<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: panic]]></title>
    <link>http://securityratty.com/tag/panic</link>
    <description></description>
    <pubDate>Thu, 15 May 2008 11:08:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Seven classic PC symptoms]]></title>
      <link>http://securityratty.com/article/5321b8454977608c63f8893cec31d278</link>
      <guid>http://securityratty.com/article/5321b8454977608c63f8893cec31d278</guid>
      <description><![CDATA[As a small-business person, you might bemoan the fact you don't have 24/7 IT support like your larger-scale competitors. Don't panic. You can solve many of the most common computer problems yourself....]]></description>
      <content:encoded><![CDATA[As a small-business person, you might bemoan the fact you don't have 24/7 IT support like your larger-scale competitors. Don't panic. You can solve many of the most common computer problems yourself. Here are some snafus you can tackle on your own, thanks to the advice of the support staff at several major hardware and software vendors:]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/support staff">support staff</category>
      <category domain="http://securityratty.com/tag/small-business person">small-business person</category>
      <category domain="http://securityratty.com/tag/larger-scale competitors">larger-scale competitors</category>
      <category domain="http://securityratty.com/tag/common computer">common computer</category>
      <category domain="http://securityratty.com/tag/software vendors">software vendors</category>
      <category domain="http://securityratty.com/tag/major hardware">major hardware</category>
      <category domain="http://securityratty.com/tag/solve">solve</category>
      <category domain="http://securityratty.com/tag/tackle">tackle</category>
      <source url="http://www.networkworld.com/news/2008/112508-seven-classic-pc.html?fsrc=rss-security">Seven classic PC symptoms</source>
    </item>
    <item>
      <title><![CDATA[Aspidistra]]></title>
      <link>http://securityratty.com/article/4adeb47a50e5774a3a549e0fa2c6f85d</link>
      <guid>http://securityratty.com/article/4adeb47a50e5774a3a549e0fa2c6f85d</guid>
      <description><![CDATA[Aspidistra was a World War II man-in-the-middle attack. The vulnerability that made it possible was that German broadcast stations were mostly broadcasting the same content from a central source; but...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Aspidistra_(transmitter)">Aspidistra</a> was a World War II man-in-the-middle attack.   The vulnerability that made it possible was that German broadcast stations were mostly broadcasting the same content from a central source; but during air raids, transmitters in the target area were switched off to prevent them being used for radio direction-finding of the target.</p>

<p>The exploit involved the very powerful (500KW) Aspidistra transmitter, coupled to a directional antenna farm.  With that power, they could make it sound like a local station in the target area.</p>

<p>With a staff of fake announcers, a fake German band, and recordings of recent speeches from high-ranking Nazis, they would smoothly switch from merely relaying the German network to emulating it with their own staff.  They could then make modifications to news broadcasts, occasionally creating panic and confusion.</p>

<blockquote>German transmitters were switched off during air raids, to prevent them from being used as navigational aids for bombers. But many were connected into a network and broadcast the same content. When a targeted transmitter switched off, Aspidistra began transmitting on their original frequency, initially retransmitting the German network broadcast as received from a still-active station. As a deception, false content and pro-Allied propaganda would be inserted into the broadcast. The first such "intrusion" was carried out on March 25, 1945, as shown in the operations order at the right.

<p>On March 30, 1945, "Aspidistra" intruded into the Berlin and Hamburg frequencies warning that the Allies were trying to spread confusion by sending false telephone messages from occupied towns to unoccupied towns. On April 8, 1945, "Aspidistra" intruded into the Hamburg and Leipzig channels to warn of forged banknotes in circulation. On April 9, 1945, there were announcements encouraging people to evacuate to seven bomb-free zones in central and southern Germany. All these announcements were false.</p>

