<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: enterprise]]></title>
    <link>http://securityratty.com/tag/enterprise</link>
    <description></description>
    <pubDate>Sun, 21 Sep 2008 17:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links List 10.3.08]]></title>
      <link>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</link>
      <guid>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</guid>
      <description><![CDATA[Well finally, an upside to the financial crisis more students in computer science. After the dot-com crash, enrollment went down in computer science, almost 50% since 2003. Many students shifted their...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/africa-map.jpg" border="0" alt="africa-map" width="204" height="240" align="left" /> Well finally, an upside to the financial crisis – more students in computer science. After the dot-com crash, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9066659" target="_blank">enrollment went down</a> in computer science, almost 50% since 2003. Many students <a href="http://www.washingtontechnology.com/online/1_1/33584-1.html" target="_blank">shifted their interest from the technology field</a> to banking and finance because they thought they’d make more money. And now the financial crisis could scare them into <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115616&amp;source=rss_news" target="_blank">choosing majors and careers that are “safer alternatives”</a>, like IT. And perhaps the trend is reversing for those already on Wall Street as well. Ben Worthen writes about the influx of resumes Kodiak Venture Partners has been getting: <a href="http://blogs.wsj.com/biztech/?s=wall+street+jobs" target="_blank">from financial-services vets who want to work at tech startups</a>, – not to “strike it rich” this time around, but just to make a living. And it’s not just the tech workers. Seems like the ones that don’t even have any real IT experience are looking too – for jobs as VPs of marketing (harrumph). (<a href="http://www.fas.org/irp/imint/docs/rst/Sect6/africa-map.jpg" target="_blank"><em>img from www.fas.org</em></a>)</p>
<p>I’m sure you already know about the other “network management” – where ISPs and carriers get their hands publicly slapped for limiting bandwidth to high-traffic offenders. But when is this kind of “network management” a good thing? At a panel sponsored by the FCC in DC, reps from carriers and ISPs discussed what steps they’ve been taking <a href="http://www.networkworld.com/news/2008/091808-telcos-pandemic.html?hpg1=bn" target="_blank">to prepare for a pandemic</a> or other major global crisis – that would force workers to stay at home or work from more remote locations to limit exposure.</p>
<p>Are people paying attention to ICANN? They’re saying that IPv4 will be fully <a href="http://blog.icann.org/?p=365" target="_blank">allocated in the next two or three years</a>. Does anyone care? In their bid to make people care, ICANN talks about the state of IPv6 adoption and <a href="http://www.thestandard.com/news/2008/09/30/africa-faster-adopting-ipv6-according-icann">touts Africa as the most rapid adopter</a>.</p>
<p><a href="http://blogs.zdnet.com/service-oriented/?p=1187" target="_blank">SOA soon part of the ‘cloud’</a>? No, please no.</p>
<p>Microsoft – The Silver Lining in Every Cloud. Joe Wilcox over at eWeek’s Microsoft Watch, has been <a href="http://www.microsoft-watch.com/content/corporate/steve_ballmer_sure_has_lots_to_say.html?kc=EWWHNEMNL10022008STR4" target="_blank">following Steve Ballmer</a> around and collecting some nice quotes on how the company is transitioning. “For many years, we had kind of what I would call the all-encompassing mission, vision and scorecard statement: a computer on every desk and in every home. …Well, our footprint and portfolio is broader than that. “ [In every hand and of course, in every cloud…] “So, as a vision statement we talk about creating seamless experiences that combine the magic of software, the power of the Internet across a world of devices.” The magic of software – something I haven’t thought about for a while. And:</p>
<blockquote><p>&#8220;You need a real platform in the cloud. When we wanted to go after the PC, we built an operating system. When we wanted to go after the phone, we built an operating system. When we wanted to go after the enterprise, we built an operating system. We&#8217;ll announce a new operating system, one that runs in the cloud and has a wide variety of capabilities.”</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:55:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/computer science">computer science</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/financial crisis">financial crisis</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/eweeks microsoft">eweeks microsoft</category>
