<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: include]]></title>
    <link>http://securityratty.com/tag/include</link>
    <description></description>
    <pubDate>Fri, 19 Sep 2008 06:08:38 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Data Mining for Terrorists Doesn't Work]]></title>
      <link>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</link>
      <guid>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</guid>
      <description><![CDATA[According to a massive report from the National Research Council, data mining for terrorists doesn't work. Here's a good summary: The report was written by a committee whose members include William...]]></description>
      <content:encoded><![CDATA[<p>According to a <a href="http://www.nap.edu/catalog.php?record_id=12452">massive report</a> from the National Research Council, data mining for terrorists doesn't work.  <a href="http://news.cnet.com/8301-13578_3-10059987-38.html?part=rss&subj=news&tag=2547-1_3-0-20">Here's</a> a good summary:</p>

<blockquote>The report was written by a committee whose members include William Perry, a professor at Stanford University; Charles Vest, the former president of MIT; W. Earl Boebert, a retired senior scientist at Sandia National Laboratories; Cynthia Dwork of Microsoft Research; R. Gil Kerlikowske, Seattle's police chief; and Daryl Pregibon, a research scientist at Google.

<p>They admit that far more Americans live their lives online, using everything from VoIP phones to Facebook to RFID tags in automobiles, than a decade ago, and the databases created by those activities are tempting targets for federal agencies. And they draw a distinction between subject-based data mining (starting with one individual and looking for connections) compared with pattern-based data mining (looking for anomalous activities that could show illegal activities).</p>

<p>But the authors conclude the type of data mining that government bureaucrats would like to do--perhaps inspired by watching too many episodes of the Fox series 24--can't work. "If it were possible to automatically find the digital tracks of terrorists and automatically monitor only the communications of terrorists, public policy choices in this domain would be much simpler. But it is not possible to do so."</p>

<p>A summary of the recommendations:</p>

<ul><li>U.S. government agencies should be required to follow a systematic process to evaluate the effectiveness, lawfulness, and consistency with U.S. values of every information-based program, whether classified or unclassified, for detecting and countering terrorists before it can be deployed, and periodically thereafter.

<p><li>Periodically after a program has been operationally deployed, and in particular before a program enters a new phase in its life cycle, policy makers should (carefully review) the program before allowing it to continue operations or to proceed to the next phase.</p>

<p><li>To protect the privacy of innocent people, the research and development of any information-based counterterrorism program should be conducted with synthetic population data... At all stages of a phased deployment, data about individuals should be rigorously subjected to the full safeguards of the framework.</p>

<p><li>Any information-based counterterrorism program of the U.S. government should be subjected to robust, independent oversight of the operations of that program, a part of which would entail a practice of using the same data mining technologies to "mine the miners and track the trackers."</p>

<p><li>Counterterrorism programs should provide meaningful redress to any individuals inappropriately harmed by their operation.</p>

<p><li>The U.S. government should periodically review the nation's laws, policies, and procedures that protect individuals' private information for relevance and effectiveness in light of changing technologies and circumstances. In particular, Congress should re-examine existing law to consider how privacy should be protected in the context of information-based programs (e.g., data mining) for counterterrorism.</ul></blockquote></p>

<p><a href="http://www.nytimes.com/2008/10/08/washington/08data.html">Here</a> <a href="http://blog.wired.com/27bstroke6/2008/10/data-mining-for.html">are</a> <a href="http://techdirt.com/articles/20081007/1242002479.shtml">more</a> news articles on the report.  I <a href="http://www.schneier.com/essay-108.html">explained</a> why data mining wouldn't find terrorists back in 2005.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=w2YwM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=w2YwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=sK5kM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=sK5kM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 02:35:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/synthetic population data">synthetic population data</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/program enters">program enters</category>
      <category domain="http://securityratty.com/tag/research scientist">research scientist</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/microsoft research">microsoft research</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/data_mining_for_1.html">Data Mining for Terrorists Doesn't Work</source>
    </item>
    <item>
      <title><![CDATA[40 Security Flaws Fixed In Mac OS X Security Update 2008-007]]></title>
      <link>http://securityratty.com/article/9e4b9e799dfaeee65d3d9efef1162688</link>
      <guid>http://securityratty.com/article/9e4b9e799dfaeee65d3d9efef1162688</guid>
      <description><![CDATA[Apple has released another pack of patches that cover a total of 40 documented vulnerabilities affecting the Mac OS X. The Security Update 2008-007, available for Tiger and Leopard, covers a range of...]]></description>
      <content:encoded><![CDATA[Apple has released another pack of patches that cover a total of 40 documented vulnerabilities affecting the Mac OS X. The Security Update 2008-007, available for Tiger and Leopard, covers a range of third-party components and Mac OS X flaws that could users at risk of remote code executions attacks.
