance requirements for all businesses accepting credit card payments online."</span><br />This may be true in part, but it is by no means an all-inclusive claim. Shopping carts continue to be sieve-like, even when apparently reviewed per <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> standards.<br />Allow me to elaborate.<br />We'll kick off our hype eliminating effort with a simple Google dork: <a href="http://www.google.com/search?hl=en&q=inurl%3A%22cart.cfm%22&btnG=Search" target="_blank"{>inurl:"cart.cfm"</a> (picking on ColdFusion again, but man, they make it easy)<br /><a href="http://www.gmpartsdirect.com/cart.cfm" target="_blank">GM Parts Direct: Your Shopping Cart</a> jumped right out at me for a number of reasons.<br />First, I sensed XSS vulns lurking like a Geiger counter senses radiation. Sound <a href="http://www.ringelkater.de/Sounds/2geraeusche_gegenst/geigerzaehler.wav" target="_blank">effect</a> for edification. :-)<br />Second, the page contained one of the growing number of aforementioned conversion-driving website <a href="http://sealserver.trustwave.com/cert.php?customerId=w6ordzctHpqOVGcB1cmBsViTpDGC2k&size=105x54&style=normal&language=en" target="_blank">security</a> seals. <br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s1600-h/GMparts.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s320/GMparts.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250473012396397122" /></a><br /><br />Tick, tick, click...the Gieger counter is getting louder. <br />Trustwave claims that the site operator "is enrolled in Trustwave's Trusted Commerce™ program to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) mandated by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard Worldwide, Visa, Inc. and Visa Europe."<br />Methinks that <a href="https://www.trustwave.com/" target="_blank">Trustwave's</a> Trusted Commerce program is missing a few fundamental security checks. Remember, XSS in PCI regulated sites, according to the <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS</a>, indicates that a site is not compliant (see section 6.5.4) if vulnerable to XSS.<br />Uh-oh.<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s1600-h/GMparts_xss_trustwave.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s320/GMparts_xss_trustwave.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250476249048608850" /></a><br />All it takes is a fake login page, as opposed to our friends at <a href="http://xssed.com/" target="_blank">XSSED.com</a>, and...well, you get the point.<br />Simply, this is one of an endless number of shopping cart not secure, and not PCI compliant. For shame. You need only browse the <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">Holisticinfosec.org Advisories</a> page to find multiple ecommerce platforms and shopping carts that are missing the mark. Trust me, these are a fraction of the <a href="http://secunia.com/advisories/search/?search=shopping+cart" target="_blank">problem</a>.<br />ecommerce<>security<br />ecommerce<><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" target="_blank">SDL</a><br />ecommerce<>PCI<br />website security seal<>security<br />Sigh.]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecommerce">ecommerce</category>
      <category domain="http://securityratty.com/tag/multiple ecommerce platforms">multiple ecommerce platforms</category>
      <category domain="http://securityratty.com/tag/ecommerce sdl">ecommerce sdl</category>
      <category domain="http://securityratty.com/tag/ecommerce perspective">ecommerce perspective</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/cart solutions">cart solutions</category>
      <category domain="http://securityratty.com/tag/cart">cart</category>
      <category domain="http://securityratty.com/tag/ecommerce security">ecommerce security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/hype-alert-internet-shopping-carts-are.html">Hype Alert: Internet Shopping Carts Are Secure</source>
    </item>
    <item>
      <title><![CDATA[Slacker Releases G2 Wi-Fi Music Player]]></title>
      <link>http://securityratty.com/article/6bf0a2996035ec73c7f3c1e291fa58bc</link>
      <guid>http://securityratty.com/article/6bf0a2996035ec73c7f3c1e291fa58bc</guid>
      <description><![CDATA[Slacker joins Apple and Microsoft in releasing new models: It's been a busy week for those who follow the latest developments in music players. Apple's new iPods, while not revolutionary, still up the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://news.cnet.com/8301-17938_105-10042321-1.html"><strong>Slacker joins Apple and Microsoft in releasing new models:</strong></a> It's been a busy week for those who follow the latest developments in music players. Apple's new iPods, while not revolutionary, still up the ante for features and quality; Microsoft's new Zunes, released today, come with fascinating new software options; and the Slacker G2 today. The G2, like the iPod touch and all Zunes, sports Wi-Fi.</p>

