<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: manuals]]></title>
    <link>http://securityratty.com/tag/manuals</link>
    <description></description>
    <pubDate>Tue, 15 Jan 2008 13:43:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[DIY Phishing Pages With Command and Control Interfaces]]></title>
      <link>http://securityratty.com/article/78a81ce667063a0a1268788bb3f66128</link>
      <guid>http://securityratty.com/article/78a81ce667063a0a1268788bb3f66128</guid>
      <description><![CDATA[The day when DIY phishing pages start coming with manuals is the day when consciously or subconsciously a phisher is lowering down the entry barriers into phishing for yet another time. A much more...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRIwl6hmo2I/AAAAAAAACa8/_1fYFgW0kzk/s1600-h/rapidshare_phishing_admin_panel.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRIwl6hmo2I/AAAAAAAACa8/_1fYFgW0kzk/s200/rapidshare_phishing_admin_panel.jpg" /></a>The day when DIY phishing pages start coming with manuals is the day when consciously or subconsciously a phisher is lowering down the entry barriers into phishing for yet another time. A much more user-friendly compared to the old-fashioned -- yet effective -- <a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">rock phish directory listing</a>, a recently released command and control interface for Rapidshare phishing campaigns aims to empower its users with easy dynamic link generation for their campaigns.<br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLdeRIJEbI/AAAAAAAACbE/ta5F-iiF2gg/s1600-h/DIY_phishing_scripts.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLdeRIJEbI/AAAAAAAACbE/ta5F-iiF2gg/s200/DIY_phishing_scripts.JPG" /></a>What they've managed to achieve is another trust factor since Rapidshare generates a second dynamic link upon clicking on the original one. The script not only generates a dynamically looking link, but also, actually logs in the victim into their account in order to avoid suspicion whereas it still logs all the accounting data.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLhzGDKcrI/AAAAAAAACbM/5-CHdeukArk/s1600-h/rapidshare_phishing_insecure_directory_permissions.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLhzGDKcrI/AAAAAAAACbM/5-CHdeukArk/s200/rapidshare_phishing_insecure_directory_permissions.JPG" /></a></div>Scammers also tend to be ironic every then and now. For instance, in this particular case, one of the users finds it ironic that the Rapidshare phishing page is hosted at Rapidshare itself. Is the script actually working? It appears so at least going through a misconfigured accounting data dump left by one of the phishers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">Phishing Pages for Every Bank are a Commodity</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/diy-phishing-kits.html">DIY Phishing Kits</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/diy-phishing-kit-goes-20.html">DIY Phishing Kit Goes 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY Phishing Kits Introducing New Features</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5kY3N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5kY3N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=r8EaN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=r8EaN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qtrtn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qtrtn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qM6qn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qM6qn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T3U6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T3U6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YwrRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YwrRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nQNrn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nQNrn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/444324371" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 03:31:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diy">diy</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <category domain="http://securityratty.com/tag/rapidshare">rapidshare</category>
      <category domain="http://securityratty.com/tag/data dump">data dump</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/campaigns">campaigns</category>
      <category domain="http://securityratty.com/tag/dynamic link">dynamic link</category>
      <category domain="http://securityratty.com/tag/pages start">pages start</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/444324371/diy-phishing-pages-with-command-and.html">DIY Phishing Pages With Command and Control Interfaces</source>
    </item>
    <item>
      <title><![CDATA[Blogging as therapy]]></title>
      <link>http://securityratty.com/article/60389f51a09ea17a747d04c584730c9c</link>
      <guid>http://securityratty.com/article/60389f51a09ea17a747d04c584730c9c</guid>
      <description><![CDATA[As some of you know, my friend Mitchell Ashley and his wife Mary Ellen have been battling against breast cancer for over 3 years now. It has been a roller coaster ride for both of them and I have seen...]]></description>
      <content:encoded><![CDATA[<p>As some of you know, my friend Mitchell Ashley and his wife Mary Ellen have been battling against breast cancer for over 3 years now. It has been a roller coaster ride for both of them and I have seen first hand how much courage it has taken for Mitchell to deal with this scourge, let alone the courage that Mary Ellen has in battling this disease. Though Mitchell has never made a secret of it, he has not made it very public either. That has now changed with a new blog that Mitchell started call <a href="http://www.breastcancerforhusbands.com/">breastcancerforhusbands.com</a>.<br><br>Mitchell wants to share his experience as the "other" spouse in this life and death battle that too many couples face. He is looking to make it a resource for others faced with a similar battle. But there is part of doing this which is therapeutic for Mitchell as well. Talking about what he is feeling and going through helps him deal with the emotions and toll it takes. At the same time he is providing resources to those who may be in need. <br><br>I applaud Mitchell for being brave enough to come forward and face these demons publicly. Though we do not work together every day, Mitchell and I still speak almost every day. I know that he and Mary Ellen fight this each and every day and am constantly amazed at their faith in God and courage. If you get a chance, check out the blog and support Mitchell, Mary Ellen and the rest of the people who do battle with this terrible disease every day.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.telegraph.co.uk/health/main.jhtml?xml=/health/2008/07/09/hbreastcancer109.xml">Cancer: seeking solace online</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.ctv.ca/servlet/ArticleNews/story/CTVNews/20080623/cancer_manuals_080623/20080623?hub=Health">Manuals offer advice on navigating breast cancer</a></li>