The more serious vulnerabilities include:
Apache: CVE-2007-6420, [...]]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:56:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/vulnerabilities include">vulnerabilities include</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/third-party components">third-party components</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/range">range</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/tiger">tiger</category>
      <source url="http://cyberinsecure.com/40-security-flaws-fixed-in-mac-os-x-security-update-2008-007/">40 Security Flaws Fixed In Mac OS X Security Update 2008-007</source>
    </item>
    <item>
      <title><![CDATA[Why Risk Management Doesnt Work (?!)]]></title>
      <link>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</link>
      <guid>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</guid>
      <description><![CDATA[Several folks (Hi Daniel , Brent , David !) sent email &amp; twitters asking us our opinion on a Dark Reading article called Why Risk Management Doesnt Work which if you click on the link should come up...]]></description>
      <content:encoded><![CDATA[<p>Several folks (Hi <a href="http://dmiessler.com/">Daniel</a>, <a href="http://stateofsecurity.com/">Brent</a>, <a href="http://www.twitter.com/debix">David</a>!) sent email &amp; twitters asking us our opinion on a Dark Reading article called &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=165107">Why Risk Management Doesn&#8217;t Work</a>&#8221; which if you click on the link should come up for you after seeing someone&#8217;s advertisement for a few seconds.</p>
<p>I&#8217;m assuming the author wants us to read the title as <strong>&#8220;Things to Look Out For in Performing Risk Analysis&#8221;</strong> and not <strong>&#8220;Risk Management is Folly - Stop, Stop, Stop!&#8221;</strong> The former is fine, the latter isn&#8217;t supported by the evidence presented by the subjects of the article.<br />
The subjects of the article are a <strong><a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">good study from Wade Baker &amp; Co. at Verizon</a></strong>, and a report from RSA&#8217;s Security for Business Innovation Council. Let&#8217;s take a look at each of these and examine why what they&#8217;re saying might contribute to poor risk management, shall we?</p>
<p><strong>1.)  THE VERIZON REPORT</strong></p>
<p>The Verizon report is an analysis of some 530 forensic investigations their company performed.  It is well worth your time as it&#8217;s chock full of interesting information.  As it relates to the Dark Reading piece, a coarse summary would be that &#8220;likelihood&#8221; is &#8220;different&#8221; for different people and so you can&#8217;t use the same &#8220;likelihood&#8221; across different industries.</p>
<p>Distilled through the lens of FAIR:</p>
<blockquote><p>&#8220;different threat communities may be applicable based on Probability of Action factors which include: Value, Level of Effort and Risk (of Getting Caught).&#8221;</p></blockquote>
<p>Or, even further distilled and in the words of my six year old son,</p>
<blockquote><p>&#8220;Duh-uh&#8221;.</p></blockquote>
<p>With regards to what I assume is the purpose of the article (What Doesn&#8217;t Work in Risk Analysis) this concept  seems just to rehash the old GIGO argument regarding risk analysis.  Great.  Can&#8217;t argue with that, nor it&#8217;s corollary QIQO (quality in, quality out).</p>
<p>But let me ask you -  <strong><em>is this really a problem common in your analysis</em></strong>?  Did reading this article make you go &#8220;Crap, we&#8217;ve been using data normalized across multiple industries in our analysis! They&#8217;re all wrong!&#8221;  Or have you already been accounting for the unique value proposition your company has to the specific threat community you&#8217;re worried about?  See, maybe I&#8217;m just not your average analyst, but even in my NIST/OCTAVE days, this has *never* been an issue for me.</p>
<p>Let me be specific, this is not a problem with Verizon&#8217;s very cool report.  It&#8217;s just that I don&#8217;t see what the big deal is.  This article is starting to feel like someone is running through the motions, trying to play the &#8221; a crazy title gets people to read a boring article&#8221; game.</p>
<p>Speaking of cool reports - You know what would be cool?  I think it would be interesting to see is the quality of these companies&#8217; &#8220;risk management process&#8221; established using good criteria,  and then correlated to the frequency and magnitude of real-world losses across the aggregate sample.  In other words, can we establish evidence that strong risk management practices not just reduce &#8220;risk&#8221; but also reduce actual incidents.</p>
<p><strong>2.)  THE RSA COUNCIL &#8220;EXPLORES WHY LEGACY METHODS OF EVALUATING INFORMATION SECURITY RISK DON&#8217;T WORK IN TODAY&#8217;S CONNECTED WORLD, IN WHICH ANY NEW BUSINESS INNOVATION INHERENTLY CARRIES SOME LEVEL OF RISK TO INFORMATION.&#8221;</strong></p>