<p>Slacker licenses music directly from publishers, and includes a perpetual subscription in the cost of the player. Slacker creates stations that feed out an endless supply of music. The new models are $200 for a 4GB model with the ability to list 25 stations (up to 2,500 songs), or $250 for an 8 GB model with 40 stations (up to 4,000 songs). You can also sync your own music in MP3 or WMA format. For $7.50 per month, you can upgrade and store songs you're listening to, as well as avoid ads.</p>

<p><img src="http://wifinetnews.com//images/2008/slacker_g2_front.jpg" alt="slacker_g2_front.jpg" border="0" width="150" height="246" align="right" />The G2 is already getting reviews as a much-improved upgrade from the first release. Like the Zune, there's no browser or other Internet features, and that might be a positive.</p>

<p>The <a href="http://www.marketwatch.com/news/story/devicescape-enables-effortless-go-wi-fi/story.aspx?guid={A30C3095-A0C9-416D-836E-691261B961B5}&dist=hppr"><strong>G2 is tied into Devicescape's Wi-Fi home and hotspot authentication system</strong></a>, which lets Slacker G2 owners pre-program encryption keys or login information for hotspots that they frequent. Devicescape's software both retrieves and stores login information, allowing the G2 to be used in places that would otherwise require either tedious entry of a WPA passphrase, or be unavailable without a Web browser to handle the login.<br clear="left"></p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:38:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/slacker">slacker</category>
      <category domain="http://securityratty.com/tag/login">login</category>
      <category domain="http://securityratty.com/tag/stores login information">stores login information</category>
      <category domain="http://securityratty.com/tag/music">music</category>
      <category domain="http://securityratty.com/tag/slacker joins apple">slacker joins apple</category>
      <category domain="http://securityratty.com/tag/login information">login information</category>
      <category domain="http://securityratty.com/tag/music players">music players</category>
      <category domain="http://securityratty.com/tag/songs">songs</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <source url="http://wifinetnews.com/archives/008442.html">Slacker Releases G2 Wi-Fi Music Player</source>
    </item>
    <item>
      <title><![CDATA[EstDomains & Intercage: A Perfect Couple in Crime]]></title>
      <link>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</link>
      <guid>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</guid>
      <description><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's take on the...]]></description>
      <content:encoded><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's <a href="http://www.google.com/search?hl=en&q=site%3Asunbeltblog.blogspot.com+estdomains+atrivo+intercage&btnG=Search" target="_blank">take</a> on the topic, or <a href="http://www.emergingthreats.net/index.php?searchword=intercage&option=com_search&Itemid=5" target="_blank">search</a> Emergingthreats to come up to speed.<br />Yesterday, EstDomains posted the most inept, ridiculous <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html" target="_blank">response</a> ever issued to the endless and worthy criticism, largely <a href="http://technewsreview.com.au/article.php?article=5882" target="_blank">leveled</a> by Brian Krebs at the Washington Post. <br />Not only can't these morons from EstDomains write, they're either so deeply clueless or flagrantly malicious (likely both), it's beyond laughable. This section sums it up best:<br /><span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality. But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance."</span><br /><span style="font-weight:bold;">What? Really?</span> <br />Again, aside from the absolute butchery of the language, did they just say <span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality."</span>? SIGH...yes, they did.<br /><br />Allow me to exemplify just how ridiculous a claim that is.<br />Following is content from a packet capture I took during a recent Storm worm analysis.<br /><br />Using the ip2asn module included in <a href="http://writequit.org/projects/nsm-console/" target="_blank">NSM-console</a> availabe in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we find:<br />27595   | 216.255.189.211  | INTERCAGE - InterCage, Inc.<br /><br />Using Etherape, also included in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s1600-h/etherape_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s320/etherape_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246478966559532178" /></a><br /><br />Using <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" target="_blank">Eric Hjelmvik's</a> <a href="http://holisticinfosec.org/toolsmith/docs/august2008.pdf" target="_blank">NetworkMiner</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s1600-h/NetworMiner_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s320/NetworMiner_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246480419744190626" /></a><br /><br />See the recurring theme? Intercage, EstDomain's <span style="font-style:italic;">"reliable ally in its battle against malware"</span>.<br />Nice work, guys...keep it up.<br /><br />I'm submitting this to <a href="http://thedailywtf.com/" target="blank">The Daily WTF</a> as we speak.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html&title=EstDomains%20&%20Intercage:%20A%20Perfect%20Couple%20in%20Crime " title="EstDomains & Intercage: A Perfect Couple in Crime ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html" title="EstDomains & Intercage: A Perfect Couple in Crime ">digg</a>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intercage">intercage</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware presence">malware presence</category>
      <category domain="http://securityratty.com/tag/intercage data center">intercage data center</category>
      <category domain="http://securityratty.com/tag/track malware issues">track malware issues</category>
      <category domain="http://securityratty.com/tag/reliable ally">reliable ally</category>
      <category domain="http://securityratty.com/tag/management services">management services</category>
      <category domain="http://securityratty.com/tag/malware vehicles">malware vehicles</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html">EstDomains &amp; Intercage: A Perfect Couple in Crime</source>
    </item>
    <item>
      <title><![CDATA[Don't Panic]]></title>
      <link>http://securityratty.com/article/171b434e504b03e183525367f4118cdd</link>
      <guid>http://securityratty.com/article/171b434e504b03e183525367f4118cdd</guid>
      <description><![CDATA[Sometimes it's easy to believe that every last thing online is going to eat into your PC, burn your house down, kill your cat and so on. The last few days I'd been hearing rumblings about some...]]></description>
      <content:encoded><![CDATA[
        Sometimes it's easy to believe that every last thing online is going to eat into your PC, burn your house down, kill your cat and so on. The last few days I'd been hearing rumblings about some "Youtube rap video" and a file that would start hijacking your PC - well, thanks to a tipoff from a forum-goer at Spywarewarrior, I can hopefully put this one to rest.<br /><br />In short, a video promoting a rap mix-tape supposedly took you to a file that "hijacked your PC with Spywarestop". In actual fact, there's no file to hijack you. Let's take a look - here's the Youtube page in question:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mixtape1.html" onclick="window.open('http://blog.spywareguide.com/images/mixtape1.html','popup','width=895,height=493,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mixtape1-thumb-395x217.gif" alt="mixtape1.gif" class="mt-image-none" style="" height="217" width="395" /></a></span><br /><br />Click to Enlarge<br /></div><br />As you can see, there's the mix-tape being advertised and a link to Mediafire, where the mix-tape is hosted. Click the Mediafire link, and all that happens is you'll see an advert for various antispyware tools - some of them on the <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm">Rogue Antispyware list</a>, some of them not on the list but known to be of little worth to the end-user.<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mixtape2.html" onclick="window.open('http://blog.spywareguide.com/images/mixtape2.html','popup','width=757,height=457,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mixtape2-thumb-357x215.gif" alt="mixtape2.gif" class="mt-image-none" style="" height="215" width="357" /></a></span><br /> </div><div><div align="center"><br />Click to Enlarge<br /></div><br />In this particular case, it's an advert for Adware Alert. It's not hijacking you, or breaking things or making your browser fly around the screen, nor is it a "virus". It's just an (admittedly loud) advert. If you're running a browser compatible with <a href="http://adblockplus.org/en/">Adblock Plus</a>, all you'll see beneath the Mediafire logo is a blank space. Even if you're vaguely alarmed by the advert, all you have to do is click the "Continue to Mediafire.com" message at the top right of the screen (missing from the above screenshot as I cropped the image too small - whoops) and you'll be taken to the file you requested.<br /><br />Like the title says - don't panic. This really isn't something to worry about too much. Even the most obnoxious rogue antispyware advert (the ones that <i>do</i> resize your browser, throw up endless popups and make annoying "Woop woop" noises) can usually be escaped by simply hitting CTRL+ALT+DEL and using Task Manage to close your browser session.<br /></div>
        
