<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: media]]></title>
    <link>http://securityratty.com/tag/media</link>
    <description></description>
    <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Nmap presentation for the ISSA in Louisville Kentucky]]></title>
      <link>http://securityratty.com/article/3b8d1a1f88e7e66d464e3f1c20d672fa</link>
      <guid>http://securityratty.com/article/3b8d1a1f88e7e66d464e3f1c20d672fa</guid>
      <description><![CDATA[This is a presentation I gave for the Kentuckiana ISSA on the security tool Nmap. I've also posted the slides and other media so you can follow along if you like. Topics covered include: port scanning...]]></description>
      <content:encoded><![CDATA[This is a presentation I gave for the <a href="http://www.issa-kentuckiana.org/">
Kentuckiana ISSA</a> on the security tool Nmap. I've also posted the
<a href="http://www.irongeek.com/downloads/issa-nmap.zip">slides and other media</a> 
so you can follow along if you like. Topics covered include: port scanning 
concepts, TCP three way handshake, stealth scans, idle scans, bounce scans, 
version detection, OS detection, NSE/LUA scripting and firewall logs. Hope some 
of you can make it to the free class we will be holding at Ivy Tech Sellersburg 
on Sept 20th, 2008 at 1pm. <a href="http://www.irongeek.com/i.php?page=contact">
Contact me to RSVP</a>. The video is about an hour long. Enjoy.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=Ufs5NZ"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=Ufs5NZ" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/385294267" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 13:03:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ivy tech sellersburg">ivy tech sellersburg</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/version detection">version detection</category>
      <category domain="http://securityratty.com/tag/security tool nmap">security tool nmap</category>
      <category domain="http://securityratty.com/tag/bounce scans">bounce scans</category>
      <category domain="http://securityratty.com/tag/sept 20th">sept 20th</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/firewall logs">firewall logs</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/385294267/i.php">Nmap presentation for the ISSA in Louisville Kentucky</source>
    </item>
    <item>
      <title><![CDATA[Nmap presentation for the ISSA in Louisville Kentucky]]></title>
      <link>http://securityratty.com/article/4993e62d52cab95ea4f31b73af8b1f0e</link>
      <guid>http://securityratty.com/article/4993e62d52cab95ea4f31b73af8b1f0e</guid>
      <description><![CDATA[This is a presentation I gave for the Kentuckiana ISSA on the security tool Nmap. I've also posted the slides and other media so you can follow along if you like. Topics covered include: port scanning...]]></description>
      <content:encoded><![CDATA[This is a presentation I gave for the <a href="http://www.issa-kentuckiana.org/">
Kentuckiana ISSA</a> on the security tool Nmap. I've also posted the
<a href="http://www.irongeek.com/downloads/issa-nmap.zip">slides and other media</a> 
so you can follow along if you like. Topics covered include: port scanning 
concepts, TCP three way handshake, stealth scans, idle scans, bounce scans, 
version detection, OS detection, NSE/LUA scripting and firewall logs. Hope some 
of you can make it to the free class we will be holding at Ivy Tech Sellersburg 
on Sept 20th, 2008 at 1pm. <a href="http://www.irongeek.com/i.php?page=contact">
Contact me to RSVP</a>. The video is about an hour long. Enjoy.<img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/U97SuFQneSU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 13:03:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ivy tech sellersburg">ivy tech sellersburg</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/version detection">version detection</category>
      <category domain="http://securityratty.com/tag/security tool nmap">security tool nmap</category>
      <category domain="http://securityratty.com/tag/bounce scans">bounce scans</category>
      <category domain="http://securityratty.com/tag/sept 20th">sept 20th</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/firewall logs">firewall logs</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/U97SuFQneSU/i.php">Nmap presentation for the ISSA in Louisville Kentucky</source>
    </item>
    <item>
      <title><![CDATA[Logging Poll #9 Analysis: Log Security]]></title>
      <link>http://securityratty.com/article/820b3554ec6a486561a49cb82afebbb2</link>
      <guid>http://securityratty.com/article/820b3554ec6a486561a49cb82afebbb2</guid>
      <description><![CDATA[This is the analysis of my last poll; the responses are here and also below

First , the most obvious conclusion: people still don't care much about log security ; I am saying that since this was BY...]]></description>
