<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: org]]></title>
    <link>http://securityratty.com/tag/org</link>
    <description></description>
    <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[78% of my email is Spam?]]></title>
      <link>http://securityratty.com/article/0f9c02618e825b72f1c253cd8c08edf7</link>
      <guid>http://securityratty.com/article/0f9c02618e825b72f1c253cd8c08edf7</guid>
      <description><![CDATA[Ouch. Well at least we Americans can be proud of something we export huh


clipped from www.crime-research.org

Spam Is Growing And Getting More Sophisticated



Besides the innovations, the overall...]]></description>
      <content:encoded><![CDATA[<div > Ouch.<br/>Well at least we Americans can be proud of something we export huh. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/2CA8E8E9-F913-4EE9-BDA9-B23A13A2B2DA/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/893ca49a-ebec-4ae2-98d8-cf1d3bd6ef2a/2CA8E8E9-F913-4EE9-BDA9-B23A13A2B2DA/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.crime-research.org/news/02.09.2008/3553/" href="http://www.crime-research.org/news/02.09.2008/3553/" style="font-size: 11px;">www.crime-research.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/02.09.2008/3553/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Spam Is Growing And Getting More Sophisticated
</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/02.09.2008/3553/ --><DIV><br />
Besides the innovations, the overall volume of spam is up, too. In July 2007, about 66 percent of all e-mail messages were spam, the report said. This year, the figure rose to 78 percent.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/2CA8E8E9-F913-4EE9-BDA9-B23A13A2B2DA/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_060908024403"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=060908024403&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=060908024403&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=060908024403&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_060908024403" /></a></P>]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 10:44:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/e-mail messages">e-mail messages</category>
      <category domain="http://securityratty.com/tag/figure">figure</category>
      <category domain="http://securityratty.com/tag/volume">volume</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/americans">americans</category>
      <category domain="http://securityratty.com/tag/innovations">innovations</category>
      <category domain="http://securityratty.com/tag/crime-research">crime-research</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=606">78% of my email is Spam?</source>
    </item>
    <item>
      <title><![CDATA[Logging Poll #9 Analysis: Log Security]]></title>
      <link>http://securityratty.com/article/820b3554ec6a486561a49cb82afebbb2</link>
      <guid>http://securityratty.com/article/820b3554ec6a486561a49cb82afebbb2</guid>
      <description><![CDATA[This is the analysis of my last poll; the responses are here and also below