<p>The German radio network tried announcing "The enemy is broadcasting counterfeit instructions on our frequencies. Do not be misled by them. Here is an official announcement of the Reich authority." The Aspidistra station made similar announcements, to cause confusion and make the official messages ineffective.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=2KImN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=2KImN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=bbShN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=bbShN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 04:07:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/aspidistra">aspidistra</category>
      <category domain="http://securityratty.com/tag/german network broadcast">german network broadcast</category>
      <category domain="http://securityratty.com/tag/german network">german network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/aspidistra station">aspidistra station</category>
      <category domain="http://securityratty.com/tag/broadcast">broadcast</category>
      <category domain="http://securityratty.com/tag/german broadcast stations">german broadcast stations</category>
      <category domain="http://securityratty.com/tag/german radio network">german radio network</category>
      <category domain="http://securityratty.com/tag/false">false</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/aspidistra.html">Aspidistra</source>
    </item>
    <item>
      <title><![CDATA[Modelling The Global Financial Meltdown]]></title>
      <link>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</link>
      <guid>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</guid>
      <description><![CDATA[Yesterday I received a call from Penny Grosman , Senior Editor, Wall Street &amp; Technology . Penny was interested in my opinion, Will risk management applications be the next killer app for CEP on Wall...]]></description>
      <content:encoded><![CDATA[<p>Yesterday I received a call from <a href="http://www.wallstreetandtech.com/penny-crosman/" target="_blank">Penny Grosman</a>, Senior Editor, <a href="http://www.wallstreetandtech.com/" target="_blank">Wall Street &amp; Technology</a>.   Penny was interested in my opinion, &#8220;Will risk management applications be the next killer app for CEP&#8221; on Wall Street.    I enjoyed talking with Penny.  She caught up with me leaving a tailor&#8217;s shop in Chiang Mai, so I hope she did not mind hearing my stories of buying unique Northern Thai cotton fabric and designing my own casual shirts in the economic turndown.</p>
<p>We read many stories on the net where folks claim that the current financial crisis could have been avoided with more or better use of technology.     This is expected, as software companies and IT professionals will often try to piggy-backtheir business development strategy on the &#8220;crisis of the day&#8221; to sell more goods and services.    Honestly, in this current situation, the main technology that we needed was simple, accurate financial models.</p>
<p>For example, in the chart above, the US economy was doing quite well with US federal funds rates low.   Housing prices in the US were skyrocketing and there was a concern about inflation.    There was an understandable concern the sustainability of that economy.</p>
<p style="text-align: center;"><img class="aligncenter" style="vertical-align: bottom;" src="http://www.thewrittenblog.com/main_1/images/97kcpv16xjh0uvsi8k7kdhaw.gif" alt="" width="277" height="415" /></p>
<p>So, in perhaps one the most ill-advised Federal Reserve actions of many decades, the folks at the helm of the Fed decided to raise their lending rates around 500 percent over a two year period.</p>
<p>As we all know, primarily because of the action by the Fed, the world faces perhaps the worst economic disaster in modern times, while the US Executive Branch and the Congress fight over how to spend $700 Billion taxpayer dollars to inject liquidity into the markets to try to head off a global financial disaster.</p>
<p>It is amazing to me that the US Federal Government, or their advisors, does not have simple financial models with cause-and-effect analysis such as:</p>
<ul>
<li>Homeowners with adjustable rate mortuages will not be able to make payments;and</li>
<li>Housing prices will fall dramatically; then</li>
<li>Homeowners will default on loans where the collateral is much less than the asset value, and</li>
<li>Banks will suffer great losses, and</li>
<li>Lending will come to a halt, then</li>
<li>Banks will collapse, then</li>
<li>Wall Street will exit the markets in panic</li>
<li>&#8230; and more trouble&#8230;.. !!</li>
</ul>
