<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ethical]]></title>
    <link>http://securityratty.com/tag/ethical</link>
    <description></description>
    <pubDate>Thu, 12 Jun 2008 04:38:35 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Another Google Bug Put Users At Phishing Risk Due To Domain Flaw And Frame Injection Possibility]]></title>
      <link>http://securityratty.com/article/a3a826883c2875f86d3d818f4095efc1</link>
      <guid>http://securityratty.com/article/a3a826883c2875f86d3d818f4095efc1</guid>
      <description><![CDATA[A security expert has demonstrated that Googles Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users login credentials....]]></description>
      <content:encoded><![CDATA[A security expert has demonstrated that Google&#8217;s Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users&#8217; login credentials. Google Calendar and other sensitive Google services are susceptible to similar tampering.
A proof-of-concept (PoC) attack, published by Adrian Pastor of the GNUCitizen ethical hacking collective, exploits [...]]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 19:05:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive google services">sensitive google services</category>
      <category domain="http://securityratty.com/tag/users login credentials">users login credentials</category>
      <category domain="http://securityratty.com/tag/spoof pages">spoof pages</category>
      <category domain="http://securityratty.com/tag/adrian pastor">adrian pastor</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/google calendar">google calendar</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/collective">collective</category>
      <source url="http://cyberinsecure.com/another-google-bug-put-users-at-phishing-risk-due-to-domain-flaw-and-frame-injection-possibility/">Another Google Bug Put Users At Phishing Risk Due To Domain Flaw And Frame Injection Possibility</source>
    </item>
    <item>
      <title><![CDATA[250k of Harvested Hotmail Emails Go For?]]></title>
      <link>http://securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</link>
      <guid>http://securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</guid>
      <description><![CDATA[50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/fQ_TqPImTk0/s1600-h/harvested_hotmail_sale.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="113" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/YJqc75ZUQgE/s200-R/harvested_hotmail_sale.png" width="200" /></a>$50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to know about. Moreover, what someone is offering for sale, may in fact be already available as a value-added addition to a managed spamming service.<br />
<br />
With metrics and quality assurance applied in a growing number of spam and phishing campaigns, filling in the niche of email harvesting by distinguishing between different types of obfuscated emails by releasing an easily embeddable module, was an anticipated move. What's to come? <a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Spam and malware campaigns across social networks</a> "as usual" will propagate faster thanks to the ongoing harvesting of usernames within social networks, that would later on get imported in Web 2.0 "marketing" tools targeting the high-trafficked sites and automatically spamming them.<br />
<br />
From a spammer's perspective, geolocating these 250k emails could increase their selling prices since the buyers would be able to launch localized attacks with messages in the native languages of the receipts. Is the demand for quality email databases fueling the developments of this market segment, or are the spammers self-serving themselves and cashing-in by reselling what they've already abused a log time ago? That seems to be the case, since there's no way a buyer could verify the freshness of the harvested emails database and whether or not it has already been abused. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/yhy61idSl6I/s1600-h/segmented_harvested_emails.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="200" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/xFYzYTCaDes/s200-R/segmented_harvested_emails.JPG" width="152" /></a>For the time being, we've got several developed and many other developing market segments within spamming and phishing as different markets with different players. On one hand are the legitimately looking spamming providers offering "direct marketing services" working with lone spammers who find a reliable business partner in the face of the spamming vendor whose customers drive both side's business models. On the other hand, you've got the <a href="http://blogs.zdnet.com/security/?p=1835">spammers excelling in outsourcing the automatic account registration process</a>, coming up with ways to build a spamming infrastructure -- already available as a module to integrate in <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming services</a> -- using legitimate services as a provider of the infrastructure.<br />
<br />
Despite that the arms race seems to be going on at several different fronts, spammers VS the industry and spammers VS spammers fighting for market share, the entire underground ecosystem is clearly allocating a lot of resources for research and development in order to ensure that they are always a step ahead of the industry.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting  Youtube Usernames for Spamming</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands  of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/automatic-email-harvesting-20.html">Automatic  Email Harvesting 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - the Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/inside-email-harvesters-configuration.html">Inside an Email Harvester's Configuration File</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">Segmenting and Localizing Spam Campaigns</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample.html">Shots from the Malicious Wild West - Sample Four</a><br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=De2zL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=De2zL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CYcFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CYcFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OQPDl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OQPDl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lhexl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lhexl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sZRFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sZRFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ifNGL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ifNGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BYibl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BYibl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402968423" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 08:13:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email harvester">email harvester</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/lone spammers">lone spammers</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <category domain="http://securityratty.com/tag/250k emails">250k emails</category>
      <category domain="http://securityratty.com/tag/automatic email">automatic email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402968423/250k-of-harvested-hotmail-emails-go-for.html">250k of Harvested Hotmail Emails Go For?</source>
    </item>
    <item>
      <title><![CDATA[Teaching Hacking at College by Sam Bowne]]></title>
      <link>http://securityratty.com/article/f464683006bea78fdf7801ca7073794b</link>
      <guid>http://securityratty.com/article/f464683006bea78fdf7801ca7073794b</guid>
      <description><![CDATA[This was a DefCon 15 presentation (August 3-5, 2007) by Sam Bowne. Sam does a great job explaining how to teach ethical hacking at a university, and since he gave me a shout out in the video I figured...]]></description>
      <content:encoded><![CDATA[This was a DefCon 15 presentation (August 3-5, 2007) by Sam Bowne. Sam does a great job explaining how to teach ethical hacking at a university, and since he gave me a shout out in the video I figured I'd post it up here. Definitely a must watch if you are trying to convince your college's administration that it's a good idea to teach such a course. Check out Sam's site at <a href="http://www.samsclass.info/">http://www.samsclass.info/</a> if you want to use his teaching curriculum.
