<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ratings]]></title>
    <link>http://securityratty.com/tag/ratings</link>
    <description></description>
    <pubDate>Wed, 14 May 2008 19:04:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Microsoft: First exploit ratings show success]]></title>
      <link>http://securityratty.com/article/dffc7515c546b02b5835629983298e8c</link>
      <guid>http://securityratty.com/article/dffc7515c546b02b5835629983298e8c</guid>
      <description><![CDATA[Microsoft was eight for 20 in its first predictions of how exploitable the flaws in its software would be. But that was good enough for the company to claim...]]></description>
      <content:encoded><![CDATA[Microsoft was eight for 20 in its first predictions of how exploitable the flaws in its software would be. But that was good enough for the company to claim success.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:677335ca695d8dab7c18daa3b9354977:d1UL7LceTDW%2F0EozAMVJPzDry11oJVWQC49nNTsT6MVXDkjYcHOSlGNmOqz9cLdKy%2BV0TNzkj5Kq'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b7e3c8117a11c0df75f3a07dce98a666:i5B8UCWRWH4lgIvfnHanuptZLpepIjHmOC5I%2BOIDfusUqQK7xtoJh9DzBLx9zZpCaLe76tZohRoXoQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:982e134d1a2d4bd9e7edc5db9a2f7f80:pvM3N%2Bd8YaFUJvFhFxcpE7aDbsmvFYTziDQyKBmPSY%2F2%2FR7JBgMrS5vroPYlyT76e9uDTctZHmXnWQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bb03914e8ddad04911bbb3cc210e266a:zKMz80LZtdhMGeMp5Brde6yI0GsA53vKsKK4AopL%2BFPBo8dPftH7%2BfwjnykmsGZp4ze0IrF4ntbwQA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=55d8b06ec75e5b6ec9677f92803b6d3e" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=55d8b06ec75e5b6ec9677f92803b6d3e" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/claim success">claim success</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/predictions">predictions</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/exploitable">exploitable</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=55d8b06ec75e5b6ec9677f92803b6d3e">Microsoft: First exploit ratings show success</source>
    </item>
    <item>
      <title><![CDATA[Our Blog Got High Ratings!]]></title>
      <link>http://securityratty.com/article/04908bcab882d6b41dfd29f0edaf1e89</link>
      <guid>http://securityratty.com/article/04908bcab882d6b41dfd29f0edaf1e89</guid>
      <description><![CDATA[Tooting our own horn on Monday morning, the excellent Thinking Problem Management blog gave us their coveted 5 pineapple rating

In your face, RISKS...]]></description>
      <content:encoded><![CDATA[<p>Tooting our own horn on Monday morning, the excellent <em><strong>Thinking Problem Management</strong></em> blog gave us their <strong><a href=" http://thinkingproblemmanagement.blogspot.com/2008/10/blogs-that-rock-october-2008.html">coveted &#8220;5 pineapple&#8221; rating!</a> </strong></p>
<p><img class="alignnone" title="Pineapples With Sunglasses" src="http://1.bp.blogspot.com/_AVODjjM-COk/SPIXUQQXGLI/AAAAAAAAIKg/SHOqWZKa9rk/s400/5pis.jpg" alt="" width="400" height="101" /></p>
<p>In your face, RISKS Digest! <img src='http://riskmanagementinsight.com/riskanalysis/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 11:02:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management blog">management blog</category>
      <category domain="http://securityratty.com/tag/risks">risks</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <category domain="http://securityratty.com/tag/pineapple">pineapple</category>
      <category domain="http://securityratty.com/tag/excellent">excellent</category>
      <category domain="http://securityratty.com/tag/horn">horn</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=482">Our Blog Got High Ratings!</source>
    </item>
    <item>
      <title><![CDATA[Wot? No I said What! Wot?]]></title>
      <link>http://securityratty.com/article/eab31d880a38c85be552b249bd88837c</link>
      <guid>http://securityratty.com/article/eab31d880a38c85be552b249bd88837c</guid>
      <description><![CDATA[OK, its my Clip, Ill write what I wanna. Came across this review of Wot at Webtoolsandtips.com this morning. This addon seems to have great reviews, Give it a look at their site


clipped from...]]></description>
      <content:encoded><![CDATA[<div > OK, its my Clip, I&#8217;ll write what I wanna.<br/>Came across this review of Wot at Webtoolsandtips.com this morning.<br/>This addon seems to have great reviews,<br/>Give it a look at their site. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/6EA8B9FC-76E9-4334-A96C-A380C5AEF85E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/b1bd3498-a992-4b18-8c15-87c2fba5fa3e/6EA8B9FC-76E9-4334-A96C-A380C5AEF85E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="https://addons.mozilla.org/en-US/firefox/addons/versions/3456#version-20080917" href="https://addons.mozilla.org/en-US/firefox/addons/versions/3456#version-20080917" style="font-size: 11px;">addons.mozilla.