<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: minutes]]></title>
    <link>http://securityratty.com/tag/minutes</link>
    <description></description>
    <pubDate>Wed, 17 Sep 2008 10:11:05 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[MSP Snapshot Monitoring with EM7]]></title>
      <link>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</link>
      <guid>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</guid>
      <description><![CDATA[Between the fifth anniversary for ScienceLogic and the Inc 500 milestone, weve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally...]]></description>
      <content:encoded><![CDATA[<p>Between the <a href="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008" target="_blank">fifth anniversary for ScienceLogic</a> and the Inc 500 milestone, we’ve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally designed with managed service providers in mind? Not so surprising when 5 of the first 6 employees (including all 3 founders) came from hosting and MSP backgrounds and had first-hand experience with the daily trials and tribulations of MSP operations – and the tools that didn’t quite work for them.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="John at Interop Vegas" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas-thumb.jpg" width="244" align="left" border="0"></a>Here we talk to John Proctor, who started out as one of our first customers (and the first MSP customer). And he believed in it so much, he eventually became part of the ScienceLogic team. (Remember &#8220;I&#8217;m not only the President, I&#8217;m also a client&#8221; from <a href="http://www.hairclub.com/inthenews_article1.php" target="_blank">the Hair Club for Men</a>?)
<p>John shares his perspectives about the service provider world and why he took a chance on a little-known product called EM7.
<p><strong>ScienceLogic:</strong> What is your background? How many years have you worked as a service provider and for what types of companies?
<p><strong>John Proctor:</strong> I have been working with Service providers for over twelve years. I worked at a major regional service provider for six years and before that I designed and built national and international networks for ISP’s and Fortune 500 companies as a consultant for PriceWaterhouseCoopers and WorldComm.
<p><strong>ScienceLogic:</strong> You were one of the first customers of EM7 – why did you choose it and how did you get over the hurdles associated with using a start-up company’s product?
<p><strong>John Proctor:</strong> We were actually customer number five. Back in 2004 when we evaluated and purchased EM7 we could see that EM7 provided about 80% of what we were looking for in one integrated solution right out of the box. One of the things that sold us on EM7 was that the ScienceLogic founders had all previously worked for a service provider, so we knew they understood our business and our challenges. But in the end, it comes down to features. Once we compared EM7 functionality to the alternatives, it was clearly a “no brainer.”
<p><strong>ScienceLogic:</strong> What other alternatives were being considered?
<p><strong>John Proctor:</strong> Well, we had started with a few point solutions, but as our business and product offerings matured, this resulted in a growing number of point solutions. What started with 3 or 4 ended up as 14 separate tools. They all had strengths but what they didn’t have was integration and because of this they could not scale. And, if the tools could not scale, our business could not grow.
<p>So, naturally we started looking at framework solutions, but they are expensive to buy, expensive to implement, and expensive to maintain. At one point, we even considered some open source projects. There were several that showed promise, but we would still be stuck with tools that were not integrated. So then we considered hiring developers to cobble something together that would work for our business. The only problem with this alternative was that we felt it would take 6 to 8 months before we could have something viable to work with.
<p><strong>ScienceLogic:</strong> What products were you using before EM7? What were your goals?
<p><strong>John Proctor:</strong> Before we purchased EM7 we used 14 different point solutions to deliver our products and services to the marketplace. Tools like NetCool, Openview, Argent, Heat, What’s Up Gold as well as several other point solutions, vendor specific applications and manually updated spreadsheets. And, as I mentioned before, this does not scale. This also adds a great deal of complexity when you begin to consider business continuity and disaster recovery. All these tools were vital to the delivery of our products and services. Any service provider will tell you it is all about uptime. So if the product is uptime, the tools used to deliver it have to be available 24&#215;7x365.
<p>Our goals were simple: scale and redundancy. As it turns out, the solution was simple as well. EM7 provided a tool that could replace the functionality of almost half of the existing point solutions and the applications that could not be replaced were integrated with EM7 to provide our staff with a “single pane of glass” to see the status and performance of each area of the business from one application. We had visibility into everything from facility systems to applications using EM7.
<p>ScienceLogic also delivers an extensible configuration that addressed uptime and redundancy. We deployed collectors throughout our network that reported back to a central pair of redundant database servers and with this configuration we were able to perform backups and add capacity without taking the system down.
<p><strong>ScienceLogic:</strong> Why are service providers different from enterprises? How are their needs different?
<p><strong>John Proctor:</strong> First and foremost, service providers face the same challenges that only the largest enterprises ever face and they also have many unique challenges that only service providers experience.
<p>One challenge we faced was that we had multiple datacenters in different states. They were all interconnected with plenty of bandwidth between each site, but the tools were not designed to be used across the WAN. Our staff in our remote data center did not have the same access as our staff in the corporate office. Since EM7 is web-based, it immediately eliminated this problem.
