<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: functionality]]></title>
    <link>http://securityratty.com/tag/functionality</link>
    <description></description>
    <pubDate>Tue, 29 Jul 2008 02:49:15 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Golf Driven Security]]></title>
      <link>http://securityratty.com/article/97c3f2f6b2c052ca89495ba3c65d43d2</link>
      <guid>http://securityratty.com/article/97c3f2f6b2c052ca89495ba3c65d43d2</guid>
      <description><![CDATA[I don't have anything against the sport, in fact I think that if the software security people want to get in the enterprise security game they have to get a lot better at golf. I blogged about how the...]]></description>
      <content:encoded><![CDATA[<p><span style="font-size: 13px; font-family: Helvetica; ">I don&#39;t have anything against the sport, in fact I think that if the software security people want to get in the enterprise security game they have to get a lot better at golf. I </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/software-security-market.html"><span style="font-size: 13px; font-family: Helvetica; ">blogged</span></a><span style="font-size: 13px; font-family: Helvetica; "> about how the network security sector is about fifteen times larger than software security sector, prompting one person to write saying that we have invested wisely in network security, eliminated the problems and will address the software security problem with internal processes and tools.</span></p><p><span style="font-size: 13px; font-family: Helvetica; "><br /></span></p><div><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; "><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: Helvetica; ">The problem is that compared to software security we are clearly overspending on network security, the hardware/software is unchanged for a decade - </span><span style="font-weight: bold; font-size: 13px; font-family: Helvetica; ">in any other area of computing the cost would be falling like a rock (</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: Helvetica; ">how much would 1995 version of Oracle or Windows cost now? 5 cents on the dollar, yet CISOs still cut $900M worth of checks to Checkpoint each year). The problem is&#160;there is no market effect because the CISO&#39;s budget keeps increasing and they have no idea what/where/how to spend so they just play golf with their Checkpoint rep and send in the renewal.&#160;</span></span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="font-size: 13px; font-family: Helvetica; "><br /></span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: Helvetica; ">Internal processes and tools are necessary yet nowhere near sufficient to &quot;solve&quot; software security. One reason we &quot;have gotten rid of&quot; network attacks is that no one cares. its a 1990s 31337 attacker goal, not a mafia enterprise goal (botnets aside). business, be they legit or criminal, wants data and functionality. so its all about apps and data. we are just at the very begining crawl stage of even understanding how to solve these problems. That&#39;s why when i hear security consultants harsh on something like static analysis I just laugh. are they better than a top 1% resource in the world? no way. do we have a multi billion dollar gap to close? ya sure, ya betcha. We need things that scale.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; min-height: 14px; font-size: 13px; font-family: Helvetica; "><br /></span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: Helvetica; ">People dont write their own virus protection, but for some reason attempt to do their own input validation, it is the same exact problem. people routinely write their own authentication, authorization and audit. i could go on.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; min-height: 14px; font-size: 13px; font-family: Helvetica; "><br /></span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: Helvetica; ">I have rarely seen an industry so ripe for disruptive innovation as software security.&#160;</span></p><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div></div>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 13:00:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/software security sector">software security sector</category>
      <category domain="http://securityratty.com/tag/software security people">software security people</category>
      <category domain="http://securityratty.com/tag/network security sector">network security sector</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/golf">golf</category>
      <category domain="http://securityratty.com/tag/internal processes">internal processes</category>
      <category domain="http://securityratty.com/tag/reason attempt">reason attempt</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/golf-driven-security.html">Golf Driven Security</source>
    </item>
    <item>
      <title><![CDATA[The web browser is sick but wheres the cure?]]></title>
      <link>http://securityratty.com/article/c1a26694b7d3db2c185a5f976e06cc90</link>
      <guid>http://securityratty.com/article/c1a26694b7d3db2c185a5f976e06cc90</guid>
      <description><![CDATA[Blogger: Ramon Krikken
The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Ramon Krikken</p>

<p>The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it does by itself, and other parts are taken care of by handlers and plug-ins. In doing so, it displays hypertext, images, videos, and even runs active content like Flash, JavaScript, and ActiveX. </p>

<p>But however much we love the browser, we’ve also come to hate the myriad of vulnerabilities that affect it. Everything from cross-site scripting to remote code execution via maliciously formed animated cursor files and Flash content can make browsing a hazardous activity. The browser is sick, and that’s not desirable for a platform we use for important business and personal transactions.</p>

<p>Worsening the browser’s diagnosis is the <a href="http://taossa.com.nyud.net:8080/archive/bh08sotirovdowdslides.pdf">recent paper</a> from Mark Dowd and Alexander Sotirov, sub-titled “Setting back browser security by 10 years,” which discusses how to bypass Microsoft Vista’s memory protection capabilities with some added effort for the exploit designers. It’s not that all of the techniques are necessarily new, but the browser appears to be particularly vulnerable to easy exploitation. </p>

<p>Surprising? Not exactly, when we take into account that the browser is suffering from the same disease as the general purpose operating system: bloat and compatibility. We expect the browser to do ever more, but everything we used it for before still needs to work as if it were yesterday. It feels a bit like people insisting on using a cardboard box as a safe, and wondering why their money keeps getting stolen.</p>

<p>It’s not like we haven’t been working on the browser’s cure, though. There have been some improvements in the browsers themselves, the operating systems have also implemented compensating controls, but most of all, there has been an enormous push for securing the web applications that deliver the data in the first place. Unfortunately, the latter two won’t help secure the browser in the long run.</p>