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: https://addons.mozilla.org/en-US/firefox/addons/versions/3456#version-20080917 --><H3 class="name"><IMG alt="" class="addon-icon" src="https://addons.mozilla.org/en-US/firefox/images/addon_icon/3456/1221571804" />WOT 20080917</H3></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: https://addons.mozilla.org/en-US/firefox/addons/versions/3456#version-20080917 --><P class="desc">WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT&#8217;s color-coded icons show you ratings for 20 million websites - green to go, yellow for caution and red to stop – helping you avoid the dangerous sites. Surf safer and add WOT to your Firefox now. </P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/6EA8B9FC-76E9-4334-A96C-A380C5AEF85E/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_260908035935"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=260908035935&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=260908035935&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=260908035935&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_260908035935" /></a></P>]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:59:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wot">wot</category>
      <category domain="http://securityratty.com/tag/deliver malware">deliver malware</category>
      <category domain="http://securityratty.com/tag/surf safer">surf safer</category>
      <category domain="http://securityratty.com/tag/risky websites">risky websites</category>
      <category domain="http://securityratty.com/tag/scam visitors">scam visitors</category>
      <category domain="http://securityratty.com/tag/front-line layer">front-line layer</category>
      <category domain="http://securityratty.com/tag/online threats">online threats</category>
      <category domain="http://securityratty.com/tag/dangerous sites">dangerous sites</category>
      <category domain="http://securityratty.com/tag/unfamiliar territory">unfamiliar territory</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=629">Wot? No I said What! Wot?</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Holy Media Codecs, Batman!]]></title>
      <link>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</link>
      <guid>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</guid>
      <description><![CDATA[Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the Zango / Dark Knight issue still rattling around my...]]></description>
      <content:encoded><![CDATA[
        Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">Zango / Dark Knight issue</a> still rattling around my brain) I thought it would be fun to see exactly how quickly it can all go wrong when looking for Dark Knight material online.<br /><br />The answer is: extremely quickly.<br /><br />There's a lot of sites out there claiming to carry "full versions" of The Dark Knight, and although they don't offer Zango, they <i>do</i> offer fake media codecs (which usually do all sorts of horrible things to a computer). Let's pull one of these sites apart as an example of how the scam fits together.<br /><br />Here's a typical site pushing what they claim to be The Dark Knight:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman000.html" onclick="window.open('http://blog.spywareguide.com/images/dbman000.html','popup','width=717,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman000-thumb-317x249.jpg" alt="dbman000.jpg" class="mt-image-none" style="" height="249" width="317" /></a></span><br />Click to Enlarge<br /></div><br />Dijgg(dot)com, an obvious Digg.com knockoff apparently hosting a large streaming window - the movie quality will be awesome, won't it? Well, actually, no it won't.<br /><br />In the middle of the video window is a popup:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0.jpg" src="http://blog.spywareguide.com/images/dbman0.jpg" class="mt-image-none" style="" height="145" width="399" /></span></div><br /><br /> <div>Install the "codec", and this won't end well. The EXE comes from a site called Favoritetube(dot)com:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman1.jpg" src="http://blog.spywareguide.com/images/dbman1.jpg" class="mt-image-none" style="" height="203" width="348" /></span></div><br /><br />A quick check for the <a href="http://www.siteadvisor.com/sites/favoritetube.net/postid?p=1063293">safety</a> <a href="http://safeweb.norton.com/report/show?name=favoritetube.net">ratings</a> of that website should be enough to tell you this is a scam. Indeed, there isn't even a movie being streamed here (despite it saying "Connecting" at the bottom of the movie player) - because if you right click on the player itself:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0000.jpg" src="http://blog.spywareguide.com/images/dbman0000.jpg" class="mt-image-none" style="" height="370" width="418" /></span></div><br /></div><div><br />You can see the "player" is actually just a static image (because I'm given the option to "Copy Image Location"). The image is hosted at Favoritetube, just