      <content:encoded><![CDATA[<p>This is the analysis of my last poll; the responses are <a href="http://www.misterpoll.com/polls/351660/results">here</a> and also below.</p>  <p><a href="http://lh6.ggpht.com/anton.chuvakin/SMGa_ncGU2I/AAAAAAAAEyo/01NCHG4omE8/s1600-h/poll9logsecurity2.png"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="196" alt="poll9-log-security" src="http://lh3.ggpht.com/anton.chuvakin/SMGbAMHtGgI/AAAAAAAAEys/t2_vBRBKK7Q/poll9logsecurity_thumb.png?imgmax=800" width="244" border="0" /></a> </p>  <p><strong>First</strong>, the most obvious conclusion: people still don't <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">care much about log security</a>; I am saying that since this was BY FAR the <em>least</em> popular of <a href="http://chuvakin.blogspot.com/search/label/poll">my polls</a>. Only 24 people responded, so everything below is pretty unscientific :-)&#160; A good way to explain it: look at <a href="http://news.google.com/news?hl=en&amp;tab=wn&amp;ned=&amp;q=data+loss&amp;btnG=Search+News">the recent media</a>? Do these people care about their <strong>key business data</strong> and their <strong>customer data</strong> security? Nope. So, how on Earth do you make them care about securing their <strong>log data</strong>?</p>  <p><strong>Second,</strong>&#160; it is entirely unsurprising that 83% of respondents want &quot;Authenticated access to log server.&quot; In fact, I'd opine that 100% of people want authenticated access to <em>any</em> of their servers :-) But, this was my &quot;red herring&quot; to set the baselines for the rest of the questions...&#160; </p>  <p>However, this is where the buck stops: other security measures are notably less popular.</p>  <p><strong>Third</strong>, &quot;Logging all access to logs&quot; is my favorite and I am happy to see it reported as popular. But do you really do it?&#160; Do you log access to log server OR access to actual logs? Think about it... I think a lot of people who do the latter still answered &quot;yes&quot; to this one.</p>  <p><strong>Fourth</strong>,&#160; &quot;Reliable / acknowledged network transfer of log data&quot; and &quot;Encryption of log data in transit &quot; are two true &quot;no-brainer&quot; security features; they took the next spot at 45% and 50% of those who answered. They are simple, they are easy, they make&#160; sense - and, obviously, they don't make logs <em>entirely</em> secure so you need to do more. Why only 50%? Where is THE OTHER 50%?! </p>  <p><strong>Fifth</strong>, &quot;all things crypto&quot; are below 40%. &quot;Cryptographic hashing of stored logs&quot;, &quot;Cryptographic signing of stored log data&quot; and &quot;Encryption of stored log data&quot; all hover at around 30%. I attribute them to general disregard of log security AND reliance on &quot;system security&quot; (separate server, etc) over &quot;data security&quot; measures for log protection. </p>  <p><strong>Finally</strong>, I am embarrassed to say that I missed&#160; the obvious security measure &quot;<strong>Separate server for logging, not accessible from the Internet;&quot; </strong>one of my readers added this using &quot;Other security measures&quot; choice. Indeed, this is a good point - and <a href="http://www.loglogic.com">a good idea to do it</a>. Another option mention there was &quot;<strong>Destroy old logs.</strong>&quot; Amen to that too!</p>  <p><strong>Possibly related posts:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Logs</a> </li>    <li><a href="http://chuvakin.blogspot.com/search/label/poll">All other polls and their analysis</a> </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=X4btL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=X4btL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=25k4L"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=25k4L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jN7qL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jN7qL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/384501630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log data">log data</category>
      <category domain="http://securityratty.com/tag/log security">log security</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/protect logs">protect logs</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/log server">log server</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/384501630/logging-poll-9-analysis-log-security.html">Logging Poll #9 Analysis: Log Security</source>
    </item>
    <item>
      <title><![CDATA[Louisville ISSA Nmap presentation slides and media posted]]></title>
      <link>http://securityratty.com/article/bbd469872f1364ae4fd2a7434ef471c1</link>
      <guid>http://securityratty.com/article/bbd469872f1364ae4fd2a7434ef471c1</guid>
      <description><![CDATA[I've posted the slides and related media for the Nmap presentation I'm giving Friday (Sept 5) for the Kentuckiana ISSA . You should be able to find the codec for the videos in the zip file. If you...]]></description>
      <content:encoded><![CDATA[I've posted the slides and related media for the Nmap presentation I'm 