<p>There are and continue to be a lot of discussion and opinions about how risk management needs improvement. and I agree.   We will also read folks talk about how technology can be used to help solve this problem, including CEP/EP and related software (see also <!-- This wrapper class appears only on Page and Single Post pages. --><a title="Capital Market CEP Fantasy Land" rel="bookmark" href="../2008/06/23/capital-market-cep-fantasy-land/">Capital Market CEP Fantasy Land</a>). However, as much I would be pleased to see more CEP/EP applications and use cases, I do not believe that event processing technology is really very useful to solve the core problem of the current financial crisis.</p>
<p>The core problem is, seemingly, that our &#8220;financial experts&#8221; do not even have simple models that will illustrate what will or could happen when you raise the fed lending rates 500 percent in two years in an economy pregnant with adjustable rate mortgages.</p>
<p>To me, this does not appear to be rocket science.  The negligence by the US Federal Reserve and their advisors is astonishing.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 02:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/simple financial models">simple financial models</category>
      <category domain="http://securityratty.com/tag/financial models">financial models</category>
      <category domain="http://securityratty.com/tag/current financial crisis">current financial crisis</category>
      <category domain="http://securityratty.com/tag/crisis">crisis</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wall street">wall street</category>
      <category domain="http://securityratty.com/tag/main technology">main technology</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <source url="http://www.thecepblog.com/2008/10/02/modelling-the-global-financial-meltdown/">Modelling The Global Financial Meltdown</source>
    </item>
    <item>
      <title><![CDATA[Don't Panic]]></title>
      <link>http://securityratty.com/article/171b434e504b03e183525367f4118cdd</link>
      <guid>http://securityratty.com/article/171b434e504b03e183525367f4118cdd</guid>
      <description><![CDATA[Sometimes it's easy to believe that every last thing online is going to eat into your PC, burn your house down, kill your cat and so on. The last few days I'd been hearing rumblings about some...]]></description>
      <content:encoded><![CDATA[
        Sometimes it's easy to believe that every last thing online is going to eat into your PC, burn your house down, kill your cat and so on. The last few days I'd been hearing rumblings about some "Youtube rap video" and a file that would start hijacking your PC - well, thanks to a tipoff from a forum-goer at Spywarewarrior, I can hopefully put this one to rest.<br /><br />In short, a video promoting a rap mix-tape supposedly took you to a file that "hijacked your PC with Spywarestop". In actual fact, there's no file to hijack you. Let's take a look - here's the Youtube page in question:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mixtape1.html" onclick="window.open('http://blog.spywareguide.com/images/mixtape1.html','popup','width=895,height=493,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mixtape1-thumb-395x217.gif" alt="mixtape1.gif" class="mt-image-none" style="" height="217" width="395" /></a></span><br /><br />Click to Enlarge<br /></div><br />As you can see, there's the mix-tape being advertised and a link to Mediafire, where the mix-tape is hosted. Click the Mediafire link, and all that happens is you'll see an advert for various antispyware tools - some of them on the <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm">Rogue Antispyware list</a>, some of them not on the list but known to be of little worth to the end-user.<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mixtape2.html" onclick="window.open('http://blog.spywareguide.com/images/mixtape2.html','popup','width=757,height=457,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mixtape2-thumb-357x215.gif" alt="mixtape2.gif" class="mt-image-none" style="" height="215" width="357" /></a></span><br /> </div><div><div align="center"><br />Click to Enlarge<br /></div><br />In this particular case, it's an advert for Adware Alert. It's not hijacking you, or breaking things or making your browser fly around the screen, nor is it a "virus". It's just an (admittedly loud) advert. If you're running a browser compatible with <a href="http://adblockplus.org/en/">Adblock Plus</a>, all you'll see beneath the Mediafire logo is a blank space. Even if you're vaguely alarmed by the advert, all you have to do is click the "Continue to Mediafire.com" message at the top right of the screen (missing from the above screenshot as I cropped the image too small - whoops) and you'll be taken to the file you requested.<br /><br />Like the title says - don't panic. This really isn't something to worry about too much. Even the most obnoxious rogue antispyware advert (the ones that <i>do</i> resize your browser, throw up endless popups and make annoying "Woop woop" noises) can usually be escaped by simply hitting CTRL+ALT+DEL and using Task Manage to close your browser session.<br /></div>
        