<li class="zemanta-article-ul-li"><a href="http://abcnews.go.com/Health/OnCallPlus/story?id=4016101&amp;page=1">Celebs Who Fought Breast Cancer and Won</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/98fd8142-cc4a-463a-aa0a-06ece49c6bfe/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=98fd8142-cc4a-463a-aa0a-06ece49c6bfe" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"></img></a></div>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=OzeSky"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=OzeSky" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TB4QxJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TB4QxJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=j5Xw7J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=j5Xw7J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=uwqruJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=uwqruJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=zW57NJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=zW57NJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ShJFUj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ShJFUj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ba98xj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ba98xj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/350179380" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 21:13:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/breast cancer">breast cancer</category>
      <category domain="http://securityratty.com/tag/cancer">cancer</category>
      <category domain="http://securityratty.com/tag/mitchell">mitchell</category>
      <category domain="http://securityratty.com/tag/friend mitchell ashley">friend mitchell ashley</category>
      <category domain="http://securityratty.com/tag/applaud mitchell">applaud mitchell</category>
      <category domain="http://securityratty.com/tag/support mitchell">support mitchell</category>
      <category domain="http://securityratty.com/tag/fought breast cancer">fought breast cancer</category>
      <category domain="http://securityratty.com/tag/wife mary">wife mary</category>
      <category domain="http://securityratty.com/tag/battle">battle</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/350179380/blogging-as-the.html">Blogging as therapy</source>
    </item>
    <item>
      <title><![CDATA[Quick thoughts on using the iPhone 3G]]></title>
      <link>http://securityratty.com/article/7e0dbb56452b0c71a5581a5ba7926361</link>
      <guid>http://securityratty.com/article/7e0dbb56452b0c71a5581a5ba7926361</guid>
      <description><![CDATA[So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer. The iPhone was incredibily easy to use and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer.&nbsp; The iPhone was incredibily easy to use and without using and manuals quickly had a most everything working and downloaded a bunch of apps from the app store.&nbsp; </p>

<p>Over all, the iPhone just is really nice to use and in many ways very easy, polished and intuitive. In other ways, it is still missing some key features in my book:</p>

<ol><li>Sort and filter email be date, sender, etc.</li>

<li>Select more than one mail at a time to delete, move, copy.&nbsp; Yes I know you can go to edit and select messages to work on, but you still have to select them one at a time. In <a class="zem_slink" title="Windows Mobile" href="http://microsoft.com/windowsmobile/" rel="homepage">Windows Mobile</a> you can just run your finger over multiple messages to complete this.</li>

<li>Deleting duplicate contacts in bulk.&nbsp; Doing them one at a time is just painful</li>

<li>A task manager. I would like to see some list that shows me which apps are running, how many resources they are using, battery usage and stuff like that.&nbsp; Also to shut down running apps</li>

<li>Better calendar integration. I tried to click on and open calendar items, but just does not seem to work.</li>

<li>The battery sucks! I am not getting more than about 6 to 7 hours of battery time. I think I have to turn off the push for my Exchange email.&nbsp; This is much less that I was getting on my Windows Mobile phone. </li></ol>

<p>I do like the phone, the iPod MP3 and camera and the overall &quot;feel&quot; of the phone. Went to the Apple store in the maill (which was jam packed) and bought a rubberized case, but was unable to get a phone car charger for it yet.&nbsp; I ordered one for 5 bucks on Amazon and will see it if works.</p>

<p>All in all, things are OK but I am going to withhold my final verdict for a while yet.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13579_3-9994744-37.html?hhTest=1&amp;part=rss&amp;subj=news">What iPhone? Apple earnings (still) about the Mac</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.tuaw.com/2008/07/21/mod-your-dock-to-work-with-iphone-3g/">Mod your dock to work with iPhone 3G</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.sauria.com/blog/2008/07/20/my-initial-iphone-experience/">My initial iPhone experience</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/85ef20ad-b620-4d16-9f87-17955147e8a7/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=85ef20ad-b620-4d16-9f87-17955147e8a7" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 05:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/phone car charger">phone car charger</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/initial iphone experience">initial iphone experience</category>
      <category domain="http://securityratty.com/tag/windows mobile phone">windows mobile phone</category>
      <category domain="http://securityratty.com/tag/windows mobile">windows mobile</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/battery time">battery time</category>
      <category domain="http://securityratty.com/tag/select messages">select messages</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/quick-thoughts.html">Quick thoughts on using the iPhone 3G</source>
    </item>
    <item>
      <title><![CDATA[Quick thoughts on using the iPhone 3G]]></title>
      <link>http://securityratty.com/article/0cfe5d9fddb01551dfe3d3dcb40ee176</link>
      <guid>http://securityratty.com/article/0cfe5d9fddb01551dfe3d3dcb40ee176</guid>
      <description><![CDATA[So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer. The iPhone was incredibily easy to use and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer.&nbsp; The iPhone was incredibily easy to use and without using and manuals quickly had a most everything working and downloaded a bunch of apps from the app store.&nbsp; </p>

<p>Over all, the iPhone just is really nice to use and in many ways very easy, polished and intuitive. In other ways, it is still missing some key features in my book:</p>

<ol><li>Sort and filter email be date, sender, etc.</li>

<li>Select more than one mail at a time to delete, move, copy.&nbsp; Yes I know you can go to edit and select messages to work on, but you still have to select them one at a time. In <a class="zem_slink" title="Windows Mobile" href="http://microsoft.com/windowsmobile/" rel="homepage">Windows Mobile</a> you can just run your finger over multiple messages to complete this.</li>

<li>Deleting duplicate contacts in bulk.&nbsp; Doing them one at a time is just painful</li>

<li>A task manager. I would like to see some list that shows me which apps are running, how many resources they are using, battery usage and stuff like that.&nbsp; Also to shut down running apps</li>

<li>Better calendar integration. I tried to click on and open calendar items, but just does not seem to work.</li>