First , the most obvious conclusion: people still don't care much about log security ; I am saying that since this was BY...]]></description>
      <content:encoded><![CDATA[<p>This is the analysis of my last poll; the responses are <a href="http://www.misterpoll.com/polls/351660/results">here</a> and also below.</p>  <p><a href="http://lh6.ggpht.com/anton.chuvakin/SMGa_ncGU2I/AAAAAAAAEyo/01NCHG4omE8/s1600-h/poll9logsecurity2.png"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="196" alt="poll9-log-security" src="http://lh3.ggpht.com/anton.chuvakin/SMGbAMHtGgI/AAAAAAAAEys/t2_vBRBKK7Q/poll9logsecurity_thumb.png?imgmax=800" width="244" border="0" /></a> </p>  <p><strong>First</strong>, the most obvious conclusion: people still don't <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">care much about log security</a>; I am saying that since this was BY FAR the <em>least</em> popular of <a href="http://chuvakin.blogspot.com/search/label/poll">my polls</a>. Only 24 people responded, so everything below is pretty unscientific :-)&#160; A good way to explain it: look at <a href="http://news.google.com/news?hl=en&amp;tab=wn&amp;ned=&amp;q=data+loss&amp;btnG=Search+News">the recent media</a>? Do these people care about their <strong>key business data</strong> and their <strong>customer data</strong> security? Nope. So, how on Earth do you make them care about securing their <strong>log data</strong>?</p>  <p><strong>Second,</strong>&#160; it is entirely unsurprising that 83% of respondents want &quot;Authenticated access to log server.&quot; In fact, I'd opine that 100% of people want authenticated access to <em>any</em> of their servers :-) But, this was my &quot;red herring&quot; to set the baselines for the rest of the questions...&#160; </p>  <p>However, this is where the buck stops: other security measures are notably less popular.</p>  <p><strong>Third</strong>, &quot;Logging all access to logs&quot; is my favorite and I am happy to see it reported as popular. But do you really do it?&#160; Do you log access to log server OR access to actual logs? Think about it... I think a lot of people who do the latter still answered &quot;yes&quot; to this one.</p>  <p><strong>Fourth</strong>,&#160; &quot;Reliable / acknowledged network transfer of log data&quot; and &quot;Encryption of log data in transit &quot; are two true &quot;no-brainer&quot; security features; they took the next spot at 45% and 50% of those who answered. They are simple, they are easy, they make&#160; sense - and, obviously, they don't make logs <em>entirely</em> secure so you need to do more. Why only 50%? Where is THE OTHER 50%?! </p>  <p><strong>Fifth</strong>, &quot;all things crypto&quot; are below 40%. &quot;Cryptographic hashing of stored logs&quot;, &quot;Cryptographic signing of stored log data&quot; and &quot;Encryption of stored log data&quot; all hover at around 30%. I attribute them to general disregard of log security AND reliance on &quot;system security&quot; (separate server, etc) over &quot;data security&quot; measures for log protection. </p>  <p><strong>Finally</strong>, I am embarrassed to say that I missed&#160; the obvious security measure &quot;<strong>Separate server for logging, not accessible from the Internet;&quot; </strong>one of my readers added this using &quot;Other security measures&quot; choice. Indeed, this is a good point - and <a href="http://www.loglogic.com">a good idea to do it</a>. Another option mention there was &quot;<strong>Destroy old logs.</strong>&quot; Amen to that too!</p>  <p><strong>Possibly related posts:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Logs</a> </li>    <li><a href="http://chuvakin.blogspot.com/search/label/poll">All other polls and their analysis</a> </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=X4btL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=X4btL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=25k4L"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=25k4L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jN7qL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jN7qL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/384501630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log data">log data</category>
      <category domain="http://securityratty.com/tag/log security">log security</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/protect logs">protect logs</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/log server">log server</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/384501630/logging-poll-9-analysis-log-security.html">Logging Poll #9 Analysis: Log Security</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - August 2008]]></title>
      <link>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</link>
      <guid>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>In a bizarre twist of fate (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my latest poll</a>), the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post in August.&#160; The analysis of said <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">log security poll</a> is coming up tomorrow. BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>:&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a> and a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually review and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>. </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li>    <li>Somewhat predictably, PCI compliance is all the rage again with <a href="http://chuvakin.blogspot.com/2008/08/run-through-pci-dss-12-changes.html">1.2 coming out soon</a>. So, <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. It discusses the fact that there is no &quot;easy list&quot; of what you MUST do to comply.</li>    <li>Finally, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>)</li> </ol>  <p>See you in September,&#160; when .... ah, come on! I will tell you later :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uVPfyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uVPfyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NrADzL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NrADzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=njcwZL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=njcwZL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/383511875" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 08:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log security poll">log security poll</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/popular post">popular post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/383511875/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</source>
    </item>
    <item>
      <title><![CDATA[Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk]]></title>
      <link>http://securityratty.com/article/ceff3c168541790ec71113285297b6e6</link>
      <guid>http://securityratty.com/article/ceff3c168541790ec71113285297b6e6</guid>
      <description><![CDATA[Synopsis: Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about
Welcome to Blue Box: The VoIP Security Podcast Special Edition...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about&quot;</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> Special Edition #26, a 55-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3" rel="enclosure">Download the show here</a> (MP3, 6MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
<p>A year ago in September 2007, I (Dan York) spoke at Astricon 2007 in Arizona, USA, about &quot;Hacking and Attacking VoIP Systems: What You Need To Worry About&quot; My presentation covered a lot of the typical VoIP security threats, tools and best practices but also expanded a bit into specific security issues with Asterisk.&nbsp; Please do keep in mind that it has been a year since this presentation and so some of the issues I mention have been addressed. (<a href="http://www.astricon.net/">Astricon</a>, for those who don't know, is an annual developer conference for those who work with the <a href="http://www.asterisk.org/">Asterisk open source telephony platform</a>. Astricon 2008 is, in fact, coming up in about 3 weeks but I will not be attending this year.)
</p>