<p>Another challenge is that service providers must manage systems across multiple domains. Back in the early version of a specific tool we were using before EM7, the only way you could implement it across multiple domains was to put the same username and password on every computer that you monitored. Beyond the security concerns, maintenance was a nightmare. Anytime we had to change the password, we would get locked out of dozens upon dozens of systems. When the password was changed on the monitoring server, it would attempt to login to the remote machines and fail. Repeated attempts would result in the account getting locked. I think that vendor eventually addressed this issue, but service providers seldom find tools that were designed for their unique situations.
<p><strong>ScienceLogic:</strong> How is EM7 geared to service providers?
<p><strong>John Proctor:</strong> Enterprise IT is a trusted part of the business; they are one of the team. Service providers are outsiders that must earn trust by showing the customer exactly what they are doing.
<p>EM7 provides a multi-tenant environment that allows service providers to manage systems across many different customers while at the same time providing the customer access to see the same information but only what’s relevant to them.
<p>EM7 was built by service providers and even includes a few features just for them. Two of my favorites are bandwidth billing and the emergency notification system. Take bandwidth billing, for instance. EM7 provides a way to collect bandwidth utilization, store subscription information, and calculate a bill from any one of about 10 different methodologies. And at the end of the billing period, EM7 sends the completed report out to whomever you chose via email.
<p>Another unique service provider feature is the emergency notification system. EM7 allows the provider to track what customers used their unique infrastructure components. If they have to perform maintenance on the infrastructure component or have a problem they can send an email to all of the impacted customers in a matter of minutes.
<p><strong>ScienceLogic:</strong> What trends do you see for service providers? What about big trends such as virtualization and cloud computing – how will they impact service providers?
<p><strong>John Proctor:</strong> Virtualization is really hot for service providers right now and for the same reasons as in the enterprise. Service providers run data centers and data centers must be powered and cooled. So, anytime they can use a virtual server instead of adding physical equipment it is a good thing. But then you add the complexity that multiple customers reside on the same host and you must track things like bandwidth utilizations by guest OS, and it all gets a little harder. Lucky for us this is not a problem for EM7.
<p>I still think it’s early days for cloud computing. Depending on who you talk to, much of what service providers (especially the big ones) have already been doing with SAAS offerings and hosted applications could be described as cloud computing already. In which case, service providers are ahead of the game. But whatever the “final” definition, cloud computing actually shares many similarities with virtualization – in that service providers (or enterprises) will need to be able to manage far more “devices” in real-time with “zero downtime” expectations by customers. What this really means is that you’re going to see much more automation in provisioning and IT monitoring tools to handle the scale and speed with which things can change in the data center given vm migration and the talked-about switching between “clouds” that can be used for high availability. </p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:51:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service providers experience">service providers experience</category>
      <category domain="http://securityratty.com/tag/service providers seldom">service providers seldom</category>
      <category domain="http://securityratty.com/tag/impact service providers">impact service providers</category>
      <category domain="http://securityratty.com/tag/em7 functionality">em7 functionality</category>
      <category domain="http://securityratty.com/tag/em7 sends">em7 sends</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider world">service provider world</category>
      <source url="http://blog.sciencelogic.com/msp-snapshot-monitoring-with-em7/10/2008">MSP Snapshot Monitoring with EM7</source>
    </item>
    <item>
      <title><![CDATA[Innovators, Imitators and Idiots]]></title>
      <link>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</link>
      <guid>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</guid>
      <description><![CDATA[Charlie Rose interviews Warren Buffett


Charlie Rose
And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage. We just lost sight...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;">Charlie Rose <a href="http://www.cnbc.com/id/26982338/page/2/">interviews</a> Warren Buffett:</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage.&#0160; We just lost sight of risk and leverage of what was appropriate?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.&#0160; Again, because it pays off for a while.&#0160; You know, you can lose leverage, and it&#39;s the only way a smart guy can go broke.&#0160; If you owe money, you can&#39;t pay them out.&#0160; You just pay for everything, you do smart things, you eventually get very rich.&#0160; If you do smart things and use leverage and do one wrong thing along the way, it could wipe you out, because anything times zero is zero.&#0160; But it&#39;s reinforcing when the people around you are doing it successfully, you&#39;re doing it successfully, and it&#39;s a lot like Cinderella at the ball.&#0160; I mean you know at midnight everything is going to turn to pumpkins and mice; right?