<p>The first issue is that not all content will come from ‘nice’ servers, the second that the server can only make an educated guess on how a browser will parse and render a given set of data, and the third that operating system controls have their own limitations, whether by design or implementation (for example needing to re-compile existing code to enable certain protections.) The browser, in the end, has to be mostly responsible for keeping itself safe; the operating system must assist it in doing so.</p>

<p>So we’re in a pickle. The browser is sick (and the operating system is too), but it’s hard to cure it without a redesign that will undoubtedly impact compatibility, the ever-so-desired multi-functionality, or its ease of use. We can layer defenses by using web filtering in the enterprise environment, but in the end – for the consumer market in particular – we need to fix the browser itself. I can think of a few things I think might help: </p>

<ul><li>Some kind of <a href="http://people.mozilla.com/~bsterne/site-security-policy/">site security policy</a>&nbsp; to restrict where the browser loads auxiliary content from, and which data it can ‘trust’, when loading a web page (I’d prefer mandatory enforcement, and adding an HTML tag to be able to indicate blocks of untrustworthy data.)</li>

<li>Restricted compartments for plug-ins to run in, ensuring that their bugs cannot easily affect the whole browser.</li>

<li>Better software development practices for the plug-ins and content parsers themselves, so that they’re less vulnerable, and compiled with the latest protection measures to begin with.</li></ul>

<p>All of this means more work, and some of it means a lot of unhappy reactions when things stop working. Even then we will of course still have to deal with additional vulnerabilities, such as those that may be present in hardware, but we will at least have taken prudent steps to ‘find a cure.’</p>