      <source url="http://blog.sciencelogic.com/links-list-10308/10/2008">Links List 10.3.08</source>
    </item>
    <item>
      <title><![CDATA[CEP, Event Noise and Asymmetric Event Processing]]></title>
      <link>http://securityratty.com/article/2749df765875344a0e16c9acc0faf260</link>
      <guid>http://securityratty.com/article/2749df765875344a0e16c9acc0faf260</guid>
      <description><![CDATA[In The Genesis of Complex Event Processing: Asymmetric Capabilities I introduced the abstract concept of asymmetric processing capabilities to describe the foundations of complex event processing. If...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Genesis of Complex Event Processing: Asymmetric Capabilities" rel="bookmark" href="../2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</a> I introduced the abstract concept of &#8220;asymmetric processing capabilities&#8221; to describe the foundations of complex event processing.   If you take a few moments to review the <a href="http://www.thecepblog.com/2008/07/07/a-blast-from-the-past-cep-at-stanford1998-2003/" target="_blank">first CEP projects</a> from <a href="http://www.stanford.edu" target="_blank">Stanford University</a>, you will see that the application of CEP was toward  solving myriad asymmetric event processing problems in distributed networks.    These applications included challenging problems such as:</p>
<ul>
<li><a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt">Network Level Monitoring and Management,<br />
</a></li>
<li><a href="http://pavg.stanford.edu/ID/">Cyber Security: Network Intrusion Detection,<br />
</a></li>
<li>Enterprise Monitoring and Management,</li>
<li><a href="http://pavg.stanford.edu/cep/final-version-131102.pdf">Modeling and Simulation of Collaborative Business Processes, </a></li>
<li>Business Policy Monitoring, and</li>
<li>Analysis and Debugging of Distributed Systems.</li>
</ul>
<p>In each of the CEP application examples above, the amount of event information available to software developers can be staggering; however, despite all the available information, the capability to sense-and-respond to threats and opportunities is crude, at best.</p>
<p>Folks who work in network and security management, for example, are bombarded with event information.  However, this deluge of event information is, for the most part, &#8220;noise&#8221; that is difficult to understand.   In network management one of the most difficult things to accomplish is to find the root cause of an outage or performance problem.   This is why researchers at Stanford were funded to focused on research topics such as (above), <em>the Analysis and Debugging of Distributed Systems</em>.</p>
<p>These are the classes of asymmetric event processing problems that define complex event processing, or CEP.   Processing events by mediating events, routing events, or running a rule-set against events and making a processing decision are all perfectly valid event processing applications.   However, the core reason to have &#8220;complex event processing&#8221; is to solve event processing problems where there exists a significant asymmetry between the deluge of &#8220;event noise&#8221;  (Professor Luckham called this phenomena the &#8220;event cloud&#8221;) and detecting business-relevant, actionable complex events in an climate of uncertainty and noise.</p>
<p>In my next post on this topic I will briefly the review motivation behind my 1999 ACM paper, <a title="Intrusion Detection Systems and Multisensor Data Fusion" rel="bookmark" href="../intrusion-detection-systems-and-multisensor-data-fusion/">Intrusion Detection Systems and Multisensor Data Fusion, </a> where we were working on solving complex distributed security challenges based on real-world experiences with the problems of asymmetric processing capabiilities.   I will discuss why we evolved from an early rule-based expert system model to a more advanced inference model that was not dependent solely on rule-based thinking.   I will also explain why other researchers and developers experienced in complex event detection applications have come to the same conclusion.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 01:22:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asymmetric event">asymmetric event</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/define complex event">define complex event</category>
      <category domain="http://securityratty.com/tag/asymmetric">asymmetric</category>
      <category domain="http://securityratty.com/tag/actionable complex events">actionable complex events</category>