&#0160; But if the evening goes along, I mean, you know, the guys look better all the time, the music sounds better, it&#39;s more and more fun, you think why the hell should I leave at quarter of 12.&#0160; I&#39;ll leave at two minutes to 12.&#0160; But the trouble is, there are no clocks on the wall.&#0160; And everybody thinks they&#39;re going to leave at two minutes to 12.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating <a href="http://1raindrop.typepad.com/1_raindrop/2007/11/dhandho-infosec.html">risk and uncertainty</a>. As our current financial situation shows, its a hard thing to pull off</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And should wise people have known better?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">People should always know better.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">I mean people -- people don&#39;t get -- they don&#39;t get smarter about things that get as basic as greed and you can&#39;t stand to see your neighbor getting rich.&#0160; You know you&#39;re smarter than he is, and he&#39;s doing these things, you know, and he&#39;s getting rich, and your spouse is getting unhappy with you because you aren&#39;t doing -- pretty soon you start doing it.&#0160; And so you get what I call the natural progression, the three Is.&#0160; The innovators, the imitators, and the idiots.&#0160; And that&#39;s what happens.&#0160; Everybody just kind of goes along.&#0160; And you look kind of silly if you disagree.&#0160; I mean, you know, you could have these crazy Internet valuations in the late 1990s, but they prove themselves out in the market.&#0160; The next day they were selling for more than they were the day before, and people said, you know, you&#39;re crazy if you don&#39;t get in on this.&#0160; So it&#39;s very human.&#0160; Now, with housing it&#39;s something even more dramatic than that, because most people aspire to own their own home.&#0160; And if you really think that houses prices are going to go up next year and the year after, you feel if I don&#39;t buy it this year, I&#39;m going to have to buy it next year.&#0160; That&#39;s not true of an Internet stock.&#0160; But it&#39;s true of a home.&#0160; And when somebody makes it very easy for you to do it by saying you don&#39;t really have to put up my money, you can lie about your income a little, or we&#39;ll give you 100 percent mortgage, you&#39;re going to do it, because everybody that&#39;s done it has been proven right.&#0160; You have what they call social tools, and, you know, you&#39;re going to feel like an idiot if you didn&#39;t do it, because the house cost more.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system.</span></div><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Oh, I think confidence will come back.&#0160; I will tell you this.&#0160; This country is going -- be living better ten years from now than it is now.&#0160; It will be living better in 20 years from now than ten years from now.&#0160; The ingredients that made this country, you know, the miracle of the world -- I mean we had a seven for one improvement in the average American standard of living in the 20th century.&#0160; Now, we had the great depression, we had two world wars, we had the flu epidemic.&#0160; You know, we had oil shock.&#0160; You know, we had all these terrible things happen.&#0160; But something about the American system unleashed more and of a potential to human beings over that hundred years so that we had a seven for one improvement in -- there&#39;s never been any -- I mean, you have centuries where if you&#39;ve got a 1 percent improvement, then it&#39;s something.&#0160; So we&#39;ve got a great system.&#0160; And we&#39;ve got more productive capacity now than we ever have.&#0160; The American worker is more productive than he&#39;s ever been.&#0160; We&#39;ve got more people to do it.&#0160; We&#39;ve got all the ingredients for a sensational future.&#0160; It&#39;s just that right now the athlete&#39;s on the floor.&#0160; But we -- this is a super athlete.</span></p></blockquote><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Again, we want to look at risk events in a broader, long term context. In Buffett&#39;s words its - &quot;be fearful when others are greedy and greedy when others are fearful.&quot; As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* Buffett&#39;s partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive.</span></div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/oeprational risk">oeprational risk</category>
      <category domain="http://securityratty.com/tag/risk events">risk events</category>
      <category domain="http://securityratty.com/tag/risk-reward balance">risk-reward balance</category>
      <category domain="http://securityratty.com/tag/wise people">wise people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/buffett raises">buffett raises</category>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/blind risk acceptance">blind risk acceptance</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/innovators-imitators-and-idiots.html">Innovators, Imitators and Idiots</source>
    </item>
    <item>
      <title><![CDATA[RFID Smartcard Vulnerability Published, Allows Anyone To Crack It In Minutes Using Inexpensive Tools]]></title>
      <link>http://securityratty.com/article/5a0a77597d26c38bcccaef92987ee312</link>
      <guid>http://securityratty.com/article/5a0a77597d26c38bcccaef92987ee312</guid>
      <description><![CDATA[Details about worlds most widely deployed radio frequency identification (RFID) smartcard vulnerability have finally been published Monday. RFID smartcards are used to control access to many...]]></description>
      <content:encoded><![CDATA[Details about world&#8217;s most widely deployed radio frequency identification (RFID) smartcard vulnerability have finally been published Monday. RFID smartcards are used to control access to many transportation systems, military installations, and other restricted areas, and it can be cracked in a matter of minutes using inexpensive tools.