</div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/364862623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 07:11:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/web browser">web browser</category>
      <category domain="http://securityratty.com/tag/browser appears">browser appears</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/cure">cure</category>
      <category domain="http://securityratty.com/tag/browser security">browser security</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/runs active content">runs active content</category>
      <category domain="http://securityratty.com/tag/browsers cure">browsers cure</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/364862623/the-web-browser.html">The web browser is sick but wheres the cure?</source>
    </item>
    <item>
      <title><![CDATA[Automated Spim on Microblogging Site Via MSN Messenger]]></title>
      <link>http://securityratty.com/article/e5a1fb1ee8285e5dda0e9ae590ea20f2</link>
      <guid>http://securityratty.com/article/e5a1fb1ee8285e5dda0e9ae590ea20f2</guid>
      <description><![CDATA[There's been a fair amount of Twitter coverage recently, but it's worth noting that other countries have their own versions of Twittering and some of them have seem to be a little easier to use in...]]></description>
      <content:encoded><![CDATA[
        There's been a fair amount of <a href="http://blogs.zdnet.com/security/?p=1640">Twitter coverage</a> recently, but it's worth noting that other countries have their own versions of Twittering and some of them have seem to be a little easier to use in conjunction with Instant Messaging, whereas Twitter still seems to have a need for <a href="http://www.twittermsn.com/">third party services</a>, <a href="http://kunal.kundaje.net/twessenger/">add-ins</a> and <a href="http://www.theyagar.com/2008/01/30/twitter-bot-for-yahoo/">other tools</a> to get the job done if the service used is something other than Google Talk, Livejournal Chat or Jabber (if it's now more straightforward for other clients too, please let me know!)<br /><br />Either way, the below illustrates why adding Instant Messaging features to services such as Twitter can cause problems in the long run and needs to be considered carefully.<br /><br />We were alerted to the fact that a large amount of Spam seemed to be coming out of China in the last day or two (indeed, one contact mentioned to me that this particular message had been sent to their Honeypot around 29,000+ times, which is a lot of spamming for one URL however you look at it). The spam in question seemed to have been sent via a Spambot, and the only mentions of this URL so far in search engines seems to be related to China - shall we take a look?<br /><br />The URL in question (with part of it redacted) is<br /><br />http: //5834******/ ;)<br /><br />You'll notice the spam is short, snappy and also includes a little smiley-face thing at the end. In fact, it looks a little bit like the kind of link people send to their contacts on Twitter, doesn't it?<br /><br />Well, let's see - a quick search and we find this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf1.html" onclick="window.open('http://blog.spywareguide.com/images/fanf1.html','popup','width=780,height=584,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf1-thumb-380x284.jpg" alt="fanf1.jpg" class="mt-image-none" style="" height="284" width="380" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />A page from Fanfou.com, which I believe is a Chinese site "<a href="http://www.twittown.com/fanfou">inspired</a>" by Twitter with much of the same features and functionality. In fact, it has one feature working straight off the bat that Twitter users previously had to rely on <a href="http://kunal.kundaje.net/twessenger/">plugins</a> for - the ability to send messages to their page via MSN Messenger updates.<br /><br />http: //5834****** doesn't actually resolve anywhere - however, a quick Ping to that address and we have an IP:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf3.html" onclick="window.open('http://blog.spywareguide.com/images/fanf3.html','popup','width=452,height=212,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf3-thumb-352x165.jpg" alt="fanf3.jpg" class="mt-image-none" style="" height="165" width="352" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Type the IP address into the browser, and via some geolocational technology, you'll see a region specific version of the following dating website:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf4.html" onclick="window.open('http://blog.spywareguide.com/images/fanf4.html','popup','width=780,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf4-thumb-380x274.jpg" alt="fanf4.jpg" class="mt-image-none" style="" height="274" width="380" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Go back to the page on Fanfou.com, scroll down and select any of the clickable links and surprise - the same page appears. This particular account on Fanfou has something like 30+ pages devoted to endless Spim links via MSN. They link to placeholder pages, sites that look as though they've been suspended and / or deleted with no way to determine what content was there previously - all interspersed with "Twitter" style messages throughout such as this:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fanf5.jpg" src="http://blog.spywareguide.com/images/fanf5.jpg" class="mt-image-none" style="" height="27" width="208" /></span>
<br /><br />Again, note everything is coming via MSN. By this point, you're probably wondering exactly how they allow you to send messages to their Twitter-style pages. Well, the solution is quite clever - check out the <a href="http://help.fanfou.com/im.html">IM page</a>. You enter your MSN address, and when you login to your MSN account, you'll suddenly find you have a new IM buddy who wants to be a contact:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fanf6.jpg" src="http://blog.spywareguide.com/images/fanf6.jpg" class="mt-image-none" style="" height="189" width="475" /></span>
<br /><br />Add it, and whenever you want to put a message on your page, send it an <a href="http://blog.spywareguide.com/image/fanf7.jpg">instant message</a> and, lo and behold, your Tweet-style message has appeared on your page:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf8.html" onclick="window.open('http://blog.spywareguide.com/images/fanf8.html','popup','width=541,height=241,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf8-thumb-341x151.jpg" alt="fanf8.jpg" class="mt-image-none" style="" height="151" width="341" /></a></span><br /><br />Click to Enlarge<br /></div><br />In conclusion, the steps here appear to be<br /><br /><b>1)</b> Create a Spambot that infects users via MSN Messenger<br /><b>2)</b> Tailor the messages it sends to be short and sweet, just like a Twitter-style message<br /><b>3)</b> Set up an account on a service such as Fanfou.com that makes it easy to send messages to your page via MSN Messenger (or other IM services affected by your bot)<br /><b>4)</b> Infect the PC running your MSN Messenger account then watch as it spams the userpage with whatever messages you want it to send.<br /><br />Of course, the links can be anything from dating sites and ringtone adverts to infection files and exploits - all made so much more easier (and far less time consuming than manually typing in URLs to your userpage) by the functionality built into the site you happen to be using. It's also worth noting that the accounts sending the Spim don't <i>have</i> to be set up by the spammer - they could be compromised accounts that had been hijacked when clicking a rogue IM link, which is a great way of filling out the spamming ranks very quickly.<br /><br />This is definitely something Twitter - and any other site out there involved in <a href="http://en.wikipedia.org/wiki/Micro-blogging">microblogging</a> - need to keep an eye out for, and consider carefully when thinking of adding integration with popular Instant Messaging clients.<br /><br />We detect the file sending the weblinks via MSN as <a href="http://www.spywareguide.com/product_show.php?id=32320">Foubot</a>.<br /><br />Research and Writeup: Christopher Boyd, Director of Malware Research<br />Additional Research: Chris Mannon, Senior Threat Researcher<br /><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 17:12:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/msn messenger">msn messenger</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/msn messenger account">msn messenger account</category>
      <category domain="http://securityratty.com/tag/twitter-style message">twitter-style message</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/msn account">msn account</category>
      <category domain="http://securityratty.com/tag/twitter-style pages">twitter-style pages</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <source url="http://blog.spywareguide.com/2008/08/automated-spim-on-microbloggin.html">Automated Spim on Microblogging Site Via MSN Messenger</source>
    </item>
    <item>
      <title><![CDATA[The Four Horsemen of CLeopatra's Barge]]></title>
      <link>http://securityratty.com/article/1b20cf9bfdb87d0ef87e844686ac5d49</link>
      <guid>http://securityratty.com/article/1b20cf9bfdb87d0ef87e844686ac5d49</guid>