      <category domain="http://securityratty.com/tag/myriad asymmetric event">myriad asymmetric event</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/security management">security management</category>
      <source url="http://www.thecepblog.com/2008/10/02/cep-event-noise-and-asymmetric-event-processing/">CEP, Event Noise and Asymmetric Event Processing</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-10-01 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</link>
      <guid>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</guid>
      <description><![CDATA[Behavioral Monitoring | securosis.com
Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization
E-Commerce News: ID...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securosis.com/2008/09/23/behavioral-monitoring/">Behavioral Monitoring | securosis.com</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/09/improved-insights-and-analysis-from-it.html">Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization</a></li>
<li><a href="http://www.ecommercetimes.com/story/64598.html">E-Commerce News: ID Security: New PCI Security Standard Falls Short</a></li>
<li><a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">Enterprise Architecture: From Incite comes Insight...: How many fingers are required to count the number of clueless IT Security Professionals?</a></li>
<li><a href="http://www.csoonline.com/article/print/450190">IT Security: Can We Be Compliant and Yet Insecure?</a></li>
<li><a href="http://blogs.gartner.com/greg_young/2008/09/30/get-rich-quick-with-network-security/">Get Rich Quick With Network Security</a></li>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/09/ids-vitamins-or-prophylactic.html">Rational Survivability: IDS: Vitamins Or Prophylactic?</a></li>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=174">PCI DSS News and Information &raquo; Great Expectations?</a></li>
<li><a href="http://www.estoregfoa.org/StaticContent/staticpages/TM0508.htm#1c">GFOA Treasury Management</a></li>
<li><a href="http://forensics.sans.org/community/top7_forensic_trends.php">SANS - Computer Forensics - Top 7 New IR/Forensic Trends In 2008</a><br/>
SANS Top 7 New IR/Forensic Trends In 2008</li>
<li><a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/">You Might be a PM if&hellip; &laquo; Mark Curphey - SecurityBuddha.com</a></li>
<li><a href="http://blogs.computerworld.com/security_is_not_a_solution">Security is not a solution | Computerworld Blogs</a><br/>
Security is not a solution</li>
<li><a href="http://www.andrewhay.ca/archives/385">Andrew Hay &raquo; Blog Archive &raquo; Secure Life Ep 3</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408931097" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/computerworld blogs security">computerworld blogs security</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/sans top">sans top</category>
      <category domain="http://securityratty.com/tag/irforensic trends">irforensic trends</category>
      <category domain="http://securityratty.com/tag/sans">sans</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408931097/anton18">Links for 2008-10-01 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Passgen tool from my book]]></title>
      <link>http://securityratty.com/article/10fd1ee17e5b6f22fc7c246edbe0163b</link>
      <guid>http://securityratty.com/article/10fd1ee17e5b6f22fc7c246edbe0163b</guid>
      <description><![CDATA[Way back in 2005, Jesper Johannson and I wrote Protect Your Windows Network . Its still available , and although its product set is now somewhat dated (Windows XP and Server 2003), much of the...]]></description>
      <content:encoded><![CDATA[<p>Way back in 2005, <a target="_blank" href="http://msinfluentials.com/blogs/jesper/">Jesper Johannson</a> and I wrote <em>Protect Your Windows Network</em>. It’s <a target="_blank" href="http://www.amazon.com/dp/0321336437">still available</a>, and although its product set is now somewhat dated (Windows XP and Server 2003), much of the practical advice about security policies, social engineering, security dependencies, and how to think about security remains relevant. That’s because we strove to write something more lasting than a simple configuration guide.</p>  <p>On the CD-ROM accompanying the book we included a tool called Passgen. In the book, we recommended that you maintain separate passwords on every local administrator and service account in your enterprise. This is, of course, almost impossible to manage without something to automate it for you. That’s what Passgen does. The tool generates unique passwords based on known input (an identifier and passphrase you define), sets those passwords remotely, and allows you to retrieve them later.