    ]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 13:03:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mediafire link">mediafire link</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/mediafire">mediafire</category>
      <category domain="http://securityratty.com/tag/browser session">browser session</category>
      <category domain="http://securityratty.com/tag/rap mix-tape supposedly">rap mix-tape supposedly</category>
      <category domain="http://securityratty.com/tag/mix-tape">mix-tape</category>
      <category domain="http://securityratty.com/tag/mediafire logo">mediafire logo</category>
      <category domain="http://securityratty.com/tag/browser compatible">browser compatible</category>
      <source url="http://blog.spywareguide.com/2008/08/dont-panic.html">Don't Panic</source>
    </item>
    <item>
      <title><![CDATA[This week in history - volcanos, hurricanes, and the risk of Black Swans]]></title>
      <link>http://securityratty.com/article/1c99044530f3bdcc78ac07456ab99c44</link>
      <guid>http://securityratty.com/article/1c99044530f3bdcc78ac07456ab99c44</guid>
      <description><![CDATA[Pouring over endless details of risks, regulations, taxonomies, and technologies can sometimes give us a narrow view of the world, so it seems worthwhile to take a minute to mark the 125th anniversary...]]></description>
      <content:encoded><![CDATA[<p><img title="Chris McClean" alt="Chris McClean" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Chris-McClean.gif" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></p>

