<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: implementation]]></title>
    <link>http://securityratty.com/tag/implementation</link>
    <description></description>
    <pubDate>Tue, 08 Jul 2008 11:42:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Security Matters: Lesson From the DNS Bug: Patching Isn't Enough]]></title>
      <link>http://securityratty.com/article/91e8b8fee8fdb20a8381e76c3ea40942</link>
      <guid>http://securityratty.com/article/91e8b8fee8fdb20a8381e76c3ea40942</guid>
      <description><![CDATA[Despite the best efforts of the security community, the details of a critical internet vulnerability discovered by Dan Kaminsky about six months ago have leaked. Hackers are racing to produce exploit...]]></description>
      <content:encoded><![CDATA[<p>
Despite the best efforts of the security community, the details of a critical internet vulnerability discovered by Dan Kaminsky about six months ago have leaked. Hackers are racing to produce exploit code, and network operators who haven't already patched the hole are scrambling to catch up. The whole mess is a good illustration of the problems with researching and disclosing flaws like this.
</p><p>
The <a href="http://darkoz.com/?p=15">details</a> of the <a href="http://blog.invisibledenizen.org/2008/07/kaminskys-dns-issue-accidentally-leaked.html">vulnerability</a> aren't important, but basically it's a form of DNS cache poisoning. The DNS system is what translates domain names people understand, like www.schneier.com, to IP addresses computers understand: 204.11.246.1. There is a whole family of vulnerabilities where the DNS system on your computer is fooled into thinking that the IP address for www.badsite.com is really the IP address for www.goodsite.com -- there's no way for you to tell the difference -- and that allows the criminals at www.badsite.com to trick you into doing all sorts of things, like giving up your bank account details. Kaminsky discovered a particularly nasty variant of this cache-poisoning attack.
</p><p>
Here's the way the timeline was supposed to work: Kaminsky discovered the vulnerability about six months ago, and quietly worked with vendors to patch it. (There's a fairly straightforward fix, although the implementation nuances are complicated.) Of course, this meant describing the vulnerability to them; why would companies like Microsoft and Cisco believe him otherwise? On July 8, he held a <a href="http://news.bbc.co.uk/2/hi/technology/7496735.stm">press conference</a> to <a href="http://www.doxpara.com/?p=1162">announce</a> the <a href="http://www.kb.cert.org/vuls/id/800113">vulnerability</a> -- but not the details -- and reveal that a patch was available from a long list of vendors. We would all have a month to patch, and Kaminsky would release details of the vulnerability at the <a href="http://www.blackhat.com/html/bh-usa-08/bh-us-08-main.html">BlackHat</a> conference early next month.
</p><p>
Of course, the details <a href="http://it.slashdot.org/it/08/07/21/2212227.shtml">leaked</a>. <a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html">How</a> isn't important; it could have leaked a zillion different ways. Too many people knew about it for it to remain secret. Others who knew the general idea were too smart <a href="http://addxorrol.blogspot.com/2008/07/on-dans-request-for-no-speculation.html">not to speculate</a> on the details. I'm kind of amazed the details remained secret for this long; undoubtedly it had leaked into the underground community before the public leak two days ago. So now everyone who back-burnered the problem is rushing to patch, while the hacker community is racing to produce working exploits. 
</p><p>
What's the moral here? It's easy to condemn Kaminsky: If he had shut up about the problem, we wouldn't be in this mess. But that's just wrong. Kaminsky found the vulnerability by accident. There's no reason to believe he was the first one to find it, and it's ridiculous to believe he would be the last. Don't shoot the messenger. The problem is with the DNS protocol; it's insecure.
</p><p>
The real lesson is that the <a href="http://www.schneier.com/crypto-gram-0103.html#1">patch treadmill</a> doesn't work, and it hasn't for years. This cycle of finding security holes and rushing to patch them before the bad guys exploit those vulnerabilities is expensive, inefficient and incomplete. We need to design security into our systems right from the beginning. We need <a href="http://www.schneier.com/blog/archives/2007/08/assurance.html">assurance</a>. We need security engineers involved in system design. This process won't prevent every vulnerability, but it's much more secure -- and cheaper -- than the patch treadmill we're all on now.
</p><p>
What a security engineer brings to the problem is a particular <a href="http://www.schneier.com/blog/archives/2008/03/the_security_mi.html">mindset</a>. He thinks about systems from a security perspective. It's not that he discovers all possible attacks before the bad guys do; it's more that he anticipates potential types of attacks, and defends against them even if he doesn't know their details. I see this all the time in good cryptographic designs. It's over-engineering based on intuition, but if the security engineer has good intuition, it generally works.
</p><p>
Kaminsky's vulnerability is a perfect example of this. Years ago, cryptographer Daniel J. <a href="http://cr.yp.to/djbdns/forgery.html">Bernstein looked at DNS security</a> and decided that Source Port Randomization was a smart design choice. That's exactly the work-around being rolled out now following Kaminsky's discovery. Bernstein didn't discover Kaminsky's attack; instead, he saw a general class of attacks and realized that this enhancement could protect against them. Consequently, the DNS program he wrote in 2000, <a href="http://cr.yp.to/djbdns/dnscache.html">djbdns</a>, doesn't need to be patched; it's already immune to Kaminsky's attack.
</p><p>
That's what a good design looks like. It's not just secure against known attacks; it's also secure against unknown attacks. We need more of this, not just on the internet but in voting machines, ID cards, transportation payment cards ... everywhere. Stop assuming that systems are secure unless demonstrated insecure; start assuming that systems are insecure unless designed securely.
</p>
<p>
---
</p>
<p><em>Bruce Schneier is chief security technology officer of BT, and author of </em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=409677f2963be2209f491c6d93077da2" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=409677f2963be2209f491c6d93077da2" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=h5CELJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=h5CELJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=boiM6j"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=boiM6j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Jt6fdj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Jt6fdj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rgr4DJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rgr4DJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=24FrZJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=24FrZJ" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=zjgcMj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=zjgcMj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=iNUmwj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=iNUmwj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=WnDE0J"><img src="http://feeds.wired.com/~f/wired/politics/security?i=WnDE0J" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/344028309" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/344028448" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 15:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security engineer">security engineer</category>
      <category domain="http://securityratty.com/tag/security engineer brings">security engineer brings</category>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/smart design choice">smart design choice</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/security engineers">security engineers</category>
      <category domain="http://securityratty.com/tag/kaminsky">kaminsky</category>
      <category domain="http://securityratty.com/tag/dan kaminsky">dan kaminsky</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/344028448/securitymatters_0723">Security Matters: Lesson From the DNS Bug: Patching Isn't Enough</source>
    </item>
    <item>
      <title><![CDATA[ICANN Approves New .INFO Policy]]></title>
      <link>http://securityratty.com/article/cd6398fad5b32c821bfe8b24969e83a1</link>
      <guid>http://securityratty.com/article/cd6398fad5b32c821bfe8b24969e83a1</guid>
      <description><![CDATA[Last month Afilias , the domain registry for .INFO , proposed a new &quot;Abusive Domain Use Policy&quot; that would appear to give them arbitrary power to decide what is and is not acceptable. Consider the...]]></description>
      <content:encoded><![CDATA[Last month <a href="http://www.afilias.com/">Afilias</a>, the domain registry for <a href="http://www.info.info/">.INFO</a>, proposed <a href="http://www.icann.org/registries/rsep/afilias-request-20jun08.pdf">a new "Abusive Domain Use Policy"</a> that would appear to give them arbitrary power to decide what is and is not acceptable. Consider the following language:<blockquote><i>Pursuant to Section 3.6.5 of the RRA, Afilias reserves the right to deny, cancel or transfer any registration or transaction, or place any domain name(s) on registry lock, hold or similar status, that it deems necessary, in its discretion;</i></blockquote>
Now it appears (<a href="http://www.domainnamenews.com/icann-policy/icann-approves-new-info-policy/1740">thanks to Domain Name News for the tip</a>) that <a href="http://www.icann.org/registries/rsep/jones-to-afilias-18jul08.pdf">ICANN has approved the proposed policy and given the green light to implementation</a>. The ICANN letter states that they found no "...significant competition or security and stability issues" and asks Afilias to report on results of the changes. But ICANN did not explicitly solicit public comment on the change before approving it.