<p>The slides for this talk <a href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know/">are available from Slideshare</a>:
</p>



<div id="__ss_178451" style="width: 425px; text-align: left;"><a title="Hacking and Attacking VoIP Systems - What You Need To Know" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;">Hacking and Attacking VoIP Systems - What You Need To Know</a><object width="425" height="355" style="margin: 0px;"><param value="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know" name="movie" /><param value="true" name="allowFullScreen" /><param value="always" name="allowScriptAccess" /><embed width="425" height="355" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a title="View Hacking and Attacking VoIP Systems - What You Need To Know on SlideShare" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="text-decoration: underline;">presentation</a> or <a href="http://www.slideshare.net/upload?src=embed" style="text-decoration: underline;">Upload</a> your own. (tags: <a href="http://slideshare.net/tag/voip" style="text-decoration: underline;">voip</a> <a href="http://slideshare.net/tag/voipsecurity" style="text-decoration: underline;">voipsecurity</a>)</div></div>
<p><em>(And yes, at some point I'll sync the audio with the slides.)</em>
</p>

<p>Production assistance on this Special Edition was provided by Michael Graves who had a very tough task given the poor quality of the recording that I gave to him!&nbsp; Kudos to Michael for getting it to sound as good as it does.

</p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 15:54:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/astricon">astricon</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/voip systems">voip systems</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <category domain="http://securityratty.com/tag/audio">audio</category>
      <category domain="http://securityratty.com/tag/specific security issues">specific security issues</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://www.blueboxpodcast.com/2008/09/blue-box-se026.html">Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk</source>
    </item>
    <item>
      <title><![CDATA[Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk]]></title>
      <link>http://securityratty.com/article/f2bb50144dae112aaea9593bf1748c51</link>
      <guid>http://securityratty.com/article/f2bb50144dae112aaea9593bf1748c51</guid>
      <description><![CDATA[Synopsis: Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about
Welcome to Blue Box: The VoIP Security Podcast Special Edition...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about&quot;</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> Special Edition #26, a 55-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3" rel="enclosure">Download the show here</a> (MP3, 6MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
<p>A year ago in September 2007, I (Dan York) spoke at Astricon 2007 in Arizona, USA, about &quot;Hacking and Attacking VoIP Systems: What You Need To Worry About&quot; My presentation covered a lot of the typical VoIP security threats, tools and best practices but also expanded a bit into specific security issues with Asterisk.&nbsp; Please do keep in mind that it has been a year since this presentation and so some of the issues I mention have been addressed. (<a href="http://www.astricon.net/">Astricon</a>, for those who don't know, is an annual developer conference for those who work with the <a href="http://www.asterisk.org/">Asterisk open source telephony platform</a>. Astricon 2008 is, in fact, coming up in about 3 weeks but I will not be attending this year.)
</p>

<p>The slides for this talk <a href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know/">are available from Slideshare</a>:
</p>



<div id="__ss_178451" style="width: 425px; text-align: left;"><a title="Hacking and Attacking VoIP Systems - What You Need To Know" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;">Hacking and Attacking VoIP Systems - What You Need To Know</a><object width="425" height="355" style="margin: 0px;"><param value="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know" name="movie" /><param value="true" name="allowFullScreen" /><param value="always" name="allowScriptAccess" /><embed width="425" height="355" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a title="View Hacking and Attacking VoIP Systems - What You Need To Know on SlideShare" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="text-decoration: underline;">presentation</a> or <a href="http://www.slideshare.net/upload?src=embed" style="text-decoration: underline;">Upload</a> your own. (tags: <a href="http://slideshare.net/tag/voip" style="text-decoration: underline;">voip</a> <a href="http://slideshare.net/tag/voipsecurity" style="text-decoration: underline;">voipsecurity</a>)</div></div>
<p><em>(And yes, at some point I'll sync the audio with the slides.)</em>
</p>

<p>Production assistance on this Special Edition was provided by Michael Graves who had a very tough task given the poor quality of the recording that I gave to him!&nbsp; Kudos to Michael for getting it to sound as good as it does.