<p>This report from the RSA council puts forth a seemingly obvious proposition, that risk must be balanced by reward.  Why is this news?  Now as I read the article it&#8217;s not clear if:</p>
<ul>
<li>The RSA Council is claiming that the CISO&#8217;s office should be the ones determining reward.  Absurd.</li>
</ul>
<p>or</p>
<ul>
<li>Businesses aren&#8217;t doing a good job at determining risk and reward.</li>
</ul>
<p>Let&#8217;s go with the latter.  So I&#8217;m pretty sure (good) businesses do a good job at estimating reward.  Businesses I&#8217;ve been a part of?  We LOVE(D) estimating reward.  We don&#8217;t tend to start projects all willy-nilly. No we tend to be careful to identify the size of the market and what it will cost to address the market.  So what could the problem be that this RSA council is trying to address?  Maybe it has to do with something like the following:</p>
<p>Yesterday, I got a demo of an IT-GRC application that shall remain nameless.  It seemed to be very good at the &#8220;C&#8221; bits - lots of information on regulations and expectations and even what sorts of controls would answer the regulations (which is goofy, but we&#8217;ll have to talk about that later).  It also gave you the ability to build workflow quite nicely.  But it measured NOTHING.  There really was no observable &#8220;G&#8221; and &#8220;R&#8221; was really Medium X Low X Low = High sorts of stuff.  So let&#8217;s use this relatively expensive tool as evidence of what your average CISO is armed with going into a Risk/Reward sort of meeting.  I imagine a nice board room with wood-grain paneling and glass bowls filled with little chocolate covered mints designed to give everyone involved in the meeting (CEO, CFO, CIO, CSO, VP S&amp;M, etc&#8230;) a little sugar rush when needed and fresh breath.  The conversation goes a little something like this (apologies to <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich</a></strong>):</p>
<blockquote><p><em><strong>Business Guy Who Wants to Make Money Because That&#8217;s What Businesses Do:</strong></em> Based on market studies, we believe that initial gross revenues from the new product and technology rollout will be eleventy gazillion dollars based on a 37% market penetration in Scandinavia, alone.</p>
<p><em><strong>CSO: </strong></em> Well now, we have a likelihood of &#8220;High&#8221; and a &#8220;C&#8221; impact of Medium, and an &#8220;I&#8221; impact of Low, and an &#8220;A&#8221; impact of &#8220;High&#8221; and because we are a (bank/hospital/retailer/basically any business that breathes anymore) we weight &#8220;C&#8221; by a factor of 2 - we multiplied those all together and got a &#8220;High&#8221;.</p>
<p>So can you guys delay the product rollout by 9 months and give me a bunch more money that&#8217;s not in the budget so that I can get this thing down to a &#8220;Medium&#8221;, please?</p></blockquote>
<p>Again, I just don&#8217;t see the problem with Information Risk Management being that our businesses have no idea what the rewards of business might be.  Now maybe we need get a seat in that boardroom just to be able to talk about our &#8220;Mediums&#8221;, sure.  And maybe we&#8217;re infantile in our ability to describe our problem space.  But I cannot fathom that &#8220;<em>Risk Management Doesn&#8217;t Work</em>&#8221; because businesses haven&#8217;t been considering &#8220;reward&#8221;.</p>
<p><strong>WHY RISK MANAGEMENT MAY  NOT BE WORKIN&#8217; FOR YOU</strong></p>
<p>Two meta-categories of causation:</p>
<ul>
<li>No skills</li>
</ul>
<p>and/or</p>
<ul>
<li>No resources</li>
</ul>
<p>Any ancillary &#8220;cause&#8221; can be mapped to one of these categories.  You could have significant resources but crappy models, and have conversations like our imaginary CSO, above.  You could have really good models and people trained and motivated to use them, but scarce time &amp; money, so no conversation happens.</p>
<p>Now my question for you is - which does it make sense to acquire *first* to solve the &#8220;<em>Why Risk Management Doesn&#8217;t Work</em>&#8221; problems, skills or resources?</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 13:15:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/information security risk">information security risk</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/cool report">cool report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=459">Why Risk Management Doesnt Work (?!)</source>
    </item>
    <item>
      <title><![CDATA[Hackers Use Neosploit To Infect Around 80,000 Sites, Including BBC And US Postal Service]]></title>
      <link>http://securityratty.com/article/186b56f8545276fcbddd00f834c8f8ee</link>
      <guid>http://securityratty.com/article/186b56f8545276fcbddd00f834c8f8ee</guid>
      <description><![CDATA[According to Ian Amit, director of security research at Aladdin Knowledge Systems, cybercriminals have used the latest version of Neosploit to booby-trap an estimated 80,000 legitimate sites with...]]></description>