</p>  <p>For a while Jesper maintained a web site for the book, running on a server in his house. His <a target="_blank" href="http://www.comcast.net/terms/subscriber/">ISP</a> changed <a target="_blank" href="http://www.comcast.net/terms/use/">policies</a> and made it impractical to continue running the site. But because the tool is still so useful, I’ve put a copy in my <a target="_blank" href="http://steveriley-ms.spaces.live.com/">SkyDrive</a>—look in the “<a target="_blank" href="http://cid-45497626ab321d20.skydrive.live.com/browse.aspx/Passgen">Passgen</a>” folder.</p>  <p>Also, note that I’ve put a new section in the right-side column, “Resources for you.” Here’s where I’ll keep links to bits and pieces that many of you will find relevant and interesting.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3130067" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 16:42:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/passwords remotely">passwords remotely</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/unique passwords based">unique passwords based</category>
      <category domain="http://securityratty.com/tag/relevant">relevant</category>
      <category domain="http://securityratty.com/tag/security remains relevant">security remains relevant</category>
      <category domain="http://securityratty.com/tag/windows network">windows network</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx">Passgen tool from my book</source>
    </item>
    <item>
      <title><![CDATA[4 steps to take control of your mobile devices]]></title>
      <link>http://securityratty.com/article/c91f2a12a9b325b1f76d7e38aa2a9e03</link>
      <guid>http://securityratty.com/article/c91f2a12a9b325b1f76d7e38aa2a9e03</guid>
      <description><![CDATA[Mobile enterprise clients pose new security and management challenges. Here's how you can meet...]]></description>
      <content:encoded><![CDATA[Mobile enterprise clients pose new security and management challenges. Here's how you can meet them.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/wirelessmobile;sz=468x60;ord=72549?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/wirelessmobile;sz=468x60;ord=72549?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management challenges">management challenges</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://www.networkworld.com/news/2008/092508-mobile-security.html?fsrc=rss-security">4 steps to take control of your mobile devices</source>
    </item>
    <item>
      <title><![CDATA[Apple's patch process a mess, say researchers]]></title>
      <link>http://securityratty.com/article/228b9395de6afa0c91349762156ce7ee</link>
      <guid>http://securityratty.com/article/228b9395de6afa0c91349762156ce7ee</guid>
      <description><![CDATA[Apple Inc.'s patching process shows the company isn't serious about moving Macs into the enterprise, two security researchers said, while a dissenting expert, said it was unfair to compare Apple's...]]></description>
      <content:encoded><![CDATA[Apple Inc.'s patching process shows the company isn't serious about moving Macs into the enterprise, two security researchers said, while a  dissenting expert, said it was unfair to compare Apple's patching procedures with  Microsoft Corp.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:92afa412b7e248fa7255773b1f0de9c4:dBLfxVsnZosmL%2BICMqPczQ2a%2FKMFACntaZmpqvwKD4RPJ4QCFRuOr81Zgp5YCVRa82AdvsiA%2FbiK45PjhhWxUn0N3kW1L61gc%2FYTYZ9mO5o%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:c0a8d64c5aac03f039c36fd0378b603a:EwnainbkmaU9N4emY42puq5G%2B9QRVgDt0obaIN7rfFfwE%2FsxOYK55fkMHjMcuqZbOi85gSqd3piG1mWjH33Ci978aHtDxotZeZFAmSWX%2F5E%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:50b47307a05e9767eb9dddb4a81f7159:7RDvm%2FoMG4KicYK6XZrEN9TosGbAJJxOCNOScUslYh13hLp4VPAGi0ZgQniOvzGhN7VTNXtfozYpRu2BYwnHsdpxqBJEM60a2JOBfTgJX2Q%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:c07f78f3d042036b0f03a97a7b314899:lxbzZdByA7SsdYQennZwd6%2BuYizHoeeONPiOb9piaIesb0uWeAfUfZKSN%2BdmMP9ZRFCJ6GCBkmfu2yCp%2FdCWNi4zyidj9ewMA0eLvVq2b1U%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=02b8681504fcf1050566d480cb699b6f"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=02b8681504fcf1050566d480cb699b6f" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=02b8681504fcf1050566d480cb699b6f" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/compare apple">compare apple</category>
      <category domain="http://securityratty.com/tag/microsoft corp">microsoft corp</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/procedures">procedures</category>
      <category domain="http://securityratty.com/tag/enterprise">enterprise</category>