<p><a href="http://feedads.googleadservices.com/~a/ffKhJm5iX4Lhl_Vt_8kxxORw8rg/a"><img src="http://feedads.googleadservices.com/~a/ffKhJm5iX4Lhl_Vt_8kxxORw8rg/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/elG29TYNdzQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 16:15:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sam">sam</category>
      <category domain="http://securityratty.com/tag/sam bowne">sam bowne</category>
      <category domain="http://securityratty.com/tag/college">college</category>
      <category domain="http://securityratty.com/tag/administration">administration</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/ethical">ethical</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/elG29TYNdzQ/i.php">Teaching Hacking at College by Sam Bowne</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</link>
      <guid>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3">Download the show here</a> (MP3, 19MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the hiatus</li>
	</ul>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/">Are your Skype username and password completely exposed if you use iSkoot?</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/chronology-of-the-blogosphere-and-iskoot-weekend-response-to-the-iskoot-security-issue/">Chronology</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/iskoot-disclosure-of-skype-credentials-resolved-new-version-by-wednesday/">iSkoot disclosure of Skype credentials resolved &#8211; new version by Wednesday</a></li>
<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a> &#8211; and Hannes Tschofenig points to <a href="http://www.emergency-services-coordination.info/esw4.html">4th Emergency Services Coordination Workshop</a> and <a href="http://www.tschofenig.priv.at/twiki/pub/EmergencyServices/EswAgenda2008/BT-ES_SDO_April_08.ppt">presentation about the UK</a></li>
<li>MarketingVOX: <a href="http://www.marketingvox.com/british-proposal-may-force-isps-to-fork-over-online-activity-emails-voip-calls-038702/">British Proposal May Force ISPs to Fork Over Online Activity, Emails, <span class="caps">VOIP </span>Calls</a> pointing to Reuters article: <a href="http://www.reuters.com/article/lifestyleMolt/idUSL2076461020080520">Britain mulls plan to store all email and calls</a></li>

<p><li>Enterprise VoIP Planet: <a href="http://www.voipplanet.com/solutions/article.php/3747161">VoIP Security: <span class="caps">SIP</span>-Versatile but Vulnerable</a></li><br />
		<li><span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/cip/?p=343">Pay Attention to VoIP Security Before The Storm</a></li></p>

<p><li>NetworkWorld: <a href="http://www.pcworld.com/businesscenter/article/145272/guide_to_voip_security.html">Business Guide to VoIP Security</a></li><br />
<li>Pocket-lint: <a href="http://www.pocket-lint.co.uk/news/news.phtml/14768/15792/Fraudsters-targeting-internet-phone-services.phtml">Fraudsters targeting VoIP Users</a> based on <a href="http://www.voip-news.co.uk/2008/05/21/newport-networks-highlights-voip-security/">report out of Newport Networks</a> (reported in VoIP News) &#8211; also covered at Fierce VoIP: <a href="http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18">Newport Networks riles up VoIP Security Fears</a> and Computeractive: <a href="http://www.computeractive.co.uk/personal-computer-world/news/2216851/phreak-voip">Phreak-out over VoIP</a> and <a href="http://www.thetechherald.com/article.php/200821/1017/Newport-Networks-raises-VoIP-identity-theft-concerns">TechHerald article</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2008/042808converge1.html">Security and management considerations when deploying <span class="caps">OCS</span></a></li><br />
<li>LXer: <a href="http://lxer.com/module/newswire/view/102328/">Secure Calling Initiative Reaches Second Milestone</a> pointing to <a href="http://www.gnutelephony.org/index.php/Secure_Call">Secure Calling Initiative</a></li><br />
	<br />
	<li>[H]Enthusiast: <a href="http://www.hardocp.com/news.html?news=MzI0NjMsLCxoZW50aHVzaWFzdCwsLDE">Mobile Phones, VoIP Not Secure, Experts Warn</a>=</li><br />
	<br />
	<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-privacy-042308/">The Essential Guide to VoIP Privacy</a></li><br />
	<br />
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/18/information-week-interviews-securelogix-about-voip-security/">Information Week interviews SecureLogix about VoIP security</a></li><br />
<li>eWeek: <a href="http://www.eweek.com/c/a/Knowledge-Center/VoIP-Security-through-Responsible-Software-Development/">VoIP Security through Responsible Software Development</a></li><br />
<li><a href="http://techdirt.com/articles/20080429/095514977.shtml">Microsoft gives back door keys to Vista to police</a></li><br />
<li>Comment (blog) from <a href="http://www.blueboxpodcast.com/2008/03/blue-box-77-sky.html#comment-108655562">Martyn Davies</a></li><br />
		<li>Comment (email) from Detlef</li><br />
