<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pre-screend]]></title>
    <link>http://securityratty.com/tag/pre-screend</link>
    <description></description>
    <pubDate>Fri, 01 Aug 2008 09:59:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[HP Hires 140,000 to Get Rid of Your Job]]></title>
      <link>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</link>
      <guid>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</guid>
      <description><![CDATA[HP completed its $13.25 billion acquisition of EDS today
Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined...]]></description>
      <content:encoded><![CDATA[<p>HP completed its $13.25 billion acquisition of EDS today. </p>
<p>Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined outsourcing unit, expects to leverage HP automation tools to cut costs and improve that margin.</p>
<p>But Rod Bourgeois, an analyst at Sanford Bernstein says, &#8220;It&#8217;s not like HP has automation tools that weren&#8217;t at <a href="http://online.wsj.com/article/SB121971997812971951.html?mod=hps_us_whats_news">EDS&#8217;s disposal before</a>.&#8221;</p>
<p>But this brings up a good point. EDS and 140,000 new bodies notwithstanding, HP seems to be positioning itself to do a big <a href="http://blogs.wsj.com/biztech/2008/08/26/the-key-to-h-p-eds-automation/?mod=djemTECH">automation push in the marketplace</a>. </p>
<p><a href="http://www.infoworld.com/article/08/05/13/What-does-the-HP-EDS-deal-really-mean_1.html?source=fssr">Of course this makes sense</a> &#8211; we&#8217;ve talked before about what a critical role automation is going to have in managing the rapidly evolving &#8220;dynamic&#8221; data center. Technologies like virtualization and cloud computing needs are pushing out the limits of real-time resources management in the data center; management tools must perform faster, integrate with more solutions across the spectrum of IT infrastructure and be smart enough to do much of this on their own.</p>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:47:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eds">eds</category>
      <category domain="http://securityratty.com/tag/hp-eds">hp-eds</category>
      <category domain="http://securityratty.com/tag/eds ceo">eds ceo</category>
      <category domain="http://securityratty.com/tag/eds profit margin">eds profit margin</category>
      <category domain="http://securityratty.com/tag/margin">margin</category>
      <category domain="http://securityratty.com/tag/dynamic data center">dynamic data center</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/automation tools">automation tools</category>
      <category domain="http://securityratty.com/tag/real-time resources management">real-time resources management</category>
      <source url="http://blog.sciencelogic.com/hp-hires-140000-to-get-rid-of-your-job/08/2008">HP Hires 140,000 to Get Rid of Your Job</source>
    </item>
    <item>
      <title><![CDATA[Went on Vacation - Missed PCI DSS 1.2 :-)]]></title>
      <link>http://securityratty.com/article/669ffcd0a9fc29935f567f47acbda31a</link>
      <guid>http://securityratty.com/article/669ffcd0a9fc29935f567f47acbda31a</guid>
      <description><![CDATA[OMG, I go on vacation for 3 days (pretty much offline) - and I miss pre-release of PCI DSS 1.2
How unfair is that

In any case, I am baaaaaack
About me:...]]></description>
      <content:encoded><![CDATA[OMG, I go on vacation for 3 days (pretty much offline) - and I miss <a href="http://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">pre-release of PCI DSS 1.2.</a><br />How unfair is that? :-)<br /><br />In any case, I am baaaaaack!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bqDeOK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bqDeOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=A38ibK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=A38ibK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=JFATMK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=JFATMK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/371058820" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 04:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/miss pre-release">miss pre-release</category>
      <category domain="http://securityratty.com/tag/vacation">vacation</category>
      <category domain="http://securityratty.com/tag/baaaaaack">baaaaaack</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/omg">omg</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <category domain="http://securityratty.com/tag/pretty">pretty</category>
      <category domain="http://securityratty.com/tag/offline">offline</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/371058820/went-on-vacation-missed-pci-dss-12.html">Went on Vacation - Missed PCI DSS 1.2 :-)</source>
    </item>
    <item>