The first among the 2 papers about this issue [...]]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 19:22:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rfid">rfid</category>
      <category domain="http://securityratty.com/tag/inexpensive tools">inexpensive tools</category>
      <category domain="http://securityratty.com/tag/smartcard vulnerability">smartcard vulnerability</category>
      <category domain="http://securityratty.com/tag/rfid smartcards">rfid smartcards</category>
      <category domain="http://securityratty.com/tag/radio frequency identification">radio frequency identification</category>
      <category domain="http://securityratty.com/tag/transportation systems">transportation systems</category>
      <category domain="http://securityratty.com/tag/military installations">military installations</category>
      <category domain="http://securityratty.com/tag/minutes">minutes</category>
      <category domain="http://securityratty.com/tag/control access">control access</category>
      <source url="http://cyberinsecure.com/rfid-smartcard-vulnerability-published-allows-anyone-to-crack-it-in-minutes-using-inexpensive-tools/">RFID Smartcard Vulnerability Published, Allows Anyone To Crack It In Minutes Using Inexpensive Tools</source>
    </item>
    <item>
      <title><![CDATA[Managed Fast Flux Provider - Part Two]]></title>
      <link>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</link>
      <guid>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</guid>
      <description><![CDATA[We're slowly entering into a stage where RBN bullet proof hosting franchises are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/geleqRWDOE0/s1600-h/pharma_spam_fastflux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/8PTQr8G6mBM/s200-R/pharma_spam_fastflux.png" /></a>We're slowly entering into a stage where <a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">RBN bullet proof hosting franchises</a> are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as "mirrored hosting" which in practice is plain simple fast flux network consisting of RBN-alike purchased netblocks, and naturally, botnet infected hosts.<br />
<br />
Managed fast-fluxing is only starting to go mainstream, for instance, in July I found evidence that <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">money mule recruiters were using ASProx's infected hosts as hosting infrastructure</a>, and in November, 2007, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">an infamous spamming software vendor</a> was also found to have been offering fast-flux services in the past.<br />
<br />
In this most recent fast-flux service, we have a known spammer and botnet master that in between self-serving himself on is way to ensure his portfolio of scammy domains remains online for a "little longer", is commercializing fast-fluxing and is offered a DIY service :<br />
<br />
"<i>Finally after hardwork and great appreciation from our normal bullet proof  hosting/server clients we are able to launch Mirrored hosting. What is </i><i>Mirrored hosting</i><i> ?</i><br />
<i><br />
================<br />
</i><i>Mirrored hosting</i><i> is a powerful mirrored  web hosting management, uses multiple Virtual servers to host  website with 100% uptime. </i><i>Mirrored hosting </i><i>is a combination of two things, which  are:<br />
<br />
1. Specially Designed Virtual Servers</i><br />
<i> 2. Powerful  Automated Control Panel</i><br />
<br />
<i>How does it work ?<br />
===============&nbsp;</i><br />
<br />
<i>Mirrored hosting</i><i> uses specially configured Virtual Servers making them link with the </i><i>Mirrored hosting</i><i> Control Panel  which is then controlled by our own control panel allowing us to provide smooth  streamline hosting with no downtime. No one is able to trace original IP of the  server or the place where the files are hosted so the websites/domains hosted  have a 100% Uptime. This is achieved by unique customisation of our Virtual Servers.<br />
<br />
<b>Actually, it takes ips around the world and our  powerful control panel just rotates the ips every 15 minutes. though all these  ips you will see will be fake no one can trace the orignal ip where files are  hosted. Sometimes the ip is from China, Korea, USA, UK, Japan, Lithuania etc.</b></i>"<br />
<br />
The concept has always been there for cybercriminals to take advantage of, but once it matures into a managed service it would undoubtedly lower down the entry barriers allowing yesterday's average phishers to take advantage of what only the "pros" were used to.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AO71M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AO71M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xZIrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xZIrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZGgOm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZGgOm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e7OAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e7OAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVPbM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVPbM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iS1HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iS1HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQOUm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQOUm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409475392" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/recent fast-flux service">recent fast-flux service</category>
      <category domain="http://securityratty.com/tag/powerful control panel">powerful control panel</category>
      <category domain="http://securityratty.com/tag/control panel">control panel</category>
      <category domain="http://securityratty.com/tag/virtual servers">virtual servers</category>
      <category domain="http://securityratty.com/tag/multiple virtual servers">multiple virtual servers</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409475392/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Gov. Palin, Yahoo! Email and SecurityA Call To Action?]]></title>
      <link>http://securityratty.com/article/79da72f5c48bc03e7980047607f10b49</link>
      <guid>http://securityratty.com/article/79da72f5c48bc03e7980047607f10b49</guid>
      <description><![CDATA[The McCain-Palin campaign has offered a rather muted response to the Yahoo! email account breach of Gov. Palin, and so far, the grand jury has opted not to indict the hacker. Is this the end to this...]]></description>