As DomainNameNews points out though, comments to any registry proposal can be submitted at any time by sending an email to registryservice (at) icann.org and are published <a href="http://forum.icann.org/lists/registryservice/">on the ICANN website</a>."<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=aafe57485cc6ab66b73f3d71762b6ff4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=aafe57485cc6ab66b73f3d71762b6ff4" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/341492192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 04:16:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/icann website">icann website</category>
      <category domain="http://securityratty.com/tag/abusive domain">abusive domain</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/afilias reserves">afilias reserves</category>
      <category domain="http://securityratty.com/tag/afilias">afilias</category>
      <category domain="http://securityratty.com/tag/icann letter">icann letter</category>
      <category domain="http://securityratty.com/tag/domain registry">domain registry</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/341492192/icann_approves_new_info_policy.html">ICANN Approves New .INFO Policy</source>
    </item>
    <item>
      <title><![CDATA[Opinion: Government security guide for VMware ESX helpful but has holes]]></title>
      <link>http://securityratty.com/article/745f663d76267688b403f2d5a18ab75c</link>
      <guid>http://securityratty.com/article/745f663d76267688b403f2d5a18ab75c</guid>
      <description><![CDATA[The government's new Security Technical Implementation Guide is the most complete that CIO 's reviewer has seen, but it still offers some strange pieces of...]]></description>
      <content:encoded><![CDATA[The government's new Security Technical Implementation Guide is the most complete that <i>CIO</i>'s reviewer has seen, but it still offers some strange pieces of advice.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=x5u2Rx"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=x5u2Rx" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/338378748" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/strange pieces">strange pieces</category>
      <category domain="http://securityratty.com/tag/reviewer">reviewer</category>
      <category domain="http://securityratty.com/tag/offers">offers</category>
      <category domain="http://securityratty.com/tag/cio">cio</category>
      <category domain="http://securityratty.com/tag/advice">advice</category>
      <category domain="http://securityratty.com/tag/complete">complete</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/338378748/article.do">Opinion: Government security guide for VMware ESX helpful but has holes</source>
    </item>
    <item>
      <title><![CDATA[Are you using the latest web browser?]]></title>
      <link>http://securityratty.com/article/f99696393f35efc81b36eae37200a248</link>
      <guid>http://securityratty.com/article/f99696393f35efc81b36eae37200a248</guid>
      <description><![CDATA[Written by Thomas Duebendorfer