</p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=ro8CGS"><img src="http://feeds.feedburner.com/~a/BlueBox?i=ro8CGS" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=lF8MaL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lF8MaL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=d2zQmL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=d2zQmL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=h8U0ZL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=h8U0ZL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=8B82bL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=8B82bL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=keFvsl"><img src="http://feeds.feedburner.com/~f/BlueBox?i=keFvsl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=WSWkOL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=WSWkOL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/382765294" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 14:54:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/astricon">astricon</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/voip systems">voip systems</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <category domain="http://securityratty.com/tag/audio">audio</category>
      <category domain="http://securityratty.com/tag/specific security issues">specific security issues</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/382765294/blue-box-se026.html">Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk</source>
    </item>
    <item>
      <title><![CDATA[What CAN You Do?]]></title>
      <link>http://securityratty.com/article/a29f74c1b9809d32446d0d95dbf058e1</link>
      <guid>http://securityratty.com/article/a29f74c1b9809d32446d0d95dbf058e1</guid>
      <description><![CDATA[This is NOT a funny post. At all

Alan is not the only one who got 0wned . I am hearing VERY disturbing rumors from some other people (sorry, can't share them here) - and they are good, paranoid...]]></description>
      <content:encoded><![CDATA[This is NOT a funny post. At all.<br /><br /><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/im-back.html">Alan </a>is not the only one who <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/im-back.html">got 0wned</a>. I am hearing VERY disturbing rumors from some other people (sorry, can't share them here) - and they are <span style="font-style: italic;">good, paranoid people</span> :-)  People who don't have a password of "password." :-)<br /><br />Now, think.  <br /><br />What can you, personally, do today if you know - or, at least,  <span style="font-style: italic;">suspect  </span>-<span style="font-weight: bold;"> that somebody is after you?<br /><br /></span>Change all passwords?<span style="font-weight: bold;"> </span>Create paper copies of financial records? Backup everything offline? What else?<br /><br />Think <span style="font-weight: bold;">PERSONAL [CYBER-]SECURITY PLAN.</span><br /><br />Maybe it will become a new blog meme... In any case, I AM thinking about it. Today!<br /><br />And I suggest you do that too.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MS8l3L"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MS8l3L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wk4UNL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wk4UNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fNPnEL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fNPnEL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/382611313" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 08:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/paranoid people">paranoid people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/personal cyber-security plan">personal cyber-security plan</category>
      <category domain="http://securityratty.com/tag/paper copies">paper copies</category>
      <category domain="http://securityratty.com/tag/financial records">financial records</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/blog meme">blog meme</category>
      <category domain="http://securityratty.com/tag/funny post">funny post</category>
      <category domain="http://securityratty.com/tag/0wned">0wned</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/382611313/what-can-you-do.html">What CAN You Do?</source>
    </item>
    <item>
      <title><![CDATA[How To Become A Security Blogger?]]></title>
      <link>http://securityratty.com/article/566eb8d7c8113949794dbf6e4eead107</link>
      <guid>http://securityratty.com/article/566eb8d7c8113949794dbf6e4eead107</guid>
      <description><![CDATA[I know, I know. Some might say that it is a silly question since you rarely seek to become a blogger - you just become one
However, I got a few emails from my readers asking me something along these...]]></description>