    ]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 13:03:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mediafire link">mediafire link</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/mediafire">mediafire</category>
      <category domain="http://securityratty.com/tag/browser session">browser session</category>
      <category domain="http://securityratty.com/tag/rap mix-tape supposedly">rap mix-tape supposedly</category>
      <category domain="http://securityratty.com/tag/mix-tape">mix-tape</category>
      <category domain="http://securityratty.com/tag/mediafire logo">mediafire logo</category>
      <category domain="http://securityratty.com/tag/browser compatible">browser compatible</category>
      <source url="http://blog.spywareguide.com/2008/08/dont-panic.html">Don't Panic</source>
    </item>
    <item>
      <title><![CDATA[Myspace Drive By]]></title>
      <link>http://securityratty.com/article/05354a2570b18bfd381d68bb5f8b561f</link>
      <guid>http://securityratty.com/article/05354a2570b18bfd381d68bb5f8b561f</guid>
      <description><![CDATA[Spotted in the wild (like they're spotted anywhere else

Apparently the following happened while someone tried to view a blog post






Click to Enlarge

A fake &quot;your system may be infected&quot; popup....]]></description>
      <content:encoded><![CDATA[
        Spotted in the wild (like they're spotted anywhere else!)<br /><br />Apparently the following happened while someone tried to view a blog post:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/msdb1.html" onclick="window.open('http://blog.spywareguide.com/images/msdb1.html','popup','width=944,height=434,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/msdb1-thumb-344x158.jpg" alt="msdb1.jpg" class="mt-image-none" style="" height="158" width="344" /></a></span><br /></div><div><div align="center"><br />Click to Enlarge<br /></div><br />A fake "your system may be infected" popup. Note the site it launches from is one of the more aggressive types (it shrinks your browser down into the bottom corner, and won't let you do anything other than cycle in an endless loop of popups until you agree to download the file being pushed).<br /><br />These kind of attacks occur because of rogue adverts being pushed into advertising space, which is likely what happened here. If you are unfortunate enough to be trapped by an attack like this, don't panic - just do a CTRL+ALT+DEL and close the browser window...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 14:58:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/browser window">browser window</category>
      <category domain="http://securityratty.com/tag/bottom corner">bottom corner</category>
      <category domain="http://securityratty.com/tag/attacks occur">attacks occur</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/endless loop">endless loop</category>
      <category domain="http://securityratty.com/tag/aggressive types">aggressive types</category>
      <category domain="http://securityratty.com/tag/rogue adverts">rogue adverts</category>
      <category domain="http://securityratty.com/tag/launches">launches</category>
      <source url="http://blog.spywareguide.com/2008/07/myspace-drive-by.html">Myspace Drive By</source>
    </item>
    <item>
      <title><![CDATA[China Quake Hacker Caught]]></title>
      <link>http://securityratty.com/article/d3e180d72ba44bd428c987a2a1b476b4</link>
      <guid>http://securityratty.com/article/d3e180d72ba44bd428c987a2a1b476b4</guid>
      <description><![CDATA[How stoopid did this guy have to be to think, gee, I should put a fake earthquake warning up and then follow through on it? How did he think it would be funny
From Network World
A 19-year old Chinese...]]></description>
      <content:encoded><![CDATA[<p>How stoopid did this guy have to be to think, &#8220;gee, I should put a fake earthquake warning up&#8221; and then follow through on it? How did he think it would be funny?</p>
<p>From Network World:</p>
<blockquote><p>A 19-year old Chinese man is in police custody after allegedly hacking into a provincial seismological bureau&#8217;s Web site to place a false earthquake warning, Chinese state media reported Monday.</p>
<p>The teenager, identified only by his surname Chen, altered the Web site of the Guangxi Seismological Bureau to warn residents in southwestern China to prepare for an impending earthquake expected to measure 9.0 on the Richter scale, according to a report on China Central Television&#8217;s Web site. </p>
<p>Such a posting could have caused a panic. On May 12 an earthquake measuring 7.8 struck China&#8217;s Sichuan province, killing over 70,000 people and leaving millions homeless. Following the quake, many people have fallen prey to rumors that earthquakes can now be predicted in a manner similar to weather forecasts, although there was no warning of the Sichuan quake. </p></blockquote>
<p>I mean seriously. 70,000 people perished in the actual earthquake a month ago.</p>
<p>What a dumbass.</p>
<p><a href="http://www.networkworld.com/news/2008/061708-china-quake-site-hacker.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=4DWtlH"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=4DWtlH" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=lNimgI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=lNimgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=1mf7Ei"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=1mf7Ei" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=0sxFqi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=0sxFqi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=nL5ixi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=nL5ixi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=V1rw2i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=V1rw2i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/315340306" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 06:59:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/earthquake">earthquake</category>