In view of mass defacements of hundreds of thousand of web pages - with the intent to misuse them to launch drive-by download attacks - security researchers from ETH...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Thomas Duebendorfer</span><br /><br />In view of mass defacements of hundreds of thousand of web pages - with the intent to misuse them to launch drive-by download attacks - security researchers from ETH Zurich, Google, and IBM Internet Security Systems were interested in looking at the other side of the attack: the web browser. By analyzing the web browser versions seen in visits to Google websites, they have shown that more than 600 million Internet users don't use the latest version of their browser.<br /><br /><b>Slow migration to latest browser version</b><br />The researchers' paper, entitled <a href="http://www.techzoom.net/insecurity-iceberg">"Understanding the Web Browser Threat"</a>, shows that as of June 2008, only 59.1% percent of Internet users worldwide use the latest major version of their preferred web browser. Firefox users are the most attentive: 92.2% of them surfed with Firefox 2, the latest major version before the recently released 3.0. Only 52.5% of Microsoft Internet Explorer users have updated to version 7, which is the most secure according to multiple publicly-cited Microsoft experts (among them Sandi Hardmeier). The study revealed that 637 million Internet users worldwide who use web browsers are either not running the latest version of their preferred browser or have not installed the latest patches. These users are vulnerable to exploitation due to their web browser's "built-in" vulnerabilities and the lack of more recent security mechanisms such as improved phishing protection.<br /><br /><b>Neglected security patches</b><br />Over the past 18 months, the study also shows, a maximum of 83.3% of Firefox users were using the latest major version of the web browser and also had all current patches installed (i.e. latest minor version). Only 56.1% and 47.6% of Opera and Internet Explorer users, respectively, were similarly utilizing fully-patched web browsers. Apple users are no better: since the public release of Safari 3, only 65.3% of users operate the latest Safari version.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_LMSk7hTEaIE/SH5ZvdukCtI/AAAAAAAAd10/-yGf2De4l8I/s1600-h/share.png"><img style="cursor: pointer;" src="http://bp1.blogger.com/_LMSk7hTEaIE/SH5ZvdukCtI/AAAAAAAAd10/-yGf2De4l8I/s400/share.png" alt="" id="BLOGGER_PHOTO_ID_5223711289765006034" border="0" /></a><br /><div><em>Maximum measured share of users surfing the web with the most secure versions of Firefox, Safari, Opera and Internet Explorer in June 2008 as seen on Google websites.</em></div><br /><br /><b>Obsolete browser warning</b><br />The study's most important finding is that technical measures now in place do not sufficiently guarantee browser security, and that users' security awareness must be further developed. The problem is that most users are unaware that they are not using their browser's latest version. It must be made clear to web browser users that outdated software is associated with significantly higher risk. The researchers therefore suggest that, as a critical component of web software, a visible warning be instituted that warns the user of missing security patches in a way analogous to the 'best before' date in the perishable food industry. Software updates must also be made easier to find. The resulting transparency would go far in contributing to end user awareness of software weaknesses, and allow users to better evaluate risks.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_LMSk7hTEaIE/SH5aAEVMy0I/AAAAAAAAd18/nXMAqQdWXno/s1600-h/expired.png"><img style="cursor: pointer;" src="http://bp0.blogger.com/_LMSk7hTEaIE/SH5aAEVMy0I/AAAAAAAAd18/nXMAqQdWXno/s400/expired.png" alt="" id="BLOGGER_PHOTO_ID_5223711575005514562" border="0" /></a><br /><div><em>Example "best before" implementation on a Web browser</em></div><br /><br />As a side effect, having users migrate faster to the latest browser version would not only increase security but also make the lives of webmasters easier, as they would need to test and optimize websites for fewer older versions of web browsers.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=JC3YMJ"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=JC3YMJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=Tt44Ej"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=Tt44Ej" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/337403441" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 09:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/web browser">web browser</category>
      <category domain="http://securityratty.com/tag/browser version">browser version</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <category domain="http://securityratty.com/tag/secure versions">secure versions</category>
      <category domain="http://securityratty.com/tag/obsolete browser">obsolete browser</category>
      <category domain="http://securityratty.com/tag/web browser versions">web browser versions</category>
      <category domain="http://securityratty.com/tag/web browser users">web browser users</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/337403441/are-you-using-latest-web-browser.html">Are you using the latest web browser?</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Doug McClure: What Makes BSM Successful?]]></title>
      <link>http://securityratty.com/article/ac3c26a14f128a8ecb49f7c474cbb36e</link>
      <guid>http://securityratty.com/article/ac3c26a14f128a8ecb49f7c474cbb36e</guid>
      <description><![CDATA[Yesterday we featured our initial Q&amp;A with Doug McClure , who took some time to answer some strategic questions on BSM Lite. Today, Doug shares his thoughts on BSM and CMDB strategies for companies...]]></description>
      <content:encoded><![CDATA[<p>Yesterday we featured <a href="http://blog.sciencelogic.com/qa-with-doug-mcclure-is-bsm-lite-the-answer/07/2008" target="_blank">our initial Q&amp;A</a> with <a href="http://dougmcclure.net/blog/" target="_blank">Doug McClure</a>, who took some time to answer some strategic questions on BSM Lite. Today, Doug shares his thoughts on BSM and CMDB strategies for companies and how his stint in the U.S. Navy helped shape his future passion for BSM.</p>
<p><strong><em>ScienceLogic:</em></strong> Can you share any of the strategies/advice that you give to companies embarking on their BSM journeys?</p>
<p><strong><em>Doug McClure:</em></strong> Well, first they&#8217;ve got to have a BSM strategy. Nearly all the clients I talk to or hear about wanting to do BSM do not have a BSM strategy. I talk a lot about this on my blog and with clients and it is relevant whether you&#8217;re going to think about &#8220;BSM Lite&#8221; or &#8220;BSM Heavy&#8221; approaches.</p>
<p>Once we have a BSM strategy, we need to establish a BSM roadmap that guides us in how we’ll implement the BSM strategy in a more tactical manner, focusing on short term iterative quick wins and 30-60-90 day projects. For more of my thoughts on BSM strategy and roadmapping, see the following blog posts.</p>
<ul>
<li>
<h3><a href="http://dougmcclure.net/blog/2007/03/elements-of-business-service-management-part-3-getting-business-service-management-on-the-radar-screen/" target="_blank">Elements of Business Service Management Part 3: Getting Business Service Management on the Radar Screen</a></h3>
</li>
<li>
<h3><a href="http://dougmcclure.net/blog/2007/09/elements-of-business-service-management-part-4-what%e2%80%99s-your-business-service-management-strategy/" target="_blank">Elements of Business Service Management Part 4: What’s your Business Service Management Strategy?</a></h3>
</li>
</ul>
<p>As I&#8217;ve alluded to previously, a client first must define and understand what &#8220;BSM Lite&#8221; may mean to them. Don&#8217;t take what the analysts or the vendors pitch for what you should do to achieve BSM or what value you should get from it.</p>
<p>For any type of BSM to be successful, each client must define what BSM means to them and state what they expect to get from BSM. They must make it personal, make it a part of their company culture and elevate it to be as an important initiative as compliance, risk management, SOA, ITIL, or other initiatives may be within the company.</p>
<p>Please don&#8217;t get scared off from this strategy thing. Please don&#8217;t blow this off as something that the secret enterprise architecture council should be doing. If you&#8217;re unable to get an audience in these areas within your company, start within your own sphere of influence.</p>
<p>Your strategy could be as simple as enabling the local operations center to more efficiently classify, triage and resolve problems based on a simple business service or application contextual understanding. Focus on how this changes the game within your environment. Come up with your own metrics and measures to assess the value this has to this organizational use. Trust me, you&#8217;ll need to justify your investment some time in the future.</p>
<p>Another trait of successful BSM implementations is that of the formal monitoring and management tools group has established some sort of database or knowledge repository that enables them to &#8220;manage the business of IT management and monitoring&#8221; if you will. In my opinion, the vendor community has let their clients down significantly in this area. The CMDB may be the correct answer, but most companies just don’t value monitoring enough to demand that this be included in their formal CMDB initiatives.</p>
<p>In my last job, we developed an application that I referred to as the &#8220;Service Management Database&#8221; or &#8220;SMDB&#8221;. Others may call it something else, but in essence, it was the database that captured what was monitored, how it was monitored, who owned it, what business services and applications it supported, the impact an outage or event from it had on the business services or applications, etc.</p>
<p>One key component of this “SMDB” was establishing the relationships of real and synthetic user and transaction monitoring steps to associated servers and applications. This is a significant gap area in many tools and vendor CMDBs.</p>
<p>Clients who have instituted something formal such as this generally have a very good handle on management and monitoring within their environment. Far too many clients do not have adequate monitoring (read visibility) in place to begin their BSM journey.</p>
<p>I&#8217;d strongly recommend a good hard look at how well the client&#8217;s monitoring and management practices are implemented and managed. Simply put, if they don&#8217;t have adequate visibility into how well those business services and applications are performing, you can&#8217;t expect to manage what you can&#8217;t “see” that may be impacting the business, clients, revenue, etc.</p>
<p>Just ask yourself this – can you explicitly state what monitoring is in place for a given business service or application? Can you quantify the impact of a simple event to a business service or application? Can you explain why something is red, yellow, purple or green and what causes it to change from one color to another? If you can’t, your BSM journey will be challenging.</p>
<p>Those with formal CMDB initiatives have their hands full with high risk, long time to value projects to just get a handle with traditional configuration management models. Taking these low level configuration items (CI&#8217;s) and establishing application and service dependencies comes after a lot of work getting through the organizational challenges of getting systems access to populate the CMDB.</p>