      <description><![CDATA[One of the more interesting session I went to yesterday was a talk by Chris Hoff called &quot; The Four Horsemen of the Virtualization Apocalypse .&quot; (If you've never read Hoff's blog, you should check it...]]></description>
      <content:encoded><![CDATA[<img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="151" alt="hoff-4horsemen" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/TheFourHorsemenofCLeopatrasBarge_AA28/hoff-4horsemen_3.png" width="200" align="left" border="0">  <p>One of the more interesting session I went to yesterday was a talk by <a href="http://rationalsecurity.typepad.com/about.html" target="_blank">Chris Hoff</a> called "<a href="https://www.blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Hoff">The Four Horsemen of the Virtualization Apocalypse</a>."&nbsp; (If you've never read Hoff's blog, you should check it out at <a title="http://rationalsecurity.typepad.com/" href="http://rationalsecurity.typepad.com/">http://rationalsecurity.typepad.com/</a>.)</p> <p>I thought I was keeping a close eye on security and virtualization issues, but this talk illustrated how wide and varied the topic really is.&nbsp; This was not about Blue Pill and it wasn't about having security monitors in the hypervisor - instead he focused on how virtualizing physical devices (e.g. switches, systems) will cause lots of problems for security architects and administrators.</p> <p>Briefly, here are the four horsemen:</p> <ul> <li>Conquest - Translating your physical capacity planning implementation to virtual devices probably won't work.  <li>Death - Virtualized networks lack several physical attributes assumed by security applications and high-availability devices today - you'll probably have to re-architect it all to get the same functionality, which might not even be possible in your new virtual world  <li>War - Adding security VAs takes away precious resources that could have been used to dynamically add VMs.&nbsp; It is a war of resources.  <li>Famine - With all of the redesigning and accommodation happening, security costs are going to eat into any savings you make on server consolidation.</li></ul> <p>Now, if you want to read the much more thorough version, see Hoff's original post <a href="http://rationalsecurity.typepad.com/blog/2008/04/the-four-horsem.html" target="_blank">here</a>.</p> <p>&nbsp;</p> <p>Okay, how does this all relate to the title of my post?&nbsp; Not much.&nbsp; However, <em><strong>much</strong></em> later on day one, things really started rolling.</p> <p>After being crowded out of the Shadow Bar, a bunch of us ended up over at <a href="http://www.vegas.com/nightlife/bars/casafuente.html">Casa Fuente</a> (A cigar bar in Caesars forum).&nbsp; Five minutes after arriving, someone spilled a drink in my lap, big fun!&nbsp; It turns out that it was <a href="http://www.stepto.com" target="_blank">Stepto's</a> birthday, and Hoff makes sure everyone has a drink and we all sing happy birthday to Stepto.&nbsp; Check out part of it, courtesy of <a href="http://blog.uncommonsensesecurity.com/" target="_blank">Jack Daniel</a>:</p> <p> <object type="application/x-shockwave-flash" height="300" width="400" data="http://www.flickr.com/apps/video/stewart.swf?v=55430" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000">     <embed type="application/x-shockwave-flash" src="http://www.flickr.com/apps/video/stewart.swf?v=55430" bgcolor="#000000" allowfullscreen="true" flashvars="intl_lang=en-us&amp;photo_secret=100e925a17&amp;photo_id=2742128920" height="300" width="400"></embed></object> </p> <p>Immediately after the toast, <a href="http://securityuncorked.squarespace.com/security-uncorked/">Jennifer Jabbusch</a> knocks over a table, falls to the floor and begins having a seizure. Stepto rushes over, trying to help, and just about that time, she flips over and starts laughing - total fakeout! Everybody bursts out laughing. </p> <p>Shortly after that, they closed for the night and kicked us out and we all headed over to Cleopatra's Barge. There weren't enough seats or tables for us, but I noticed that the "reserved" barge seating was empty. Drawing upon a clever technique (i.e. sometimes called "asking") I social engineered a waitress into letting us have the reserved area. Within mere minutes, several security geeks are on the dance floor, doing us proud. </p> <p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="260" alt="hoff-cleopatra2" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/TheFourHorsemenofCLeopatrasBarge_AA28/hoff-cleopatra2_6.jpg" width="200" align="right" border="0"></p> <p>This leads me to the Four Horsemen of Cleopatra's Barge.&nbsp; (Though I was out there too, I am excluding myself since simply because I can.)</p> <ul> <li>JJ, for leadership</li> <li>Hoff, who owned the dance floor.</li> <li>Ryan Naraine, for getting low, low, low</li> <li>David, for letting his hair down.</li></ul> <p>Though our collective dancing does not signal the end of the world, it certainly capped an excellent day</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3102312" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 16:36:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architects">security architects</category>
      <category domain="http://securityratty.com/tag/security vas takes">security vas takes</category>
      <category domain="http://securityratty.com/tag/security geeks">security geeks</category>
      <category domain="http://securityratty.com/tag/security costs">security costs</category>
      <category domain="http://securityratty.com/tag/hoff">hoff</category>
      <category domain="http://securityratty.com/tag/chris hoff">chris hoff</category>
      <category domain="http://securityratty.com/tag/barge">barge</category>
      <category domain="http://securityratty.com/tag/floor">floor</category>
      <source url="http://blogs.technet.com/security/archive/2008/08/07/the-four-horsemen-of-cleopatra-s-barge.aspx">The Four Horsemen of CLeopatra's Barge</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Cross-site scripting CAN be used to hack a server]]></title>
      <link>http://securityratty.com/article/731632e92c0fca2d6e043211ca4b8c08</link>
      <guid>http://securityratty.com/article/731632e92c0fca2d6e043211ca4b8c08</guid>
      <description><![CDATA[Likely you remember when Joseph Pierini at McAfee Secure / Hacker Safe said XSS wasn't important because &quot;cross-site scripting can't be used to hack a server. You may be able to do other things with...]]></description>
      <content:encoded><![CDATA[Likely you remember when Joseph Pierini at McAfee Secure / Hacker Safe said XSS wasn't important because <span style="font-style:italic;">"cross-site scripting can't be used to hack a server. You may be able to do other things with it. You may be able to do things that affect the end-user or the client. But the customer data protected with the server, in the database, isn't going to be compromised by a cross-site scripting attack, not directly."</span><br />That gem has made McAfee <a href="http://pwnie-awards.org/2008/awards.html#lamestvendor" target="_blank">Pwnie</a> worthy (winners announced tomorrow!); may the Lamest Vendor win. <br />That said, anyone with a clue knows that XSS attacks are ideal for credential theft, and if you can steal credentials, you can hack a server.<br />Looking for a textbook example? Check out <a href="http://skeptikal.org/static.php?page=about_mckt" target="_blank">mckt's</a> new blog, <a href="http://skeptikal.org/" target="_blank">skeptikal.org</a>.<br /><span style="font-weight:bold;">Here's a highlight:</span><br /><span style="font-style:italic;">"Every cPanel user's account contains a file titled .contactemail in its home directory. This is used to tell the server and administrators who to email when things go south, and can be changed by the user through the cPanel interface, the file manager tool, FTP, or through local scripts. It's only a text file, after all. Assuming we set our email address to:<br />"onmouseover="alert(1337)<br />When the friendly system administrator tries to reset our email address (because we forgot our password, obviously), he will receive an alert box in his browser.<br />But an alert box doesn't really demonstrate anything. Fortunately the WHM (Web Hosting Manager) interface has enough functionality that we can perform just about any system-level task we want. This one will reset the root password to 'owned':<br />"onmouseover="f=document.forms[0];f.action='/scripts/passwd';f.user.value='root';<br />f.removeChild(f.domain);d=document.createElement('input');f.appendChild(d);<br />d.name='password';d.value='owned';d=document.createElement('input');f.appendChild(d);<br />d.name='password2';d.value='owned';f.submit()<br />Of course, the only limit is your imagination- WHM can set up cron jobs, add and delete users, send full backups to a server of your choice, and reformat hard drives."</span><br /><br />Hmm...I'd say that would be a server hack. ;-)<br />Welcome, Mike...keep up the good work.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/08/cross-site-scripting-can-be-used-to.html&title=Cross-site%20scripting%20can%20be%20used%20to%20hack%20a%20server " title="Cross-site scripting can be used to hack a server ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/08/cross-site-scripting-can-be-used-to.html" title="Cross-site scripting can be used to hack a server ">digg</a>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 18:06:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/server hack">server hack</category>