      <content:encoded><![CDATA[<p>I know, I know. Some might say that it is a silly question <strong>since you rarely <em>seek to become</em> a blogger - you just <em>become</em> one.</strong></p>  <p>However, I got a few emails from my readers asking me something along these line, thus this post. For example, I got asked &quot;Should I focus more on targeting security professionals or general IT users?&quot;, &quot;Any pitfalls I should be aware of?&quot; as well as general questions about how to start, what content is best, etc all the way to &quot;How did I profit from my blog?&quot;</p>  <p>&#160;</p>  <p><em>Q: Who should I blog to?</em></p>  <p>A: Blog to colleagues first i.e. infosecurity pros. Blogging to IT or general public is - in some sense - harder or - gasp! - will turn you into a journalist (someone who knows nothing about everything BUT writes about it as an &quot;expert&quot; :-)) Maybe you can broaden it later. <strong>Even better, write for YOU (!)</strong>     <br /></p>  <p><em>Q: What area of security I should focus my blogging on?</em></p>  <p>A: Focus on the area of security that you <strong>like the most or know them most</strong>: IDS? Patching? PIX administration? Linux? AD esoterica? Logs, maybe? :-) Then broaden if you feel like it or as you learn new areas</p>  <p>&#160;</p>  <p><em>Q: Any advice on site design, themes, etc?</em></p>  <p>A: Site design, themes, etc will all come later; just pick something basic and <strong>FOCUS on content</strong>, not on SEO, design, etc. MUST have RSS feed; make it highly visible (HTML is out, RSS is IN :-)) </p>  <p>&#160;</p>  <p><em>Q: Any security blogging pitfalls that I should avoid? Any other tips?</em></p>  <p><em>A:</em></p>  <ul>   <li>Don't stick to only long, deep posts? Unbelievably, people often prefer shorter posts or a mix of short/shallow and longer/deep posts (that came as a shock to me early on!)</li>    <li>Tips on how to do whatever useful work well; comments on hot issues (that you understand) works too for a shorter post.</li>    <li>Definitely comment on other bloggers posts (more often early on, later - as you wish...) </li>    <li>Avoid long breaks in blogging (&gt;7 days); it will&#160; lead to reader loss (you should only care about it later - focus on fun content first!)</li>    <li>Join Security Bloggers Network (drop an email to Alan Shimel for it) </li> </ul>  <p><em>Q:&#160; Has blogging in this niche generated any income for you? If so, how much?</em></p>  <p>A: Exactly $0. The reason is that I never wanted to &quot;monetize&quot; my blog;&#160; I don't have banners, etc. This is by design. </p>  <p><em>Q: How did it help your professional career in a significant way?</em></p>  <p>Yes, I think it helped my career and connected me to a lot of fun people! I sure hope I am not &quot;known only as as blogger&quot;, but blog can definitely make one much more known professionally, especially if you create fun and/or useful content.</p>  <p>Overall, blog is a time commitment, but it is also a passion. It does help your career, but &quot;forcing &quot; yourself to do it just for &quot;career benefits&quot; is,&#160; IMHO, a wrong approach.</p>  <p>Yo, my fellow bloggers; help the newbies out, will ya?! Let's start a series of posts on &quot;how to be a good security blogger!&quot;</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=HbVc3K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=HbVc3K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NtynTK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NtynTK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=iousXK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=iousXK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/378283723" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 07:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blogger">blogger</category>
      <category domain="http://securityratty.com/tag/security blogger">security blogger</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/bloggers posts">bloggers posts</category>
      <category domain="http://securityratty.com/tag/longerdeep posts">longerdeep posts</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/site design">site design</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/378283723/how-to-become-security-blogger.html">How To Become A Security Blogger?</source>
    </item>
    <item>
      <title><![CDATA[Nmap presentation and class in Louisville area]]></title>
      <link>http://securityratty.com/article/fba5f949cefda2cf331d68c8dbb27300</link>
      <guid>http://securityratty.com/article/fba5f949cefda2cf331d68c8dbb27300</guid>
      <description><![CDATA[Hi all, my GRE test went well and I'm back to working on the site. I've been invited by the Kentuckiana ISSA chapter to give a presentation on Nmap and its use. The event happens Sept 5, 11:30AM at...]]></description>
      <content:encoded><![CDATA[Hi all, my GRE test went well and I'm back to working on the site. I've been 
invited by the <a href="http://www.issa-kentuckiana.org/">Kentuckiana ISSA</a> 
chapter to give a presentation on
<a href="http://www.irongeek.com/i.php?page=videos/nmap1">Nmap</a> and its use.&nbsp; 