<p>I strongly recommend that the formal monitoring and management tools group create an authoritative database that enables them to establish end-to-end visibility into the service and application delivery chain and the impacts it has on the business, customer, etc. This ultimately becomes part of a more realistic federated CMDB within the business.</p>
<p><strong>ScienceLogic:</strong> Can you provide an example of a successful implementation of BSM? Were there specific factors that especially contributed to its success?</p>
<p><strong><em>Doug McClure:</em></strong> I&#8217;ve touched on the highlights of the most successful BSM implementations throughout my previous answers. Clients that have rallied around an organizational change or transformation focusing every team member’s efforts and energy towards ensuring that the business goals and objectives are being met through the delivery of highly available business services and applications.</p>
<p>Far too often the “change” never happens and it’s the “talking heads” that are preaching to the choir about what should be done. Every person on the front line, in the support teams, at the help desk, etc. must understand how they support or impact the business in business terms. Try putting this simple phrase after job titles “Hi, my name is Doug. I’m a Systems Administrator, Supporting the Business”.</p>
<p>That was a mouthful, but simply put, these clients have an impressively instrumented business and IT environment with the right amount of visibility into each area, joined together with an organization that thinks, operates and responds based on their understanding of the business goals and objectives and how these business services and applications enable business success.</p>
<p>The operational model for an organization fully adopting BSM identifies ways to establish a service management mentality across the entire business service and application delivery and support chain. The delivery, operations and support organizations must be incented to manage the services and applications being delivered with this end-to-end context.</p>
<p>A leading, outside the box “service management organization” may include the traditional IT silos but within a matrixed fashion focused on one or more key business services and applications. The &#8220;service management organization&#8221; is then incented to work together, as a team, for the end-to-end delivery and support of these services or applications.</p>
<p>It’s no longer one’s job to just be the systems administrator, database administrator or network engineer, their job is now to support specific business services and applications. They provide the subject matter expertise needed to support the services and applications together, as a team, eliminating the finger pointing or “not my problem” attitudes that exist in the majority of IT organizations today.</p>
<p>Overall, the KISS approach is what will enable BSM of any type (lite, heavy) to be the most successful. If it just feels natural, doesn&#8217;t take any additional effort, clicks or tasks to do then it&#8217;s going to work. BSM should be transparent and not just another buzz word. It&#8217;s not a form that gets filled out or a special process to follow in the run book. It&#8217;s doing the right thing for the business, no matter what the situation, crisis, buzz word or technology initiative of the day is.</p>
<p><strong><em>ScienceLogic:</em></strong> How did you get involved in BSM?</p>
<p><strong><em>Doug McClure:</em></strong> I think the foundations of my service management background and passion were initially established during my service in the US Navy. Today, I relate that experience to what I call BSM for the Military or Mission Services Management (MSM).</p>
<p>We had been taught over and over that extreme attention to the details of the mission at hand (aka &#8220;the business&#8221;) was the number one priority and that all of our technology, services, and applications existed for those Sailors and Marines on the other end (the &#8220;customer&#8221;). I can recall countless instances where mission critical communications services (telephony, orderwires, teletypes, command and control systems, etc.) were impacted in one way or another. It was extremely critical that we understood who was impacted and to what degree so that contingency plans could be activated. We weren’t just talking about lost revenue, poor sales or customer experience; we were talking about human lives and the security of the United States.</p>
<p>It is that military bearing, attention to detail and real world experience that drives me with many of my modern day BSM endeavors. That migration from &#8220;Mission Services Management&#8221; to BSM was honed working for over 10 years working in the Internet Service Provider (ISP) and datacenter, hosting and colocation business.</p>
<p>In those rapid growth businesses during the Internet boom, service differentiation was what &#8220;made you millions&#8221; or paved your way to bankruptcy. The companies I worked for had an extreme passion and focus on ensuring that their services, applications and Internet access products were of the highest quality, highly reliable and just plain better than the competition.</p>
<p>Again, the IT infrastructure, service quality and customer experience relationship was ingrained in all of our heads. It was all hands on deck when Webmail, Internet access, DNS, or the network experienced problems. We were measured in terms of how many customers experienced a busy signal or dropped connection or if you couldn’t log in fast enough to read your email. Companies like Keynote Systems and LionBridge/Veritest/Inverse tested the quality of our networks, services and applications and publicly ranked us against our competition. We thought in terms of customer experience and impact every minute of the day, 24&#215;7.</p>
<p>It was in my last job managing a traditional enterprise management and monitoring development group for a nationwide ISP where I was able to work with emerging technology to help get a handle on the complexities of these rapidly growing IT environments filled with emerging technologies and products. Applying this early technology to complex service problems in our environment proved to me that the technology, coupled with the right emphasis on how the technology was implemented and an emphasis on the people and processes within the organization could bring BSM to life.</p>
<p>Where I felt left out in the cold was with my vendor relationship. While their technology gave me the potential, they didn&#8217;t teach me how to work through the organizational and technological problems to successfully implement the BSM strategy. My very first end-to-end BSM pilot was extremely successful and provided visibility into the IT environment and business service impact that have never been available before.</p>
<p>And here I am today, working at a software vendor for the first time. Welcome to the &#8220;dark side&#8221; as they say. The approach and methodology we followed for BSM has become the basis of the core BSM Methodology that I teach IBMers and our clients around the world today.</p>
<p>My personal mission and drive here at IBM Tivoli is to ensure that BSM is something that the typical monitoring tools administrator can actually implement and that our BSM story is something that any of our clients can be successful with. The sales and marketing slicks must be backed up by something like this whomever you are these days. Clients shouldn&#8217;t put up for “marketecture”, me too and gee whiz buzz words.</p>
<p>BSM takes a partnership and commitment to every client&#8217;s success, and I want to be involved in those BSM efforts in every industry or market worldwide. We need more thought leaders collaborating together in an open and public forum to change legacy attitudes about BSM and do what we can to enable client’s to be as successful as they can be.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26amp%3BA+with+Doug+McClure%3A+What+Makes+BSM+Successful%3F&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-doug-mcclure-what-makes-bsm-successful%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 15:02:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/service management database">service management database</category>
      <category domain="http://securityratty.com/tag/management tools">management tools</category>
      <category domain="http://securityratty.com/tag/service management mentality">service management mentality</category>
      <category domain="http://securityratty.com/tag/business service management">business service management</category>
      <category domain="http://securityratty.com/tag/business service">business service</category>
      <category domain="http://securityratty.com/tag/business service impact">business service impact</category>
      <category domain="http://securityratty.com/tag/mission services management">mission services management</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <source url="http://blog.sciencelogic.com/qa-with-doug-mcclure-what-makes-bsm-successful/07/2008">Q&amp;A with Doug McClure: What Makes BSM Successful?</source>
    </item>
    <item>
      <title><![CDATA[VMware VI Client plug-ins and how to manage them]]></title>
      <link>http://securityratty.com/article/13386f5858840e1efa1a95fe22e346b3</link>
      <guid>http://securityratty.com/article/13386f5858840e1efa1a95fe22e346b3</guid>
      <description><![CDATA[VMware VI Client plug-ins can provide a VirtualCenter implementation with a functionality boost. Discover more on plug-in management tactics and plug-in options, including the Juxtaposition RDP...]]></description>
      <content:encoded><![CDATA[VMware VI Client plug-ins can provide a VirtualCenter implementation with a functionality boost. Discover more on plug-in management tactics and plug-in options, including the Juxtaposition RDP plug-in, in this tip.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/336121695" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 06:04:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/client plug-ins">client plug-ins</category>
      <category domain="http://securityratty.com/tag/juxtaposition rdp plug-in">juxtaposition rdp plug-in</category>
      <category domain="http://securityratty.com/tag/plug-in management tactics">plug-in management tactics</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/virtualcenter implementation">virtualcenter implementation</category>
      <category domain="http://securityratty.com/tag/plug-in options">plug-in options</category>
      <category domain="http://securityratty.com/tag/functionality boost">functionality boost</category>
      <category domain="http://securityratty.com/tag/discover">discover</category>
      <category domain="http://securityratty.com/tag/tip">tip</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/336121695/0,289483,sid179_gci1321254,00.html">VMware VI Client plug-ins and how to manage them</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Doug McClure: Is BSM Lite the Answer?]]></title>
      <link>http://securityratty.com/article/183e734958786a07b2c4d4b988eb60cc</link>
      <guid>http://securityratty.com/article/183e734958786a07b2c4d4b988eb60cc</guid>
      <description><![CDATA[We had the opportunity to chat with Doug McClure , who is currently the Senior Managing Consultant for Business Service Management (BSM) and IT Service Management (ITSM) for the IBM Software Services...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/07/dougmcclurefeb2008-web.jpg" border="0" alt="dougmcclureFeb2008-web" width="105" height="156" align="left" /> We had the opportunity to chat with <a href="http://dougmcclure.net/blog/" target="_blank">Doug McClure</a>, who is currently the Senior Managing Consultant for Business Service Management (BSM) and IT Service Management (ITSM) for the IBM Software Services for Tivoli (ISST) team at IBM Tivoli (part of Software Group (SWG)). He currently leads the Virtual BSM Practice within IBM Software Services for Tivoli.</p>