      <content:encoded><![CDATA[<p>The McCain-Palin campaign has offered a rather muted  response to the Yahoo! email account breach of Gov. Palin, and so far, the  grand jury has opted not to indict the hacker. Is this the end to this sordid  tale? Not quite. I believe that the average citizen has been left with a myriad  of questions as to the security in as basic a utility as free email. </p>
<p><strong>What&rsquo;s  going on? </strong></p>
<p>&ldquo;Rubico&rdquo;, as the hacker called himself, used an automated  password recovery tool where he was asked fairly simple questions to identify  himself as Gov. Palin [birthday, zip code, etc.]. Rubico found answers to these  within 45 minutes on Google and Wikipedia! Wow! <B>Is it really that easy to hack into email or messaging services  that the common person uses globally?...</b>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/palin">palin</category>
      <category domain="http://securityratty.com/tag/free email">free email</category>
      <category domain="http://securityratty.com/tag/mccain-palin campaign">mccain-palin campaign</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/fairly simple questions">fairly simple questions</category>
      <category domain="http://securityratty.com/tag/email account breach">email account breach</category>
      <category domain="http://securityratty.com/tag/gov">gov</category>
      <category domain="http://securityratty.com/tag/palin birthday">palin birthday</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1355">Gov. Palin, Yahoo! Email and SecurityA Call To Action?</source>
    </item>
    <item>
      <title><![CDATA[Of Planes and Ships]]></title>
      <link>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</link>
      <guid>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</guid>
      <description><![CDATA[Tom Barnett is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.thomaspmbarnett.com/weblog/2008/09/column_121.html">Tom Barnett</a> is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the &quot;nail it to the wall&quot; quote at the end):</p><p><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">One of the main problems in counterterrorism today is that there are so many people and vehicles, and so much data and material, moving through globalization&#39;s myriad networks that it seems virtually impossible to track it all effectively. Nowhere has this problem been more acute than on the high seas.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In 2006, Adm. Harry Ulrich, then U.S. commander of NATO Naval Forces Europe, decided to do something about it. Despite having virtually no resources, his dream was to transpose the global air-traffic control system onto sea traffic.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Worldwide, aircraft are transparent, because they&#39;re all required to carry an identification beacon that allows them to be tracked leaving and entering airports, and monitored between airports, by a global network of sensors. Act suspiciously and somebody&#39;s fighter aircraft will soon be on your tail.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">No such pervasive system currently exists globally for maritime traffic. While bigger ships carry an ID beacon similar to aircraft, without a shared monitoring network, that&#39;s like tracking only selected commercial jets and giving everyone else a pass.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">So Ulrich, upon taking command, asked a simple question: &quot;If we can do that in the air, why can&#39;t we do it on the sea?&quot; He made a point of pioneering his sea-traffic-control effort first inside the Mediterranean, where NATO&#39;s southern naval forces have historically been concentrated, but his real target was waters off Africa -- the most ungoverned maritime space in the world.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich knew the U. S. Navy couldn&#39;t do it alone, much less bring Africa&#39;s meager coast-guard-like navies up to snuff so they could do it on their own. So he quickly created a network of assets -- both public and private -- to manage that space, modeling his monitoring system on international air-traffic control.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich began stitching together a network of shore-based sensors ringing the Mediterranean. His naval command then began initial monitoring by tapping into the International Maritime Organization&#39;s existing Automated Identification System, transforming NATO&#39;s ability to track ship traffic in the Med.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Almost overnight, NATO went from tracking dozens of ships on the Mediterranean to thousands, and instead of getting the data sometimes up to 72 hours late, now the contacts were being tracked in one to five minutes -- to an accuracy within 50 feet on the earth&#39;s surface.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When the classic big-firm systems integrators told Ulrich it would be too costly to pull it off, the admiral turned to the Volpe Center in Cambridge, Massachusetts, a U.S. Department of Transportation research center. Instead of hundreds of millions of dollars, Ulrich&#39;s initial network cost $900,000. The shore-based receivers are small, roughly the size of a radar dish you might find on a pleasure craft.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The strength of the system is a function of its reach: the more countries join, the larger the shared operational picture. By the time Ulrich retired at the end of 2007, he had enlisted 32 countries throughout the Mediterranean, the North Atlantic, along the west coast of Africa, around the Black Sea, and in the Pacific. Today, the network continues to spread around the planet.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; font-size: 14px; line-height: 20px; "><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">With Ulrich&#39;s system in place, local police, coast guards, and border patrols catch most bad guys, obviating American military responses. As Harry told me for an article I wrote about his work in a fall 2007 issue of Esquire, </span><span style="font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;I don&#39;t do defense; I do security. When you talk defense, you talk containment and mutually assured destruction. When you talk security, you talk collaboration and networking. This is the future.