<li>The battery sucks! I am not getting more than about 6 to 7 hours of battery time. I think I have to turn off the push for my Exchange email.&nbsp; This is much less that I was getting on my Windows Mobile phone. </li></ol>

<p>I do like the phone, the iPod MP3 and camera and the overall &quot;feel&quot; of the phone. Went to the Apple store in the maill (which was jam packed) and bought a rubberized case, but was unable to get a phone car charger for it yet.&nbsp; I ordered one for 5 bucks on Amazon and will see it if works.</p>

<p>All in all, things are OK but I am going to withhold my final verdict for a while yet.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13579_3-9994744-37.html?hhTest=1&amp;part=rss&amp;subj=news">What iPhone? Apple earnings (still) about the Mac</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.tuaw.com/2008/07/21/mod-your-dock-to-work-with-iphone-3g/">Mod your dock to work with iPhone 3G</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.sauria.com/blog/2008/07/20/my-initial-iphone-experience/">My initial iPhone experience</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/85ef20ad-b620-4d16-9f87-17955147e8a7/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=85ef20ad-b620-4d16-9f87-17955147e8a7" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=9KiZv6"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=9KiZv6" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=IOYoQJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=IOYoQJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=mSxf2J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=mSxf2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=OhjTRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=OhjTRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vXaNrJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vXaNrJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=3F1Amj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=3F1Amj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RXYnnj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RXYnnj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/342550630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 04:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/phone car charger">phone car charger</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/initial iphone experience">initial iphone experience</category>
      <category domain="http://securityratty.com/tag/windows mobile phone">windows mobile phone</category>
      <category domain="http://securityratty.com/tag/windows mobile">windows mobile</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/battery time">battery time</category>
      <category domain="http://securityratty.com/tag/select messages">select messages</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/342550630/quick-thoughts.html">Quick thoughts on using the iPhone 3G</source>
    </item>
    <item>
      <title><![CDATA[When does a bodyguard need to shoot into a crowd?]]></title>
      <link>http://securityratty.com/article/adcb3350b4f47491a7cfbcf84b9f26fe</link>
      <guid>http://securityratty.com/article/adcb3350b4f47491a7cfbcf84b9f26fe</guid>
      <description><![CDATA[A story out of Mumbai,India caught my attention today. A politician's bodyguard shot into a crowd of people and killed a man