<p><em><strong>ScienceLogic:</strong></em> What is “BSM Lite” and how is it different from “heavy” BSM?</p>
<p><strong><em>Doug McClure:</em></strong> I think the concepts that <a href="http://netforecast.com/" target="_blank">Peter Sevcik from Net Forecast</a> initially <a href="http://www.networkworld.com/community/node/27818" target="_blank">outlined in his blog post</a> sum up what &#8220;BSM Lite&#8221; is all about: a simpler, less expensive, more responsive way of achieving the goals and objectives of Business Service Management (BSM).  He&#8217;s contrasted this nicely against what he termed &#8220;BSM Heavy&#8221; being the larger investments in time and resources to deploy domain specific tools and solutions each providing a view into the business service delivery with some aggregation and consolidation to tie up all of the disparate tool&#8217;s information into a concise end-to-end business service management story.</p>
<p>I&#8217;m pleased that he leveraged some of my thinking around a better working definition of what BSM really is from the <a href="http://dougmcclure.net/blog/business-service-management-bsm-defined/" target="_blank">BSM Defined page on my blog</a>. Of course, these definitions are going to vary depending on whom you talk with and how they see the overall BSM Maturity Model.  I&#8217;ve created a BSM Maturity Model that aligns with the famous Gartner IT maturity model.  I&#8217;d like to think that a &#8220;BSM Lite&#8221; solution is one attacking the low hanging fruit, enabling one to achieve value quicker, and in a more tactical manner.  The &#8220;BSM Heavy&#8221; solutions are capable of the same, but span all along the BSM Maturity Model by adding additional point solutions, products and technologies from their broader portfolio. </p>
<p><strong><em>ScienceLogic:</em></strong> Does “BSM Lite” just refer to the tools, or can it refer to the process and methodology as well?</p>
<p><strong><em>Doug McClure:</em></strong> I think that BSM is as much a philosophy as it is technology, process, people and methodology.  If we can get people to think, operate and respond differently than they do today with a focus on the business, customers, quality, revenue, or whatever else is most important to their business goals and objectives, than that is Business Service Management and could be &#8220;BSM Lite&#8221; if you will. </p>
<p>Being that I work for IBM Tivoli, one of my personal objectives is to identify ways to use our key BSM enabling products in a more efficient, effective and BSM centric way. This was a huge driver for trying to hold DevCampTivoli focused on &#8220;Collaborative Development of End-to-End BSM Solutions&#8221;. </p>
<p>In my opinion, we don’t make things very easy for our clients and the answer can’t be to “buy this product, module or widget” to fill in the gaps.  In my opinion, we must establish a BSM overlay within IBM Tivoli’s development and product management organization that ensures that we have clearly thought about how to enable BSM with the hundreds or products that we sell.  In my opinion, every product release must incorporate the fundamentals of enabling BSM in addition to the core domain specific functionality intended. I hope to keep this spirit alive and get our smartest IBMers and clients thinking about the best way to take a &#8220;BSM Heavy&#8221; solution and make it &#8220;lighter&#8221;. I hope to share more about my plans here and guidance for the industry in general soon.</p>
<p>That said, I am always interested in consulting with clients and collaborate with peers in the industry to figure out how to get the focus on the people, process and technology as key components of their BSM strategies.  I am absolutely convinced that without a documented BSM strategy, roadmap and top level sponsorship within the business and IT, the chances of BSM success greatly diminish.</p>
<p><strong><em>ScienceLogic:</em></strong> Given the complexities involved in implementing a BSM strategy and dealing with the people and processes components of any business, how does “BSM Lite” really work? Should the expectations and outcomes be “lite” as well?</p>
<p><strong><em>Doug McClure:</em></strong> Time will tell if &#8220;BSM Lite&#8221; will work.  I&#8217;m seeing emerging companies that are already breaking down some of the barriers to BSM success.  I do not expect that those choosing to begin with a &#8220;BSM Lite&#8221; approach should expect &#8220;lite&#8221; outcomes. </p>
<p>The outcomes are the same regardless of the approach IF you&#8217;ve got a documented BSM strategy, roadmap and top level sponsorship in place before you begin. New features, capabilities and technologies will be needed as the needs of the business change and companies mature in BSM and fundamental IT management. This will likely force companies to move in more &#8220;BSM Heavy&#8221; directions to fill those gaps. </p>
<p>In my opinion, this is the ideal scenario now as it gives &#8220;BSM Lite&#8221; vendors opportunities to grow their products and solutions. It also GREATLY improves the chances for success with a &#8220;BSM Heavy&#8221; solution because the organization would have already had matured enough to approach a &#8220;BSM Heavy&#8221; solution than if they hadn&#8217;t done a &#8220;BSM Lite&#8221; solution in the past.</p>
<p><strong><em>ScienceLogic:</em></strong> Is “BSM Lite” more appropriate for a small or midsized organization, or does it apply equally to large companies? Is there an ideal profile for a company that can successfully implement a BSM strategy? Is there a different profile for “BSM Lite”?</p>
<p><strong><em>Doug McClure:</em></strong> From an economic perspective, the concepts of &#8220;BSM Lite&#8221; are appropriate for all companies.  Remember, with &#8220;BSM Lite&#8221; we&#8217;re focused on identifying ways to make the goals and objectives of BSM easier to implement and in a more cost effective way.  Any company concerned about their IT cost overhead should care about this, especially when the risks of starting out with a &#8220;BSM Heavy&#8221; type deployment are much greater and the time to value generally much longer.</p>
<p>The &#8220;ideal&#8221; profile for any company is one where the BSM initiative begins by establishing top level buy in through creation of a formal BSM strategy for the company. This BSM strategy personalizes how the company defines what BSM is, what value the company expects from it, and how it will use BSM as a competitive differentiator for delivery of its business and IT services, products, etc.</p>
<p>The organizational &#8220;profile&#8221; I&#8217;ve seen most successful is when implementing a BSM strategy originates from within or actively includes a group that many companies have now that serves as a liaison or relationship management role between the various lines of business and IT. Sometimes this group is often seen as the gatekeeper to filter (and hinder) business driven requirements into the IT organization. In the ideal scenario, this group works very closely with the business and IT (usually staffed by business people and not IT people) to understand both the business side and IT side of complex business services and applications. </p>
<p>Apart from the traditional IT components, what this group can do is help IT really understand the business perspective.  Analysis of the impact on the business in business terms is only possible by collaborating with a group such as this.  True value oriented BSM becomes attainable when we get to this level of IT and business alignment, cooperation, collaboration and communication.</p>
<p>If BSM is an IT only initiative, this will likely result in an IT centric perspective severely lacking in the necessary business perspective.  In these cases where IT doesn&#8217;t invest their BSM efforts with the business as an equal partner, the implementation ultimately becomes a &#8220;CYA&#8221; tool for IT and not achieve the desired value oriented expected.</p>
<p>To some degree &#8220;BSM Lite&#8221; may have an entirely different profile. If we see the price points, complexity and time to value change significantly we may see these types of deployments originate exclusively within the Line of Business. The possibility may exist where large enterprises operating in a shared IT services or IT outsourcing type model that the Line of Business brings in a &#8220;BSM Lite&#8221; solution to gain the visibility, checks and balances needed to ensure that the LoB’s needs are being met from the internal/external provider. I&#8217;d envision that &#8220;BSM Lite&#8221; may even be capable of operating within a &#8220;SaaS&#8221; model or other managed service type offering where the price points are below the signing levels triggering broader IT involvement and review.</p>
<p><em>To Be Continued&#8230;</em></p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26amp%3BA+with+Doug+McClure%3A+Is+BSM+Lite+the+Answer%3F&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-doug-mcclure-is-bsm-lite-the-answer%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 20:02:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lite">lite</category>
      <category domain="http://securityratty.com/tag/bsm heavy">bsm heavy</category>
      <category domain="http://securityratty.com/tag/bsm heavy directions">bsm heavy directions</category>
      <category domain="http://securityratty.com/tag/bsm">bsm</category>
      <category domain="http://securityratty.com/tag/outcomes">outcomes</category>
      <category domain="http://securityratty.com/tag/expect lite outcomes">expect lite outcomes</category>
      <category domain="http://securityratty.com/tag/bsm lite approach">bsm lite approach</category>
      <category domain="http://securityratty.com/tag/approach">approach</category>
      <category domain="http://securityratty.com/tag/bsm heavy solution">bsm heavy solution</category>
      <source url="http://blog.sciencelogic.com/qa-with-doug-mcclure-is-bsm-lite-the-answer/07/2008">Q&amp;A with Doug McClure: Is BSM Lite the Answer?</source>
    </item>
    <item>
      <title><![CDATA[Malware and Office Documents Joining Forces]]></title>
      <link>http://securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</link>
      <guid>http://securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</guid>
      <description><![CDATA[Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/X83g6Zkr9hg/s1600-h/screen1.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/b0YAu_NWEQk/s200-R/screen1.jpg" style="border: 0pt none ;" /></a>Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into consideration the time of their attack if the social engineering campaign is either going to be based on a current/upcoming event, or on an event anticipated due to information gathered through open source intelligence, often make it through common signature based scanning solutions.<br />
<br />
Despite the relatively easy to obtain, point'n'click <a href="http://www.f-secure.com/weblog/archives/00001450.html">DIY tools for backdooring common office files</a> are available for the script kiddies to take advantage of, some are <a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">naturally remaining proprietary tools</a>, making them harder to analyze unless a copy is obtained. Like this one, generating "undetected" by signatures based scanning, office documents and spreadsheets that would drop the actual malware on the PC.<br />
<br />
Automatic translation of its description and core features :<br />
<br />