&quot;</span></span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The admiral&#39;s legacy program, the Maritime Safety and Security Information System, earned the Volpe Center a prestigious &quot;Innovations in American Government&quot; award this month from Harvard University&#39;s Ash Institute for Democratic Governance and Innovation.</span></p></blockquote><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Security Collaboration + Networking &#160;= Federation. This is indeed the future - SAML came along just at the nick of time.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When you assume that to do access control you must have &quot;Complete Mediation&quot; in Saltzer and Schroeder&#39;s terms of the subject (users), the objects (data), the session, and the roles, then you are going to have an interesting life trying to deliver anything. And if you do it will mucho expensive.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">if you take the federated autonomous nodes approach, agree upon an attribute schema plus a protection model for same, and basic protocol, you are then free to move about the country. Security doesn&#39;t have to equal centralization or high cost. Get the attributes from point a to point b securely.</span></div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 19:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architect">security architect</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/identification system">identification system</category>
      <category domain="http://securityratty.com/tag/initial network cost">initial network cost</category>
      <category domain="http://securityratty.com/tag/initial">initial</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/ulrich">ulrich</category>
      <category domain="http://securityratty.com/tag/time ulrich">time ulrich</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/of-planes-and-ships.html">Of Planes and Ships</source>
    </item>
    <item>
      <title><![CDATA[SDL Sessions at BlueHat]]></title>
      <link>http://securityratty.com/article/bddb4f5b0c8437f73140811dafbc6401</link>
      <guid>http://securityratty.com/article/bddb4f5b0c8437f73140811dafbc6401</guid>
      <description><![CDATA[Bryan here. Last January, I wrote a post on this blog bemoaning the difficulty of making security interesting and sexy to developers. Applied research conferences generally place a much greater...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Bryan here. Last January, I wrote a post on this blog bemoaning the difficulty of making security interesting and “</FONT><A href="http://blogs.msdn.com/sdl/archive/2008/01/29/sexy-development-lifecycle.aspx"><FONT face=Calibri color=#0000ff size=3>sexy</FONT></A><FONT face=Calibri size=3>” to developers. Applied research conferences generally place a much greater emphasis on revealing new vulnerabilities and new attack techniques, and much less emphasis on educating people on how to actually fix those vulnerabilities. I was at </FONT><A href="http://www.rsaconference.com/"><FONT face=Calibri color=#0000ff size=3>RSA Conference</FONT></A><FONT size=3><FONT face=Calibri> last April, and I attended a session by a very well-regarded, high-profile security researcher. He gave an eloquent and educational presentation on the dangers of a significant new attack vector, but all the prescriptive guidance he gave for dealing with the threat amounted to something like, “If you’re worried about this kind of thing, talk to your browser manufacturer.” No offense to this presenter, but if I’m going to listen to 70 minutes of discussion of a dangerous threat, I want to leave the room with a clear understanding of what I can do to solve the problem! It’s not enough just to know that the problem exists.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>So, in conjunction with the </FONT><A href="http://blogs.technet.com/bluehat/"><FONT face=Calibri size=3>BlueHat</FONT></A><FONT size=3><FONT face=Calibri> team, I am pleased to announce that the SDL team will be organizing the sessions for the second day of the fall BlueHat conference. The BlueHat SDL sessions will be laser-focused on not just describing vulnerabilities but also solving them. Every attendee should leave every presentation with a clear idea of exactly what he or she needs to do to protect themselves from the threat that was discussed during the session.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>The sessions will begin, appropriately, with the topic of secure design. Danny Dhillon of </FONT><A href="http://www.emc.com/"><FONT face=Calibri size=3>EMC</FONT></A><FONT face=Calibri size=3> and the SDL team’s own Adam Shostack will each present their organization’s approach to threat modeling. As a bonus, Adam will also be demonstrating the new </FONT><A href="http://download.microsoft.com/download/1/5/0/150636A9-9EA8-4D00-9E6B-2723F4C188B4/Microsoft%20SDL%20Threat%20Modeling%20Tool%203.0.pdf"><FONT face=Calibri size=3>SDL Threat Modeling tool</FONT></A><FONT face=Calibri size=3> that you might have heard about </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx"><FONT face=Calibri size=3>last week</FONT></A><FONT size=3><FONT face=Calibri>. <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Next up is Matt Miller, a recent and very welcome </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2008/08/18/matt-miller-joins-the-security-science-team.aspx"><FONT face=Calibri size=3>addition</FONT></A><FONT face=Calibri size=3> to the Microsoft Security Science team. Matt has a fantastic presentation on the evolution of buffer overflow attacks and on the corresponding development of overflow mitigations. From there we will switch gears to look at some managed code implementation issues: </FONT><A href="http://www.isecpartners.com/"><FONT face=Calibri size=3>iSEC Partners</FONT></A><FONT size=3><FONT face=Calibri>’ Scott Stender and Alex Vidergar will demonstrate coding techniques to mitigate elusive concurrency vulnerabilities in web applications.