<p>Pouring over endless details of risks, regulations, taxonomies, and technologies can sometimes give us a narrow view of the world, so it seems worthwhile to take a minute to mark the 125th anniversary of the <a href="http://www.wired.com/science/discoveries/news/2008/08/dayintech_0826">cataclysmic eruption of Krakatoa</a> this week. For those of us that want to think big but can’t remember that far back, this week is also the 3rd anniversary of <a href="http://www.hhs.gov/disasters/emergency/naturaldisasters/hurricanes/katrina/index.html">Hurricane Katrina’s devastating sweep</a> across a wide stretch of the US Gulf Coast. </p>

<p>By now, I expect that most of you have read or are familiar with the 2007 book, The Black Swan, by <a href="http://www.fooledbyrandomness.com/">Nassim Nicholas Taleb</a>, which argues that these kinds of unpredictable, outlying occurrences are the ones that really shape businesses, countries, economies, and people. Taleb argues that although these “Black Swan” events are almost completely unforeseeable, we mistakenly try to explain the circumstances at the time and make predictions about similar events in the future. </p>

<p>In my ERM work with clients, and especially in the context of research I’ve been doing with my colleague <a href="http://www.forrester.com/rb/analyst/stephanie_balaouras?internal=1">Stephanie Balaouras</a> on business continuity and resiliency, questions come up about how to plan for catastrophes... and they’re good questions. Were the CardSystems or TJX data breaches foreseeable? What about the Societe General debacle or the 2004 Indian Ocean tsunami? What’s next? Should these types of events be included in our risk assessments? </p>

<p>We’d like to get your opinion on these and other risks that may be on the very edge of the statistical tail. At what point do they belong in your risk register? </p>