giving Friday (Sept 5) for the <a href="http://www.issa-kentuckiana.org/">	Kentuckiana ISSA</a>. You should be able to find the codec for the videos in the zip file.&nbsp; If you plan to come to the free class at Ivy Tech 	(Sellersburg Indiana) on the 20th please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a>.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=ZRsQMm"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=ZRsQMm" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/383739632" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 17:07:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nmap presentation">nmap presentation</category>
      <category domain="http://securityratty.com/tag/ivy tech">ivy tech</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/zip file">zip file</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/sellersburg indiana">sellersburg indiana</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa">kentuckiana issa</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/383739632/issa-nmap.zip">Louisville ISSA Nmap presentation slides and media posted</source>
    </item>
    <item>
      <title><![CDATA[Louisville ISSA Nmap presentation slides and media posted]]></title>
      <link>http://securityratty.com/article/f387eebef71a2cc826a73e5f487aa218</link>
      <guid>http://securityratty.com/article/f387eebef71a2cc826a73e5f487aa218</guid>
      <description><![CDATA[I've posted the slides and related media for the Nmap presentation I'm giving Friday (Sept 5) for the Kentuckiana ISSA . You should be able to find the codec for the videos in the zip file. If you...]]></description>
      <content:encoded><![CDATA[I've posted the slides and related media for the Nmap presentation I'm 
giving Friday (Sept 5) for the <a href="http://www.issa-kentuckiana.org/">	Kentuckiana ISSA</a>. You should be able to find the codec for the videos in the zip file.&nbsp; If you plan to come to the free class at Ivy Tech 	(Sellersburg Indiana) on the 20th please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a>.<img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/LRahduBv5Oo" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 17:07:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nmap presentation">nmap presentation</category>
      <category domain="http://securityratty.com/tag/ivy tech">ivy tech</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/zip file">zip file</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/sellersburg indiana">sellersburg indiana</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa">kentuckiana issa</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/LRahduBv5Oo/issa-nmap.zip">Louisville ISSA Nmap presentation slides and media posted</source>
    </item>
    <item>
      <title><![CDATA[Upcoming Microsoft patch lineup could be 'massive,' says researcher]]></title>
      <link>http://securityratty.com/article/ef2867505c98129d17695f92baa0750d</link>
      <guid>http://securityratty.com/article/ef2867505c98129d17695f92baa0750d</guid>
      <description><![CDATA[Microsoft next Tuesday will ship four security updates to fix critical flaws in Windows, Office, Windows Media Player and other parts of the company's software...]]></description>
      <content:encoded><![CDATA[Microsoft next Tuesday will ship four security updates to fix critical flaws in Windows, Office, Windows Media Player and other parts of the company's software portfolio.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=D0Dxwm"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=D0Dxwm" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/383533778" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/fix critical flaws">fix critical flaws</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/software portfolio">software portfolio</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/ship">ship</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/383533778/article.do">Upcoming Microsoft patch lineup could be 'massive,' says researcher</source>
    </item>
    <item>
      <title><![CDATA[Upcoming Microsoft patch lineup could be 'massive,' says researcher]]></title>
      <link>http://securityratty.com/article/6d15b18731bd50db45491f19f43d8388</link>
      <guid>http://securityratty.com/article/6d15b18731bd50db45491f19f43d8388</guid>
      <description><![CDATA[Microsoft next Tuesday will ship four security updates to fix critical flaws in Windows, Office, Windows Media Player and other parts of the company's software...]]></description>