      <category domain="http://securityratty.com/tag/actual earthquake">actual earthquake</category>
      <category domain="http://securityratty.com/tag/false earthquake">false earthquake</category>
      <category domain="http://securityratty.com/tag/quake">quake</category>
      <category domain="http://securityratty.com/tag/fake earthquake">fake earthquake</category>
      <category domain="http://securityratty.com/tag/guangxi seismological bureau">guangxi seismological bureau</category>
      <category domain="http://securityratty.com/tag/sichuan quake">sichuan quake</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/315340306/">China Quake Hacker Caught</source>
    </item>
    <item>
      <title><![CDATA[Cisco IPS Jumbo Frame DoS]]></title>
      <link>http://securityratty.com/article/30454d5fc63a7266c8e9e99fd78bec4d</link>
      <guid>http://securityratty.com/article/30454d5fc63a7266c8e9e99fd78bec4d</guid>
      <description><![CDATA[For a networking company, thats gotta hurt
From Cisco
Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial...]]></description>
      <content:encoded><![CDATA[<p>For a networking company, that&#8217;s gotta hurt.</p>
<p>From Cisco:</p>
<blockquote><p>Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulnerability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operation. Platforms deployed in promiscuous mode only or that do not contain gigabit network interfaces are not vulnerable.</p>
<p>Cisco has released free software updates that address this vulnerability. There is a workaround for this vulnerability.</p></blockquote>
<p>Update or workaround? Which is it then? At the very least get your patch on.</p>
<p><a href="http://www.cisco.com/warp/public/707/cisco-sa-20080618-ips.shtml">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=Vm2zt9"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=Vm2zt9" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=bkPt2I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=bkPt2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=yttCii"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=yttCii" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YD8Jki"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YD8Jki" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=9543ri"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=9543ri" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=NbWq0i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=NbWq0i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/314909884" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 18 Jun 2008 17:22:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gigabit network interfaces">gigabit network interfaces</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/service vulnerability">service vulnerability</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/jumbo ethernet frames">jumbo ethernet frames</category>
      <category domain="http://securityratty.com/tag/recover platform operation">recover platform operation</category>
      <category domain="http://securityratty.com/tag/kernel panic">kernel panic</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/power cycle">power cycle</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/314909884/">Cisco IPS Jumbo Frame DoS</source>
    </item>
    <item>
      <title><![CDATA[China quake fake in police custody]]></title>
      <link>http://securityratty.com/article/d20eb8e499b6d81edca362cebe0b2de7</link>
      <guid>http://securityratty.com/article/d20eb8e499b6d81edca362cebe0b2de7</guid>
      <description><![CDATA[A 19-year-old computer intruder who broke into a provincial seismological bureau's Web site to place a false earthquake warning could have caused widespread panic in the rattled Sichuan...]]></description>
      <content:encoded><![CDATA[A 19-year-old computer intruder who broke into a provincial seismological bureau's Web site to place a false earthquake warning could have caused widespread panic in the rattled Sichuan region.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=xGuVZy"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=xGuVZy" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/313626181" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 05:24:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/provincial seismological bureau">provincial seismological bureau</category>
      <category domain="http://securityratty.com/tag/19-year-old computer intruder">19-year-old computer intruder</category>
      <category domain="http://securityratty.com/tag/false earthquake">false earthquake</category>
      <category domain="http://securityratty.com/tag/sichuan region">sichuan region</category>
      <category domain="http://securityratty.com/tag/widespread panic">widespread panic</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/313626181/article.do">China quake fake in police custody</source>
    </item>
    <item>
      <title><![CDATA[Pocono Mountain School District "irregularities"]]></title>
      <link>http://securityratty.com/article/428a87c41a9a2ff786e39b2738b49910</link>
      <guid>http://securityratty.com/article/428a87c41a9a2ff786e39b2738b49910</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/30/08