<i>"The program represents a generator OfficeJoiner macros in the language Visual Basic for Application (VBA), for introduction in the document Microsoft Office Word / Microsoft Office Excel executable file (win32 exe), followed by fully automatic recovery and launch, without any&nbsp; additional action by the user. The only requirement that formed in such a way xls / doc files is to support&nbsp; VBA macros on the computer end-user formed file and permission to launch macros.</i><br />
<br />
<i>The program uses NOT a vulnerability (exploit) or macro-virus tools for the introduction, extraction or running embedded files. This means that it has generated macros compatible with ALL versions of Microsoft Office products starting with Microsoft Office 97 package, with any established "patches" and the service pack. Macros generated by this program not detected antivirus, for the simple reason that they are not viruses or macro viruses. The program uses only "established" means products built into Microsoft Excel VBA language to achieve their goals.</i><br />
<br />
<i>- Fully automatic generation of macro for the introduction of documents word / excel any given exe-file with his persistence in the body and subsequent documents automatic recovery and launch, when opening a document word / excel.&nbsp;</i><br />
<br />
<i>- Generated macros are compatible with all versions of ms word / excel since version 97,&nbsp; employments and regardless of the presence / absence of any patches / servicepacs.&nbsp;</i><br />
<br />
<i>- Generated macros are not macro-viruses, exploits do not use and do not contain any malicious code, so do not be detected by any antivirus tools as viruses.&nbsp;</i><br />
<br />
<i>- Conversion body ex-file macro happening in such a way that while in doc / xls file it not detected any antivirus, and can be freely sent by mail safely passed all checks, even if in itself contains viral code defined antivirus. <br />
&nbsp;</i><br />
<i>- Sgenerirovanny and attached to the body of the document macro can be protected with a password or signed certificate, using funds established Microsoft Office, which does not affect him productivity or efficiency (macro, in any case remain fully workable).&nbsp;</i><br />
<br />
<i>- Box macro can be made both in the new document, and in any document containing data and-or other macros. Generated program code is fully compatible with any other embedded in the document macros or entering data, and will not interfere with their work, as well as maintain its efficiency.</i><br />
<br />
<div dir="ltr" id="result_box"><i>- Added auto-finding ways to extract exe-file; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Added possibility of a macro arbitrary text in the body of the instrument; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Optimized algorithm macro-generation code; <br />
</i></div>
<div dir="ltr" id="result_box"><i>&nbsp;</i> </div>
<div dir="ltr" id="result_box"></div>
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<div dir="ltr" id="result_box"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/BtNJaK_13LM/s1600-h/officedocs_malware_sample.PNG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/xhaiKacT-eM/s200-R/officedocs_malware_sample.PNG" style="border: 0pt none ;" /></a><i>Enabling this option will lead to the creation macro code, who himself will find a way to unpack and run embedded exe-file. Auto-search finds the current user folder and produces there extraction and launch embedded file. The peculiarity of this method is that this method will work on the computers of users with a limited account, because in its user folder in any case has the right to record / performance. Using this option is justified to improve the "punching" macro on computers with limited account or unknown file structure (let Windows installed on the disk is different from C). <br />
<br />
You can specify a name for final file independently, or leave blank, then the name will be generated automatically.</i> </div>
<div dir="ltr" id="result_box"><i><br />
</i></div>
<div dir="ltr" id="result_box"><i>On this possibility has asked for a user program, its essence is that after running a macro, retrieval and downloading exe-file the document with the introduction of exe-file will be withdrawn posed text. Perhaps in this way can improve the application of social engineering, designed to force the user to allow support for macros. For example, in the text of the document indicate: <br />
<br />
"This document contains hidden text (password, a system of calculation formulas, interactive components, etc.), Which can be viewed only after the inclusion of support macros. Please enable support for macros and re-opening this document ". <br />
<br />
After resolving support macros, and the implementation of embedded exe-file, the document will be withdrawn given a string containing probable "password" or any other textual information.</i>  " </div>
<br />
Despite that the tool is proprietary, the underground economy's leaks are largely driven by bargain hunters who would exchange proprietary tool, whose often biased exclusiveness may increase the profit margins, for a service or a good that may be worthless for them in general, but impossible to obtain and take advantage of in the present. It will not just leak in one way or another, someone will inevitably backdoor the backdooring tool and trick the novice bargain hunters into running it, by having both their host infected and money taken.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-diy-proprietary-malware.html">Yet Another DIY Proprietary Malware Builder</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit - Proprietary</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">DIY Exploit Embedding Tool - A Proprietary Release</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype Spamming Tool in the Wild - Proprietary Release</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mMDIJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mMDIJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vtGZUJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vtGZUJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Voeqqj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Voeqqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QZJLHj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QZJLHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4VmcIJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4VmcIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rqLHKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rqLHKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LnaC8j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LnaC8j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/335226251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 07:20:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/document">document</category>
      <category domain="http://securityratty.com/tag/document macros">document macros</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/enable support">enable support</category>
      <category domain="http://securityratty.com/tag/macro">macro</category>
      <category domain="http://securityratty.com/tag/macro viruses">macro viruses</category>
      <category domain="http://securityratty.com/tag/support vba macros">support vba macros</category>
      <category domain="http://securityratty.com/tag/exe-file">exe-file</category>
      <category domain="http://securityratty.com/tag/extract exe-file">extract exe-file</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/335226251/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</source>
    </item>
    <item>
      <title><![CDATA[Effective Security with a Continuous Approach to ISO 27001 Compliance]]></title>
      <link>http://securityratty.com/article/742a0f6337db9ec4d8b2ea17dead37c7</link>
      <guid>http://securityratty.com/article/742a0f6337db9ec4d8b2ea17dead37c7</guid>
      <description><![CDATA[Source: Tripwire) The ISO 27001 standard is primarily referred to as the Information Security Management System (ISMS) certification standard. Organizations that seek to implement an ISMS are examined...]]></description>
      <content:encoded><![CDATA[<b>(Source: Tripwire)</b>  The ISO 27001 standard is primarily referred to as the Information Security Management System (ISMS) certification standard.  Organizations that seek to implement an ISMS are examined against ISO 27001. As with several global standards, the scope of this standard is far reaching, with several sets of control objectives and guidelines. Its fundamental purpose is to act as a compendium of techniques for securing IT environments and thus effectively managing business risk as well as demonstrating regulatory compliance.<p>ISO 27001 is recognized internationally as a structured methodology for information security. Companies that choose to adopt ISO 27001 demonstrate their commitment to high levels of information security, however it does not mandate specific procedures nor define the implementation techniques for gaining certification. Thus, companies being audited for ISO 27001 compliance deal with the same issues that plague companies facing regulatory audits: how to effectively achieve compliance and, following an audit, cost-effectively maintain it.<p>The Tripwire Enterprise solution provides organizations with powerful configuration control through its configuration assessment and change auditing capabilities. In this white paper, learn how with Tripwire Enterprise, organizations can quickly achieve IT configuration integrity by proactively assessing how their current configurations measure up to specifications as given in ISO 27001. This provides immediate visibility into the state of their systems, and through automating the process, saves time and effort over a manual efforts.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=k034He"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=k034He" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/331677375" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iso">iso</category>
      <category domain="http://securityratty.com/tag/tripwire enterprise">tripwire enterprise</category>
      <category domain="http://securityratty.com/tag/tripwire enterprise solution">tripwire enterprise solution</category>
      <category domain="http://securityratty.com/tag/adopt iso">adopt iso</category>
      <category domain="http://securityratty.com/tag/tripwire">tripwire</category>
      <category domain="http://securityratty.com/tag/certification standard">certification standard</category>
      <category domain="http://securityratty.com/tag/certification">certification</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/plague companies">plague companies</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/331677375/whitepapers.do">Effective Security with a Continuous Approach to ISO 27001 Compliance</source>
    </item>
    <item>
      <title><![CDATA[ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars]]></title>
      <link>http://securityratty.com/article/913d52903ceaedff758808be4b11d5bf</link>
      <guid>http://securityratty.com/article/913d52903ceaedff758808be4b11d5bf</guid>
      <description><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, such as this one , based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy...]]></description>
      <content:encoded><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, <a href="http://www.domainnamenews.com/miscellaneous/icann-board-resolution-kills-domain-tasting/1689">such as this one</a>, based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy change. But there was confusion over exactly what the policy was; most people just assumed it followed the recommendations of the GNSO council from April.  The incomplete information caused some confused analysis such as <a href="http://www.cadna.org/en/newsroom/press-releases/icann-tasting-solution">this from CADNA (the Coalition Against Domain Name Abuse)</a>.