		<li>Comment (email) from Dan McGinn-Combs</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>41:43 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=labVEA"><img src="http://feeds.feedburner.com/~a/BlueBox?i=labVEA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=PJqInK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=PJqInK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=DKnQRK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=DKnQRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=0ojlsK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=0ojlsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=zQkKxK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=zQkKxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=j1XWBk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=j1XWBk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=t89cyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=t89cyK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/375722849" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 16:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip users based">voip users based</category>
      <category domain="http://securityratty.com/tag/enterprise voip planet">enterprise voip planet</category>
      <category domain="http://securityratty.com/tag/voip calls">voip calls</category>
      <category domain="http://securityratty.com/tag/voip privacy">voip privacy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/375722849/blue-box-81-isk.html">Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Security Assessments as Fraud, Waste, and Abuse]]></title>
      <link>http://securityratty.com/article/d54a2c8a9fbbd6efa3d8d80caadc1a71</link>
      <guid>http://securityratty.com/article/d54a2c8a9fbbd6efa3d8d80caadc1a71</guid>
      <description><![CDATA[Im going to put on my Government Security Heretic Hat for awhile here, bear me out. By my estimate, half of the security assessments received by the Government have some kind of fraud, waste, and...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;m going to put on my Government Security Heretic Hat for awhile here, bear me out.  By my estimate, half of the security assessments received by the Government have some kind of fraud, waste, and abuse.</p>
<p>What makes me say this is the amount of redundancy in some testing that I&#8217;ve seen without any value added.</p>
<p>The way to avoid this redundancy is the concept of common/shared controls.  The whole idea is that you take whatever security controls you have across the board and put them into one bucket.  You test that bucket once and then whenever something  shares controls with that bucket, you look at the shared control bucket and make sure that the assessment is still relevant and accurate.</p>
<p>So, what makes a security assessment not fraud, waste, and abuse?  It&#8217;s a good assessment if it does the following:</p>
<ul>
<li>Does not repeat a previous assessment.</li>
<li>Discovers previously-undiscovered vulnerabilities, weaknesses, or findings.</li>
<li>Has findings that get fed into a risk management plan (accepted, avoided, transferred, etc&#8211;think POA&amp;M).</li>
<li>Is not exhaustive when it doesn&#8217;t need to be.</li>
<li>Provides value to the project team, system owner, and Authorizing Official to make key decisions.</li>
</ul>
<p>Now the problem is that the typical auditor has a hard time stopping&#8211;they have an ethical obligation to investigate anything that their &#8220;professional skepticism&#8221; tells them is out of place, just like cops have an ethical obligation to investigate anything that they think is a crime.</p>
<p>The Solution?  Don&#8217;t use auditors! The public accounting model that we adopted for information security does not scale the way that we need it to for ST&amp;E, and we need to understand this in order to fix security in the Government.</p>
<p>What we need to be doing is Security Test and Evaluation which is focused on risk, not on compliance using a checklist of control objectives.  Usually if you know enough to say &#8220;Wow, your patch management process is whacked, you&#8217;re at a high risk!&#8221; then that&#8217;s enough to stop testing patch management controls.  This is one of the beefs I have with 800-53A in the hands of less-than-clueful people:  they will test until exhaustion.</p>
<p>There isn&#8217;t a whole lot of difference between ST&amp;E and an audit, just the purpose.  Audits are by nature confrontational because you&#8217;re trying to prove that fraud, waste, and abuse hasn&#8217;t occured.  ST&amp;E is helping the project team find things that they haven&#8217;t thought of before and eventually get the large problems funded and fixed.</p>
<p style="text-align: center;"><em><img src="http://farm3.static.flickr.com/2419/2491873473_0acd6805d1.jpg?v=0" alt="The Little Frauds Songbook" width="385" height="500" /></em></p>
<p style="text-align: center;"><em>The Little Frauds Harrigan &amp; Hart&#8217;s Songs &amp; Sketches Photo by <a href="http://www.flickr.com/photos/boston_public_library/" target="_blank">Boston Public Library</a></em></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/434&amp;title=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Del.icio.us" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/434&amp;title=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to digg" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/434&amp;title=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to reddit" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse&amp;url=http://www.guerilla-ciso.com/archives/434&amp;version=0.7" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Feed Me Links" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/434" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Technorati" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/434&amp;t=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Yahoo