      <content:encoded><![CDATA[According to Ian Amit, director of security research at Aladdin Knowledge Systems, cybercriminals have used the latest version of Neosploit to booby-trap an estimated 80,000 legitimate sites with malicious code. Victims of the attack include government, Fortune 500, and a weapons manufacturing firm. Victims of the attack also included the US Postal Service, which has [...]]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 17:39:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack include government">attack include government</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/postal service">postal service</category>
      <category domain="http://securityratty.com/tag/aladdin knowledge systems">aladdin knowledge systems</category>
      <category domain="http://securityratty.com/tag/neosploit">neosploit</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://securityratty.com/tag/security research">security research</category>
      <category domain="http://securityratty.com/tag/ian amit">ian amit</category>
      <source url="http://cyberinsecure.com/hackers-use-neosploit-to-infect-around-80000-sites-including-bbc-and-us-postal-service/">Hackers Use Neosploit To Infect Around 80,000 Sites, Including BBC And US Postal Service</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 8]]></title>
      <link>http://securityratty.com/article/d60cc90ef226fd7624953a3c03f282d4</link>
      <guid>http://securityratty.com/article/d60cc90ef226fd7624953a3c03f282d4</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #7, dated October 2nd, 2008
Great...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #7, dated October 2nd, 2008.</p>  <ol>   <li><a href="http://www.darkreading.com/document.asp?doc_id=162936">Great paper</a> that complements the whole &quot;SIEM is dead?&quot; saga - &quot;Most enterprises are looking for a product that <em>will solve all of their problems in some sort of off-the-shelf miracle</em>, and when they find out that the currently available tools can't do it, they either postpone their deployment or put them on the back burner. &quot; </li>    <li>&quot;<a href="http://financialcryptography.com/mt/archives/001093.html">The Mess: looking for someone to blame?</a>&quot; is an awesome piece on Internet security and its architecture - and so is Gunnar's follow-up (&quot;<a href="http://1raindrop.typepad.com/1_raindrop/2008/09/if-a-tree-falls-in-someone-elses-silo.html">If a tree falls in someone else's silo...</a>&quot;) </li>    <li>Mike call to &quot;<a href="http://securityincite.com/blog/mike-rothman/rise-up-against-mediocrity">Rise up against Mediocrity</a>.&quot;&#160; - &quot;Dilbert makes the risk of the lowest common denominator approach abundantly clear.&quot;; in other words, you say 'best practices', I say 'mediocrity!' Mike also remind us, in vain, to do &quot;Security FIRST!&quot; (and compliance second) </li>    <li>A great piece from Burton: &quot;<a href="http://srmsblog.burtongroup.com/2008/08/on-response.html">On Response</a>&quot; - I think the world needs another 10-20 million reminders that PREVENTION FAILS. <a href="http://srmsblog.burtongroup.com/2008/08/on-response.html">This</a> is definitely a good one for those still in the &quot;we'll just block the threat world&quot; - &quot;we will not win a continuing war of escalation&quot; and &quot;using response can be more cost effective than installing the latest and greatest preventative tool&quot; </li>    <li><a href="http://blog.isc2.org/isc2_blog/2008/08/security-metric.html">More on metrics</a>, including the highly-awaited ISO27004. </li>    <li><a href="http://www.ecommercetimes.com/story/64598.html">Pretty dumb paper</a> by a person confused by why PCI DSS exists (the guy needs to read <a href="http://treasuryinstitute.org/blog/index.php?itemid=174">this</a>). PCI doesn't &quot;fall short,&quot; it helps people who will otherwise not do <em>anything</em> and their systems will &quot;power&quot; those botnets of the future... </li>    <li>While we are on this subject: <a href="http://pcianswers.com/2008/10/01/pci-dss-version-12-differences-and-updates/">a really good coverage of PCI 1.2. changes</a>, released Oct 1st. More PCI fun <a href="http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/">here.</a> And more <a href="http://www.computerweekly.com/blogs/stuart_king/2008/09/i-was-supposed-to-be.html">here</a> (&quot;<a href="http://www.computerweekly.com/blogs/stuart_king/2008/09/i-was-supposed-to-be.html">PCI Compliance - dispelling some common myths</a>&quot;). And, <a href="http://www.estoregfoa.org/StaticContent/staticpages/TM0508.htm#1c">more PCI myths</a>. And <a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-29-2008">more good ideas</a> on PCI from Mike R. Sorry, can't stop thinking about PCI :-)&#160; - also <a href="http://pcidss.wordpress.com/2008/09/19/the-inside-story-of-pci-confessions-of-a-qsa-commentary-by-james-deluccia/">this is good.