      <title><![CDATA[EPTS: Proposed Event Processing Definitions, September 20, 2006]]></title>
      <link>http://securityratty.com/article/c90d53785950324b36b55747a92766da</link>
      <guid>http://securityratty.com/article/c90d53785950324b36b55747a92766da</guid>
      <description><![CDATA[For interested readers, here are the event processing definitions we provided to the (future) EPTS working group on September 20, 2006, coordinated (edited)by David Luckham and Roy Schulte
adaptive...]]></description>
      <content:encoded><![CDATA[<p>For interested readers, here are the <a href="http://www.thecepblog.com/pdf/EVENT.PROCESSING.DRAFT.GLOSSARY.V4.SEPT.pdf" target="_blank">event processing definitions</a> we provided to the (future) EPTS working group on September 20, 2006, <a href="http://complexevents.com/?p=195" target="_blank">coordinated (edited) by David Luckham and Roy Schulte</a>;</p>
<p><strong>adaptive process management</strong> (n.) an element of resource and business process management, adaptive search and event processing. Sometimes referred to as “Level 4” event processing or process refinement.</p>
<p><strong>application concept</strong> (n.) a definition of a set of properties that represent the data fields of an application entity. An application concept can describe relationships among themselves. For example, an order concept might have a parent/child relationship with an item concept. A department concept might be related to a purchase requisition concept based on the shared property, department_id. Application concepts can include an application state model.</p>
<p><strong>application state modeler</strong> (n.) a UML-compliant application that allows you to model the life cycle of a concept instance — that is, for each instance of a given concept, you can define which states it will pass through and how it will transition from state to state. States have entry actions, exit actions, and conditions, providing precision control over the behavior of an event processing agent. Transitions between states also may have rules. Multiple types of states and transitions maximize the versatility and power of the application state modeler.</p>
<p><strong>derived event</strong> (n.) an event that is created as a result of processing one or more other events.</p>
<p><strong>complex event</strong> (n.) an event that is a situation-entity abstraction of two or more simple, derived or other complex events.</p>
<p><strong>complex event processing</strong> (n.) CEP is a technology for extracting information from message-based systems. CEP is primarily an event processing concept that deals with the task of processing multiple events from an event cloud with the goal of identifying the meaningful events within the event cloud. CEP employs techniques such as detection of complex patterns of many events, event correlation and abstraction, event hierarchies, and relationships between events such as causality, membership, and timing, and event-driven processes.</p>
<p><strong>event</strong> (n.) a instance of an event definition. It is an immutable object that represents a business activity that happened at a single point in time. Just as one cannot change the fact that a given activity occurred, one cannot change an event — events are immutable.</p>
<p><strong>event aggregation</strong> (n.) the aggregation of simple, derived or complex events into higher levels of event abstractions.</p>
<p><strong>event definition</strong> (n.) a set of properties related to a given activity that represents an important or interesting change of state in a human, system or computational activity. An event definition includes event properties such as event priority, event time to live (TTL), and a description of the payload, which is comprehensive information related to the activity that occurred. Events expire when the TTL has elapsed, unless the event processing agent has instructions to consume them prior to that time.</p>
<p><strong>event channel</strong> (n.) a communications channel in which events are transmitted from event source to event receivers, typically received as electronic messages. Each channel can have multiple destination and. events can be configured to transmit to a default destination. JMS is an example of an event channel.</p>
<p><strong>event cloud</strong> (n.) a partially ordered set of events (poset), either bounded or unbounded, where the partial orderings are imposed by the causal, timing and other relationships between the events. Typically an event cloud is created by the events produced by one or more distributed systems. An event cloud may contain many event types, event streams and event channels. The difference between a cloud and a stream is that there is no event relationship that totally orders the events in a cloud.</p>