like the "codecs":<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman2.html" onclick="window.open('http://blog.spywareguide.com/images/dbman2.html','popup','width=655,height=570,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman2-thumb-355x308.jpg" alt="dbman2.jpg" class="mt-image-none" style="" height="308" width="355" /></a></span><br /><br />Click to Enlarge<br /></div><br />There are quite a lot of these sites floating around out there at present:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman3.html" onclick="window.open('http://blog.spywareguide.com/images/dbman3.html','popup','width=738,height=532,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman3-thumb-338x243.jpg" alt="dbman3.jpg" class="mt-image-none" style="" height="243" width="338" /></a></span><br /><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman4.html" onclick="window.open('http://blog.spywareguide.com/images/dbman4.html','popup','width=599,height=533,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman4-thumb-399x355.jpg" alt="dbman4.jpg" class="mt-image-none" style="" height="355" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman100.html" onclick="window.open('http://blog.spywareguide.com/images/dbman100.html','popup','width=625,height=516,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman100-thumb-325x268.jpg" alt="dbman100.jpg" class="mt-image-none" style="" height="268" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />At this point, it's a given that I'm going to show you what happens if you install one of the files typically pushed from the above sites, right? Well, wait no longer - this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman7.jpg" src="http://blog.spywareguide.com/images/dbman7.jpg" class="mt-image-none" style="" height="81" width="84" /></span></div><br /></div><div><br />...will deposit a rogue antispyware tool on your desktop (one of more more obnoxious ones that refuses to leave you alone):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/antispycheck1.html" onclick="window.open('http://blog.spywareguide.com/images/antispycheck1.html','popup','width=877,height=668,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/antispycheck1-thumb-377x287.jpg" alt="antispycheck1.jpg" class="mt-image-none" style="" height="287" width="377" /></a></span><br /><br />Click to Enlarge<br /></div><br />Strange and annoying icons will start to creep across your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman8.jpg" src="http://blog.spywareguide.com/images/dbman8.jpg" class="mt-image-none" style="" height="82" width="245" /></span></div><br /></div><div><br />....and you'll have more fake system alerts than you can shake a very large stick at:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="antispycheck22.jpg" src="http://blog.spywareguide.com/images/antispycheck22.jpg" class="mt-image-none" style="" height="304" width="273" /></span></div><br /><br />This concludes my public safety announcement. I'm off to see Dark Knight again...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dark knight issue">dark knight issue</category>
      <category domain="http://securityratty.com/tag/dark knight">dark knight</category>
      <category domain="http://securityratty.com/tag/movie player">movie player</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/image">image</category>
      <category domain="http://securityratty.com/tag/copy image location">copy image location</category>
      <category domain="http://securityratty.com/tag/movie">movie</category>
      <source url="http://blog.spywareguide.com/2008/08/holy-media-codecs-batman.html">Holy Media Codecs, Batman!</source>
    </item>
    <item>
      <title><![CDATA[Is Your Firewall a High Risk Entity]]></title>
      <link>http://securityratty.com/article/b83df16599a33872ec0881b1127c5aed</link>
      <guid>http://securityratty.com/article/b83df16599a33872ec0881b1127c5aed</guid>
      <description><![CDATA[Not trying to be overly snarky here, but I was reviewing some GRC product literature recently. And there was a screenshot of an application window showing how the software helps identify high risk...]]></description>
      <content:encoded><![CDATA[<p>Not trying to be overly snarky here, but I was reviewing some GRC product literature recently.  And there was a screenshot of an application window showing how the software helps identify &#8220;high risk entities&#8221;.  And in the screenshot, there were 5 of these entities listed, each with corresponding risk ratings (High/Medium/Low) and scores (really just non-measurement ordinal numbers).  The screenshot showed that the riskiest entity of the five shown was a Checkpoint Firewall-an assertion backed up by the non-measurement &#8220;Risk Score&#8221;.  The lowest risk scores were shared by a nameless Web Application and an entity called &#8220;Oracle App&#8221;.</p>