The event happens Sept 5, 11:30AM at the following location:<br>
<br>
<a href="http://maps.google.com/maps?hl=en&q=Innovative+Productivity+/+McConnell+Technology+401+Industry+Road,+Louisville,+KY+40208&ie=UTF8&ll=38.215795,-85.764019&spn=0.008227,0.013819&t=h&z=16">
Innovative Productivity / McConnell Technology<br>
401 Industry Rd, Louisville, KY 40208</a><br>
<br>
The ISSA would like to have an RSVP. Also, I'll be giving a longer hands on 
demonstration and lab later on in September where people can bring their own 
laptops and use a private network to get some hands on experience with Nmap. We 
are not sure of all of the details yet, but it will likely be held Sept 20th at 
the Ivy Tech campus in Sellersburg, IN.<p>Also, this month's Louisville 2600 meeting is coming up on Thursday, Sept 
24th. More details can be found here:
<a target="_blank" href="http://louisville2600.org/">http://louisville2600.org/</a>
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=DeMZkt"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=DeMZkt" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/377558601" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 15:03:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sept">sept</category>
      <category domain="http://securityratty.com/tag/sept 24th">sept 24th</category>
      <category domain="http://securityratty.com/tag/issa">issa</category>
      <category domain="http://securityratty.com/tag/held sept 20th">held sept 20th</category>
      <category domain="http://securityratty.com/tag/louisville">louisville</category>
      <category domain="http://securityratty.com/tag/nmap">nmap</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa chapter">kentuckiana issa chapter</category>
      <category domain="http://securityratty.com/tag/ivy tech campus">ivy tech campus</category>
      <category domain="http://securityratty.com/tag/mcconnell technology">mcconnell technology</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/377558601/">Nmap presentation and class in Louisville area</source>
    </item>
    <item>
      <title><![CDATA[Nmap presentation and class in Louisville area]]></title>
      <link>http://securityratty.com/article/2f6458dad28d7d34cf1af16a26adb2a7</link>
      <guid>http://securityratty.com/article/2f6458dad28d7d34cf1af16a26adb2a7</guid>
      <description><![CDATA[Hi all, my GRE test went well and I'm back to working on the site. I've been invited by the Kentuckiana ISSA chapter to give a presentation on Nmap and its use. The event happens Sept 5, 11:30AM at...]]></description>
      <content:encoded><![CDATA[Hi all, my GRE test went well and I'm back to working on the site. I've been 
invited by the <a href="http://www.issa-kentuckiana.org/">Kentuckiana ISSA</a> 
chapter to give a presentation on
<a href="http://www.irongeek.com/i.php?page=videos/nmap1">Nmap</a> and its use.&nbsp; 
The event happens Sept 5, 11:30AM at the following location:<br>
<br>
<a href="http://maps.google.com/maps?hl=en&q=Innovative+Productivity+/+McConnell+Technology+401+Industry+Road,+Louisville,+KY+40208&ie=UTF8&ll=38.215795,-85.764019&spn=0.008227,0.013819&t=h&z=16">
Innovative Productivity / McConnell Technology<br>
401 Industry Rd, Louisville, KY 40208</a><br>
<br>
The ISSA would like to have an RSVP. Also, I'll be giving a longer hands on 
demonstration and lab later on in September where people can bring their own 
laptops and use a private network to get some hands on experience with Nmap. We 
are not sure of all of the details yet, but it will likely be held Sept 20th at 
the Ivy Tech campus in Sellersburg, IN.<p>Also, this month's Louisville 2600 meeting is coming up on Thursday, Sept 
24th. More details can be found here:
<a target="_blank" href="http://louisville2600.org/">http://louisville2600.org/</a><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/Wbbmb53vUyo" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 15:03:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sept">sept</category>
      <category domain="http://securityratty.com/tag/sept 24th">sept 24th</category>
      <category domain="http://securityratty.com/tag/issa">issa</category>
      <category domain="http://securityratty.com/tag/held sept 20th">held sept 20th</category>
      <category domain="http://securityratty.com/tag/louisville">louisville</category>
      <category domain="http://securityratty.com/tag/nmap">nmap</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa chapter">kentuckiana issa chapter</category>
      <category domain="http://securityratty.com/tag/ivy tech campus">ivy tech campus</category>
      <category domain="http://securityratty.com/tag/mcconnell technology">mcconnell technology</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/Wbbmb53vUyo/">Nmap presentation and class in Louisville area</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</link>
      <guid>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel?? to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
  </channel>
</rss>