Organization
Pocono Mountain School District

Contractor/Consultant/Branch
None

Victims
Students and parents

Number Affected
Unknown

SCHOOL...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/poconosd.jpg" align="right" height="103" width="72"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/30/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.pmsd.org/Home/tabid/36/Default.aspx">Pocono Mountain School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Students and parents<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*"SCHOOL DISTRICT ENROLLMENT (2007-2008) 11,500 students K-12 (Current as of Oct. 17, 2007)"</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>"Student ID, network password, SSN if provided, ethnicity, gender, birthdate, grade, grade year, building no., building name, homeroom no., homeroom teacher, attendance code (if absent today), dietary allergies (for food services), bus assignment, free/reduced lunch status, home phone, primary home mailing address, secondary mailing address, parent names, parent phone numbers, emergency contact names, and emergency contact phone numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"An apparent cyber break-in of Pocono Mountain School District's computer system has put at potential risk personal information about students and parents, the district announced Friday.<br><br>District Superintendent Dwight Pfennig sent home letters on Friday afternoon telling parents about the apparent breach, which the district found out about the previous evening, according to Wendy Frable, director of public information."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.pmsd.org/Home/tabid/36/mid/1293/newsid1293/64/Letter-to-Parents-on-Computer-Security/Default.aspx">Pocono Mountain School District "Letter to Parents"</a> <br><a href="http://www.poconorecord.com/apps/pbcs.dll/article?AID=/20080601/NEWS/806010334">Pocono Record</a> <br><a href="http://www.mcall.com/news/local/all-b4_3pocono.6436000may31,0,1422227.story">The Morning Call</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Pocono Mountain School District<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A hacker apparently broke into the computers at Pocono Mountain School District and may have tapped into confidential information concerning students and their parents, the district's superintendent said Friday.<br><span style="font-style: italic;">[Evan] This statement is provided by Joe McDonald of The Morning Call.&nbsp; It is unclear if a "hacker" breached the system or if there was another cause for the "irregularities" reported at the school.</span><br><br>District Superintendent Dwight Pfennig sent home letters on Friday afternoon telling parents about the apparent breach, which the district found out about the previous evening, according to Wendy Frable, director of public information.<br><span style="font-style: italic;">[Evan] This is a quick notification.&nbsp; I think it is possible to be too quick in notifying victims, almost like The Boy Who Cried Wolf.&nbsp; It seems as though the school has not gathered the facts required to make a proper notification.&nbsp; Judge for yourself.</span><br><br>Frable said the district's technical staff had noted some irregularities during a routine security check Thursday night. "They detected some activity that seemed a little unusual," she said.<br><br>The technical staff is checking to see to what extent any personal information — and to whom it may belong — had been compromised.<br><br>The district referred the matter to Pennsylvania State Police at Swiftwater for further investigation, Frable said.<br><br>The information that may have been compromised includes the following: Student ID, network password, SSN if provided, ethnicity, gender, birthdate, grade, grade year, building no., building name, homeroom no., homeroom teacher, attendance code (if absent today), dietary allergies (for food services), bus assignment, free/reduced lunch status, home phone, primary home mailing address, secondary mailing address, parent names, parent phone numbers, emergency contact names, and emergency contact phone numbers.<br><br>"We don't know if anything was accessed," she said, adding that the district will contact anyone whose data had been found to be compromised. Frable also said that very few records include children's Social Security numbers.<br><span style="font-style: italic;">[Evan] A breach involving children's personal information is especially bothersome. </span><br><br>We have conducted an internal investigation and suggest you take the following preventative measures now to help prevent and detect any misuse of your or your child’s information.<br><br>"As a first step to protect yourself from the possibility of identity theft, we recommend you closely monitor any accounts that may contain any or some of this information," Pfennig wrote in his letter to parents.<br><br>If you see any unauthorized activity, promptly contact your service provider and or office of the Executive Director of Technology at (570) 873-7121 Ext. 10151.<br><br>"We're just trying to do what's right by everyone," Frable said. "There's no reason to panic anyone, but people should just be cautious."<br><span style="font-style: italic;">[Evan] Understandable, but some people will panic anyway.&nbsp; This is why it’s a good idea to gather facts before notification.</span><br><br>Parents got the letters when their children returned at the end of the school day, and at least one parent felt the school was being rather nonchalant. <br><br>''It sounds to me like they're trying to downplay it,'' said Ralph Ortega, who lives in Jackson Township. ''It's incredibly vague.''<br><span style="font-style: italic;">[Evan] I agree.&nbsp; I question whether this is because there aren't enough facts available yet, or whether the school is not being square with the victims.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>This breach leaves us with more questions than answers.&nbsp; People will speculate where there is a lack of clarity.&nbsp; I hope students and parents get the answers to the questions that they should demand answers too. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/02/poconosd.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 08:36:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/contact">contact</category>
      <category domain="http://securityratty.com/tag/promptly contact">promptly contact</category>
      <category domain="http://securityratty.com/tag/school district enrollment">school district enrollment</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/emergency contact names">emergency contact names</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <source url="http://breachblog.com/2008/06/02/poconosd.aspx">Pocono Mountain School District "irregularities"</source>
    </item>
    <item>
      <title><![CDATA[Oklahoma State University Parking Services server is compromised]]></title>
      <link>http://securityratty.com/article/f74dd3d54ef8465c68b7797c38075517</link>
      <guid>http://securityratty.com/article/f74dd3d54ef8465c68b7797c38075517</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/14/08