      <category domain="http://securityratty.com/tag/hack">hack</category>
      <category domain="http://securityratty.com/tag/manager">manager</category>
      <category domain="http://securityratty.com/tag/file manager tool">file manager tool</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/root password">root password</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/cpanel user">cpanel user</category>
      <source url="http://holisticinfosec.blogspot.com/2008/08/cross-site-scripting-can-be-used-to.html">Cross-site scripting CAN be used to hack a server</source>
    </item>
    <item>
      <title><![CDATA[Poor security quality in software. Someone is watching over me.]]></title>
      <link>http://securityratty.com/article/5d5ac42e7f537f2a4fe1612773543dc3</link>
      <guid>http://securityratty.com/article/5d5ac42e7f537f2a4fe1612773543dc3</guid>
      <description><![CDATA[Last week, Ben Worthen of the Wall Street Journal had a conversation with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded...]]></description>
      <content:encoded><![CDATA[<p>Last week, Ben Worthen of the Wall Street Journal had a <a href="http://blogs.wsj.com/biztech/2008/07/21/buggy-software-is-your-fault-too/?mod=djemTECH">conversation</a> with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded.</p>
<p>Howard Schmidt, who was once the CSO of Microsoft, knows a thing or two about vendors shipping insecure software.  He offers this advice relating to his iPhone, &#8220;Just because a piece of software was distributed through Apple’s App Store, don’t assume that it is vulnerability free.&#8221;  I think that sums up the problem pretty well.  Customers assume the software they are getting is vulnerability free until it is proved otherwise.</p>
<p>If it&#8217;s distributed by the Apple Store it is coming from a trusted brand. &#8220;It must be secure&#8221;, many think.  The same thinking is used by people who install social networking applets and give them access to their personal data.  Someone, somewhere is taking care of the software security so I don&#8217;t have to.  It must be the platform provider, the store, some industry body, my antivirus provider, or maybe even the government.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security.jpg"><img class="size-medium wp-image-147 alignright" title="Mall Security" src="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security-300x184.jpg" alt="" width="300" height="184" /></a></p>
<p>You can see how this thinking pervades the consumer space because there are regulatory bodies governing all other aspects of safety and security in our personal lives.  I&#8217;m safe in a plane or car because the government is looking out for me with standards and testing requirements.  I am safe in the mall parking lot because the men in the white SUV are patrolling.</p>
<p>This thinking also pervaded the b2b space.  I talk to companies which are outsourcing critical applications to offshore development companies and they assume that security testing is taking place as part of the development process.  I ask them if they have made security quality part of the requirements of the project and they say no.  Then I ask them what evidence does the offshore developer provide to demonstrate they have a certain level of security quality in the software they are producing and they tell me they have never asked.</p>
<p>I can tell you what would happen if they did ask because I have also spoken with the offshore developers.  They have no evidence.  Their concern is getting the software functionality done on time and on budget. They consider fixing security vulnerabilities, once discovered, rework which the customer pays for.  So not only are they not looking for vulnerabilities and relying on the customer to find them, they are charging the customer to fix the problems.  The customer has to this date accepted this model.</p>
<p>The same goes for commercial off the shelf software and open source.  Surely the developers writing the software are trained in secure software engineering.  Surely commercial software companies are using 3rd parties to test their software just like the banks have the big 4 audit their accounting or auto manufacturers submit to testing by the <a href="http://www.nhtsa.dot.gov/">NHTSA</a>. And of course open source has &#8220;many eyes&#8221; reviewing the code for security defects and informing the developers.  The customer has accepted a model where this is almost never true.</p>
<p>But times are changing and it is partially due to the availability of software that can automate the process of looking for security vulnerabilities. David Rice, the author of <a href="http://www.geekonomicsbook.com/">&#8220;Geekanomics: The Real Cost of Insecure Software&#8221;</a> was <a href="http://beastorbuddha.com/2008/07/29/talking-with-david-rice-insecure-software-implications-regulation-vendors-making-change-and-other-things/">interviewed recently by Drazin Drazic his Beast or Buddha blog</a>.  He said the trend is toward a future of secure software and automated security analysis is one of the sparks:</p>
<blockquote><p><strong>BorB: I recently wrote in a post that little is changing. We are not learning from the lessons of the past. There are few, if any new technologies that exist today, that we have great faith and trust in as being secure now, and expecting them to continue to be secure in the future. Any solutions to even basic security issues need a starting point and a significant change to current thinking, and even then, it will takes years to see the impacts of this. What are your thoughts on this? Are we seeing anything at present to make us more confident of the future?</strong></p>
<p>DR: It is true that it takes years to see the positive impacts of a change of mindset. And we are in the unfortunate position of repeating many old lessons.</p>
<p>At base, human history is a collection of exhaustive, expensive, and protracted engagements; only the relentless survive and have a chance at succeeding (notice no guarantee here). Confronting some of our most complex problems like highway safety, nuclear proliferation, or insecure software is painful, difficult, complicated, and troublesome. Human endeavors of any significance are like this. But we must do it. The inertia of culture and status quo is difficult to overcome, but overcome it we can; otherwise, we would not have the better parts of the world we enjoy today.</p>
<p>I believe the technology space is no different. We are just a little dazed and bewildered by all the changes technology has introduced so quickly and on such a grand scale. For every change we react to, another two or three rapidly appear.</p>
<p>I do see sparks of hope emerging. In the United States some members of government are beginning to understand the problem and are willing to start discussing how to approach insecure software from a policy perspective. On the technology front, companies like Ounce, Fortify, and Veracode are beginning to give software buyers an automated method of evaluating assurance levels of software. While not complete in and of themselves, these solutions are, as I stated, “sparks” that can help us progress down paths that were once not easily open to us.</p>
<p>As for the larger issue of cyber security, which software assurance is only a part of, society has a lot of adjusting to do. The Internet is a new environment for many still, and many more to come. There is a learning curve that must be confronted. It took the United States almost 80 years to develop the highway system we know and enjoy today. Nearly $400 billion was spent on this endeavor with hundreds of thousands of lives lost. As this shows, learning how to govern and navigate a new environment is expensive. Failing to learn even more so.</p></blockquote>
<p>Independent, automated, and repeatable software security testing is an essential component of a safe and secure online environment.  Without it we are stuck with the assumption of vendors perfoming software security as our imaginary security blanket that allows us to operate in the current online world.</p>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 10:51:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/approach insecure software">approach insecure software</category>
      <category domain="http://securityratty.com/tag/insecure software">insecure software</category>
      <category domain="http://securityratty.com/tag/repeatable software security">repeatable software security</category>
      <category domain="http://securityratty.com/tag/secure online environment">secure online environment</category>
      <category domain="http://securityratty.com/tag/environment">environment</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/software assurance">software assurance</category>
      <source url="http://www.veracode.com/blog/?p=145">Poor security quality in software. Someone is watching over me.</source>
    </item>
    <item>
      <title><![CDATA[Poor Security Quality In Software; Someone Is Watching Over Me]]></title>
      <link>http://securityratty.com/article/aeb219e925a6f8176126d93b8eb2be49</link>
      <guid>http://securityratty.com/article/aeb219e925a6f8176126d93b8eb2be49</guid>