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>At this point we will have covered the Design and Implementation phases of the SDL; where better to go from here than Verification? One of the most important activities in the Verification phase is fuzzing, and we have a trio of security experts from the Microsoft Security Science team to talk about it. Jason Shirk, Lars Opstad, and Dave Weinstein will answer three of the most common fuzzing questions: How should I fuzz? When have I fuzzed enough? And what do I do now that I’ve fuzzed? <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Finally, we will wrap up the Verification phase talks with a return appearance to BlueHat by </FONT><A href="http://www.stachliu.com/"><FONT face=Calibri size=3>Stach &amp; Liu</FONT></A><FONT size=3><FONT face=Calibri>’s Vinnie Liu. Vinnie will compare different approaches to security verification – static code analysis, blackbox analysis, and manual code review – and make recommendations as to when each approach is best used.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Even if you can’t make it in to BlueHat in person, you can still watch the sessions via streaming media on </FONT><A href="http://technet.microsoft.com/"><FONT face=Calibri color=#0000ff size=3>TechNet</FONT></A><FONT face=Calibri size=3>. Additionally, webcast interviews with the speakers – condensed “Cliff’s Notes” versions of their full presentations – will be posted on </FONT><A href="http://channel9.msdn.com/Search/Default.aspx?Term=bluehat"><FONT face=Calibri color=#0000ff size=3>Channel 9</FONT></A><FONT size=3><FONT face=Calibri>. And we’ll be continuing the BlueHat tradition of inviting speakers and other industry notables to guest blog about their topics and the latest security trends. More information on all of these resources will be posted here when it becomes available.<o:p></o:p></FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8965212" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/bluehat">bluehat</category>
      <category domain="http://securityratty.com/tag/sessions">sessions</category>
      <category domain="http://securityratty.com/tag/sdl team">sdl team</category>
      <category domain="http://securityratty.com/tag/sdl threat">sdl threat</category>
      <category domain="http://securityratty.com/tag/bluehat sdl sessions">bluehat sdl sessions</category>
      <category domain="http://securityratty.com/tag/bluehat conference">bluehat conference</category>
      <category domain="http://securityratty.com/tag/verification phase talks">verification phase talks</category>
      <category domain="http://securityratty.com/tag/verification phase">verification phase</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/25/sdl-sessions-at-bluehat.aspx">SDL Sessions at BlueHat</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: CSIRO Wins Patent Appeal; Zune-Fi in SF; Kodak ESP 9]]></title>
      <link>http://securityratty.com/article/95aa70e977b254cabeb9c3b2679b4b8d</link>
      <guid>http://securityratty.com/article/95aa70e977b254cabeb9c3b2679b4b8d</guid>
      <description><![CDATA[Australian tech office wins appeal: Buffalo sinks further into the hole as it loses its appeal against a judgement over its use of what the Australian CSIRO technical agency asserts is its patented...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.zdnet.com.au/news/hardware/soa/CSIRO-victorious-in-Wi-Fi-appeal/0,130061702,339292134,00.htm?omnRef=1337"><strong>Australian tech office wins appeal:</strong></a> Buffalo sinks further into the hole as it loses its appeal against a judgement over its use of what the Australian CSIRO technical agency asserts is its patented technology used in all 802.11 implementations. The case, in the patent-holder-friendly US Eastern District Court of Texas--a venue that may be dethroned as a <em>forum coveniens</em> for patentholders' suits in new legislation--prevents Buffalo from importing or selling gear in the US with Wi-Fi technology embedded. In Japan, the patent office threw out CSIRO's patent. While Cisco paid CSIRO as the result of an acquisition of an Australian company a few years ago, most US-based technology giants are involved in resisting the patent's continued validation and enforcement. I've read the patent and some of the suits, and as a non-patent expert, it's clear CSIRO original invention didn't cover what's at stake. However, CSIRO was allowed in a subsequent filing to extend its patent to cover already-in-use technology in a way that seems odd to me, but happens in patents all the time. Many millions of dollars and many more years may be expended before a resolution happens. CSIRO apparently isn't asking for insane fees, although anything paid to them would be passed along to consumers. If companies settled, this might result in an increase of 1 to 5 percent on retail prices. It may ultimately effect WiMax, too, though no suits in that area have been filed.</p>

<p><a href="http://news.cnet.com/8301-10805_3-10046542-75.html"><strong>Finding Zune-Fi:</strong></a> Ina Fried of News.com wanders the polite streets of San Francisco in search of Zune connections over Wi-Fi. She finds a few, and has a good experience. One cafe owner sees the ease with which she can stream music and calls it cool. She can't connect at the long-running Google-sponsored free Wi-Fi at Union Square, however, which means the Wi-Fi likely has an accept button that must be pressed. Surely Microsoft could insert a little technology that would allow a browser-free acceptance of terms? Probably involves Yet Another Protocol: the Wi-Fi Terms Browser-Free Presentation Protocol (WTBFPP).</p>

<p><img src="http://wifinetnews.com//images/2008/kodakesp9.jpg" alt="kodakesp9.jpg" border="0" width="150" height="120" align="right" /><a href="http://www.kodak.com/eknec/PageQuerier.jhtml?pq-path=13572&pq-locale=en_US"><strong>Kodak adds interesting Wi-Fi enabled all-in-one:</strong></a> The new Kodak ESP 9 is a multi-function printer (fax, scan, print, copy) that connects to a network via Wi-Fi or Ethernet. The $300 device spits out 30 pages per minutes in color, 32 ppm in black only. Kodak claims that the model line to which the ESP belongs uses ink in a vastly more efficient manner than the "average of comparable consumer inkjet printers." </p>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 05:53:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csiro">csiro</category>
      <category domain="http://securityratty.com/tag/patent">patent</category>
      <category domain="http://securityratty.com/tag/cover">cover</category>
      <category domain="http://securityratty.com/tag/cover already-in-use technology">cover already-in-use technology</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/kodak">kodak</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wi-fi technology">wi-fi technology</category>