My Web" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/434&amp;title=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Stumble Upon" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/434&amp;title=Security+Assessments+as+Fraud%2C+Waste%2C+and+Abuse" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Google Bookmarks" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/434" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Squidoo" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/434" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Security Assessments as Fraud, Waste, and Abuse' to Bloglines" alt="Add 'Security Assessments as Fraud, Waste, and Abuse' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=z2EthJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=z2EthJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=tQtoJj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=tQtoJj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/338409934" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 17:34:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/controls">controls</category>
      <category domain="http://securityratty.com/tag/security controls">security controls</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/shares controls">shares controls</category>
      <category domain="http://securityratty.com/tag/waste">waste</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/security assessment">security assessment</category>
      <category domain="http://securityratty.com/tag/bucket">bucket</category>
      <category domain="http://securityratty.com/tag/control bucket">control bucket</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/338409934/434">Security Assessments as Fraud, Waste, and Abuse</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</link>
      <guid>http://securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 13:20:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://www.blueboxpodcast.com/2008/07/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</link>
      <guid>http://securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=fNSqdO"><img src="http://feeds.feedburner.com/~a/BlueBox?i=fNSqdO" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=lbjc2J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lbjc2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=7bk2TJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7bk2TJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=3wwMDJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=3wwMDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=sD0qZJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=sD0qZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Y7dDJj"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Y7dDJj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uKgX6J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uKgX6J" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/336458984" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 12:22:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/336458984/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Attention - Lawyers and Private Investigators!]]></title>
      <link>http://securityratty.com/article/4008bfcd8922c7f6396c4d8d4a5e179a</link>
      <guid>http://securityratty.com/article/4008bfcd8922c7f6396c4d8d4a5e179a</guid>
      <description><![CDATA[Lawyers are always in need of process servers to serve civil papers. More often than not, they use the services of a Private Investigator or process service company

If the P.I. or process server is...]]></description>
      <content:encoded><![CDATA[Lawyers are always in need of process servers to serve civil papers.  More often than not, they use the services of a Private Investigator or process service company.   <br /><span id="fullpost"><br />If the P.I. or process server is credible and ethical, there should not be a problem.  If on the other hand, the server "claims" to have served the paper, charges the Law Firm for services rendered but does not actually effect the necessary service, it could be the makings of a significant lawsuit.  This is what happened in Massachusetts.   <br /></span><br />The plaintiff in <a href="http://www.law.com/jsp/article.jsp?id=1202422391413">that case</a>was awarded $3,000,000.00 when the State Court ruled that the Bermuda businessman, Donald P.Lines, had not been served by the company hired to effect the service, Boston based "Stokes & Levin". It later transpired that the company had used pre-fabricated stamps of the signature of a process server who no longer worked for the company.  It did not enhance the image of the Securities and Exchange Commission either as the SEC were the ones who hired "Stokes & Levin".<br /><br />I have heard stories of one elderly P.I. in Virginia who gets confused when he serves civil papers and sometimes puts the same time on two different papers even when they are served 20 miles or more apart.  Yet, he continues to get requests for service from lawyers that he has known a while.  I hope this story serves as a reminder to him and those who hire him that you stand to lose a lot if you don't get it right - both in reputation and finacial terms.  There's no shame in hanging up the gun belt when the sun starts to set on your career.  It's always better to go out a winner than a defendant.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 21:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/company hired">company hired</category>