      <category domain="http://securityratty.com/tag/expert">expert</category>
      <category domain="http://securityratty.com/tag/unfair">unfair</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=02b8681504fcf1050566d480cb699b6f">Apple's patch process a mess, say researchers</source>
    </item>
    <item>
      <title><![CDATA[Pieces of the WLAN mgmt. puzzle that cant be solved by WLAN gear vendors ]]></title>
      <link>http://securityratty.com/article/70de91a40d8a68aec42aa3567c72c758</link>
      <guid>http://securityratty.com/article/70de91a40d8a68aec42aa3567c72c758</guid>
      <description><![CDATA[As robust as they are, the management systems shipping with todays WLAN gear are only part of the whole enterprise WLAN management picture. There are several classes of ad-hoc tools that address a...]]></description>
      <content:encoded><![CDATA[As robust as they are, the management systems shipping with today’s WLAN gear are only part of the whole enterprise WLAN management picture. There are several classes of ad-hoc tools that address a number of broad management areas that may not be included in any given management system from a WLAN gear vendor.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/wirelessmobile;sz=468x60;ord=88602?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/wirelessmobile;sz=468x60;ord=88602?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wlan gear vendor">wlan gear vendor</category>
      <category domain="http://securityratty.com/tag/todays wlan gear">todays wlan gear</category>
      <category domain="http://securityratty.com/tag/broad management">broad management</category>
      <category domain="http://securityratty.com/tag/ad-hoc tools">ad-hoc tools</category>
      <category domain="http://securityratty.com/tag/management system">management system</category>
      <category domain="http://securityratty.com/tag/management systems">management systems</category>
      <category domain="http://securityratty.com/tag/classes">classes</category>
      <category domain="http://securityratty.com/tag/robust">robust</category>
      <category domain="http://securityratty.com/tag/address">address</category>
      <source url="http://www.networkworld.com/reviews/2008/092208-wlan-management-side.html?fsrc=rss-security">Pieces of the WLAN mgmt. puzzle that cant be solved by WLAN gear vendors </source>
    </item>
    <item>
      <title><![CDATA[Apple's patch process a mess, say researchers]]></title>
      <link>http://securityratty.com/article/3cfc0da3e75ea66b54976972f0023bab</link>
      <guid>http://securityratty.com/article/3cfc0da3e75ea66b54976972f0023bab</guid>
      <description><![CDATA[Apple's patching process proves that the company isn't serious about moving Macs into the enterprise, security researchers said...]]></description>
      <content:encoded><![CDATA[Apple's patching process proves that the company isn't serious about moving Macs into the enterprise, security researchers said Monday.]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/process proves">process proves</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/enterprise">enterprise</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <category domain="http://securityratty.com/tag/macs">macs</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://www.networkworld.com/news/2008/092208-apples-patch-process-a-mess.html?fsrc=rss-security">Apple's patch process a mess, say researchers</source>
    </item>
    <item>
      <title><![CDATA[XSF & XSS: Double your pleasure, double your fun]]></title>
      <link>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</link>
      <guid>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</guid>
      <description><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less...]]></description>
      <content:encoded><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less familiar with is <a href="http://www.xssed.com/news/26/Cross-site_framed/" target="_blank">cross-site framing</a>, which largely couples the best of both above-mentioned vulnerabilities. <br />What then, if there's a cross-site framing vulnerability coupled with cross-site scripting in the content offered by the frame? All sorts of problems come to mind: phishing, malware, credential theft; all arguably twice removed from the attacker's source, tucked away in the context of two victim sites.<br />First, I'll discuss the original XSS issue that led to this finding.<br />Recently, I was investigating a flawed parameter in <a href="http://www.openhire.com/" target="_blank">Openhire</a>, a career posting vendor used by major companies like <a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?company_id=15635&version=1" target="_blank">Crate&Barrel</a>, Eileen Fisher, Enterprise, Benjamin Moore, Scottrade, and Getty Images.