<p><strong>event-driven</strong> (n.) the behavior of a human, system or computational entity whose execution or actuation is in response to events, typically received as electronic messages.</p>
<p><strong>event-driven architecture</strong> (n.) an architectural style for distributed computing applications in which some of the components are event-driven and communicate by means of events.</p>
<p><strong>event processing</strong> (n.) computing that performs operations on events, including modifying, creating and destroying events.</p>
<p><strong>event-object</strong> (n.) an software object that represents an event, generally for the purpose of computer processing, that exhibits both encapsulation, inheritance and polymorphism.</p>
<p><strong>event prediction</strong> (n.) computational activity where the impact of events, complex events, and situations caused by events identified, including both opportunity or threat. Sometimes referred to as “Level 2” event processing, impact assessment or predictive analytics.</p>
<p><strong>event pre-processing</strong> (n.) computational activity where events are cleansed or normalized to produce semantically understandable data. Sometimes referred to as “Level 0” event processing.</p>
<p><strong>event processing</strong> (n.) computational activities on events dealing with the association, correlation, and combination of event data and information from single and multiple event sources to achieve refined identity and situation estimates for observed event objects, and to achieve complete and timely assessments of opportunities, threats, and their significance. Event processing is characterized by continuous refinements of event estimates and assessments and by evaluation of the need for additional sources, or modification of the process itself, to achieve improved results.</p>
<p><strong>event processing agent</strong> (n.) an EPA is a computational entity that performs event processing.</p>
<p><strong>event processing network</strong> (n.) a set of event processing agents and a set of event channels connecting them.</p>
<p><strong>event properties</strong> (n.) data representation of an event, typically by name-value pairs of type string, integer, real, boolean or a complex data type.</p>
<p><strong>event refinement</strong> (n.) filter, identify and track events &amp; make initial processing decisions based on association, correlation and state estimation. Sometimes referred to as “Level 1” event, or event-object, track and trace.</p>
<p><strong>event stream</strong> (n.) a time-ordered sequence of events. An event stream may be bounded by a certain time interval or other contextual dimension (content, space, source, certainty), or be open ended and unbounded.</p>
<p><strong>event stream processing</strong> (n.) a time-ordered sequence of events. An event stream may be bounded by a certain time interval or other contextual dimension (content, space, source, certainty), or be open ended and unbounded.</p>
<p><strong>rule</strong> (n.) defines what triggers unusual, suspicious, problematic, or advantageous activity within an event processing agent and what the EPA does when it discovers these types of activities. Rules execute actions based on certain conditions on events, instances, or a combination of both. A rule includes a group of condition-rule statements and action-rule statements. The condition statements instruct the EPA what to look for in events, and action statements instruct the EPA how to respond when conditions are met. If all the conditions in a rule are satisfied by events or instances or both, the EPA fires the actions. The action might be to execute tasks, create an event instance, modify property values in an event instance, create and send an event, or something else.</p>
<p><strong>rules engine</strong> (n.) a type of event processing agent that uses a declarative programming model to process events. Formally described as &#8220;an abstract structure that describes a formal language precisely, i.e., a set of rules that mathematically delineates a (usually infinite) set of finite-length strings over a (usually finite) alphabet“. Informally, it can be any system that uses rules, in any form, that can be applied to data to produce outcomes.</p>
<p><strong>rule language</strong> (n.) is an artificial language that is used to control the behavior of an event processing agent. Rules languages, like human languages, have syntactic and semantic rules to define meaning.</p>
<p><strong>situation refinement</strong> (n.) identify situations, or complex events, based on event clustering, event-event relationships and relationship analysis and context. Sometimes referred to as “Level 2” event processing.</p>
<p><strong>simple event</strong> (n.) an event that is not an abstraction or composition of other events.</p>
<p><strong>virtual event</strong> (n.) an event that is imagined, modeled or simulated.</p>