      <source url="http://wifinetnews.com/archives/008452.html">Wee-Fi: CSIRO Wins Patent Appeal; Zune-Fi in SF; Kodak ESP 9</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Keynotes: Cisco]]></title>
      <link>http://securityratty.com/article/c55a3293fe594f4363a5830f6da4d48c</link>
      <guid>http://securityratty.com/article/c55a3293fe594f4363a5830f6da4d48c</guid>
      <description><![CDATA[After some rousing introduction music, Marie Hatter , Vice President, Network Systems and Security Solutions Marketing / CMO of Cisco began her presentation on virtualization
Introduction...]]></description>
      <content:encoded><![CDATA[<p>After some rousing introduction music, <a href="http://blogs.cisco.com/authors/bio/83" target="_blank">Marie Hatter</a>, Vice President, Network Systems and Security Solutions Marketing / CMO of Cisco began her presentation on virtualization.</p>
<p><strong>Introduction</strong></p>
<p>Virtualization is a word used by consumers and also by IT. But, do we all mean the same thing?</p>
<p>A very cool video from Cisco provided answers to &#8220;what is virtualization&#8221; from an  engineering perspective, data center perspective, IT perspective and the user perspective (virtual world).</p>
<p>Virtualization is about breaking the bonds between applications and server hardware, nodes and networks, applications and operating systems.</p>
<p>Why is this interesting? Virtualization holds the promise to transform the way we work, live, learn and play.</p>
<p><strong>Why virtualize?</strong></p>
<p>The real estate boom over the last 30 years has driven people to the suburbs. People didn&#8217;t mind commuting for an hour with lower gas prices. Today, we have a weak economy and gas prices are high. Something has to change.</p>
<p>Many are opting to stay at home. Businesses are trying out telecommuting, some (like Cisco) are even offering telepresence. This helps by reducing carbon footprint. Corporations are breaking free from physical requirements. The global workforce is also having an impact on the network. These changes are having a huge impact on the network.</p>
<p>We are on the cusp of transitioning from virtualization to VIRTUALIZATION.</p>
<p><strong>&#8220;One to many&#8230;.many to one.&#8221;</strong></p>
<p>This is Cisco&#8217;s idea of virtualization.</p>
<p>Consider the different roles we play in life - one to many. Spouse, executive, friend, parent, gym rat. This would be &#8220;one to many&#8221;. This is exactly what virtualization does. It allows you to partition resources off that you can use on the fly.</p>
<p><strong>Where do I start?</strong></p>
<p>Virtualization starts with server and storage. But, it&#8217;s the network that touches everything - it spans the physical, the virtual, and the cloud. This provides the connectivity to all these resources. The network brings transparency to the picture. It allows you to better monitor performance and better implement security - great benefits!</p>
<p><strong>Why do I need this?</strong></p>
<p>At Cisco, we saw that we were only using 20% of our storage utilization. We wanted to virtualize our datacenters. When we did that, we were able to get 68% storage utilization. For each year that we were able to defer buildup, we saved $40 million.</p>
<p>From a business standpoint, virtualization helps you differentiate and work faster. Provisioning in minutes, improved productivity and competitive differentiation, using less power (environmental impact), and up the ante of business continuity. If VMWare fails? It&#8217;s OK. You can reprovision it on the fly.</p>
<p><strong>Is it for everyone?</strong></p>
<p>IT organizations tend to be siloed. You have the IT side and the Operations side. Each has responsibility. For virtualization to work, these walls have to come down. The concept of virtualization depends on shared resources.</p>
<p><strong><a href="http://en.wikipedia.org/wiki/Metcalfe%27s_law" target="_blank">Metcalfe&#8217;s Law of the Network</a> Effect</strong></p>
<p>Everytime you add a node to the network, you increase the value. This is what happens with virtualization. Every device you virtualize increases the power of each device. More control of environment and more efficiency.</p>
<p>This leads to&#8230;</p>
<p><strong>Cloud computing.</strong></p>
<p>Wow, show of hands from the audience when Marie asked &#8220;how many are using cloud computing?&#8221; and &#8220;how many are using your own clouds?&#8221; - not a lot of hands were raised. Interesting considering the coverage cloud computing has and the focus of it.</p>
<p>Cloud computing has three possibilities at Cisco:</p>
<ul>
<li>Flexible infrastructure (hosting)</li>
<li>Abstract services (APIs)</li>
<li>Application services (SaaS)</li>
</ul>
<p>Automation is going to be key, and will need to integrate virtualization-aware elements.</p>
<p>Can you imagine if you wanted interoperability in the cloud? People haven&#8217;t even begun thinking about it.</p>
<p><strong>Conclusion</strong></p>
<p>As you virtualize, your role will change. You will think more about strategy. But keep in mind these &#8220;minefields&#8221; of virtualization:</p>
<ul>
<li>Insufficient planning</li>
<li>Lack of standards</li>
<li>Weak security</li>
</ul>
<p>Security cannot be an afterthought. It has to be planned. We&#8217;ve seen new forms of malware, hypervisor attacks, and root kit infections.</p>
<p>As higher expectations from end users evolve, we&#8217;re becoming not server oriented, but SERVICE oriented.</p>
<p><strong>Tips:</strong></p>
<ul>
<li>Think holistically</li>
<li>Consider IT culture - equipment and people</li>
</ul>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 10:11:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization starts">virtualization starts</category>
      <category domain="http://securityratty.com/tag/virtualization helps">virtualization helps</category>
      <category domain="http://securityratty.com/tag/helps">helps</category>
      <category domain="http://securityratty.com/tag/virtualization depends">virtualization depends</category>
      <category domain="http://securityratty.com/tag/virtualization holds">virtualization holds</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network brings transparency">network brings transparency</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <source url="http://blog.sciencelogic.com/interop-ny-keynotes-cisco/09/2008">Interop NY Keynotes: Cisco</source>
    </item>
  </channel>
</rss>