</a> </li>    <li><a href="http://securosis.com/2008/09/23/behavioral-monitoring/">Adrian on behavioral monitoring</a>; mostly in DAM, but also elsewhere in security. </li>    <li>&quot;<a href="http://www.darkreading.com/blog.asp?blog_sectionid=327&amp;doc_id=164144">Premature Chasm-Crossing</a>&quot;&#160; - a must-read for all security vendors and especially their marketing (and&#160; their easily-excitable PR teams...) - &quot;Shouldn't vendors be spending more time fighting the problems that security managers are facing today, right this minute?&quot; (Mike R <a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-24-2008">also comments</a> on that). A related - and&#160; just as interesting point is made here: &quot;<a href="http://blogs.computerworld.com/security_is_not_a_solution">Security is not a solution</a>&quot; </li>    <li><a href="http://www.csoonline.com/article/print/450190">More</a> on compliance and security checklists, good and bad: &quot;I think this is a dangerous trend unless the &quot;checklist&quot; is all inclusive.&quot; (how can a checklist include <strong>ALL? :-)</strong>) </li>    <li><a href="http://forensics.sans.org/community/top7_forensic_trends.php">&quot;SANS Top 7 New IR/Forensic Trends In 2008&quot;</a> </li>    <li>Read &quot;<a href="http://theinvisiblethings.blogspot.com/2008/09/three-approaches-to-computer-security.html">The three approaches to computer security!</a>&quot;&#160; Why? Come on, it is from <a href="http://theinvisiblethings.blogspot.com">Joanna</a>! :-) </li>    <li><a href="http://rationalsecurity.typepad.com/blog/2008/09/ids-vitamins-or-prophylactic.html">A fun discussion</a> about a hot new technology:<em> network IDS. </em>Is IDS <em>absolutely</em> indispensable to <em>ALL</em> companies? No. Can it be incredibly useful? You bet. End of discussion. </li>    <li>On an unrelated note, are lasers the future of warfare? <a href="http://blog.wired.com/defense/2008/09/why-lasers-wont.html">Some say no.</a> </li>    <li>Finally, some security humor from Gartner (!): &quot;<a href="http://blogs.gartner.com/greg_young/2008/09/30/get-rich-quick-with-network-security/">Get Rich Quick With Network Security</a>&quot; </li> </ol>  <p>Enjoy!</p>  <p><a href="http://chuvakin.blogspot.com/search/label/reading">Previous security reading.</a></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pqMsM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pqMsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=avlNM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=avlNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=EvcjM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=EvcjM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/409462346" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 06:31:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security managers">security managers</category>
      <category domain="http://securityratty.com/tag/previous security">previous security</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss exists">pci dss exists</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/pci fun">pci fun</category>
      <category domain="http://securityratty.com/tag/security checklists">security checklists</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/409462346/fun-reading-on-security-8.html">Fun Reading on Security - 8</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kit Comes with Disclaimer]]></title>
      <link>http://securityratty.com/article/f53d9a8c84706cb980c1a5fe00e3e2f8</link>
      <guid>http://securityratty.com/article/f53d9a8c84706cb980c1a5fe00e3e2f8</guid>
      <description><![CDATA[Such disclaimers make you wonder what's the point of including a notice forwarding the responsibility for the upcoming cybercrime activities to the buyer, when the seller himself is offering daily...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOPmoVr-3KI/AAAAAAAACNQ/L7Fxlk4j_Gg/s1600-h/1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOPmoVr-3KI/AAAAAAAACNQ/IZ-phgyZJpY/s200-R/1.JPG" /></a>Such disclaimers make you wonder what's the point of including a notice forwarding the responsibility for the upcoming cybercrime activities to the buyer, when the seller himself is offering daily updates with undetected bots, and is promising to include new exploits within the kit.<br />
<br />
For the time being, this recently released copycat web exploitation malware kit, includes two PDF exploits, IE snapshot, and naturally MDAC, with a DIY builder for the binary. Here's the disclaimer, greatly reminding us of <a href="http://www.theregister.co.uk/2008/04/28/malware_copyright_notice/">Zeus's copyright notice</a> : <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQEl4WjyJI/AAAAAAAACNw/bup8hAFSOIA/s1600-h/3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQEl4WjyJI/AAAAAAAACNw/J0Uxe3C2IPI/s200-R/3.JPG" /></a>"<i>Purchasing this product, you hold the full responsibility for its usage and for consequences which may have been caused by incorrect usage or the usage with some evil intent or violation of the usage rules. The author excludes the placement of the scripts somewhere on the Internet, you can only place them on localhost, virtual machine or on a test botnet (minibotnet). WARNING! The usage of this product with evil intent leads to the criminal responsibility!