While professional Executive Protection Agents no longer refer to...]]></description>
      <content:encoded><![CDATA[A story out of Mumbai,India caught my attention today.  A politician's <a href="http://sify.com/news/fullstory.php?id=14699537">bodyguard shot into a crowd </a>of people and killed a man.<br /> <br /><span id="fullpost"><br />While professional Executive Protection Agents no longer refer to themselves as "bodyguards", if we nonetheless examine that "handle", we can break it down as; "a person who guards (protects) the body of another".  If I was tasked with the investigation of this shooting incident in India, one of the very first places I would look at would be the training manuals of those involved.  If they were Policemen, I would demand to be allowed to inspect that Department's training guides that were used when training their "bodyguards".  Same thing would apply if they belonged to a  private company/entity.<br /><br />I very seriously doubt that I would find any directive anywhere authorizing those assigned to the protective detail to fire haphazzardly into a crowd of people.  To me, this suggests that the bodyguard either panicked or was placed in the position without any professional training (most probable explanation).  Anyone who has spent more than 15 minutes in E.P. training knows that the responsibility of the Protective Agent(s) is to evacuate their client (Principal).  Shooting into crowds of people would be out of place, even in far-fetched Hollywood.  I am quite sure that Indian society is nothing near as litigious as it is here in the Western world, but I still suspect that there is a smart lawyer somewhere in India trying to contact the victim's family.  I believe the case will be his for the winning.<br /><br />Ironically, I contactd a company in India a couple of months back with a proposal to train their Executive Protection staff.  Without ever hearing a price, they contacted me back and said they were sure they couldn't afford us (eventhough they are one of the largest employers in India).  Which makes me wonder, how do you put a price on a human life and what would you consider a fair price to have your people professionally trained so that you were not sued by the family/next of kin of someone killed by one of your employees?  By the way, this question can be asked of any employer anywhere in the world who is in the business of either safeguarding their own employees, or protecting the life of others.     <br /></span><br /><br />In Real Estate it is about; "Location, Location, Location".  In security, it is about; "Training, Training, Training".  I sincerely hope that many get to know of this incident (including nearly all of the Hollywood stars who allow their Protectors to assault people on a regular basis)and begin to realize the importance of having a professionally trained person taking care of them.  Hiring some big guy with a couple of years military experience is not good enough.  <br /><br />That would be like hiring a person for a plastic surgery procedure whose only experience was carving the Thanksgiving turkey.  Who'd be the turkey then?<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 19:28:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bodyguard">bodyguard</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/assault people">assault people</category>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/fair price">fair price</category>
      <category domain="http://securityratty.com/tag/price">price</category>
      <category domain="http://securityratty.com/tag/crowd">crowd</category>
      <category domain="http://securityratty.com/tag/experience">experience</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <source url="http://www.thebulletproofblog.com/2008/06/when-does-bodyguard-need-to-shoot-into.html">When does a bodyguard need to shoot into a crowd?</source>
    </item>
    <item>
      <title><![CDATA[Network Based Entitlement... A Rose by Any Other Name]]></title>
      <link>http://securityratty.com/article/1235aa79d8be8aac2c9fe9cd19da120a</link>
      <guid>http://securityratty.com/article/1235aa79d8be8aac2c9fe9cd19da120a</guid>
      <description><![CDATA[Shimels interesting-as-usual reply to one of Stiennons I-hate-NAC articles is certainly nothing new, but this most recent exchange piqued my interest enough to get me clicking and reading around a...]]></description>
      <content:encoded><![CDATA[<p>Shimel&#8217;s <a class="offsite-link-inline" href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/if-rohati-is-ki.html" target="_blank">interesting-as-usual reply</a>&nbsp;to one of Stiennon&#8217;s &#8220;<a class="offsite-link-inline" href="http://www.networkworld.com/community/node/28837" target="_blank">I-hate-NAC&#8221; articles</a> is certainly&nbsp;nothing new, but this most recent exchange piqued my interest enough to get me clicking and reading around a bit. </p><p>Stiennon talks about <strong>Rohati</strong> and their &#8216;new&#8217; approach to NAC in the form of their <strong>NBEC</strong>, Network-based Entitlement Control. I, unlike some bloggers in our network, decided to check it out before formulating an opinion. </p><p>So, I checked it out and I&#8217;m a little disappointed&#8230; on several fronts. First, all the information I have with which to draw a conclusion is limited to the online &#8216;product demo&#8217; available on their <a class="offsite-link-inline" href="http://www.rohati.com/" target="_blank">website</a>. It&#8217;s <strong>not really a product demo</strong>, hence disappointment <strong>number 1</strong>. </p><p><span class="full-image-float-right"><img style="width: 200px; height: 150px" alt="image_rose_nac_nbec.jpg" src="http://www.securityuncorked.com/storage/image_rose_nac_nbec.jpg" /></span>Let down <strong>number 2</strong> comes in the realization that the features they&#8217;re touting in the &#8216;product demo&#8217; are actually<strong> things we can do today</strong>, with traditional hardware-based NAC solutions from those daily house-hold names&#8230; Symantec, StillSecure, Juniper, ProCurve, Enterasys&nbsp;and even Cisco.&nbsp;Rohati does&nbsp;(potentially) have a unique statement of&nbsp;being able to enforce policies without touching the client. But, again, we &#8216;can&#8217; do that with several of the products I just mentioned. And I&#8217;m wondering how we could create the tunnel-like enforcement and security Rohati claims to offer without some type of agent on the client&#8230; after all, any encryption tunnel has to have endpoints, right?</p><p>I attempted what I usually do when I&#8217;m checking out security solutions, I went to the <strong>support section of the website</strong> to download product manuals or configuration and implementation guides. Even some white papers. I wanted to see how they&#8217;re really going about it all. But, disappointment <strong>number 3</strong> jumped up and got me when I saw that the only resource on their support page was an email address. Hmm&#8230;. </p><p>The company&nbsp;seems to be comprised mostly of long-term <strong>ex-Cisco employees</strong>. Out of the 8 members of the management team, there&#8217;s 1 President, 6 VPs and&nbsp;a director- 5 of which are co-founders. With just 2 years under their belt, I&#8217;m wondering what all they can have up their sleeve past a slight variation of current NAC solutions. </p><p><strong>I may be completely wrong</strong> about the company and product(s). If I am, I&#8217;m sure someone will offer to send over some product manuals for me to read through&#8230; </p><p><strong>The bottom line is&#8230; a rose by any other name would smell as sweet&#8230; or stink as bad.</strong></p><p># # #</p>