<hr />Note:  The Emerging Technologies Engineering Team at <a href="http://www.tibco.com" target="_blank">TIBCO Software </a>significantly contributed to these event processing terms and definitions.</p>
]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 01:47:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event-object">event-object</category>
      <category domain="http://securityratty.com/tag/business process management">business process management</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/event correlation">event correlation</category>
      <category domain="http://securityratty.com/tag/process refinement">process refinement</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/simple event">simple event</category>
      <category domain="http://securityratty.com/tag/process events">process events</category>
      <source url="http://www.thecepblog.com/2008/08/21/epts-proposed-event-processing-definitions-september-20-2006/">EPTS: Proposed Event Processing Definitions, September 20, 2006</source>
    </item>
    <item>
      <title><![CDATA[The Secret Sauce is the Situation Models]]></title>
      <link>http://securityratty.com/article/e137f84c371e05c9a9841a0cc1ff27ec</link>
      <guid>http://securityratty.com/article/e137f84c371e05c9a9841a0cc1ff27ec</guid>
      <description><![CDATA[AlanLundberg wrote, Intelligent Business Process Platform? in response to Bringing Order to Chaos where someone from PWC linked event processing to business intelligence and business process...]]></description>
      <content:encoded><![CDATA[<p>Alan Lundberg wrote, <a href="http://tibcoblogs.com/cep/2008/08/04/intelligent-business-process-platform/">Intelligent Business Process Platform?</a> in response to <a href="http://www.pwc.com/extweb/home.nsf/docid/FB2EF3AC6E351ECC8525746B00676021" target="_blank">Bringing Order to Chaos</a> where someone from PWC linked event processing to business intelligence and business process management.  In turn, James Taylor penned <a href="http://smartenoughsystems.com/wp/2008/08/05/using-decision-management-to-deliver-intelligent-business-performance/">Using decision management to deliver intelligent business performance</a> where James rightly said that it does not require &#8220;heroic efforts&#8221; to integrate event processing, BI, BPM and other decision support tools.  </p>
<p>As a reference, you may have seen this briefing, one of many where I show these functional relationships, <a href="http://debs.msrg.utoronto.ca/bass.pdf">Mythbusters: Event Stream Processing Versus Complex Event Processing</a>, from DEBS2007.  For example slide 23 shows the functional relationship between events, pre-processing, event tracking, situational detection, historical patterns (the output of BI tools, for example), visualization and business process management.</p>
<p>In <a href="http://rvsoapbox.blogspot.com/2008/08/faithful-representation.html" target="_blank">Faithful Representation</a>, Richard Veryard reminds his readers that the most challenging part is in the situation models (not the system integration).  Unfortunately, by accident, Richard incorrectly attributes Opher Etzion&#8217;s &#8220;first order situation model approximation&#8221; to both Opher and I in this quote from Richard&#8217;s post, <em>&#8220;a simple situation model of complex events, in which events (including derived, composite and complex events) represent the &#8220;situation&#8221;.    </em></p>
<p>Actually, that simple situation model above is Opher&#8217;s, not mine.  I have offered a more general and comprehensive (first draft) situation model, in <a title="A Simple Situation Model for Complex Events" rel="bookmark" href="http://www.thecepblog.com/2008/07/15/a-simple-situation-model-for-complex-events/">A Simple Situation Model for Complex Events</a> based on a cognitive situation model used by <a href="http://www.nd.edu/~memory/theory.html" target="_blank">researchers at the University of Notre Dame</a>.  I do not believe that complex events and situations can be modelled accurately using Opher&#8217;s simple model of <em>derived, composite and complex events.   </em>This model is overly simple, in my opinion. to represent the vast majority of CEP classes of problems, perhaps explaining why Opher and I do not agree on the state-of-the-art of CEP.  Opher tends to view CEP as mostly an extension of active database technology where I see CEP as a technology that is much more closely aligned with the cognitive models represented in the <a href="http://www.thecepblog.com/what-is-complex-event-processing/" target="_blank">art-and-science of multi-sensor data fusion (MSDF).</a>  </p>