<p>My friend, I&#8217;m going to give you a hint.  If your firewall is &#8220;high risk&#8221; and your actual business applications are &#8220;low risk&#8221; - you might be doing it wrong.</p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 11:15:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/non-measurement risk score">non-measurement risk score</category>
      <category domain="http://securityratty.com/tag/low risk">low risk</category>
      <category domain="http://securityratty.com/tag/risk entities">risk entities</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <category domain="http://securityratty.com/tag/risk scores">risk scores</category>
      <category domain="http://securityratty.com/tag/checkpoint firewall-an assertion">checkpoint firewall-an assertion</category>
      <category domain="http://securityratty.com/tag/entity">entity</category>
      <category domain="http://securityratty.com/tag/actual business applications">actual business applications</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=383">Is Your Firewall a High Risk Entity</source>
    </item>
    <item>
      <title><![CDATA[The top 10 celebrity spammers]]></title>
      <link>http://securityratty.com/article/82b1840db975b13b6c3647912d0b50dc</link>
      <guid>http://securityratty.com/article/82b1840db975b13b6c3647912d0b50dc</guid>
      <description><![CDATA[No one will deny the global celebrity of Angelina Jolie. She's on the cover of magazines, stars in blockbuster movies and is a ratings bonanza each time she appears on TV. Now that she's had twins,...]]></description>
      <content:encoded><![CDATA[No one will deny the global celebrity of Angelina Jolie. She's on the cover of magazines, stars in blockbuster movies and is a ratings bonanza each time she appears on TV. Now that she's had twins, she's got triple the appeal for some fans.]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/angelina jolie">angelina jolie</category>
      <category domain="http://securityratty.com/tag/blockbuster movies">blockbuster movies</category>
      <category domain="http://securityratty.com/tag/global celebrity">global celebrity</category>
      <category domain="http://securityratty.com/tag/ratings bonanza">ratings bonanza</category>
      <category domain="http://securityratty.com/tag/stars">stars</category>
      <category domain="http://securityratty.com/tag/appeal">appeal</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/twins">twins</category>
      <category domain="http://securityratty.com/tag/deny">deny</category>
      <source url="http://www.networkworld.com/news/2008/080608-the-top-10-celebrity.html?fsrc=rss-security">The top 10 celebrity spammers</source>
    </item>
    <item>
      <title><![CDATA[McAfee's Site Advisor Blocking n.runs AG - "for starters"]]></title>
      <link>http://securityratty.com/article/980eb4d1bd34b658bcb6d139b3d762f1</link>
      <guid>http://securityratty.com/article/980eb4d1bd34b658bcb6d139b3d762f1</guid>
      <description><![CDATA[Following the recent, and now fixed false positive blocking sans.org due to the already considered malicious dshield.org and giac.org it's also interesting to note that n.runs AG ( nruns.com ), whose...]]></description>
      <content:encoded><![CDATA[<div class="" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SJHp1ZiyMHI/AAAAAAAAB-8/ALBebqDtrl0/s1600-h/nruns_siteadvisor_false.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJHp1ZiyMHI/AAAAAAAAB-8/1_qCXyFB8b8/s200-R/nruns_siteadvisor_false.bmp" style="border: 0pt none ;" /></a>Following the recent, and now fixed <a href="http://isc.sans.org/diary.html?storyid=4799">false positive blocking sans.org</a> due to the already considered malicious <b>dshield.org</b> and <b>giac.org</b> it's also interesting to note that n.runs AG (<b>nruns.com</b>), whose <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">research into vulnerabilities in antivirus products</a> received a lot of attention lately, is also flagged as <a href="http://www.siteadvisor.com/sites/nruns.com/downloads/15713425/">a dangerous site</a>.</div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"><br />
Excluding the conspiracy theories, a false positive when your solution is integrated in the second most popular search engine is bad, especially when other <a href="http://www.google.com/safebrowsing/diagnostic?site=nruns.com">automated crawling approaches</a> are successfully detecting the site as a non-malicious one. How come? It's all a matter of how you define malicious activity, and what exactly are you trying to protect your users from.<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJMiqmiaOxI/AAAAAAAAB_M/T74a9Ztjt8U/s1600-h/invisiblethings_siteadvisor.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJMiqmiaOxI/AAAAAAAAB_M/JtWk3WVLlug/s200-R/invisiblethings_siteadvisor.bmp" style="border: 0pt none ;" /></a>In this case, Site Advisor seems to be trying to protect the end user from herself, but flagging sites hosting some sort of hacking/pen-testing tool in a clear directory structure, since SiteAdvisor isn't capable of automatically flagging a SQL injected site as a malicious one, the approach it takes for assessing whether or not a specific site is malicious is flawed, namely integrating McAfee's signatures based malware database and flagging a site hosting anything detected as malware as a badware site itself. <a href="http://www.theregister.co.uk/2008/08/01/siteadvisor_sans_snafu/page2.html">McAfee's comments</a>:</div><div class="" style="text-align: left; clear: both;"><br />