<p>Of course, it’s possible to define mitigating controls for crises, disasters, or incidents without knowing for sure what they’re going to look like. That’s one of the hallmarks of a good crisis management plan. And that’s an important point, because trying to predict the next unforeseeable event can be a real challenge sometimes. </p>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 07:07:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/similar events">similar events</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/black swan events">black swan events</category>
      <category domain="http://securityratty.com/tag/black swan">black swan</category>
      <category domain="http://securityratty.com/tag/plan">plan</category>
      <category domain="http://securityratty.com/tag/crisis management plan">crisis management plan</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/colleague stephanie balaouras">colleague stephanie balaouras</category>
      <category domain="http://securityratty.com/tag/argues">argues</category>
      <source url="http://blogs.forrester.com/srm/2008/08/this-date-in-hi.html">This week in history - volcanos, hurricanes, and the risk of Black Swans</source>
    </item>
    <item>
      <title><![CDATA[ColdFusion: Hack Me or Help Me]]></title>
      <link>http://securityratty.com/article/9fb9073abbbbfc649c8feeed2afceb21</link>
      <guid>http://securityratty.com/article/9fb9073abbbbfc649c8feeed2afceb21</guid>
      <description><![CDATA[For your consideration, the endless battle between security and convenience
Front and center: ColdFusion
I've been picking on ColdFusion-built apps again a bit lately, and one of my observations has...]]></description>
      <content:encoded><![CDATA[For your consideration, the endless battle between security and convenience.<br />Front and center: ColdFusion.<br />I've been picking on ColdFusion-built apps again a bit lately, and one of my observations has been that consistently, if mismanaged, the verbose error reporting features in ColdFusion can be really problematic.<br /><br /><a href="http://holisticinfosec.org/content/view/78/45/" target="_blank">HIO-2008-0713 JOBBEX JobSite SQLi & XSS</a><br /><a href="http://holisticinfosec.org/content/view/79/45/" target="_blank">HIO-2008-0729 BookMine SQLi & XSS</a><br /><br />Recently, I stumbled on an example of way too much information disclosure in a few sites running a ColdFusion-built CMS. The error reporting was so verbose it included the base path, data source name, database username, and yes, the <strong>database password</strong>.<br />I've cleaned it up for the protection of all involved, but here's a screen shot of only 1/4 of the details this site coughed up when I tweaked the input to a calendar date variable.<br /><br /><a href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SLblWNYqSmI/AAAAAAAAACc/BIPkxSBOxpg/s1600-h/ColdFusionTMI.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SLblWNYqSmI/AAAAAAAAACc/BIPkxSBOxpg/s320/ColdFusionTMI.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5239627386205129314" /></a><br /><br />When I reached out to the developers of this app (always and immediately responsive), they assured me that this was not due to a flaw in the app, but that the "information should be protected, and is by default for our installations" and that the client disabled the security check and turned debugging on. I accept this explanation entirely, but it leads to the classic debate around the dangers of mismanaged debugging features, be they developer added or ColdFusion feature driven. Stupid user tricks are always an issue, but how much rope should they be given to hang themselves? Does error reporting really need to include the database username and password?<br /><br />Allow me to present a few different perspectives.<br />First, rvdh's take on <a href="http://www.0x000000.com/?i=610" target="_blank">Attacking ColdFusion</a>. Developers can learn a lot from this post, if only in that it precisely points out attack vectors. Ronald sums up my concerns aptly:<br />"As we know, error messages are important. Especially error messages generated by database software we want to inject. This, is useful for obtaining information about table structures that can be a real time-saver for attackers. If the right information is available, attackers do not have to guess database tables and fields anymore, nor having to brute force them. I have never seen so much information regarding the site's structure, used database, table names, drivers, server setup and other information useful for attackers that those of ColdFusion. It almost says: Please Hack Me!"<br />As I can't presume to improve on this stance, I won't. Well said.<br /><br />Next, a developer's take on the issue from <a href="http://www.usefulconcept.com/" target="_blank">Joshua Cyr</a>, who has declared it <a href="http://www.usefulconcept.com/index.cfm/2008/8/27/ColdFusion-Errors-and-Security" target="_blank">Check Your Error Output Day</a>. Joshua highlights two key points:<br />1) Do NOT enable the robust errors setting in CF Administrator.<br />2) Don't forget to remove debugging dump code.<br />Heed this advice, ColdFusion fans!<br /><br />One destination that all "secure" ColdFusion paths should lead to is the use of <em>cfqueryparam</em>. Ronald spells it out well mid way through his <a href="http://www.0x000000.com/?i=610" target="_blank">discussion</a>, and so do the following resources:<br /><a href="http://www.coldfusionjedi.com/index.cfm/2008/7/29/What-Folks-arent-using-cfqueryparam" target="_blank">coldfusionjedi</a><br /><a href="http://www.coldfusionmuse.com/index.cfm/2008/7/28/cfqueryparam-protects-against-daleks" target="_blank">Coldfusion Muse</a><br /><br />Further excellent resources for ColdFusion security issues:<br /><a href="http://www.coldfusionmuse.com/index.cfm/2008/7/18/Injection-Using-CAST-And-ASCII" target="_blank">SQL Injection Part II (Make Sure You Are Sitting Down)</a><br /><a href="http://www.12robots.com/index.cfm/Security" target="_blank">12Robots.com</a><br /><br />In closing, security and convenience needn't always be at odds, but often allowing for both requires a higher state of awareness for developers and end-users. Let common sense prevail; perhaps it'll give me less to do in the way of <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">research</a>. ;-)<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/08/coldfusion-hack-me-or-help-me.html&title=ColdFusion:%20Hack%20Me%20or%20Help%20Me " title="ColdFusion: Hack Me or Help Me ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/08/coldfusion-hack-me-or-help-me.html" title="ColdFusion: Hack Me or Help Me ">digg</a>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 06:13:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/coldfusion">coldfusion</category>
      <category domain="http://securityratty.com/tag/coldfusion paths">coldfusion paths</category>
      <category domain="http://securityratty.com/tag/coldfusion fans">coldfusion fans</category>
      <category domain="http://securityratty.com/tag/coldfusion security issues">coldfusion security issues</category>
      <category domain="http://securityratty.com/tag/error">error</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database username">database username</category>
      <category domain="http://securityratty.com/tag/error messages">error messages</category>
      <category domain="http://securityratty.com/tag/coldfusion feature">coldfusion feature</category>
      <source url="http://holisticinfosec.blogspot.com/2008/08/coldfusion-hack-me-or-help-me.html">ColdFusion: Hack Me or Help Me</source>
    </item>
    <item>
      <title><![CDATA[Spamblogs Pushing Rogue Antivirus Programs]]></title>
      <link>http://securityratty.com/article/b6b356c5aefde884fbcf56de64cf84ab</link>
      <guid>http://securityratty.com/article/b6b356c5aefde884fbcf56de64cf84ab</guid>
      <description><![CDATA[Nothing earth-shattering, but worth a mention anyway. I've noticed a couple of blogs pushing security blog feeds are also hawking pretend Youtube vids