<p>Complex events represent situations, and situations must be accurately modelled if we are going to accurately detect them in real-time.  If your business cannot model a complex event (situation) then it does not matter what software you buy, how much money you spend, or what event processing and integration platform you use.   The models are hard.  The system integration is relatively easy.</p>
<p>The secret sauce is the situation and complex event models.</p>
<p>As mentioned here a few times, it does not matter how fast you process events in real-time, if your model is wrong, you just detect the wrong thing very fast.  This is very bad and quite dangerous.  You will make bad decisions fast.  You will waste time, money and resources.</p>
<p>This is why CEP benchmarks should be based on accuracy in situation detection, not in latency and other low-level performance metrics.   First, get the models right; then refine to detect faster, if speed is required.   What has happened in CEP to date, is that the models are so simple, they do not really detect complex events, they just process and act on simple events that are easy to model. </p>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 06:23:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/situation">situation</category>
      <category domain="http://securityratty.com/tag/situation detection">situation detection</category>
      <category domain="http://securityratty.com/tag/cognitive situation model">cognitive situation model</category>
      <category domain="http://securityratty.com/tag/simple situation model">simple situation model</category>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/situation models">situation models</category>
      <category domain="http://securityratty.com/tag/situation model approximation">situation model approximation</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/complex events based">complex events based</category>
      <source url="http://www.thecepblog.com/2008/08/09/the-secret-sauce-is-the-situation-models/">The Secret Sauce is the Situation Models</source>
    </item>
    <item>
      <title><![CDATA[Pedal to the metal NAC]]></title>
      <link>http://securityratty.com/article/7521a3b0531ce4d781c478df46961baf</link>
      <guid>http://securityratty.com/article/7521a3b0531ce4d781c478df46961baf</guid>
      <description><![CDATA[OK, I am not really a big car racing fan. I dont know, Long Island was not a NASCAR hot bed. Of course the Indy 500 was always big news. In any event I have become much more of a race fan since Chip...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>OK, I am not really a big car racing fan.&nbsp; I don’t know, Long Island was not a NASCAR hot bed. Of course the Indy 500 was always big news.&nbsp; In any event I have become much more of a race fan since Chip Ganassi racing became a StillSecure customer.&nbsp; They are using a complete NAC solution that performs both pre and post connect testing. Racing today is not about some gearheads putting in spark plugs and changing tires.&nbsp; It is high, hi-tech and their information security needs to protect their IP are high priority.&nbsp; </p>

<p>Rather than the usual case study, our VP of marketing Jayson Ayers actually tried something new.&nbsp; A video case study is what we have done.&nbsp; I think it is pretty cool and in the spirit of the YouTube generation, am embedding it here.&nbsp; You can read more about this <a href="http://www.stillsecure.com/library/case_studies/ganassi.php">on our site here</a>.</p>

<table cellspacing="0" cellpadding="2" width="400" border="0"><tbody><tr><td valign="top" width="200"><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/image.png"><img title="image" height="346" alt="image" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/image_thumb.png" width="274" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a> </td>

<td valign="top" width="200"><embed src="http://www.youtube.com/v/cTNNDnXPkUo&amp;hl=en&amp;fs=1" width="425" height="344" type="application/x-shockwave-flash" allowfullscreen="true"></embed></td></tr></tbody></table></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=tRam5k"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=tRam5k" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=7ARydK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=7ARydK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LIqnKK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LIqnKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=VIW8dK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=VIW8dK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=jLzWYK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=jLzWYK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JRWh9k"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JRWh9k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=gDfMWk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=gDfMWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/359748366" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 12:01:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fan">fan</category>