      <category domain="http://securityratty.com/tag/process service company">process service company</category>
      <category domain="http://securityratty.com/tag/serves civil papers">serves civil papers</category>
      <category domain="http://securityratty.com/tag/papers">papers</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/process server">process server</category>
      <category domain="http://securityratty.com/tag/lawyers">lawyers</category>
      <source url="http://www.thebulletproofblog.com/2008/06/attention-lawyers-and-private.html">Attention - Lawyers and Private Investigators!</source>
    </item>
    <item>
      <title><![CDATA[EU bloggers under assault by the European Parliament - they need your help]]></title>
      <link>http://securityratty.com/article/42471dd2ecc3d3795053ea76949e5eeb</link>
      <guid>http://securityratty.com/article/42471dd2ecc3d3795053ea76949e5eeb</guid>
      <description><![CDATA[One of the nice things about having started the SBN was that I have gotten to meet (mostly virtually) many security bloggers from around the world. Some of the most prolific contributors to the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the nice things about having started the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed" target="_blank">SBN</a> was that I have gotten to meet (mostly virtually) many security <a class="zem_slink" title="Blog" href="http://en.wikipedia.org/wiki/Blog" rel="wikipedia">bloggers</a> from around the world.&nbsp; Some of the most prolific contributors to the content of the SBN has been the members of the <a href="http://pipes.yahoo.com/pipes/pipe.run?_id=ViJDI2KQ3BGXtQrlnkartA&amp;_render=rss" target="_blank">Belgian Security Bloggers Network</a>.&nbsp; I received word today from one of the authors of one of the blogs, <a href="http://belsec.skynetblogs.be/post/5962674/alarm--european-parliament-wants-to-take-on-b" target="_blank">belsec</a>, that they are under assault by the EU government.&nbsp; It seems in their wisdom, the <a href="http://www.europarl.europa.eu/meetdocs/2004_2009/documents/pr/712/712320/712320en.pdf" target="_blank">European Parliament has decided</a> that in the interests of &quot;media pluralism&quot;, all blog owners should declare their ownership, affiliations and status of weblog authors.</p>

<p>The explanatory notes of the proposed regulation says this:</p><blockquote><p><em>In this context the report points out that the undetermined and unindicated status of authors and publishers of weblogs causes uncertainties regarding impartiality, reliability, source protection, applicability of ethical codes and the assignment of liability in the event of lawsuits.<br />It recommends clarification of the legal status of different categories of weblog authors and publishers as well as disclosure of interests and voluntary labelling of weblogs.</em></p></blockquote><p>As the belsec author points out, disclosure of their identities would effectively silence their voices.&nbsp; There is no first amendment freedom of speech or <a class="zem_slink" title="Freedom of the press" href="http://en.wikipedia.org/wiki/Freedom_of_the_press" rel="wikipedia">freedom of press</a> constitutional right in Europe. Of course if forced to do so, the Belgian authors could take up blogs based here in the US and escape the disclosure laws of the EU, but why should they have too.&nbsp; The EU is a democratic, progressive entity.&nbsp; Forcing these bloggers to make their &quot;status and identity&quot; public should not be mandatory here.</p>

<p>Blogs are todays pamphlets.&nbsp; Basic <a class="zem_slink" title="Freedom of speech" href="http://en.wikipedia.org/wiki/Freedom_of_speech" rel="wikipedia">freedom of expression</a>, speech and press have been protected for hundreds of years. Forcing these bloggers to identify themselves is a violation of their rights.&nbsp; What would <a class="zem_slink" title="Thomas Paine" href="http://en.wikipedia.org/wiki/Thomas_Paine" rel="wikipedia">Thomas Paine</a> and others like him think of this restriction? </p>

<p>If you feel that this is an unfair and unjust restriction on bloggers rights, blog about it. It is our right and to do so and we should use the medium to do so.&nbsp; If you are a EU citizen write to your representative and demand that this proposed regulation does not go into effect!</p>

<p>Do not take your right to blog lightly.&nbsp; If you don't stand up for it, it can be taken away from you.</p>

<p><em>&quot;The world is my country, all mankind are my brethren, and to do good is my religion.&quot; - </em>Thomas Paine </p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/4f5ed85c-539c-4c67-8e62-8644ef78190e/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=4f5ed85c-539c-4c67-8e62-8644ef78190e" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 05:38:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://securityratty.com/tag/weblog authors">weblog authors</category>
      <category domain="http://securityratty.com/tag/authors">authors</category>
      <category domain="http://securityratty.com/tag/bloggers rights">bloggers rights</category>
      <category domain="http://securityratty.com/tag/freedom">freedom</category>
      <category domain="http://securityratty.com/tag/legal status">legal status</category>