<br />Most of these sites simply link to the Openhire offering that hosts job postings on their behalf which, in turn, has been crafted to look like the referring site.<br />As an example, here's Scottrade's employment page hosted by Openhire.<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624</a></span><br /><br />Standard stuff, looks nicely like the Scottrade site, so everything's cool, right?<br />Wrong? What if someone hosting a service on your behalf suffers a security gap?<br /><span style="font-weight:bold;">You're only as strong as your weakest link!</span><br />Here's the posting for an Application Security Engineer (funny, eh?) at Scottrade as hosted on their behalf by Openhire:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80</a></span><br /><br />Now here the same job posting spewing massive cookie data:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</a></span><br /><br />Screen shot offered below, as the code above will likely be repaired very soon by Openhire. I notified them this past Thursday.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s1600-h/Scottrade_Openhire.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s320/Scottrade_Openhire.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248697340769067154" /></a><br /><br />It's bad enough when there's an application security hole in code someone else is hosting on your behalf, but what if your method of displaying said code is also at risk? Enter the Getty Images Jobs page.<br /><br /><span style="font-style:italic;"><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778</a></span><br /><br />Watch what happens when you pull the Openhire code. Can you say self-replicating frame loop from hell (in Firefox)? Trust me your browser will crash if you leave this running too long. This will likely be fixed soon, so if the URL doesn't work, the screen shot exemplifies the issue.<br /><br /><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html</a><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s1600-h/GettyonGetty.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s320/GettyonGetty.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248710327339022210" /></a><br /><br />What if, instead of Openhire's Getty Images page, or nothing at all (which obviously creates its own issue), we drop in an arbitrary URL?<br />Yep, you guessed it.<br /><span style="font-style:italic;"><br />http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://www.xssed.com/news/26/Cross-site_framed/</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s1600-h/Getty_XSF.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s320/Getty_XSF.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248706395295990562" /></a><br /><br />Now, bringing it all home for double the pleasure, double the fun, what if we coupled the original Openhire cross-site scripting vuln with Getty Images cross-site frame vuln?<br /><br />It hurts twice as much, in my book.<br /><br /><span style="font-style:italic;">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s1600-h/Getty%2BScottrade.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s320/Getty%2BScottrade.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248708789483249346" /></a><br /><br />The lessons learned:<br />1) Ensure your partners are writing secure code on you behalf.<br />2) Ensure that the code you utilize to incorporate said partner's code is also well written. ;-)<br /><br />Double the headache, double the dumb.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html&title=XSF%20&%20XSS:%20Double%20your%20pleasure,%20double%20your%20fun " title="XSF & XSS: Double your pleasure, double your fun ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html" title="XSF & XSS: Double your pleasure, double your fun ">digg</a>]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 17:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/openhire code">openhire code</category>
      <category domain="http://securityratty.com/tag/openhire">openhire</category>
      <category domain="http://securityratty.com/tag/original openhire cross-site">original openhire cross-site</category>
      <category domain="http://securityratty.com/tag/scottrade site">scottrade site</category>
      <category domain="http://securityratty.com/tag/scottrade">scottrade</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/secure code">secure code</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html">XSF &amp; XSS: Double your pleasure, double your fun</source>
    </item>
  </channel>
</rss>