      <description><![CDATA[Last week, Ben Worthen of the Wall Street Journal had a conversation with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded...]]></description>
      <content:encoded><![CDATA[<p>Last week, Ben Worthen of the Wall Street Journal had a <a href="http://blogs.wsj.com/biztech/2008/07/21/buggy-software-is-your-fault-too/?mod=djemTECH">conversation</a> with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded.</p>
<p>Howard Schmidt, who was once the CSO of Microsoft, knows a thing or two about vendors shipping insecure software.  He offers this advice relating to his iPhone, &#8220;Just because a piece of software was distributed through Apple’s App Store, don’t assume that it is vulnerability free.&#8221;  I think that sums up the problem pretty well.  Customers assume the software they are getting is vulnerability free until it is proved otherwise.</p>
<p>If it&#8217;s distributed by the Apple Store it is coming from a trusted brand. &#8220;It must be secure&#8221;, many think.  The same thinking is used by people who install social networking applets and give them access to their personal data.  Someone, somewhere is taking care of the software security so I don&#8217;t have to.  It must be the platform provider, the store, some industry body, my antivirus provider, or maybe even the government.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security.jpg"><center><img class="size-medium wp-image-147 alignright photoborder" title="Mall Security" src="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security-300x184.jpg" alt="" width="300" height="184" /></center></a></p>
<p>You can see how this thinking pervades the consumer space because there are regulatory bodies governing all other aspects of safety and security in our personal lives.  I&#8217;m safe in a plane or car because the government is looking out for me with standards and testing requirements.  I am safe in the mall parking lot because the men in the white SUV are patrolling.</p>
<p>This thinking also pervaded the b2b space.  I talk to companies which are outsourcing critical applications to offshore development companies and they assume that security testing is taking place as part of the development process.  I ask them if they have made security quality part of the requirements of the project and they say no.  Then I ask them what evidence does the offshore developer provide to demonstrate they have a certain level of security quality in the software they are producing and they tell me they have never asked.</p>
<p>I can tell you what would happen if they did ask because I have also spoken with the offshore developers.  They have no evidence.  Their concern is getting the software functionality done on time and on budget. They consider fixing security vulnerabilities, once discovered, rework which the customer pays for.  So not only are they not looking for vulnerabilities and relying on the customer to find them, they are charging the customer to fix the problems.  The customer has to this date accepted this model.</p>
<p>The same goes for commercial off the shelf software and open source.  Surely the developers writing the software are trained in secure software engineering.  Surely commercial software companies are using 3rd parties to test their software just like the banks have the big 4 audit their accounting or auto manufacturers submit to testing by the <a href="http://www.nhtsa.dot.gov/">NHTSA</a>. And of course open source has &#8220;many eyes&#8221; reviewing the code for security defects and informing the developers.  The customer has accepted a model where this is almost never true.</p>
<p>But times are changing and it is partially due to the availability of software that can automate the process of looking for security vulnerabilities. David Rice, the author of <a href="http://www.geekonomicsbook.com/">&#8220;Geekanomics: The Real Cost of Insecure Software&#8221;</a> was <a href="http://beastorbuddha.com/2008/07/29/talking-with-david-rice-insecure-software-implications-regulation-vendors-making-change-and-other-things/">interviewed recently by Drazin Drazic his Beast or Buddha blog</a>.  He said the trend is toward a future of secure software and automated security analysis is one of the sparks:</p>
<blockquote><p><strong>BorB: I recently wrote in a post that little is changing. We are not learning from the lessons of the past. There are few, if any new technologies that exist today, that we have great faith and trust in as being secure now, and expecting them to continue to be secure in the future. Any solutions to even basic security issues need a starting point and a significant change to current thinking, and even then, it will takes years to see the impacts of this. What are your thoughts on this? Are we seeing anything at present to make us more confident of the future?</strong></p>
<p>DR: It is true that it takes years to see the positive impacts of a change of mindset. And we are in the unfortunate position of repeating many old lessons.</p>
<p>At base, human history is a collection of exhaustive, expensive, and protracted engagements; only the relentless survive and have a chance at succeeding (notice no guarantee here). Confronting some of our most complex problems like highway safety, nuclear proliferation, or insecure software is painful, difficult, complicated, and troublesome. Human endeavors of any significance are like this. But we must do it. The inertia of culture and status quo is difficult to overcome, but overcome it we can; otherwise, we would not have the better parts of the world we enjoy today.</p>
<p>I believe the technology space is no different. We are just a little dazed and bewildered by all the changes technology has introduced so quickly and on such a grand scale. For every change we react to, another two or three rapidly appear.</p>
<p>I do see sparks of hope emerging. In the United States some members of government are beginning to understand the problem and are willing to start discussing how to approach insecure software from a policy perspective. On the technology front, companies like Ounce, Fortify, and Veracode are beginning to give software buyers an automated method of evaluating assurance levels of software. While not complete in and of themselves, these solutions are, as I stated, “sparks” that can help us progress down paths that were once not easily open to us.</p>
<p>As for the larger issue of cyber security, which software assurance is only a part of, society has a lot of adjusting to do. The Internet is a new environment for many still, and many more to come. There is a learning curve that must be confronted. It took the United States almost 80 years to develop the highway system we know and enjoy today. Nearly $400 billion was spent on this endeavor with hundreds of thousands of lives lost. As this shows, learning how to govern and navigate a new environment is expensive. Failing to learn even more so.</p></blockquote>
<p>Independent, automated, and repeatable software security testing is an essential component of a safe and secure online environment.  Without it we are stuck with the assumption of vendors perfoming software security as our imaginary security blanket that allows us to operate in the current online world.</p>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 10:51:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/approach insecure software">approach insecure software</category>
      <category domain="http://securityratty.com/tag/insecure software">insecure software</category>
      <category domain="http://securityratty.com/tag/repeatable software security">repeatable software security</category>
      <category domain="http://securityratty.com/tag/secure online environment">secure online environment</category>
      <category domain="http://securityratty.com/tag/environment">environment</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/software assurance">software assurance</category>
      <source url="http://www.veracode.com/blog/2008/07/poor-security-quality-in-software-someone-is-watching-over-me/">Poor Security Quality In Software; Someone Is Watching Over Me</source>
    </item>
    <item>
      <title><![CDATA[Symantec takes a fling it on the wall approach to NAC]]></title>
      <link>http://securityratty.com/article/5fdd01f2a0625307de1c754d60d3d1b2</link>
      <guid>http://securityratty.com/article/5fdd01f2a0625307de1c754d60d3d1b2</guid>
      <description><![CDATA[I was reading Tim Greene's column this morning about Symantec 's new on demand web log in for guests as part of their SNAC appliance offering. I have to admit that even I who follows the NAC market...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>I was reading <a href="http://www.networkworld.com/newsletters/vpn/2008/072808nac1.html">Tim Greene's column</a> this morning about <a class="zem_slink" title="Symantec" href="http://www.symantec.com/" rel="homepage">Symantec</a>'s new on demand web log in for guests as part of their SNAC appliance offering. I have to admit that even I who follows the NAC market and competition pretty closely, get pretty confused with all of the different offerings Symantec has come out with around NAC. Symantec seems to be following a fling stuff on the wall and see what sticks strategy when it comes to NAC.&nbsp; The problem is separating the keepers from the rest of it when evaluating their offering.</p>