      <category domain="http://securityratty.com/tag/race fan">race fan</category>
      <category domain="http://securityratty.com/tag/nascar hot bed">nascar hot bed</category>
      <category domain="http://securityratty.com/tag/complete nac solution">complete nac solution</category>
      <category domain="http://securityratty.com/tag/stillsecure customer">stillsecure customer</category>
      <category domain="http://securityratty.com/tag/youtube generation">youtube generation</category>
      <category domain="http://securityratty.com/tag/jayson ayers">jayson ayers</category>
      <category domain="http://securityratty.com/tag/study">study</category>
      <category domain="http://securityratty.com/tag/chip ganassi">chip ganassi</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/359748366/pedal-to-the-me.html">Pedal to the metal NAC</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[As They Say: When in Rome, Do as the Romans.]]></title>
      <link>http://securityratty.com/article/624f835f95a4530197ae74e67f88feb4</link>
      <guid>http://securityratty.com/article/624f835f95a4530197ae74e67f88feb4</guid>
      <description><![CDATA[Recently I had a nice conversation with the head of Asia-Pacific of an international company about how to succeed in Thailand. I explained how businesses in Thailand do not respond well to companies...]]></description>
      <content:encoded><![CDATA[<p>Recently I had a nice conversation with the head of Asia-Pacific of an international company about how to succeed in Thailand.   I explained how businesses in Thailand do not respond well to companies that come to Thailand with no experience, track record or support infrastructure here in the Kingdom.  I also explained how Thailand has a strong cultural tradition around &#8220;the teacher culture,&#8221; where teachers are considered much higher than mere consultants and integrators.</p>
<p>The conversation went well, I thought, until I received a call from another person in the company who proceeded to tell me how to do business in Thailand and how to determine the target market, and how to set up sales.   Now mind you, I had already explained that there would be no immediate sales opportunities for a few years, realistically, and that this was a long term initiative, designed around a solid education and training program - build infrastructure first.  From a strong education and training program, the market would become clear.</p>
<p>This is such a simple win-win-win situation, but companies do not seem to understand it.  They just want to exploit every contact, event situation, for a quarterly sell.   Why not take the long view as well, since it does not cost you any money?</p>
<p>The guy on the other end of the phone would have nothing to do with our way of thinking in Thailand.  He seemed to be  pushing to insure pre-sales contact immediately.   Instead of supporting us, he wanted to manage us from overseas!!  We asked for support to build their brand, what they seemed to offer was management by proxy!</p>
<p>Folks, this will not work in Thailand (or most Asia countries).</p>
<p>If you want to tap into the fast growing Asia market, leave behind your aggressive New York or Silicon Valley sales guns and forceful presale tactics, where you are content to find an opening, exploit it, make a sale, and report the sale on your quarterly report.  You can get aggressive when you have built a sustainable infrastructure.   The same is true in Japan, not only Thailand.</p>
<p>In Asia, do as the Asians.  In Rome, do as the Romans.  In Thailand, do as the Thais.  In Japan, do as the Japanese.</p>
<p>It is easy to make money in Thailand (and other Asia countries) if you follow their way of business.   Educate, teach, build a workforce, build a sustainable infrastructure on the ground, and then sell, sell, sell.</p>
<p>Granted, many companies do not have  resources to do this overseas.  In that case, enable your partners to do it and let them build the business; don&#8217;t manage them, support them.</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 06:19:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asia">asia</category>
      <category domain="http://securityratty.com/tag/asia market">asia market</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/support infrastructure">support infrastructure</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/asia countries">asia countries</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/sustainable infrastructure">sustainable infrastructure</category>
      <source url="http://www.thecepblog.com/2008/08/07/as-they-say-when-in-rome-do-as-the-romans/">As They Say: When in Rome, Do as the Romans.</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Simulating Email in .NET]]></title>