"<i>Our tests are very accurate," Dowling said. "The frequency of false positives is fewer than one a month. Changes in classifications we make are almost always because sites have changed their behaviour. "The email tests are the ones than have the most false positives. Users can have confidence in our ratings.</i>"<br />
<br />
</div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SJMjH58t8FI/AAAAAAAAB_U/jFxueEROzkM/s1600-h/hackinthebox_siteadvisor.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJMjH58t8FI/AAAAAAAAB_U/Wj65aLQMO3M/s200-R/hackinthebox_siteadvisor.bmp" style="border: 0pt none ;" /></a>There are even more surprising false positives, such as, <b>Hack in the Box security conference, Defcon.org, Zone-H France, Invisiblethings.org, AME Info - Middle East business and financial news</b> and more :</div><div class="" style="text-align: left; clear: both;"><a href="http://www.siteadvisor.com/sites/milw0rm.com"><b>milw0rm.com</b></a></div><div class="" style="text-align: left; clear: both;"><a href="http://www.siteadvisor.com/sites/hackinthebox.org/summary/"><b>hackinthebox.org</b></a></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/defcon.org">defcon.org</a> <br />
<a href="http://www.siteadvisor.com/sites/hitb.org"><b>hitb.org</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/invisiblethings.org/summary/"><b>invisiblethings.org</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/zone-h.fr/summary/"><b>zone-h.fr</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/ussrback.com/summary/"><b>ussrback.com</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><b><a href="http://www.siteadvisor.com/sites/ameinfo.com">ameinfo.com</a></b><br />
<br />
</b>Take for instance the Hack in the Box security conference, which is considered as the <a href="http://www.siteadvisor.com/sites/hitb.org/downloads/11950271/">download publisher of a file hosted at packetstormsecurity.org</a>. What's interesting to point out is that just like a huge percentage of already flagged as potentially harmful sites that haven't been re-checked in months, with Hack in the Box's case the link was last checked in February, 2008. And since <b>hitb.org</b> is now distributing spyware, any site that it links to is also flagged as badware, like <b>hackinthebox.org</b> itself :<br />
<br />
"<i>When we tested this site we found links to hitb.org, which we found to be a distributor of downloads some people consider adware, spyware or other potentially unwanted programs.</i>'<br />
<br />
These sites aren't SQL injected, IFRAME-ed or embedded with malware whatsoever, so it's like flagging a gun store as a malicious store because of the inventory there - wrong generalization aiming to bring order into the underground chaos at the first place is prone to result in lots of false positives, <a href="http://ddanchev.blogspot.com/2007/07/insecure-bureaucracy-in-germany.html">a wrong mentality that certain countries are starting to embrace</a>.</div><br />
The bottom line - is the "<i>do not visit unknown or potentially harmful sites</i>" security tip on the verge of extinction? Probably, as these days, exploited legitimate sites are hosting or redirecting to more malware than potentially harmful sites are.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6BU3YK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6BU3YK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WYGGVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WYGGVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=osuqWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=osuqWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ysc5ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ysc5ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S0nWuK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S0nWuK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x7tmHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x7tmHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdrCPk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdrCPk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/355386532" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 05:42:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site advisor">site advisor</category>
      <category domain="http://securityratty.com/tag/org due">org due</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/dangerous site">dangerous site</category>