]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 15:50:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online product demo">online product demo</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/download product manuals">download product manuals</category>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/current nac solutions">current nac solutions</category>
      <category domain="http://securityratty.com/tag/product manuals">product manuals</category>
      <category domain="http://securityratty.com/tag/stiennons i-hate-nac articles">stiennons i-hate-nac articles</category>
      <category domain="http://securityratty.com/tag/product demo">product demo</category>
      <category domain="http://securityratty.com/tag/nac solutions">nac solutions</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/15/network-based-entitlement-a-rose-by-any-other-name.html">Network Based Entitlement... A Rose by Any Other Name</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: May 30th]]></title>
      <link>http://securityratty.com/article/5f9dc8ad7b1ff37b31e5b18be1463138</link>
      <guid>http://securityratty.com/article/5f9dc8ad7b1ff37b31e5b18be1463138</guid>
      <description><![CDATA[What a week - its like Im swimming uphill both ways and its snowing. An extra large helping of news to make up for being late this morning. And hey - thanks to all of our new subscribers that joined...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>What a week - it&#8217;s like I&#8217;m swimming uphill both ways and it&#8217;s snowing. An extra large helping of news to make up for being late this morning. And hey - thanks to all of our new subscribers that joined us yesterday. Welcome! </p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a></p>
<p>And now, the news&#8230;</p>
<ol>
<li><A HREF="http://revision3.com/blog/2008/05/29/inside-the-attack-that-crippled-revision3">The Attack that made Kevin Rose Cry - Revision3</A></li>
<li><A HREF="http://news.bbc.co.uk/2/hi/science/nature/7423184.stm">BBC NEWS | Science/Nature | Monkey&#8217;s brain controls robot arm</A> <i>Always mount a scratch monkey - seriously.</i></li>
<li><A HREF="http://www.theregister.co.uk/2008/05/30/mobile_phone_forensics/">Will your mobile squeal to the police? | The Register</A> <i>Will your mobile find a horse head in it&#8217;s bed?</i></li>
<li><A HREF="http://www.theregister.co.uk/2008/05/30/notts_al_qaeda_manual_case/">Download al Qaeda manuals from the DoJ, go to prison? | The Register</A> <i>Another pair of articles analyzing the somewhat chilling effect of doing research and finding yourself in jail&#8230; do we accept this as a society or not?</i></li>
<li><A HREF="http://www.theregister.co.uk/2008/05/30/student_arrested_downloading_book/">The New Order: When reading is a crime | The Register</A></li>
<li><A HREF="http://www.theregister.co.uk/2008/05/30/villa_facebooked/">Facebook mob trashes Â£4.4m Spanish villa | The Register</A> <i>Anyone else surprised that the girl didn&#8217;t claim it was hackers &#8212; and faintly reminiscent of the Craigslist &#8220;The contents of this house must go&#8221; issue.</i></li>
<li><A HREF="http://www.bletchleypark.org.uk/news/docview.rhtm/516816">Bletchley Park and the decay of the museum buildings</A> <i>Plcurecuernxf - fcraq n craal ba gur ravtzn naq fnir gur jbeyq sebz Uvgyre ntnva - be gur npnqrzvp trgf vg.</i></li>
<li><A HREF="http://www.lemonde.fr/technologies/article/2008/05/29/vingt-deux-jeunes-hackers-interpelles-dans-toute-la-france_1051095_651865.html">22 French Hackers Arrested</A> <i>22 SkriptKiddies singing the Jean Valjean lines from Les Miserables&#8230; the horror.</i></li>
<li><A HREF="https://www.blackhat.com/html/bh-usa-08/bh-usa-08-schedule.html">USA 2008 : Briefings Schedule</A> <i>All your briefs belong to Jeff Moss</i></li>
<li><A HREF="http://www.randsinrepose.com/archives/2008/05/15/we_travel_in_tribes.html">Rands In Repose: We Travel in Tribes</A> <i>I&#8217;m sneaking this one in to see if you are paying attention - which Diamond Age phyle do you belong to?</i></li>
<li><A HREF="http://www.akamai.com/stateoftheinternet/">State of the Internet</A> <i>It&#8217;s all about the metrics baby.</i></li>
<li><A HREF="http://webworkerdaily.com/2008/05/22/red-curtain-an-unsung-free-security-application/">Red Curtain: An Unsung, Free Security Application</A> <i>Anyone willing to sing in the comments?</i></li>
<li><A HREF="http://www.theglobeandmail.com/servlet/story/RTGAM.20080529.wgtporno0529/BNStory/Technology/?page=rss&#038;id=RTGAM.20080529.wgtporno0529">Computer trained to read minds</A> <i>Neo sez - BLUE PILL, take the frakkin blue one!</i></li>
<li><A HREF="http://www.nationaljournal.com/njmagazine/cs_20080531_6948.php">National Journal Magazine - Chinas Cyber-Militia</A> <i>Good catch Matt Franz - is this responsible journalism or just journalistic asshattery.</i></li>
<li><A HREF="http://blog.wired.com/27bstroke6/2008/05/did-hackers-cau.html">Did Hackers Cause the 2003 Northeast Blackout? Umm, No | Threat Level from Wired.com</A> <i>And 27/b6 weighs in on the issue&#8230; with maybe a little more journalistic integrity.</i></li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=y0mvH5"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=y0mvH5" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=nTAEqH"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=nTAEqH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=O5S0yh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=O5S0yh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=THcwWh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=THcwWh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YRnE3h"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YRnE3h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xCt1ah"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xCt1ah" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/301291977" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 30 May 2008 10:29:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/bbc news">bbc news</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/french hackers">french hackers</category>
      <category domain="http://securityratty.com/tag/register">register</category>
      <category domain="http://securityratty.com/tag/free security application">free security application</category>
      <category domain="http://securityratty.com/tag/gur npnqrzvp trgf">gur npnqrzvp trgf</category>
      <category domain="http://securityratty.com/tag/diamond age phyle">diamond age phyle</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/301291977/">Security Briefing: May 30th</source>
    </item>
    <item>
      <title><![CDATA[Manuals (CIA and NGO)]]></title>
      <link>http://securityratty.com/article/f79909b794373dbd85e9ba45580ad086</link>
      <guid>http://securityratty.com/article/f79909b794373dbd85e9ba45580ad086</guid>
      <description><![CDATA[Today is midweek manual day, and here's a quick selection of interesting manuals to read