      <link>http://securityratty.com/article/0c454dbe28b5b63d07ee0089e019de77</link>
      <guid>http://securityratty.com/article/0c454dbe28b5b63d07ee0089e019de77</guid>
      <description><![CDATA[I use email as a notification mechanism a lot, and often in class I'll demo sending email via a technique that I use frequently when developing code. It allows you to simulate sending an email...]]></description>
      <content:encoded><![CDATA[<p>I use email as a notification mechanism a lot, and often in class I&#39;ll demo sending email via a technique that I use frequently when developing code. It allows you to simulate sending an email message.</p> <p>The trick to doing this is not to hardcode things like host, port, etc. for your SMTP server when you use System.Net.Mail to send mail. Instead, use the default ctor for <a href="http://msdn.microsoft.com/en-us/library/system.net.mail.smtpclient.aspx" target="_blank">SmtpClient</a> as I&#39;ve done in the code below.</p> <blockquote><pre class="csharpcode"><span class="kwrd">static</span> <span class="kwrd">void</span> Main(<span class="kwrd">string</span>[] args)
{
    <span class="rem">// note the use of the MailAddress class</span>
    <span class="rem">// this allows me to specify display names as well as email addresses</span>
    MailAddress from = <span class="kwrd">new</span> MailAddress(<span class="str">&quot;admin@fabrikam.com&quot;</span>, <span class="str">&quot;Fabrikam Website&quot;</span>);
    MailAddress to = <span class="kwrd">new</span> MailAddress(<span class="str">&quot;mari@fabrikam.com&quot;</span>, <span class="str">&quot;Mari Joyce&quot;</span>);

    MailMessage msg = <span class="kwrd">new</span> MailMessage(from, to);
    msg.Subject  = <span class="str">&quot;Testing 123&quot;</span>;
    msg.Body = <span class="str">&quot;This is only a test!&quot;</span>;

    <span class="rem">// note use of default ctor</span>
    <span class="rem">// this looks in config to figure out how to send mail</span>
    <span class="kwrd">new</span> SmtpClient().Send(msg);
}</pre></blockquote>
.csharpcode, .csharpcode pre
{
	font-size: small;
	color: black;
	font-family: consolas, &quot;Courier New&quot;, courier, monospace;
	background-color: #ffffff;
	/*white-space: pre;*/
}
.csharpcode pre { margin: 0em; }
.csharpcode .rem { color: #008000; }
.csharpcode .kwrd { color: #0000ff; }
.csharpcode .str { color: #006080; }
.csharpcode .op { color: #0000c0; }
.csharpcode .preproc { color: #cc6633; }
.csharpcode .asp { background-color: #ffff00; }
.csharpcode .html { color: #800000; }
.csharpcode .attr { color: #ff0000; }
.csharpcode .alt 
{
	background-color: #f4f4f4;
	width: 100%;
	margin: 0em;
}
.csharpcode .lnum { color: #606060; }


<p>What you&#39;re telling .NET by using the default ctor for SmtpClient is, &quot;please use my config file to figure out how to send mail&quot;. Now you can use the system.net/mailSettings/smtp section in config to specify the details of your mail server, and all of the code in your app that is written to use the default SmtpClient ctor will inherit these settings. Here&#39;s an example of what the config on a production server might look like (if you put passwords in your config files, be sure to <a href="http://msdn.microsoft.com/en-us/library/ms998283.aspx" target="_blank">encrypt those sections</a>): </p><pre class="csharpcode"><span class="kwrd">&lt;</span><span class="html">configuration</span><span class="kwrd">&gt;</span>
  <span class="kwrd">&lt;</span><span class="html">system.net</span><span class="kwrd">&gt;</span>
    <span class="kwrd">&lt;</span><span class="html">mailSettings</span><span class="kwrd">&gt;</span>
      <span class="kwrd">&lt;</span><span class="html">smtp</span> <span class="attr">deliveryMethod</span><span class="kwrd">=&quot;Network&quot;</span><span class="kwrd">&gt;</span>
        <span class="kwrd">&lt;</span><span class="html">network</span> <span class="attr">host</span><span class="kwrd">=&quot;mail.fabrikam.com&quot;</span>
                 <span class="attr">port</span><span class="kwrd">=&quot;25&quot;</span>
                 <span class="attr">userName</span><span class="kwrd">=&quot;WebsiteMailAccount&quot;</span>
                 <span class="attr">password</span><span class="kwrd">=&quot;whatever&quot;</span><span class="kwrd">/&gt;</span>
      <span class="kwrd">&lt;/</span><span class="html">smtp</span><span class="kwrd">&gt;</span>
    <span class="kwrd">&lt;/</span><span class="html">mailSettings</span><span class="kwrd">&gt;</span>
  <span class="kwrd">&lt;/</span><span class="html">system.net</span><span class="kwrd">&gt;</span>
<span class="kwrd">&lt;/</span><span class="html">configuration</span><span class="kwrd">&gt;</span></pre><pre class="csharpcode">&nbsp;</pre>
.csharpcode, .csharpcode pre
{
	font-size: small;