      <content:encoded><![CDATA[Microsoft next Tuesday will ship four security updates to fix critical flaws in Windows, Office, Windows Media Player and other parts of the company's software portfolio.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ed3d10dc114a9c919881aa34f2163b82:Jbw2mlNLEb4CW3UDwYXhNMA3lPK4NlW5wzN9Fmo1Um6YvVpzbI6%2Fm1y1eRYa9JO574QYDl7g8K6yWv%2BmwDIRWVC1Az6KLP7JclFztKAcO9E%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:21921ea7057af312425ef5eb4d358a0a:fZcpGd66x%2FLahG68bpW4o%2BJ9rrTy1VtIBbeoPqikwWTo7rwddfnzPczYPgNhua2IE7jehGTxwH8zmAdIrJxJKRVC3h6FYP7sfYjjX%2FabzLE%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:cae4e74cf5ba2ce38a5b6dc56fc25395:B2KLjMUxaEeiK%2BPmw2bmoHX1kVDa3vP1dTryHdxq1sLF031J4mLjRw1uKPE1lwxwZyY%2BeBHMCWBoycuLTTzNY9KDa5dEXHJquH%2FqYgc9m0w%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:deea14778eb2c5a83c3dcc3815020937:VmEtpo4%2Fkp%2F8whddVTmqu7Vv04R4QX6POld%2F4nLWWe0IghrqYy9PjGiStQiM%2Fiy14bBkDy%2FICTXUQfkVkLpujJhfHQg6dq0hMge8LnLJgJA%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a81acc584ddca8b38a67238a0fc7ec0c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a81acc584ddca8b38a67238a0fc7ec0c" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/fix critical flaws">fix critical flaws</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/software portfolio">software portfolio</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/ship">ship</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a81acc584ddca8b38a67238a0fc7ec0c">Upcoming Microsoft patch lineup could be 'massive,' says researcher</source>
    </item>
    <item>
      <title><![CDATA[Zango And The Batman Online Videogame]]></title>
      <link>http://securityratty.com/article/df88ab063f04def43d02f931dfa23c42</link>
      <guid>http://securityratty.com/article/df88ab063f04def43d02f931dfa23c42</guid>
      <description><![CDATA[This is Newsarama, a site (mostly) geared around comics and other related media





Click to Enlarge

You'll notice Batman, over on the right there. Let's take a closer look





Free Online Batman...]]></description>
      <content:encoded><![CDATA[
        This is Newsarama, a site (mostly) geared around comics and other related media:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang1.html" onclick="window.open('http://blog.spywareguide.com/images/batzang1.html','popup','width=839,height=492,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang1-thumb-339x198.jpg" alt="batzang1.jpg" class="mt-image-none" style="" height="198" width="339" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br />You'll notice Batman, over on the right there. Let's take a closer look:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batzang2.gif" src="http://blog.spywareguide.com/images/batzang2.gif" class="mt-image-none" style="" height="266" width="316" /></span></div><br /></div><div><br />"Free Online Batman Game"? Well, that's curious because I follow comics pretty closely and I'd be the first to know if an "Online Batman Game" had been in the works (this advert has been doing the rounds on <a href="http://forums.superherohype.com/showthread.php?p=15406107">numerous</a> <a href="http://dcboards.warnerbros.com/web/message.jspa?messageID=2004718393#2004718393">comic-related</a> <a href="http://www.comicforum.de/showpost.php?s=543cba941aeb245f8174ec4943be2adc&amp;p=2733165&amp;postcount=29">websites</a>. Visit the URL in the ad - Batmangame.info - and you'll see this...<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang3.html" onclick="window.open('http://blog.spywareguide.com/images/batzang3.html','popup','width=725,height=666,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang3-thumb-325x298.gif" alt="batzang3.gif" class="mt-image-none" style="" height="298" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />There it is again - "Online Batman Game". Furthermore, the text goes on to say:<br /><i><br />"Batman Online lets you do anything and every little thing you'd like in a Batman game. From leveling up your character to destroying villans, it has it all. Download and play this amazing game now, all for free! I'm sure you'll be playing for hours on end, it's that much fun.<br /><br />&nbsp;&nbsp;&nbsp; Level Up Your Character<br />&nbsp;<br />&nbsp;&nbsp; Explore a Huge Vast World<br />&nbsp;<br />&nbsp;&nbsp; Play Online With Your Friends<br />&nbsp;<br />&nbsp;&nbsp; Hundreds of Quests To Finish<br />&nbsp;<br />&nbsp;&nbsp; Perfect Battle System<br /><br />So start your Batman adventure today! Download the&nbsp; full game below and fight them all!"</i><br /><br />Note that they specifically call it "Batman Online". It specifically sounds like a text blurb you'd expect to see with a <a href="http://en.wikipedia.org/wiki/Massively_multiplayer_online_role-playing_game">MMORPG</a>. However, something isn't quite right here.<br /><br /><b>1)</b> The only DC licensed MMORPG anybody knows of is <a href="http://en.wikipedia.org/wiki/DC_Universe_%28video_game%29">this</a>, and it isn't due out until 2009. It's not Batman-centric, either.<br /><br /><b>2)</b> The screenshots are lifted from the <a href="http://en.wikipedia.org/wiki/Batman_Begins_%28video_game%29">Batman Begins videogame</a>, which came out in 2005. If you were offering a "Batman Online Game", wouldn't you use screenshots from that instead of an unrelated title?<br /><br /><b>3)</b> Absolutely no licensing, copyright or legal mumbo-jumbo on the page anywhere. DC and Warner Bros don't roll like that.<br /><br /><b>4)</b> The website - Batmangame(dot)info - is <a href="http://whois.domaintools.com/batmangame.info">registered anonymously</a>. Not exactly something you see everyday for websites related to licensed DC franchises such as Batman videogames.<br /><br /><b>5)</b> "To download and play the Batman Online Game you must download and install Zango as well. It is free, very easy to install and will give you access to the full game."