Organization
Oklahoma State University (&quot;OSU

Contractor/Consultant/Branch
OSU Parking &amp; Transit Services

Victims
OSU faculty, staff and...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/okstate.jpg" align="right" height="127" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/14/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://osu.okstate.edu/">Oklahoma State University ("OSU")</a>&nbsp; <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.parking.okstate.edu/">OSU Parking &amp; Transit Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>OSU faculty, staff and students who had purchased a parking permit between July 2002 and March 2008<br><br><span style="font-weight: bold;">Number Affected:</span><br>as many as 70,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Oklahoma State University has discovered that a server under the control of OSU Parking and Transit Services had been accessed from another country without authorization. The database contained confidential information, specifically the names, addresses and Social Security numbers of OSU faculty, staff and students who had purchased a parking permit between July 2002 and March 2008."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://idalert.okstate.edu/incident_00003.html">Oklahoma State University Alert</a> <br><a href="http://www.koco.com/news/16267153/detail.html">KOCO Channel 5 News</a> <br><a href="http://ocolly.com/2008/05/15/student-faculty-and-staff-info-exposed-in-osu-parking-server-breach/">The Daily O'Collegian</a> <br><a href="http://newsok.com/osu-admits-computer-security-breach/article/3243594/?tm=1210801442">The Oklahoman</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Oklahoma State University<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>STILLWATER, Okla. -- Personal information belonging to anybody who got a parking pass at Oklahoma State University over the last five years has been compromised, university officials said Wednesday.<br><br>Oklahoma State University has discovered that a server under the control of OSU Parking and Transit Services had been accessed from another country without authorization. The database contained confidential information, specifically the names, addresses and Social Security numbers of OSU faculty, staff and students who had purchased a parking permit between July 2002 and March 2008.<br><span style="font-style: italic;">[Evan] What does the OSU Parking and Transit Services department need Social Security numbers for?&nbsp; Do you suppose information security personnel knew that sensitive personal information was stored on the server prior to this incident?</span><br><br>Upon discovering this intrusion, the IT Information Security Office immediately removed the server from the network to evaluate server activity to ascertain if personal information had been accessed.<br><br>The confidential information has been removed from the database.<br><br>The illegal access was limited to the parking and transit server.<br><br>As a result of its investigation, OSU believes the intruder's purpose and only action was to use the OSU server for storage capacity and bandwidth to upload and distribute illegal and inappropriate content.<br><span style="font-style: italic;">[Evan] I wonder if I am getting this right.&nbsp; Was there a direct network path from the public Internet through a firewall to the compromised database server running http, ftp, or some other file transfer protocol?&nbsp; That's not cool.&nbsp; A database server storing confidential information should not be accessible from the internet directly through a firewall. It is generally a good practice to separate the database function from the file transfer function into different servers and different firewall DMZs.&nbsp; All this for parking?&nbsp; Ugh.</span><br><br>OSU contacted and worked with federal law enforcement authorities.<br><br>After evaluation of all available data related to this incident, OSU found no evidence which would indicate that the database was copied or viewed by the hacker; however, OSU cannot say with 100 percent certainty that the hacker did not access personally identifiable information.<br><span style="font-style: italic;">[Evan] I wonder what evidence they looked for and how they went about gathering it.</span><br><br>We are not aware of any instances of misuse of this information or of any identify theft as a result of the temporary availability of this information.<br><br>OSU recommends you carefully review any bills or financial transactions you receive in the near future to ensure that the charges associated with your accounts are accurate.<br><span style="font-style: italic;">[Evan] Yeah!&nbsp; Review your bills (pay them occasionally) and financial transactions carefully.&nbsp; But wait, you do this already?&nbsp; Disappointing statement coming from an organization that did not carefully review their controls in securing your personal information.</span><br style="font-style: italic;"><br>OSU President Burns Hargis said, "This breakdown in security is totally unacceptable. We are conducting a full review and will take whatever steps are necessary to protect our network from unauthorized access. This is a serious matter and we will deal with it aggressively. We regret the circumstances and concern this situation has caused."<br><span style="font-style: italic;">[Evan] This is my favorite statement from this story!&nbsp; What do you suppose his stance was prior to being notified of the breach?&nbsp; </span><br><br><span style="font-style: italic;">In my experience, there are primarily ("primarily" because there are always exceptions) four types of senior information security management.