At the top of the list is the CIA's Psychology of Intelligence Analysis by Richards J. Heuer. This is a must...]]></description>
      <content:encoded><![CDATA[Today is midweek manual day, and here's a quick selection of interesting manuals to read.<br /><br />At the top of the list is the <a href="https://www.cia.gov/library/center-for-the-study-of-intelligence/csi-publications/books-and-monographs/psychology-of-intelligence-analysis/index.html">CIA's Psychology of Intelligence Analysis</a> by Richards J. Heuer. This is a must read if you're into critical thinking and the inner game of security. It covers information gathering, analysis and the various biases that can creep in and influence decisions. The content presented in this manual should be taught in every introductory humanitarian security course.<br /><br />Next up, Charlie writes in with some links to a few humanitarian security manuals and resources:<br /><br /><a href="http://www.frontlinedefenders.org/manuals/protection" target="_blank">http://www.frontlinedefenders<wbr>.org/manuals/protection</a><br /><br /><a href="http://www.frontlinedefenders.org/manuals" target="_blank">http://www.frontlinedefenders<wbr>.org/manuals</a><br /><br /><a href="http://www.aidworkers.net/?q=advice/security" target="_blank">http://www.aidworkers.net/?q<wbr>=advice/security</a><br /><br /><a href="http://ec.europa.eu/echo/evaluation/security_review_en.htm">http://ec.europa.eu/echo/evaluation/security_review_en.htm</a><br /><br />(A few of these may seem familiar, but it's good to mention again for new blog readers.)]]></content:encoded>
      <pubDate>Wed, 07 May 2008 12:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/manuals">manuals</category>
      <category domain="http://securityratty.com/tag/humanitarian security manuals">humanitarian security manuals</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/manual">manual</category>
      <category domain="http://securityratty.com/tag/introductory humanitarian security">introductory humanitarian security</category>
      <category domain="http://securityratty.com/tag/midweek manual day">midweek manual day</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/intelligence analysis">intelligence analysis</category>
      <category domain="http://securityratty.com/tag/covers information">covers information</category>
      <source url="http://ngosecurity.blogspot.com/2008/05/manuals-cia-and-ngo.html">Manuals (CIA and NGO)</source>
    </item>
    <item>
      <title><![CDATA[Terror on the Internet - Conflict of Interest]]></title>
      <link>http://securityratty.com/article/4d84e41b4c977b7092f8d353c8e6895e</link>
      <guid>http://securityratty.com/article/4d84e41b4c977b7092f8d353c8e6895e</guid>
      <description><![CDATA[Insightful article by Greg Goth, discussing various aspects of the pros and cons of monitoring cyber jihadist sites next to shutting them down, as well as mentioning my analysis of the Mujahideen...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp0.blogger.com/_wICHhTiQmrA/R9G7dU-0F6I/AAAAAAAABcQ/1bS4lvI4w-M/s1600-h/terrorist_database_hoax.jpg"><img id="BLOGGER_PHOTO_ID_5175123559348180898" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R9G7dU-0F6I/AAAAAAAABcQ/1bS4lvI4w-M/s200/terrorist_database_hoax.jpg" border="0" /></a>Insightful article by Greg Goth, discussing various aspects of the pros and cons of monitoring cyber jihadist sites next to shutting them down, as well as mentioning <a href="http://ddanchev.blogspot.com/2008/01/mujahideen-secrets-2-encryption-tool.html">my analysis</a> of the <a href="http://ddanchev.blogspot.com/2007/04/mujahideen-secrets-encryption-tool.html">Mujahideen Secrets encryption tool v1.0</a> and v2.0. <a href="http://dsonline.computer.org/portal/pages/dsonline/2008/03/o3003news.html">Terror on the Internet: A Complex Issue, and Getting Harder</a> :</div><br />"<em>Indeed, politicians around the world call at regular intervals for terrorist websites to be removed from their host sites’ servers or for search engines to block access to them. They also call for laws that would make posting instructions on how to kill or maim people or destroy property punishable by law. Franco Frattini, the European Commission’s Vice President for Freedom, Justice, and Security, </em><a href="http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/07/505&amp;format=HTML&amp;aged=0&amp;language=EN&amp;guiLanguage=en"><em>called for a prohibition on websites that post bomb-making instructions in September 2007</em></a><em>. And just as quickly, he rushed to announce that in doing so he was not trying to impinge on freedom of speech or information access or to inhibit law enforcement agencies from monitoring sites.</em>"<br /><br /><div>There're three perspectives related to cyber jihad, should the virtual communities be shut down, monitored, or censored so that they cannot be accessed by people who would potentially get radicalized and brainwashed by the amazingly well created propaganda in the form of interactive multimedia? Given the different mandates given to different intelligence services and independent researchers, is where the conflict of interest begins. Moreover, don't forget that independent researchers sometimes come up with the final piece of the puzzle to have an intelligence agency come up with the big picture in a cost-effective and timely manner, given they actually believe in OSINT and trust the source of the intell data of course. Now, picture the situation where an intelligence agency is shutting down cyber jihadist sites on a large scale not believing in the value that the intelligence data they they could provide, another one given a mandate to censor cyber jihadist communities compiling reports stating that someone's shutting them down before they could even censor them, and a third one who would have to again play cat and mouse game the locate them once they've shut down by the first intel agency already. Ironic or not, different mandates and empowerment is where the contradiction begins. Let's discuss the three mandates and go in-depth into the pros and cons of each of them to come up with a philosophic solution to the problem, as I belive it's perhaps the only way to provoke some thought on the best variant.</div><br /><div></div><strong>Shutting the communities down</strong> -<br /><div>Before shuting them down you need to know where they are, their neighbourhood of supporters who will indirectly tip you on the their latest location once they have their previous domain shut down. Personal experience and third party research indicates that over 90% of the cyber jihadist communities/blogs are hosted by U.S based not owned companies. And with the lack of real-time intell sharing between the agencies themselves, the first who picks up the community will be responsible for its faith, literally. But in reality, preserving the integrity of a cyber jihadist community, and convincing the right people that balanced monitoring next to shutting it down is more beneficial, remains an idea yet to be considered. Back in 2007, I did an experiment, namely I <a href="http://ddanchev.blogspot.com/2007/08/analyses-of-cyber-jihadist-forums-and.html">crawled ten cyber jihadist forums and blogs and extracted all the outgoing links from these communities</a> to see their preferred choice for online video and files hosting. A couple of months later, the communities got shut down, so when the same thing happened while I was crawling the Global Islamic Media Front's, and Inshallahshaheed's web presence, it became clear that while some are crawling, and others censoring, third parties are shutting them down.