<p>This latest offering appears to sure up a hole that was called out in the recent <a href="http://www.crn.com/security/209101095;jsessionid=4CV2CAHUGZHEMQSNDLRSKHSCJUNN2JVN?pgno=1">CRN review</a> of their product in a bake off against Sophos and StillSecure's Safe Access. In that review Symantec's drop off in functionality between agent and agentless was called out.&nbsp; So within just a few days comes this announcement addressing the issue.&nbsp; Very timely indeed.&nbsp; This comes on the heels of Symantec's peer-to-peer approach to NAC, which came on the heels of their Endpoint Security product version 11 which had NAC included (and which I understand has already been patched/upgraded several times since its release).&nbsp; </p>

<p>At this point you have Symantec NAC with their endpoint suite which is a throw in but has no guest access option on its own. Than you have the Symantec NAC appliance which can do enforcement of managed devices beyond what just endpoint suite gives you.&nbsp; Now you also have on demand/dissolvable agents available with the Symantec NAC server (but I guess not with the endpoint suite). You also have the Symantec peer-to-peer stuff, which I think also requires the SNAC server.&nbsp; Starting to get confusing? I guess this is what happens when your NAC offering is made up of an amalgamation of several different products lumped together.</p>

<p>Not to worry though, I am sure Big Yellow will still sell plenty of all flavors of their NAC offering. At the end of the day some of this stuff is bound to stick.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/a9b9cd5b-92ba-48a1-b363-de44351587fe/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=a9b9cd5b-92ba-48a1-b363-de44351587fe" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 03:41:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/symantec nac appliance">symantec nac appliance</category>
      <category domain="http://securityratty.com/tag/symantec nac">symantec nac</category>
      <category domain="http://securityratty.com/tag/symantec nac server">symantec nac server</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/offerings symantec">offerings symantec</category>
      <category domain="http://securityratty.com/tag/symantec peer-to-peer stuff">symantec peer-to-peer stuff</category>
      <category domain="http://securityratty.com/tag/nac market">nac market</category>
      <category domain="http://securityratty.com/tag/endpoint suite">endpoint suite</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/symantec-takes.html">Symantec takes a fling it on the wall approach to NAC</source>
    </item>
    <item>
      <title><![CDATA[Symantec takes a fling it on the wall approach to NAC]]></title>
      <link>http://securityratty.com/article/0df0f414409f58415c15cbc4f2fea03c</link>
      <guid>http://securityratty.com/article/0df0f414409f58415c15cbc4f2fea03c</guid>
      <description><![CDATA[I was reading Tim Greene's column this morning about Symantec 's new on demand web log in for guests as part of their SNAC appliance offering. I have to admit that even I who follows the NAC market...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>I was reading <a href="http://www.networkworld.com/newsletters/vpn/2008/072808nac1.html">Tim Greene's column</a> this morning about <a class="zem_slink" title="Symantec" href="http://www.symantec.com/" rel="homepage">Symantec</a>'s new on demand web log in for guests as part of their SNAC appliance offering. I have to admit that even I who follows the NAC market and competition pretty closely, get pretty confused with all of the different offerings Symantec has come out with around NAC. Symantec seems to be following a fling stuff on the wall and see what sticks strategy when it comes to NAC.&nbsp; The problem is separating the keepers from the rest of it when evaluating their offering.</p>