<br /><br />Shall we continue?<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang4.html" onclick="window.open('http://blog.spywareguide.com/images/batzang4.html','popup','width=757,height=638,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang4-thumb-357x300.gif" alt="batzang4.gif" class="mt-image-none" style="" height="300" width="357" /></a></span><br />Click to Enlarge<br /></div><br />A Zango installer prompt, complete with picture of Batman at the top. If you say "No" to the install, you end up on Google.com. What happens if you click "Start"? Well, you'll get the <a href="http://blog.spywareguide.com/images/batzang5.gif">usual collection</a> of <a href="http://blog.spywareguide.com/images/batzang6.gif">Zango installer screens</a> including one that rather humorously has a guy in a superhero costume.<br /><br /></div><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batzang7.gif" src="http://blog.spywareguide.com/images/batzang7.gif" class="mt-image-none" style="" height="333" width="419" /></span></div><div><br />Once everything is installed, you're taken to another page and from here things just get plain confusing. Remember, up to this point you've been promised an "Online Batman Game", the description of which is clearly intended to evoke images of a MMORPG. However....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batveng.html" onclick="window.open('http://blog.spywareguide.com/images/batveng.html','popup','width=841,height=623,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batveng-thumb-341x252.jpg" alt="batveng.jpg" class="mt-image-none" style="" height="252" width="341" /></a></span><br />Click to Enlarge<br /></div><br />All of a sudden, you're being told you're downloading "Batman: Vengeance" on a cheap-looking splash page and shown what looks like an unofficially ripped <a href="http://www.youtube.com/watch?v=D1WqzbNB8tM&amp;eurl=http://www.batmangame.info/setup.exe">Batman: Vengeance trailer</a> on Youtube.<br /><br />In case you're unaware, Batman: Vengeance is a videogame <a href="http://en.wikipedia.org/wiki/Batman_Vengeance">first launched way back in 2001</a> for consoles (followed shortly after by a PC version). What does this have to do with an "Online Batman Game"? Well, nothing, actually. Aside from the fact you were presented with one thing and are now handed another, things get even stranger when you see the download location:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang00.html" onclick="window.open('http://blog.spywareguide.com/images/batzang00.html','popup','width=542,height=281,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang00-thumb-342x177.gif" alt="batzang00.gif" class="mt-image-none" style="" height="177" width="342" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Have you ever heard of an officially licensed game being offered via Rapidshare downloads? It's possible, I guess, but it seems a little odd. However, the <i>real</i> oddness is reserved for the "Online Batman game" itself.<br /><br />Remember, we've been promised "Hundreds of quests", "A huge vast world", the ability to "level up your character" and (of course) the "play online with your friends" promise of greatness.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batinstall.html" onclick="window.open('http://blog.spywareguide.com/images/batinstall.html','popup','width=811,height=549,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batinstall-thumb-311x210.gif" alt="batinstall.gif" class="mt-image-none" style="" height="210" width="311" /></a></span><br />Click to Enlarge<br /></div><br />Imagine your dismay, then, when you've installed Zango, downloaded the game from Rapidshare using up around 140MB of bandwidth, installed it and....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batdemo.gif" src="http://blog.spywareguide.com/images/batdemo.gif" class="mt-image-none" style="" height="288" width="451" /></span></div><br />Oh dear.<br /><br />Not only are you given a totally different game than what was advertised, you're given a DEMO VERSION of that game with <a href="http://blog.spywareguide.com/images/menu.gif">four short sample levels</a> present, no online functionality and quite a few less quests than the "hundreds" advertised.<br /><br />Hilariously, you can download a 100% legit copy of this demo <a href="http://www.fileplanet.com/110885/110000/fileinfo/Batman-Vengeance-Demo">here at Fileplanet</a>, sans Adware. Setting aside the issue of whether this file is actually sitting on Rapidshare with either Ubisoft or DC / Warner Bros permission (and if it IS okay to be there, I'm pretty sure it's NOT okay to falsely advertise it as some kind of MMORPG) there are some questions that need to be raised here.<br /><br />When this guy approached them with his website, did nobody stop to think that this game did not actually match up with the "Online Batman" game it was touted as? Didn't someone at Zango Quality Control actually download the game and see the big "This is a demo" wording as soon as it starts up? Or question why the <a href="http://blog.spywareguide.com/images/begins1.gif">screenshots</a> on the website don't look like the graphics for <a href="http://blog.spywareguide.com/images/batveng1.gif">Batman: Vengeance</a> in the slightest?