I asked ICANN and they sent me the actual e-mail that they sent out to registrars. It is published below. My analysis of it is in <a href="http://www.eweek.com/c/a/Security/Yes-Domain-Tasting-Will-End/">a column on eWEEK</a>.

<blockquote>
Dear Registrar,

This message is intended to explain how certain decisions that were made by the ICANN Board of Directors at its meeting in Paris last week may affect your registrar.

Specifically, the Board adopted GNSO recommendations on domain tasting that included both budget and non-budget provisions designed to restrict the applicability of the Add Grace Period (AGP).  Please note that this message is a summary of changes that affect registrars.  You should refer to the adopted budget document and adopted motions for further information.


Summary of Important Timing Issues

After several months of discussion and public comment on both the budget and the GNSO recommendations, the Board has approved the proposed budget containing a provision for collecting transaction fees above a threshold during the AGP.  Effective 1 July 2008, the registrar-level transaction fee will be collected on transactions, including names added on or after 1 July
2008 and deleted during the Add Grace Period above a certain minimum threshold.  Each "transaction" will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if
offered)
will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  The budget assumes the transaction fee rate will remain at US ./send.20.

The second change prohibits registries from issuing refunds above a similar threshold for names registered and deleted during the AGP (although some registries have made plans to charge for such transactions independent of this motion).  The implementation timing of this change has not been set, but should be expected to take place over a period of some months.  ICANN staff will solicit public comments and post a registrar advisory prior to implementation of this aspect of the GNSO recommendation.