</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQE_GioZeI/AAAAAAAACN4/-TgImabe7zw/s1600-h/5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQE_GioZeI/AAAAAAAACN4/TC5-5hqbJ0I/s200-R/5.JPG" /></a>What happens when the buyer tries to resell the kit? - "<i>If you try to resell, decode, remove the boundaries, you will lose all the  support, updates and guarantees.</i>" which is surreal considering that the kit is open source one, and just like we've seen with a recent modification of Zeus if it were to include unique features -- which it doesn't -- others would build upon its foundations.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SOQFHcVCuhI/AAAAAAAACOA/gyW259ojaII/s1600-h/7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SOQFHcVCuhI/AAAAAAAACOA/XvJB5TF7UCE/s200-R/7.JPG" /></a><br />
Going through the exploitation statistics of a sample campaign, you can clearly see that out of the 859 unique visits 250 got exploited with outdated and already patched vulnerabilities. Therefore, diversifying the exploits set would have increased the number of exploited hosts.<br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQFq13TnPI/AAAAAAAACOI/Ubkw74c4Wn0/s1600-h/9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQFq13TnPI/AAAAAAAACOI/nvO4FBQ3s3k/s200-R/9.JPG" /></a>With IE6 visitors exploited at 46% as a whole, it would be hard not to notice that just like Stormy Wormy's historical persistence of using outdated vulnerabilities, a great majority of today's botnets have been aggregated using old exploits.<br />
<br />
Trying to enforce the intellectual property of a malware kit means you're claiming ownership, and therefore the disclaimer becomes irrelevant.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7NZmM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7NZmM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DOidM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DOidM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7V8tm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7V8tm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wAlLm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wAlLm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6EqeM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6EqeM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZZ3BM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZZ3BM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0wv6m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0wv6m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409055131" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 22:58:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/usage rules">usage rules</category>
      <category domain="http://securityratty.com/tag/usage">usage</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/pdf exploits">pdf exploits</category>
      <category domain="http://securityratty.com/tag/incorrect usage">incorrect usage</category>
      <category domain="http://securityratty.com/tag/evil intent">evil intent</category>
      <category domain="http://securityratty.com/tag/evil intent leads">evil intent leads</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409055131/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Modified Zeus Crimeware Kit Comes With Built-in MP3 Player]]></title>
      <link>http://securityratty.com/article/b4e5929a51488e98a9fe58b74de94b94</link>
      <guid>http://securityratty.com/article/b4e5929a51488e98a9fe58b74de94b94</guid>
      <description><![CDATA[Modified versions of popular open source crimeware kits rarely make the headlines due to the fact that anyone can hijack a crimeware kit's brand, build and innovate using its foundations , and claim...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOFSuEL8pNI/AAAAAAAACMg/GaTGj9uQ9hA/s1600-h/zeus_modified_mp3_player.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOFSuEL8pNI/AAAAAAAACMg/vkspv62-OAY/s200-R/zeus_modified_mp3_player.jpg" width="200" /></a>Modified versions of popular <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">open source crimeware kits</a> rarely make the headlines due to the fact that anyone can hijack a crimeware kit's brand, build and <a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html">innovate using its foundations</a>, and claim it's a new version <a href="http://ddanchev.blogspot.com/2008/05/custom-ddos-attacks-within-popular.html">released by the original authors</a>. That's of course in between the tiny time frame until he's exposed as the fake author of Zeus that may have in fact came up with a unique feature that the original authors didn't include.<br />
<br />