Click to Enlarge

When the videos are...]]></description>
      <content:encoded><![CDATA[
        Nothing earth-shattering, but worth a mention anyway. I've noticed a couple of blogs pushing security blog feeds are also hawking pretend Youtube vids:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/sblog1.html" onclick="window.open('http://blog.spywareguide.com/images/sblog1.html','popup','width=755,height=622,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/sblog1-thumb-355x292.jpg" alt="sblog1.jpg" class="mt-image-none" style="" height="292" width="355" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br />When the videos are clicked, you'll find your browser vanishes down onto the taskbar, replaced by this sitting in the middle of the screen:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sblog2.jpg" src="http://blog.spywareguide.com/images/sblog2.jpg" class="mt-image-none" style="" height="146" width="540" /></span><br /><br />Once you click the popup box away, you're confronted with this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/sblog3.html" onclick="window.open('http://blog.spywareguide.com/images/sblog3.html','popup','width=790,height=585,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/sblog3-thumb-390x288.jpg" alt="sblog3.jpg" class="mt-image-none" style="" height="288" width="390" /></a></span><br /><br />Click to Enlarge<br /></div><br />...a randomly selected rogue antivirus product. From here on it, any and all attempts to get rid of this page results in an endless barrage of popups, scare tactics ad hilariously lame warning messages (note the first one is called a "Security Update"):<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sblog4.jpg" src="http://blog.spywareguide.com/images/sblog4.jpg" class="mt-image-none" style="" height="265" width="436" /></span><br /><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sblog5.jpg" src="http://blog.spywareguide.com/images/sblog5.jpg" class="mt-image-none" style="" height="121" width="336" /></span><br /></div><div><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sblog6.jpg" src="http://blog.spywareguide.com/images/sblog6.jpg" class="mt-image-none" style="" height="173" width="507" /></span><br /></div><div><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sblog7.jpg" src="http://blog.spywareguide.com/images/sblog7.jpg" class="mt-image-none" style="" height="191" width="533" /></span><br /></div><div><br />Wow, they just get more and more hysterical, don't they?<br /><br />The site to block that's pimping the fake videos is<br /><br />thoughtcrime(dot)blogtodo(dot)com<br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 14:50:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security blog feeds">security blog feeds</category>
      <category domain="http://securityratty.com/tag/rogue antivirus product">rogue antivirus product</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/videos">videos</category>
      <category domain="http://securityratty.com/tag/pretend youtube vids">pretend youtube vids</category>
      <category domain="http://securityratty.com/tag/fake videos">fake videos</category>
      <category domain="http://securityratty.com/tag/scare tactics">scare tactics</category>
      <category domain="http://securityratty.com/tag/endless barrage">endless barrage</category>
      <source url="http://blog.spywareguide.com/2008/08/spamblogs-pushing-rogue-antivi.html">Spamblogs Pushing Rogue Antivirus Programs</source>
    </item>
    <item>
      <title><![CDATA[Automated Spim on Microblogging Site Via MSN Messenger]]></title>
      <link>http://securityratty.com/article/e5a1fb1ee8285e5dda0e9ae590ea20f2</link>
      <guid>http://securityratty.com/article/e5a1fb1ee8285e5dda0e9ae590ea20f2</guid>
      <description><![CDATA[There's been a fair amount of Twitter coverage recently, but it's worth noting that other countries have their own versions of Twittering and some of them have seem to be a little easier to use in...]]></description>
      <content:encoded><![CDATA[
        There's been a fair amount of <a href="http://blogs.zdnet.com/security/?p=1640">Twitter coverage</a> recently, but it's worth noting that other countries have their own versions of Twittering and some of them have seem to be a little easier to use in conjunction with Instant Messaging, whereas Twitter still seems to have a need for <a href="http://www.twittermsn.com/">third party services</a>, <a href="http://kunal.kundaje.net/twessenger/">add-ins</a> and <a href="http://www.theyagar.com/2008/01/30/twitter-bot-for-yahoo/">other tools</a> to get the job done if the service used is something other than Google Talk, Livejournal Chat or Jabber (if it's now more straightforward for other clients too, please let me know!)<br /><br />Either way, the below illustrates why adding Instant Messaging features to services such as Twitter can cause problems in the long run and needs to be considered carefully.<br /><br />We were alerted to the fact that a large amount of Spam seemed to be coming out of China in the last day or two (indeed, one contact mentioned to me that this particular message had been sent to their Honeypot around 29,000+ times, which is a lot of spamming for one URL however you look at it). The spam in question seemed to have been sent via a Spambot, and the only mentions of this URL so far in search engines seems to be related to China - shall we take a look?<br /><br />The URL in question (with part of it redacted) is<br /><br />http: //5834******/ ;)<br /><br />You'll notice the spam is short, snappy and also includes a little smiley-face thing at the end. In fact, it looks a little bit like the kind of link people send to their contacts on Twitter, doesn't it?