Budget - Registrar Fees Effective 1 July 2008

The Operating Plan and Budget details for 2008-2009 fiscal year can be found at:

http://www.icann.org/en/financials/proposed-opplan-budget-v3-fy09-25jun0
8-en.pdf

Relevant section from the approved budget:

* Registrar-Level Transaction Fees

In FY08 the per transaction-year rate was ./send.20 (or a 5 cent discount from the established ./send.25 rate).  The draft FY09 budget assumes that the ./send.20 rate will continue for registrar transaction fees.  As in past years, each transaction will be defined as one-year domain registration increment caused by a successful add renewal or transfer command.  FY09 revenue is estimated to be .4 million for registrar-level transaction fees.  Each "transaction"
will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if offered) will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  Therefore per-transaction fee will continue to be charged for each one-year increment of every transaction (e.g.  at a ./send.20 fee level, the fee for a three-year renewal will be US ./send.60), and registrars will continue to have the option to "defer" payment of the fees for the years beyond one for each transaction.  n

Note, as in previous years, ICANN can collect such fees directly from the registrars only if they are "expressly approved by registrars who account, in the aggregate, for payment of two-thirds of all registrar-level fees collected by ICANN." ICANN will shortly undertake the process of requesting such approval for the 2008-09 fiscal year.  While ICANN is grateful for consistent approval by registrars of fee levels in prior years, and is optimistic about such approval this year, if for some reason the necessary approval is not achieved, the fees will be collected by ICANN, as permitted under the registry agreements through the registries.  (Note that the amount of such fees varies by registry, but in no case exceeds US ./send.25.) Registries will then be able to collect those payments from registrars to the extent permitted under the relevant contracts.  It is expected that the same transaction increments (including AGP) will be covered, whether collected directly by ICANN or in! directly by the registries, so registrars should anticipate this liability under either scenario.


ICANN Board Resolution

Whereas, ICANN community stakeholders are increasingly concerned about domain tasting, which is the practice of using the add grace period (AGP) to register domain names in bulk in order to test their profitability.

Whereas, on 17 April 2008, the GNSO Council approved, by a Supermajority vote, a motion to prohibit any gTLD operator that has implemented an AGP from offering a refund for any domain name deleted during the AGP that exceeds 10% of its net new registrations in that month, or fifty domain names, whichever is greater.  <http://gnso.icann.org/meetings/minutes-gnso-17apr08.shtml>

Whereas, on 25 April 2008, the GNSO Council forwarded its formal "Report to the ICANN Board - Recommendation for Domain Tasting"
<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>,
which outlines the full text of the motion and the full context and procedural history of this proceeding.

Whereas, the Board is also considering the Proposed FY 09 Operating Plan and Budget <http://www.icann.org/financials/fiscal-30jun09.htm>, which includes (at the encouragement of the GNSO Council) a proposal similar to the GNSO policy recommendation to expand the applicability of the ICANN transaction fee in order to limit domain tasting.

Resolved (2008.06.26.06), the Board adopts the GNSO policy recommendation on domain tasting, and directs staff to implement the policy following appropriate comment and notice periods on the implementation documents.


Domain tasting motion approved by the GNSO Council 17 April 2008

<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>

Whereas, the GNSO Council has discussed the Issues Report on Domain Tasting and the Final Outcomes Report of the ad hoc group on Domain Tasting;

Whereas, the GNSO Council resolved on 31 October 2007 to launch a PDP on Domain Tasting;

Whereas, the GNSO Council authorized on 17 January 2008 the formation of a small design team to develop a plan for the deliberations on the Domain Tasting PDP (the "Design Team"), the principal volunteers to which had been members of the Ad Hoc Group on Domain Tasting and were well-informed of both the Final Outcomes Report of the Ad Hoc Group on Domain Tasting and the GNSO Initial Report on Domain Tasting (collectively with the Issues Report, the "Reports on Domain Tasting");

Whereas, the GNSO Council has received the Draft Final Report on Domain Tasting;

Whereas, PIR, the .org registry operator, has amended its Registry Agreement to charge an Excess Deletion Fee; and both NeuStar, the .biz registry operator, and Afilias, the .info registry operator, are seeking amendments to their respective Registry Agreements to modify the existing AGP;

The GNSO Council recommends to the ICANN Board of Directors that:

1.  The applicability of the Add Grace Period shall be restricted for any gTLD which has implemented an AGP ("Applicable gTLD Operator").
Specifically, for each Applicable gTLD Operator:

  a.  During any given month, an Applicable gTLD Operator may not offer any
  refund to a registrar for any domain names deleted during the AGP that
  exceed (i) 10% of that registrar's net new registrations in that month
  (defined as total new registrations less domains deleted during AGP), or
  (ii) fifty (50) domain names, whichever is greater.

  b.  A Registrar may seek an exemption from the application of such
  restriction in a specific month, upon the documented showing of
  extraordinary circumstances.  For any Registrar requesting such an
  exemption, the Registrar must confirm in writing to the Registry Operator
  how, at the time the names were deleted, these extraordinary circumstances
  were not known, reasonably could not have been known, and were outside of
  the Registrar's control.  Acceptance of any exemption will be at the sole
  reasonable discretion of the Registry Operator, however "extraordinary
  circumstances" which reoccur regularly will not be deemed extraordinary.

  c.  In addition to all other reporting requirements to ICANN, each
  Applicable gTLD Operator shall identify each Registrar that has sought an
  exemption, along with a brief descriptive identification of the type of
  extraordinary circumstance and the action (if any) that was taken by the
  Applicable gTLD Operator.

2.  Implementation and execution of these recommendations shall be monitored by the GNSO.  Specifically;

  a.  ICANN Staff shall analyze and report to the GNSO at six month intervals
  for two years after implementation, until such time as the GNSO resolves
  otherwise, with the goal of determining;

    i.  How effectively and to what extent the policies have been implemented
    and followed by Registries and Registrars, and

    ii.  Whether or not modifications to these policies should be considered
    by the GNSO as a result of the experiences gained during the
    implementation and monitoring stages,

  b.  The purpose of these monitoring and reporting requirements are to allow
  the GNSO to determine when, if ever, these recommendations and any ensuing
  policy require additional clarification or attention based on the results
  of the reports prepared by ICANN Staff.

</blockquote>

<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=152f487f101abbcdd9c900fc3eb46268" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=152f487f101abbcdd9c900fc3eb46268" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/330098895" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 11:42:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/fees directly">fees directly</category>
      <category domain="http://securityratty.com/tag/fees">fees</category>
      <category domain="http://securityratty.com/tag/registrar fees effective">registrar fees effective</category>
      <category domain="http://securityratty.com/tag/effective">effective</category>
      <category domain="http://securityratty.com/tag/registrar-level fees">registrar-level fees</category>
      <category domain="http://securityratty.com/tag/fee">fee</category>
      <category domain="http://securityratty.com/tag/per-transaction fee">per-transaction fee</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/330098895/ch_icanns_announcement_of_antidomain_tasting_measures_to_registrars.html">ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars</source>
    </item>
  </channel>
</rss>