      <category domain="http://securityratty.com/tag/specific site">specific site</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/harmful sites">harmful sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/355386532/mcafees-site-advisor-blocking-nruns-ag.html">McAfee's Site Advisor Blocking n.runs AG - "for starters"</source>
    </item>
    <item>
      <title><![CDATA[Can Moodys solve your third party assessment problem?]]></title>
      <link>http://securityratty.com/article/7e6b67ff0436ef607531dfb5fd3b619f</link>
      <guid>http://securityratty.com/article/7e6b67ff0436ef607531dfb5fd3b619f</guid>
      <description><![CDATA[Moodys recently launched their Vendor Information Risk (VIR) ratings service. The main objective of this service is to reduce the overall burden of conducting risk assessments for organizations, as...]]></description>
      <content:encoded><![CDATA[<p><img title="Khalid Kark" alt="Khalid Kark" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Kark_Khalid.gif" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></p>

<p>Moody’s recently launched their Vendor Information Risk (VIR) ratings service. The main objective of this service is to reduce the overall burden of conducting risk assessments for organizations, as well as their service providers. The whole idea being that if Moody’s can do a risk assessment on behalf of multiple subscribers, it can make the assessment process a lot more efficient.&nbsp; The service provider will not have to go through multiple assessments and the subscribers will share the cost, and therefore have a much lower price point. </p>

<p>Many CISOs I talk to are sick of performing third party risk assessments; it takes up valuable time, is expensive, and most importantly, pulls resources away from doing actual security work within the company. On the other hand service providers are also having a hard time keeping up with these assessments. A compliance manager at a large service provider estimated that they responded to over 300 audit requests in 2007, and that number would be around 400 in 2008. Thus, a service like this could potentially save millions of dollars for service providers and subscribers. </p>

<p>Industry efforts, such as the BITS framework, have so far focused on providing methodologies but haven’t really addressed the issue of building a platform to ensure consistency across assessments. It was refreshing to see this service from Moody’s that endeavors to take the burden off of your shoulders. </p>

<p>If this service delivers on its promise and is able to gain traction, it has the potential to move others in the industry to follow its approach. Although I think this is a great idea, here are some things to keep in mind as you evaluate this service for your organization.&nbsp; &nbsp; </p>

<ul><li>It can reduce the time, resources, and cost, if enough people use this service. There is no question that it would be much cheaper, less resource intensive, and a lot quicker to go through a Moody’s report as opposed to doing the assessment yourself. The trick would be to convince your service provider to go through an extensive assessment (Moody’s estimates two-three weeks), spend a substantial amount of money (Moody’s primary business model estimates US$ 23K for the initial rating and US$ 10K/year monitoring, volume purchase agreements are also available) for an assessment that may not be accepted by many other organizations. So the real value for a service provider be to have multiple companies subscribing to the VIR service. </li>

<li>Ongoing monitoring reduces time consuming remediation follow-ups. I think this is a very valuable part of the service if Moody’s gets it right. They will rely on a quarterly questionnaire and publicly available sources to identify changes in a service provider environment. Thus, it may be a little bit of challenge to get a clear risk picture if the service provider isn’t honest in providing all the necessary information or if the information isn’t public. Having said that, it is still better than the current situation where there is no monitoring at all, just an annual audit. Quarterly follow-ups on previously identified decencies by Moody’s will also ensure that the service provider stays on its toes. </li>

<li>Consultant expertise and consistency in scoring will improve over time. Having done a lot of assessments myself, you get better and more consistent as you go through the assessment process repeatedly. Although the current consultant skill set seems pretty good and appropriate checks are in place to check for consistency, it is only natural that different consultants will assess differently. Security assessments may be a very different beast compared to the financial assessments that Moody’s is used to doing primarily because there is a decent amount of subjectivity in these assessments.&nbsp; </li></ul>

<p>Lastly, the pricing structure may also influence the decision making for subscribers as well as service providers. I personally think that the current pricing structure is pretty reasonable for the current marketing conditions. Lets hope Moody’s is able to nail this one. What do you think about this service? Does it address your pain points? Are you skeptical? I’d love to hear your thoughts on this.&nbsp; </p>]]></content:encoded>