</div><br /><div> </div>The bottom line - shutting them down doesn't mean that they'll dissapear and will never come back, exactly the opposite. Personal experience while handling the Global Islamic Media Front is perhaps the perfect and best hands-on experience on the benefits of shutting them down, given you've built enough convidence in your abilities to locate their new location. If you think that the cyber jihadist site or community you're currently monitoring is a star, look above, it's full of starts everywhere, once you start drawing the lines between them, a figure of something known emerges, in this case once a cyber jihadist community is shut down, its most loyal and closely connected cyber jihadist communities will expose their intimate connection not by just starting to promote their new location online, but even better, you'll have them use the second cyber jihadist community to directly reach their audience by the time they set up the new location and resume the propaganda and radicalization.<br /><div> </div><br /><div>There's no shortage of cyber jihadist blogs, forums and sites, and personal experience shows that upon having a cyber jihadist community shut down, they re-appear at another location. It's shut down again, it re-appears for a second time. I've seen this situation with Instahaleed and GIMF, and each and every time they had their blogs and sites removed from their hosting providers, mainly because it's rather disturbing that the majority of such communities are hosted on U.S servers, it's this short time frame which will either lead you to their new location, you risk loosing their tracks. However, the vivid supporters of PSYOPs are logically visionary enough to understand what does undermining their audiences' confidence in the community's capability to remain online means.</div><br /><div> </div><strong>Monitoring the communities</strong> -<br /><div>In order to reach the "shut it down or monitor it" stage in your analysis process, you really need to know where the cyber jihadists forums and sites are, else, you will be wasting your time, money and energy to create <a href="http://ddanchev.blogspot.com/2007/03/cyber-traps-for-wannabe-jihadists.html">fake cyber jihadist communities in the form of web honeypots for jihadist communication</a>. Monitoring is tricky, especially when you don't know what you're looking for, don't prioritize, don't have a contingency plan or an offline copy of the communitiy and wrongly building confidence in its ability to remain online. Moreover, <a href="http://cryptome.org/able-danger-ig-02.jpg">monitoring for too long</a> results in terrabytes of noise, and from a psychological perspective sometimes <a href="http://en.wikipedia.org/wiki/Able_Danger">the rush for yet another fancy social networking graph</a> to better communicate <a href="http://cryptome.org/able-danger-ig-01.jpg">the collected data</a>, ends up in the worst possible way - you miss the tipping point moment.</div><br /><div> </div><strong>Censoring the communities -</strong><br /><div>I often come across wishful comments in the lines of "blocking access to bomb and poison making tutorials", missing a very important point, namely, that these very same manuals, and jihadist magazines are not residing in a cyber-jihad.com/bomb-making-guide.zip domain and file extension form, making the process a bit more complex to realize. Unless of course the censorship systems figures out ways to detect the content in password encrypted archive files served with random file names and hosted on one of the hundreds free web space providers. Then again, given the factual evidence that cyber jihadists are encouraging the use of Internet anonymization services and software, your censorship efforts will remain futile.</div><br /><div> </div>As I'm posting this overview of various ways of handling cyber jihadist communities, yet another community is starting to attract cyber jihadists, thanks to their understanding of noise generation by teaching the novice cyber jihadists on the basics of running and maintaing such a community. What's perhaps most important to keep in mind is that, what you're currently analyzing, trying to shut down or censor whatsoever, is the public web, the Dark Web, the one closed behind authentication and invite-only access yet remains to be located and properly analyzed. If cyber jihad is really a priority, then there's nothing more effective than the combination of independent researchers and intelligence analysts.<br /><div> </div><br /><div><strong>Related posts:<br /><a href="http://ddanchev.blogspot.com/2007/12/inshallahshaheed-come-out-come-out.html"><span style="font-weight: normal;">Inshallahshaheed - Come Out, Come Out Wherever You Are</span></a><br /></strong><a href="http://ddanchev.blogspot.com/2007/07/gimf-switching-blogs.html">GIMF Switching Blogs</a><br /><a href="http://ddanchev.blogspot.com/2007/08/gimf-now-permanently-shut-down.html">GIMF Now Permanently Shut Down</a><br /><a href="http://ddanchev.blogspot.com/2007/08/gimf-we-will-remain.html">GIMF - "We Will Remain"</a><br /><strong><a href="http://ddanchev.blogspot.com/2007/10/wisdom-of-anti-cyber-jihadist-crowd.html"><span style="font-weight: normal;">Wisdom of the Anti Cyber Jihadist Crowd</span></a><br /><a href="http://ddanchev.blogspot.com/2007/11/cyber-jihadist-blogs-switching.html"><span style="font-weight: normal;">Cyber Jihadist Blogs Switching Locations</span></a><br /></strong></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a><br /><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><a href="http://ddanchev.blogspot.com/2007/11/botnet-of-infected-terrorists.html">A Botnet of Infected Terrorists?