This <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">modified version of Zeus</a> is yet another example of how <a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">cybercriminals are actively modifying crimeware kits</a>, literally making such practices as keeping version numbers irrelevant. While the administrator is managing his botnet, he can load local, or tunein the built-in online radio stations the author of this modification included, next to changing Zeus entire graphical layout.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOFXXUuuCcI/AAAAAAAACMo/amKui3kRUEU/s1600-h/pinchy_2008_modified_opensource.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOFXXUuuCcI/AAAAAAAACMo/6el-_eHnyQs/s200-R/pinchy_2008_modified_opensource.jpg" /></a>Let's take into consideration another example, the infamous Pinch DIY malware builder, that's been around for over 4 years. With <a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">the populist arrest of its authors in 2007</a>, cybercriminals are still innovating on the foundations offered by Pinch, and <a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">thanks to its publicly obtainable source code</a>. It's also worth pointing out that these two Zeus and Pinch modifications are courtesy of a single individual, that in between modifications of popular crimeware kits, seems to be busy porting different modules on different malware kits and web based malware, knowingly or unknowingly contributing to the convergence of spamming, DDoS, web based malware, and botnet management kits.<br />
<br />
From a sarcastic perspective - what's next? Perhaps a built-in slideshow of random screenshots taken from malware infected desktops in the botnet, or even a pink layout modification for female botnet masters. Customerization, and <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">customer tailored services can make anything happen</a>, and naturally enjoy the higher profit margins.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NlAiL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NlAiL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JOcjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JOcjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iqcal"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iqcal" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8Mjyl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8Mjyl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9dQOL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9dQOL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MQJML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MQJML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4yQcl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4yQcl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/406690696" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 13:55:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/female botnet masters">female botnet masters</category>
      <category domain="http://securityratty.com/tag/popular crimeware kits">popular crimeware kits</category>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/crimeware kits">crimeware kits</category>
      <category domain="http://securityratty.com/tag/authors">authors</category>
      <category domain="http://securityratty.com/tag/original authors">original authors</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/406690696/modified-zeus-crimeware-kit-comes-with.html">Modified Zeus Crimeware Kit Comes With Built-in MP3 Player</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: Hypervisor Quick Poll]]></title>
      <link>http://securityratty.com/article/5f4e1b85bcb4d172e0ed7994ef95ea8e</link>
      <guid>http://securityratty.com/article/5f4e1b85bcb4d172e0ed7994ef95ea8e</guid>
      <description><![CDATA[On the final day of Interop NY 2008 , we conducted a second quick poll of attendees ( check out the first poll on virtualization here ), asking which hypervisors were currently in use. In asking the...]]></description>
      <content:encoded><![CDATA[<p><b><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" height="99" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image002.gif" width="91" align="left" border="0"></b>On the final day of <a href="http://www.interop.com/">Interop NY 2008</a>, we conducted a second quick poll of attendees (<a href="http://blog.sciencelogic.com/interop-ny-virtualization-quick-poll/09/2008">check out the first poll on virtualization here</a>), asking which hypervisors were currently in use. In asking the question, we had certain assumptions – mainly that most people were currently using VMware – and that the real question here was to gauge how quickly Microsoft Hyper-V adoption was coming along. The results both confirmed what we thought and surprised us.
<p><b>The Results: </b>
<p><b><i>Which hypervisor(s) are you currently using?</i></b><i></i>
<ul>
<li><b>72%</b> VMware </li>
<li><b>17%</b> Using something else </li>
<li><b>9%</b> Hyper-V and VMware </li>
<li><b>2%</b> Hyper-V </li>
</ul>
<p>(based on 46 responses)
<p>So the VMware responses were in line with what we thought, although I’ve seen numbers up to 90% share of the market. And about 10% are at least playing with Hyper-V – pretty good numbers just a few months out from launch. But look at 17% using a hypervisor other than Hyper-V and VMware!