<br /><br />Well, let's see - a quick search and we find this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf1.html" onclick="window.open('http://blog.spywareguide.com/images/fanf1.html','popup','width=780,height=584,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf1-thumb-380x284.jpg" alt="fanf1.jpg" class="mt-image-none" style="" height="284" width="380" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />A page from Fanfou.com, which I believe is a Chinese site "<a href="http://www.twittown.com/fanfou">inspired</a>" by Twitter with much of the same features and functionality. In fact, it has one feature working straight off the bat that Twitter users previously had to rely on <a href="http://kunal.kundaje.net/twessenger/">plugins</a> for - the ability to send messages to their page via MSN Messenger updates.<br /><br />http: //5834****** doesn't actually resolve anywhere - however, a quick Ping to that address and we have an IP:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf3.html" onclick="window.open('http://blog.spywareguide.com/images/fanf3.html','popup','width=452,height=212,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf3-thumb-352x165.jpg" alt="fanf3.jpg" class="mt-image-none" style="" height="165" width="352" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Type the IP address into the browser, and via some geolocational technology, you'll see a region specific version of the following dating website:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf4.html" onclick="window.open('http://blog.spywareguide.com/images/fanf4.html','popup','width=780,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf4-thumb-380x274.jpg" alt="fanf4.jpg" class="mt-image-none" style="" height="274" width="380" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Go back to the page on Fanfou.com, scroll down and select any of the clickable links and surprise - the same page appears. This particular account on Fanfou has something like 30+ pages devoted to endless Spim links via MSN. They link to placeholder pages, sites that look as though they've been suspended and / or deleted with no way to determine what content was there previously - all interspersed with "Twitter" style messages throughout such as this:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fanf5.jpg" src="http://blog.spywareguide.com/images/fanf5.jpg" class="mt-image-none" style="" height="27" width="208" /></span>
<br /><br />Again, note everything is coming via MSN. By this point, you're probably wondering exactly how they allow you to send messages to their Twitter-style pages. Well, the solution is quite clever - check out the <a href="http://help.fanfou.com/im.html">IM page</a>. You enter your MSN address, and when you login to your MSN account, you'll suddenly find you have a new IM buddy who wants to be a contact:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fanf6.jpg" src="http://blog.spywareguide.com/images/fanf6.jpg" class="mt-image-none" style="" height="189" width="475" /></span>
<br /><br />Add it, and whenever you want to put a message on your page, send it an <a href="http://blog.spywareguide.com/image/fanf7.jpg">instant message</a> and, lo and behold, your Tweet-style message has appeared on your page:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf8.html" onclick="window.open('http://blog.spywareguide.com/images/fanf8.html','popup','width=541,height=241,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf8-thumb-341x151.jpg" alt="fanf8.jpg" class="mt-image-none" style="" height="151" width="341" /></a></span><br /><br />Click to Enlarge<br /></div><br />In conclusion, the steps here appear to be<br /><br /><b>1)</b> Create a Spambot that infects users via MSN Messenger<br /><b>2)</b> Tailor the messages it sends to be short and sweet, just like a Twitter-style message<br /><b>3)</b> Set up an account on a service such as Fanfou.com that makes it easy to send messages to your page via MSN Messenger (or other IM services affected by your bot)<br /><b>4)</b> Infect the PC running your MSN Messenger account then watch as it spams the userpage with whatever messages you want it to send.<br /><br />Of course, the links can be anything from dating sites and ringtone adverts to infection files and exploits - all made so much more easier (and far less time consuming than manually typing in URLs to your userpage) by the functionality built into the site you happen to be using. It's also worth noting that the accounts sending the Spim don't <i>have</i> to be set up by the spammer - they could be compromised accounts that had been hijacked when clicking a rogue IM link, which is a great way of filling out the spamming ranks very quickly.<br /><br />This is definitely something Twitter - and any other site out there involved in <a href="http://en.wikipedia.org/wiki/Micro-blogging">microblogging</a> - need to keep an eye out for, and consider carefully when thinking of adding integration with popular Instant Messaging clients.<br /><br />We detect the file sending the weblinks via MSN as <a href="http://www.spywareguide.com/product_show.php?id=32320">Foubot</a>.<br /><br />Research and Writeup: Christopher Boyd, Director of Malware Research<br />Additional Research: Chris Mannon, Senior Threat Researcher<br /><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 17:12:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/msn messenger">msn messenger</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/msn messenger account">msn messenger account</category>
      <category domain="http://securityratty.com/tag/twitter-style message">twitter-style message</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/msn account">msn account</category>
      <category domain="http://securityratty.com/tag/twitter-style pages">twitter-style pages</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <source url="http://blog.spywareguide.com/2008/08/automated-spim-on-microbloggin.html">Automated Spim on Microblogging Site Via MSN Messenger</source>
    </item>
    <item>
      <title><![CDATA[Myspace Drive By]]></title>
      <link>http://securityratty.com/article/05354a2570b18bfd381d68bb5f8b561f</link>
      <guid>http://securityratty.com/article/05354a2570b18bfd381d68bb5f8b561f</guid>
      <description><![CDATA[Spotted in the wild (like they're spotted anywhere else