&nbsp; You have the organizations that just don't get it and don't really care or know that they don't get it.&nbsp; These organizations lose information over and over and dangerously continue to operate in a business as usual manner. </span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-style: italic;">Secondly, you have the organizations that didn't get it, suffer some adverse event, then HOLY &amp;$#^!&nbsp; They respond with all guns blazing and overspend on controls they don't need and run a very cost ineffective security program (I guess they really never got it either).&nbsp; </span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-style: italic;">Thirdly, there is the company that didn't get it, suffered an adverse event and admitted they have a problem.&nbsp; These companies may seek guidance and consultation in the effort to build a comprehensive information security program.&nbsp; These programs should be built around business objectives and sound risk management.&nbsp; </span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-style: italic;">Lastly, there are the companies that were proactive and built a sound information security program because it was good business.&nbsp; These organizations didn't need an adverse event or breach before taking action.&nbsp; These organizations don't panic when an adverse event occurs.&nbsp; They know that eventually an adverse event will occur and they will be prepared when it does.</span><br style="font-style: italic;"><br>The server is believed to have been compromised on November 23, 2007. OSU learned of the breech [sic] on March 20, 2008 and blocked access to the server immediately.<br><span style="font-style: italic;">[Evan] Wow.&nbsp; The server was 0wn3d (like my 1337 5p34k?) for almost 4 months before anyone noticed?!&nbsp; That is way, way, way too long for a compromised server to go unnoticed.&nbsp; We can now assume that there was no effective IDS/IPS (host or network) and no effective logging and monitoring of the server.</span><br><br>The OSU Parking Department has altered their procedures for the collection of private information. Additionally, the server which was located at the OSU Parking Service's office will be relocated to the IT Data Center for enhanced security. OSU is conducting a full review and will be taking additional steps to protect our network from unauthorized access.<br><span style="font-style: italic;">[Evan] It's a very good idea to not collect private information if it is not required.&nbsp; It's too bad that it took a breach for this to happen.&nbsp; Moving the server from the Parking Service's office to the IT Data Center will help protect against physical security attacks, but this was a logical attack.&nbsp; Maybe the IT Data Center has better firewalls or something <img src="http://breachblog.com/emoticons/smile.png" border="0" />.&nbsp; I like the "full review".&nbsp; This should be done no less than annually.</span><br><br>The IT Information Security Office has made security recommendations to the OSU Parking Office which include physical relocation of their server and database to a more secure location, additional training for server administrators, and added vulnerability assessments.<br><br>Q. How will I know if any of my personal information was used by someone else? <br>A. The best way to find out is to obtain your credit reports from the three major credit bureaus: Equifax, Experian and Trans Union. If you notice accounts on your credit report that you did not open or applications for credit ("inquiries") that you did not make, these could be indications that someone else is using your personal information, without your permission.<br><span style="font-style: italic;">[Evan] "If you notice accounts on your credit report that you did not open or applications for credit ("inquiries") that you did not make", then chances are you have <span style="font-weight: bold;">already</span> become an identity-theft victim.&nbsp; I'm not saying whether this is likely, or not.</span><br><br>Q. Why did you have my personal information? <br>A. You provided this information to us when you applied to Oklahoma State University, or during your tenure as a student or employee here. Oklahoma State, like other institutions, maintains records of all employees and students who have attended the University.<br><span style="font-style: italic;">[Evan] Great question!&nbsp; Why did you have my personal information (on a publicly accessible server used in a department that doesn't really need it without proper protections and without proper monitoring)?</span><br><br><span style="font-weight: bold;">Commentary:</span><br>This breach torques me a little, in case you didn't pick up on that from the comments above.&nbsp; I made plenty.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/15/okstate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 15 May 2008 11:08:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/server administrators">server administrators</category>
      <category domain="http://securityratty.com/tag/server immediately">server immediately</category>
      <category domain="http://securityratty.com/tag/server prior">server prior</category>
      <category domain="http://securityratty.com/tag/database server">database server</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <source url="http://breachblog.com/2008/05/15/okstate.aspx">Oklahoma State University Parking Services server is compromised</source>
    </item>
  </channel>
</rss>