<p>We know from talking with people that several brought up Xen. I have to tell you that other than from media and analysts, we never hear about Xen (Citrix), which is why we didn’t include it in the survey as a specific selection. Perhaps it took the introduction of Hyper-V, with the attendant marketing juggernaut, to break people of the VMware-only habit. Xen couldn’t really carry that “heterogeneous” hypervisor environment message on its own, but now that Hyper-V is available, the genie’s out of the bottle. Bears watching.
<p>On another note: We were more successful in hanging onto our marbles on day two – people seemed more in tune to the poll and less focused on collecting giveaways than on day one! [Note: no attendees were <a href="http://blog.sciencelogic.com/interop-ny-virtualization-quick-poll/09/2008">irrevocably harmed</a> during the execution of the polls. :)] At Interop Vegas, May 17 – 19, 2009, we’ll be about a year out from Microsoft launching Hyper-V and will make sure to ask the same question then to track changes in hypervisor adoption.</p>
]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 14:30:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware-only habit">vmware-only habit</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/quick poll">quick poll</category>
      <category domain="http://securityratty.com/tag/hypervisor">hypervisor</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/hyper-v">hyper-v</category>
      <category domain="http://securityratty.com/tag/hyper-v pretty">hyper-v pretty</category>
      <category domain="http://securityratty.com/tag/vmware responses">vmware responses</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <source url="http://blog.sciencelogic.com/interop-ny-hypervisor-quick-poll/09/2008">Interop NY: Hypervisor Quick Poll</source>
    </item>
    <item>
      <title><![CDATA[Merged Banks' Names Already Cyber-squatted]]></title>
      <link>http://securityratty.com/article/2e490f1861f13ae3554a91a0487bf943</link>
      <guid>http://securityratty.com/article/2e490f1861f13ae3554a91a0487bf943</guid>
      <description><![CDATA[Domain name speculators are already buying up names of recently merged banks , according to the BBC. In fact, names are being bought even in the speculation of sales. Earlier this week, as Lehman...]]></description>
      <content:encoded><![CDATA[<a href="http://news.bbc.co.uk/2/hi/technology/7621647.stm">Domain name speculators are already buying up names of recently merged banks</a>, according to the BBC.

In fact, names are being bought even in the speculation of sales. Earlier this week, as Lehman Brothers was failing and rumors circulated as to who might buy them, the names barclayslehman.com, hsbclehman.com, hsbclehmanbrothers.com and bofalehman.com were all reserved. The buyers are in the Netherlands and New York City, and one domain is registered anonymously.

The same phenomenon is occurring in the U.K., where speculation surrounding the merger of Lloyds TSB with HBOS led someone to buy lloydstsbhbos.com and hboslloydstsb.com.

Some of these domains include a notice that they are for sale. The person who bought bankofamericamerrilllynch.com went further, including a link to an eBay auction where the domain is for sale with a $1,500 reserve. About two days into the auction, no bids have been made. People who reserve domain names with clear trademarks in them routinely lose them in arbitration cases brought, under <a href="http://www.icann.org/en/udrp/#udrp">ICANN's Uniform Domain Name Dispute Resolution Policy</a>, by the trademark holders.
<p><a href="http://feedads.googleadservices.com/~a/LRPJk9bZbQjdjTpzsK54lwxP7q0/a"><img src="http://feedads.googleadservices.com/~a/LRPJk9bZbQjdjTpzsK54lwxP7q0/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/HSwU0TmTLAk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:08:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/reserve domain names">reserve domain names</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/uniform domain">uniform domain</category>
      <category domain="http://securityratty.com/tag/reserve">reserve</category>
      <category domain="http://securityratty.com/tag/names barclayslehman">names barclayslehman</category>
      <category domain="http://securityratty.com/tag/dispute resolution policy">dispute resolution policy</category>
      <category domain="http://securityratty.com/tag/auction">auction</category>
      <category domain="http://securityratty.com/tag/ebay auction">ebay auction</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/HSwU0TmTLAk/merged_banks_names_already_cybersquatted.html">Merged Banks' Names Already Cyber-squatted</source>
    </item>
  </channel>
</rss>