<p>This latest offering appears to sure up a hole that was called out in the recent <a href="http://www.crn.com/security/209101095;jsessionid=4CV2CAHUGZHEMQSNDLRSKHSCJUNN2JVN?pgno=1">CRN review</a> of their product in a bake off against Sophos and StillSecure's Safe Access. In that review Symantec's drop off in functionality between agent and agentless was called out.&nbsp; So within just a few days comes this announcement addressing the issue.&nbsp; Very timely indeed.&nbsp; This comes on the heels of Symantec's peer-to-peer approach to NAC, which came on the heels of their Endpoint Security product version 11 which had NAC included (and which I understand has already been patched/upgraded several times since its release).&nbsp; </p>

<p>At this point you have Symantec NAC with their endpoint suite which is a throw in but has no guest access option on its own. Than you have the Symantec NAC appliance which can do enforcement of managed devices beyond what just endpoint suite gives you.&nbsp; Now you also have on demand/dissolvable agents available with the Symantec NAC server (but I guess not with the endpoint suite). You also have the Symantec peer-to-peer stuff, which I think also requires the SNAC server.&nbsp; Starting to get confusing? I guess this is what happens when your NAC offering is made up of an amalgamation of several different products lumped together.</p>

<p>Not to worry though, I am sure Big Yellow will still sell plenty of all flavors of their NAC offering. At the end of the day some of this stuff is bound to stick.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/a9b9cd5b-92ba-48a1-b363-de44351587fe/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=a9b9cd5b-92ba-48a1-b363-de44351587fe" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=2Val4x"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=2Val4x" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=QOQfsJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=QOQfsJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1VUC0J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1VUC0J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=jtR7aJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=jtR7aJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=OoZFwJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=OoZFwJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BrlZNj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BrlZNj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1KoExj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1KoExj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/349362002" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 02:49:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/symantec nac appliance">symantec nac appliance</category>
      <category domain="http://securityratty.com/tag/symantec nac">symantec nac</category>
      <category domain="http://securityratty.com/tag/symantec nac server">symantec nac server</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/offerings symantec">offerings symantec</category>
      <category domain="http://securityratty.com/tag/symantec peer-to-peer stuff">symantec peer-to-peer stuff</category>
      <category domain="http://securityratty.com/tag/nac market">nac market</category>
      <category domain="http://securityratty.com/tag/endpoint suite">endpoint suite</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/349362002/symantec-takes.html">Symantec takes a fling it on the wall approach to NAC</source>
    </item>
  </channel>
</rss>