      <pubDate>Wed, 28 May 2008 08:36:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service provider environment">service provider environment</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/ratings service">ratings service</category>
      <category domain="http://securityratty.com/tag/vir service">vir service</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/service provider stays">service provider stays</category>
      <category domain="http://securityratty.com/tag/moodys">moodys</category>
      <source url="http://blogs.forrester.com/srm/2008/05/can-moodys-solv.html">Can Moodys solve your third party assessment problem?</source>
    </item>
    <item>
      <title><![CDATA[Q1 2008 - Client OS Vulnerability Scorecard]]></title>
      <link>http://securityratty.com/article/7b8af4c00571d063bc5dfa725eaa52ca</link>
      <guid>http://securityratty.com/article/7b8af4c00571d063bc5dfa725eaa52ca</guid>
      <description><![CDATA[This paper is a compilation of vulnerability data for client operating systems for the first 3 month, January through March, of 2008. Vulnerabilities and fixes for the following products are...]]></description>
      <content:encoded><![CDATA[<p>This paper is a compilation of vulnerability data for client operating systems for the first 3 month, January through March, of 2008. Vulnerabilities and fixes for the following products are discussed:  <ul> <li>Microsoft Windows Vista  <li>Microsoft Windows XP SP2  <li>Red Hat Enterprise Linux Desktop (v. 5 client)  <li>Red Hat Enterprise Linux WS (V. 4)  <li>Ubuntu 6.06 LTS Desktop  <li>Apple Mac OS X 10.5 (Leopard)  <li>Apple Mac OS X 10.4 (Tiger)</li></ul> <p>For January through March of 2008, Mac OS X users experienced the highest number of vulnerabilities as well as the highest number of High severity vulnerabilities while Windows Vista users experienced the fewest and the fewest High severity vulnerabilities.  <p>Here is the chart breaking down all of the OSes by <a href="http://nvd.nist.gov/" mce_href="http://nvd.nist.gov/">NVD</a> severity ratings:  <p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="330" alt="q108-client-scorecard-chart" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/Q12008ClientOSVulnerabilityScorecard_E197/q108-client-scorecard-chart_1.png" width="479" border="0" mce_src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/Q12008ClientOSVulnerabilityScorecard_E197/q108-client-scorecard-chart_1.png">  <p><a href="http://blogs.technet.com/security/attachment/3055337.ashx">Download the attached paper</a> for full details. </p><span class="sbmLink"> <table cellspacing="1" cellpadding="1"> <tbody> <tr> <td class="sbmText">Share this post : </td> <td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"><a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx&amp;;title=Q1 2008 Client OS Vulnerability Scorecard" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0"></a> <td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"><a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;url=http://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx&amp;title=Q1 2008 Client OS Vulnerability Scorecard" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0"></a> <td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"><a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;mkt=en-us&amp;url=http://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx&amp;title=Q1 2008 Client OS Vulnerability Scorecard" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0"></a> <td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"><a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx&amp;title=Q1 2008 Client OS Vulnerability Scorecard" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0"></a> <td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"><a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx&amp;t=Q1 2008 Client OS Vulnerability Scorecard" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0"></a></td></tr></tbody></table></span><img src="http://blogs.technet.com/aggbug.aspx?PostID=3055337" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 14 May 2008 19:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/severity vulnerabilities">severity vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/microsoft windows vista">microsoft windows vista</category>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/apple mac">apple mac</category>
      <category domain="http://securityratty.com/tag/microsoft windows">microsoft windows</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/windows vista users">windows vista users</category>
      <category domain="http://securityratty.com/tag/client">client</category>
      <source url="http://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx">Q1 2008 - Client OS Vulnerability Scorecard</source>
    </item>
  </channel>
</rss>