</a><br /><a href="http://ddanchev.blogspot.com/2007/09/infecting-terrorist-suspects-with.html">Infecting Terrorist Suspects with Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/09/dark-web-and-cyber-jihad.html">The Dark Web and Cyber Jihad</a><br /><a href="http://ddanchev.blogspot.com/2007/12/cyber-jihadist-hacking-teams.html">Cyber Jihadist Hacking Teams</a><br /><a href="http://ddanchev.blogspot.com/2005/12/cyberterrorism-dont-stereotype-and-its.html">Cyberterrorism - don't stereotype and it's there</a><br /><a href="http://ddanchev.blogspot.com/2006/06/tracking-down-internet-terrorist.html">Tracking Down Internet Terrorist Propaganda</a><br /><a href="http://ddanchev.blogspot.com/2006/05/arabic-extremist-group-forum-messages.html">Arabic Extremist Group Forum Messages' Characteristics</a><br /><a href="http://ddanchev.blogspot.com/2006/08/cyber-terrorism-communications-and_22.html">Cyber Terrorism Communications and Propaganda</a><br /><a href="http://ddanchev.blogspot.com/2006/05/techno-imperialism-and-effect-of.html">Techno Imperialism and the Effect of Cyberterrorism</a><br /><a href="http://ddanchev.blogspot.com/2006/10/cost-benefit-analysis-of-cyber.html">A Cost-Benefit Analysis of Cyber Terrorism</a><br /><a href="http://ddanchev.blogspot.com/2006/12/current-state-of-internet-jihad.html">Current State of Internet Jihad</a><br /><a href="http://ddanchev.blogspot.com/2007/02/characteristics-of-islamist-websites.html">Characteristics of Islamist Websites</a><br /><a href="http://ddanchev.blogspot.com/2006/09/hezbollahs-dns-service-providers-from.html">Hezbollah's DNS Service Providers from 1998 to 2006</a><br /><a href="http://ddanchev.blogspot.com/2006/12/full-list-of-hezbollahs-internet-sites.html">Full List of Hezbollah's Internet Sites</a><br /><a href="http://ddanchev.blogspot.com/2007/03/cyber-traps-for-wannabe-jihadists.html">Cyber Traps for Wannabe Jihadists</a><br /><a href="http://ddanchev.blogspot.com/2007/04/mujahideen-secrets-encryption-tool.html">Mujahideen Secrets Encryption Tool</a><br /><a href="http://ddanchev.blogspot.com/2006/12/analysis-of-technical-mujahid-issue-one.html">An Analysis of the Technical Mujahid Issue One</a><br /><a href="http://ddanchev.blogspot.com/2007/06/analysis-of-technical-mujahid-issue-two.html">An Analysis of the Technical Mujahid Issue Two</a><br /><a href="http://ddanchev.blogspot.com/2007/07/terrorist-groups-brand-identities.html">Terrorist Groups' Brand Identities</a><br /><a href="http://ddanchev.blogspot.com/2007/06/list-of-terrorists-blogs.html">A List of Terrorists' Blogs</a><br /><a href="http://ddanchev.blogspot.com/2007/05/jihadists-anonymous-internet-surfing.html">Jihadists' Anonymous Internet Surfing Preferences</a><br /><a href="http://ddanchev.blogspot.com/2007/05/sampling-jihadists-ips.html">Samping Jihadist IPs</a><br /><a href="http://ddanchev.blogspot.com/2007/07/cyber-jihadists-and-tor.html">Cyber Jihadists' and TOR</a><br /><a href="http://ddanchev.blogspot.com/2007/08/cyber-jihadist-dos-tool.html">A Cyber Jihadist DoS Tool</a><br /><a href="http://ddanchev.blogspot.com/2007/08/gimf-now-permanently-shut-down.html">GIMF Now Permanently Shut Down</a><br /><a href="http://ddanchev.blogspot.com/2006/08/steganography-and-cyber-terrorism.html">Steganography and Cyber Terrorism Communications</a><br /></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9ODTvnF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9ODTvnF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=glFBi8F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=glFBi8F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=D198AFf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=D198AFf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z0vTnMf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z0vTnMf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sALMAMF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sALMAMF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LlGGhJF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LlGGhJF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GIrrUWf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GIrrUWf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/253973814" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Mar 2008 16:58:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cyber jihadist">cyber jihadist</category>
      <category domain="http://securityratty.com/tag/cyber jihadist communities">cyber jihadist communities</category>
      <category domain="http://securityratty.com/tag/novice cyber jihadists">novice cyber jihadists</category>
      <category domain="http://securityratty.com/tag/jihadists">jihadists</category>
      <category domain="http://securityratty.com/tag/cyber jihadist forums">cyber jihadist forums</category>
      <category domain="http://securityratty.com/tag/cyber jihadist sites">cyber jihadist sites</category>
      <category domain="http://securityratty.com/tag/attract cyber jihadists">attract cyber jihadists</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/cyber jihadists">cyber jihadists</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/253973814/terror-on-internet-conflict-of-interest.html">Terror on the Internet - Conflict of Interest</source>
    </item>
    <item>
      <title><![CDATA[Tear Gas/Pepper Spray Resource]]></title>
      <link>http://securityratty.com/article/a36c8d37629a2f74dc6d42322ecb7bcd</link>
      <guid>http://securityratty.com/article/a36c8d37629a2f74dc6d42322ecb7bcd</guid>
      <description><![CDATA[Tear gas and pepper spray are widely used by police and military forces throughout the world to control crowds. Because of the dynamic nature of protests, aid workers may find themselves exposed to...]]></description>
      <content:encoded><![CDATA[Tear gas and pepper spray are widely used by police and military forces throughout the world to control crowds. Because of the dynamic nature of protests, aid workers may find themselves exposed to riot control agents (if you've never been gassed before, the first time can be very disconcerting). Unfortunately, this topic isn't discussed very much in traditional humanitarian security training and manuals. So to learn more we need to look to other sources, in this case, street medics.<br /><br />Street medics are independent, trained volunteer medical personnel who support activists during protests. Organized <a href="http://en.wikipedia.org/wiki/List_of_street_medic_organizations">street medic groups</a> have sprung up in a number of Western, urban locations. One of the groups, known as the <a href="http://www.blackcrosscollective.org/">Black Cross Health Collective</a>, has published extensive information on the effects of and treating tear gas and pepper spray. Check it out.]]></content:encoded>
      <pubDate>Tue, 15 Jan 2008 13:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tear gas">tear gas</category>
      <category domain="http://securityratty.com/tag/pepper spray">pepper spray</category>
      <category domain="http://securityratty.com/tag/street medics">street medics</category>
      <category domain="http://securityratty.com/tag/volunteer medical personnel">volunteer medical personnel</category>
      <category domain="http://securityratty.com/tag/traditional humanitarian security">traditional humanitarian security</category>
      <category domain="http://securityratty.com/tag/riot control agents">riot control agents</category>
      <category domain="http://securityratty.com/tag/street medic">street medic</category>
      <category domain="http://securityratty.com/tag/support activists">support activists</category>
      <category domain="http://securityratty.com/tag/extensive information">extensive information</category>
      <source url="http://ngosecurity.blogspot.com/2008/01/tear-gaspepper-spray-resource.html">Tear Gas/Pepper Spray Resource</source>
    </item>
  </channel>
</rss>