Apparently the following happened while someone tried to view a blog post






Click to Enlarge

A fake &quot;your system may be infected&quot; popup....]]></description>
      <content:encoded><![CDATA[
        Spotted in the wild (like they're spotted anywhere else!)<br /><br />Apparently the following happened while someone tried to view a blog post:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/msdb1.html" onclick="window.open('http://blog.spywareguide.com/images/msdb1.html','popup','width=944,height=434,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/msdb1-thumb-344x158.jpg" alt="msdb1.jpg" class="mt-image-none" style="" height="158" width="344" /></a></span><br /></div><div><div align="center"><br />Click to Enlarge<br /></div><br />A fake "your system may be infected" popup. Note the site it launches from is one of the more aggressive types (it shrinks your browser down into the bottom corner, and won't let you do anything other than cycle in an endless loop of popups until you agree to download the file being pushed).<br /><br />These kind of attacks occur because of rogue adverts being pushed into advertising space, which is likely what happened here. If you are unfortunate enough to be trapped by an attack like this, don't panic - just do a CTRL+ALT+DEL and close the browser window...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 14:58:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/browser window">browser window</category>
      <category domain="http://securityratty.com/tag/bottom corner">bottom corner</category>
      <category domain="http://securityratty.com/tag/attacks occur">attacks occur</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/endless loop">endless loop</category>
      <category domain="http://securityratty.com/tag/aggressive types">aggressive types</category>
      <category domain="http://securityratty.com/tag/rogue adverts">rogue adverts</category>
      <category domain="http://securityratty.com/tag/launches">launches</category>
      <source url="http://blog.spywareguide.com/2008/07/myspace-drive-by.html">Myspace Drive By</source>
    </item>
    <item>
      <title><![CDATA[CCleaner and SpyBot are in the top five!]]></title>
      <link>http://securityratty.com/article/14f215a49046d1f13a23bb1af3a0d0fa</link>
      <guid>http://securityratty.com/article/14f215a49046d1f13a23bb1af3a0d0fa</guid>
      <description><![CDATA[Great post over at LifeHacker today. It would heed you to listen up to the advice given


clipped from lifehacker.com

Five Best Windows Maintenance Tools


You download, create, delete, and move...]]></description>
      <content:encoded><![CDATA[<div > Great post over at LifeHacker today. It would heed you to listen up to the advice given. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/5E5BEA3C-18FB-475E-A714-64784D100A93/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/88587796-cd37-40a7-ac99-83f586727ba4/5E5BEA3C-18FB-475E-A714-64784D100A93/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://lifehacker.com/397792/five-best-windows-maintenance-tools" href="http://lifehacker.com/397792/five-best-windows-maintenance-tools" style="font-size: 11px;">lifehacker.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://lifehacker.com/397792/five-best-windows-maintenance-tools -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;"><A class="top" href="http://lifehacker.com/397792/five-best-windows-maintenance-tools">Five Best Windows Maintenance Tools</A></div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://lifehacker.com/397792/five-best-windows-maintenance-tools --><br />
You download, create, delete, and move around countless files and endless piles of data on your PC every day. While your PC would ideally handle all of this data for you, it doesn&#8217;t take long before you end up with a disorganized, cluttered computer.</td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/5E5BEA3C-18FB-475E-A714-64784D100A93/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 15:13:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows maintenance tools">windows maintenance tools</category>
      <category domain="http://securityratty.com/tag/lifehacker">lifehacker</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/endless piles">endless piles</category>
      <category domain="http://securityratty.com/tag/countless files">countless files</category>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/heed">heed</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/handle">handle</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=492">CCleaner and SpyBot are in the top five!</source>
    </item>
  </channel>
</rss>