      <category domain="http://securityratty.com/tag/blog owners">blog owners</category>
      <category domain="http://securityratty.com/tag/basic freedom">basic freedom</category>
      <category domain="http://securityratty.com/tag/status">status</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/eu-bloggers-und.html">EU bloggers under assault by the European Parliament - they need your help</source>
    </item>
    <item>
      <title><![CDATA[EU bloggers under assault by the European Parliament - they need your help]]></title>
      <link>http://securityratty.com/article/495d89a1106383a495fba74b3adf8fdb</link>
      <guid>http://securityratty.com/article/495d89a1106383a495fba74b3adf8fdb</guid>
      <description><![CDATA[One of the nice things about having started the SBN was that I have gotten to meet (mostly virtually) many security bloggers from around the world. Some of the most prolific contributors to the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the nice things about having started the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed" target="_blank">SBN</a> was that I have gotten to meet (mostly virtually) many security bloggers from around the world.&nbsp; Some of the most prolific contributors to the content of the SBN has been the members of the <a href="http://pipes.yahoo.com/pipes/pipe.run?_id=ViJDI2KQ3BGXtQrlnkartA&amp;_render=rss" target="_blank">Belgian Security Bloggers Network</a>.&nbsp; I received word today from one of the authors of one of the blogs, <a href="http://belsec.skynetblogs.be/post/5962674/alarm--european-parliament-wants-to-take-on-b" target="_blank">belsec</a>, that they are under assault by the EU government.&nbsp; It seems in their wisdom, the <a href="http://www.europarl.europa.eu/meetdocs/2004_2009/documents/pr/712/712320/712320en.pdf" target="_blank">European Parliament has decided</a> that in the interests of "media pluralism", all blog owners should declare their ownership, affiliations and status of weblog authors.</p> <p>The explanatory notes of the proposed regulation says this:</p> <blockquote> <p><em>In this context the report points out that the undetermined and unindicated status of authors<br>and publishers of weblogs causes uncertainties regarding impartiality, reliability, source<br>protection, applicability of ethical codes and the assignment of liability in the event of<br>lawsuits.<br>It recommends clarification of the legal status of different categories of weblog authors and<br>publishers as well as disclosure of interests and voluntary labelling of weblogs.</em></p></blockquote> <p>As the belsec author points out, disclosure of their identities would effectively silence their voices.&nbsp; There is no first amendment freedom of speech or freedom of press constitutional right in Europe. Of course if forced to do so, the Belgian authors could take up blogs based here in the US and escape the disclosure laws of the EU, but why should they have too.&nbsp; The EU is a democratic, progressive entity.&nbsp; Forcing these bloggers to make their "status and identity" public should not be mandatory here.&nbsp; </p> <p>If you feel that this is a restriction on bloggers rights, blog about it. It is our right and to do so and we should use the medium to do so.&nbsp; If you are a EU citizen write to your representative and demand that this proposed regulation does not go into effect!</p> <p>Do not take your right to blog lightly.&nbsp; If you don't stand up for it, it can be taken away from you.</p> <p><em>"The world is my country, all mankind are my brethren, and to do good is my religion." - </em>Thomas Paine </div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=RZd6mh"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=RZd6mh" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cFCkbI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cFCkbI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2okMgI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2okMgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YN5ouI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YN5ouI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ApS9WI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ApS9WI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=oYLcIi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=oYLcIi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ebgmPi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ebgmPi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/310405700" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 04:38:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://securityratty.com/tag/weblog authors">weblog authors</category>
      <category domain="http://securityratty.com/tag/authors">authors</category>
      <category domain="http://securityratty.com/tag/legal status">legal status</category>
      <category domain="http://securityratty.com/tag/blog owners">blog owners</category>
      <category domain="http://securityratty.com/tag/status">status</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/bloggers rights">bloggers rights</category>
      <category domain="http://securityratty.com/tag/european parliament">european parliament</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/310405700/eu-bloggers-und.html">EU bloggers under assault by the European Parliament - they need your help</source>
    </item>
  </channel>
</rss>