	color: black;
	font-family: consolas, &quot;Courier New&quot;, courier, monospace;
	background-color: #ffffff;
	/*white-space: pre;*/
}
.csharpcode pre { margin: 0em; }
.csharpcode .rem { color: #008000; }
.csharpcode .kwrd { color: #0000ff; }
.csharpcode .str { color: #006080; }
.csharpcode .op { color: #0000c0; }
.csharpcode .preproc { color: #cc6633; }
.csharpcode .asp { background-color: #ffff00; }
.csharpcode .html { color: #800000; }
.csharpcode .attr { color: #ff0000; }
.csharpcode .alt 
{
	background-color: #f4f4f4;
	width: 100%;
	margin: 0em;
}
.csharpcode .lnum { color: #606060; }


<p>During development, I use different settings because I don&#39;t usually want to deal with the hassle of installing an SMTP server on my development box. Instead, I want email messages delivered as individual files in a directory on my hard drive (I always have a c:\mail directory on my development box for just this purpose):</p>
<blockquote><pre class="csharpcode"><span class="kwrd">&lt;</span><span class="html">configuration</span><span class="kwrd">&gt;</span>
  <span class="kwrd">&lt;</span><span class="html">system.net</span><span class="kwrd">&gt;</span>
    <span class="kwrd">&lt;</span><span class="html">mailSettings</span><span class="kwrd">&gt;</span>
      <span class="kwrd">&lt;</span><span class="html">smtp</span> <span class="attr">deliveryMethod</span><span class="kwrd">=&quot;SpecifiedPickupDirectory&quot;</span><span class="kwrd">&gt;</span>
        <span class="kwrd">&lt;</span><span class="html">specifiedPickupDirectory</span> <span class="attr">pickupDirectoryLocation</span><span class="kwrd">=&quot;c:\mail&quot;</span><span class="kwrd">/&gt;</span>
      <span class="kwrd">&lt;/</span><span class="html">smtp</span><span class="kwrd">&gt;</span>
    <span class="kwrd">&lt;/</span><span class="html">mailSettings</span><span class="kwrd">&gt;</span>
  <span class="kwrd">&lt;/</span><span class="html">system.net</span><span class="kwrd">&gt;</span>
<span class="kwrd">&lt;/</span><span class="html">configuration</span><span class="kwrd">&gt;</span></pre></blockquote>
.csharpcode, .csharpcode pre
{
	font-size: small;
	color: black;
	font-family: consolas, &quot;Courier New&quot;, courier, monospace;
	background-color: #ffffff;
	/*white-space: pre;*/
}
.csharpcode pre { margin: 0em; }
.csharpcode .rem { color: #008000; }
.csharpcode .kwrd { color: #0000ff; }
.csharpcode .str { color: #006080; }
.csharpcode .op { color: #0000c0; }
.csharpcode .preproc { color: #cc6633; }
.csharpcode .asp { background-color: #ffff00; }
.csharpcode .html { color: #800000; }
.csharpcode .attr { color: #ff0000; }
.csharpcode .alt 
{
	background-color: #f4f4f4;
	width: 100%;
	margin: 0em;
}
.csharpcode .lnum { color: #606060; }


<p>Now when I run the program above, I get a .EML file in my c:\mail directory:</p>
<p><a href="http://www.pluralsight.com/community/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/keith/image_5F00_2.png"><img style="border-right:0px;border-top:0px;margin:0px 0px 0px 35px;border-left:0px;border-bottom:0px;" height="230" alt="image" src="http://www.pluralsight.com/community/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/keith/image_5F00_thumb.png" width="404" border="0" /></a> </p>
<p>Outlook Express is normally registered as the viewer for .EML files, so double-click the file to view it:</p>
<p><a href="http://www.pluralsight.com/community/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/keith/image_5F00_4.png"><img style="border-right:0px;border-top:0px;margin:0px 0px 0px 35px;border-left:0px;border-bottom:0px;" height="287" alt="image" src="http://www.pluralsight.com/community/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/keith/image_5F00_thumb_5F00_1.png" width="292" border="0" /></a> </p>
<p>If you&#39;ve never seen this method of simulating email before, I hope you find it as useful as I have. Happy coding!</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=52305" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 09:59:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csharpcode pre">csharpcode pre</category>
      <category domain="http://securityratty.com/tag/pre">pre</category>
      <category domain="http://securityratty.com/tag/csharpcode">csharpcode</category>
      <category domain="http://securityratty.com/tag/color">color</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email addresses mailaddress">email addresses mailaddress</category>
      <category domain="http://securityratty.com/tag/mailaddress">mailaddress</category>
      <category domain="http://securityratty.com/tag/mail server">mail server</category>
      <category domain="http://securityratty.com/tag/mail">mail</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/08/01/simulating-email-in-net.aspx">Simulating Email in .NET</source>
    </item>
  </channel>
</rss>