<br /><br />However you look at it, this is a scam, pure and simple. Whoever came up with the idea of an "Online Batman Game" is lying through their teeth. Of course, because their website is registered anonymously we have no idea who the culprit is, unless of course Zango want to deposit them on the steps of Gotham City and let me dispense some Batman-style justice to their posterior.<br /><br />However, based on the way these things tend to go - God forbid anyone ever offer up the identity of someone happily scamming the public at large, even when that person is dragging the name of the company associated with them through the mud by their antics - I think I might be waiting some time for the Bat Signal...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 07:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/batman">batman</category>
      <category domain="http://securityratty.com/tag/batman online">batman online</category>
      <category domain="http://securityratty.com/tag/batman game">batman game</category>
      <category domain="http://securityratty.com/tag/online batman game">online batman game</category>
      <category domain="http://securityratty.com/tag/batman online game">batman online game</category>
      <category domain="http://securityratty.com/tag/batman adventure">batman adventure</category>
      <category domain="http://securityratty.com/tag/batman begins videogame">batman begins videogame</category>
      <category domain="http://securityratty.com/tag/batman-centric">batman-centric</category>
      <category domain="http://securityratty.com/tag/batman-style justice">batman-style justice</category>
      <source url="http://blog.spywareguide.com/2008/09/zango-and-the-batman-online-vi.html">Zango And The Batman Online Videogame</source>
    </item>
    <item>
      <title><![CDATA[Relax, the Net Backbone Has Space for Your Lolcats]]></title>
      <link>http://securityratty.com/article/b00a463d2bb0a5e64116bda67d599849</link>
      <guid>http://securityratty.com/article/b00a463d2bb0a5e64116bda67d599849</guid>
      <description><![CDATA[Many people have feared that lolcats and other traffic are going to block the tubes, but Ars says today that the net backbone bandwidth is in fact growing and plenty prepared to swallow those cats....]]></description>
      <content:encoded><![CDATA[<p>Many people have feared that lolcats and other traffic are going to block the &#8216;tubes, but Ars says today that the net backbone bandwidth is in fact growing and plenty prepared to swallow those cats. Actually they use a prettier analogy&#8211;</p>
<blockquote><p>Given recent media coverage, it&#8217;s easy to believe that P2P and streaming video traffic is a rising hurricane battering upon ISP levees, that ISPs are frantically sandbagging their systems against disaster, that throttling, bandwidth caps, and traffic management are urgent and absolute necessities to keep the storm surge at bay. But new research from Telegeography only confirms what we&#8217;ve been saying for some time: the Internet backbone isn&#8217;t drowning beneath any kind of exaflood. In fact, backbone capacity has grown faster than Internet traffic in the last year—for the second year in a row.</p></blockquote>
<p>Check out the <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20080903-what-exaflood-net-backbone-shows-no-signs-of-osteoporosis.html">full article</a>, it even has some shiny graphs. It also reminds me of <a rel="nofollow" target="_blank" href="http://xkcd.com/470/">XKCD</a> the other day&#8230; header: &#8220;I get in trouble for showing up contented to protests,&#8221; and the stick figure&#8217;s holding signs: &#8220;Things are pretty OK!&#8221; and &#8220;Anyone for Scrabble later?&#8221;</p>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 06:21:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/internet traffic">internet traffic</category>
      <category domain="http://securityratty.com/tag/video traffic">video traffic</category>
      <category domain="http://securityratty.com/tag/traffic management">traffic management</category>
      <category domain="http://securityratty.com/tag/net backbone bandwidth">net backbone bandwidth</category>
      <category domain="http://securityratty.com/tag/recent media coverage">recent media coverage</category>
      <category domain="http://securityratty.com/tag/isp levees">isp levees</category>
      <category domain="http://securityratty.com/tag/lolcats">lolcats</category>
      <category domain="http://securityratty.com/tag/grown faster">grown faster</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382565188/">Relax, the Net Backbone Has Space for Your Lolcats</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</link>
      <guid>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel?? to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
  </channel>
</rss>
