<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: refresh]]></title>
    <link>http://securityratty.com/tag/refresh</link>
    <description></description>
    <pubDate>Thu, 28 Feb 2008 08:38:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Cybercriminals Abusing Lycos Spain To Serve Malware]]></title>
      <link>http://securityratty.com/article/fabff11bf2453e9de90b96225f66ceab</link>
      <guid>http://securityratty.com/article/fabff11bf2453e9de90b96225f66ceab</guid>
      <description><![CDATA[Spanish cybercriminals have recently started taking advantage of the bogus accounts at Lycos Spain, which they seem to be registering on their own, by releasing a do-it-yourself malicious link...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SO3K1YNzr7I/AAAAAAAACRg/Few0-Tx3rNw/s1600-h/lycos_spain_fake_video_generator2.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SO3K1YNzr7I/AAAAAAAACRg/iAII9VuZa4c/s200-R/lycos_spain_fake_video_generator2.PNG" /></a>Spanish cybercriminals have recently started taking advantage of the bogus accounts at Lycos Spain, which they seem to be registering on their own, by releasing a do-it-yourself malicious link generator redirecting to fake YouTube and Adobe Flash video pages. Whereas the concept of abusing legitimate web services for infection and propagation isn't new, what's new is the fact that <a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">the FTP access is efficiently abused</a>.&nbsp; <br />
<br />
Here's a description of the link generator : <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tM6_O7ZI/AAAAAAAACRI/nmOCnp413_4/s1600-h/lycos_spain_fake_video_generator1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tM6_O7ZI/AAAAAAAACRI/eipfSy4XHQA/s200-R/lycos_spain_fake_video_generator1.png" /></a>"<i>Download the program and run it asks for an ID (identifier), then copy it and paste it there, then press' Create Installer 'and the program will create the Installer! (this program to run a simulation that is installing the Adobe Flash and indicates to our page that "has been installed Adobe Flash," in order to show the video when YouVideo refresh the page, this you must file tie it in with your server! and what flames or Installer Setup (simulating being an installer)!&nbsp; Now you need to upload that file you've joined an FTP, click Next and put the path of that file in the next step!</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tdIn5AuI/AAAAAAAACRY/MxLdkIGeP-k/s1600-h/lycos_spain_fake_video_generator6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tdIn5AuI/AAAAAAAACRY/Ajrlsv2pXY8/s200-R/lycos_spain_fake_video_generator6.png" /></a>Whereas the tool is exclusively relying on Lycos Spain to host the binaries and the campaign itself, the recent <a href="http://ddanchev.blogspot.com/2008/10/syndicating-google-trends-keywords-for.html">blackhat SEO campaign relying on pre-registered Windows Live Spaces and AOL Journals</a> syndicating hot Google Trends keywords, further indicates the malicious attacker's capabilities of efficiently abusing legitimate services. And with the process of <a href="http://ddanchev.blogspot.com/2008/08/exposing-indias-captcha-solving-economy.html">bogus accounts registration</a> performed automatically, or <a href="http://blogs.zdnet.com/security/?p=1835">outsourced entirely</a>, malicious services aiming to automate the abuse process are only going to get more efficient.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=k5GGM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=k5GGM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Z15BM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Z15BM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=G192m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=G192m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Moy2m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Moy2m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Dp6KM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Dp6KM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Ysa5M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Ysa5M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S6Dhm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S6Dhm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/415620254" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 00:28:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lycos spain">lycos spain</category>
      <category domain="http://securityratty.com/tag/installer setup">installer setup</category>
      <category domain="http://securityratty.com/tag/installer">installer</category>
      <category domain="http://securityratty.com/tag/bogus accounts">bogus accounts</category>
      <category domain="http://securityratty.com/tag/bogus accounts registration">bogus accounts registration</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/malicious services">malicious services</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/adobe flash">adobe flash</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/415620254/cybercriminals-abusing-lycos-spain-to.html">Cybercriminals Abusing Lycos Spain To Serve Malware</source>
    </item>
    <item>
      <title><![CDATA[Internet Explorer security levels compared]]></title>
      <link>http://securityratty.com/article/cce1e6c584435126c5c4900522285f44</link>
      <guid>http://securityratty.com/article/cce1e6c584435126c5c4900522285f44</guid>
      <description><![CDATA[A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &quot;medium&quot; and &quot;medium-high&quot; security settings. I did some digging, and found...]]></description>
      <content:encoded><![CDATA[<p>A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &quot;medium&quot; and &quot;medium-high&quot; security settings. I did some digging, and found only this on MSDN: <a href="http://msdn.microsoft.com/en-us/library/ms537186(VS.85).aspx" target="_blank">About URL security zone templates</a>. No wonder it's difficult to find -- the terminology is different, and the table is organized by URL actions, not by the text in the dialog.</p>  <p>Someone on the IE security team forwarded me a document that had additional details. So here, for your enjoyment, is a chart listing the default settings for each security level. To answer the newsgroup poster, &quot;medium&quot; and &quot;medium-high&quot; aren't the same.</p>  <p>About the formatting: to get it to fit within the width of the blog's text section, I've made some abbreviations.</p>  <table cellspacing="0" cellpadding="0" width="290" border="0"><tbody>     <tr>       <td valign="top" width="145"><strong><u>Column headings</u></strong></td>        <td valign="top" width="145"><strong><u>Entries</u></strong></td>     </tr>   </tbody></table>  <table cellspacing="0" cellpadding="0" width="290" border="0"><tbody>     <tr>       <td valign="top" width="25">H</td>        <td valign="top" width="120">High</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="120">Disable</td>     </tr>      <tr>       <td valign="top" width="25">MH</td>        <td valign="top" width="120">Medium-high</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="120">Enable</td>     </tr>      <tr>       <td valign="top" width="25">M</td>        <td valign="top" width="120">Medium</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="120">Prompt</td>     </tr>      <tr>       <td valign="top" width="25">ML</td>        <td valign="top" width="120">Medium-low</td>        <td valign="top" width="25">&#160;</td>        <td valign="top" width="120">&#160;</td>     </tr>      <tr>       <td valign="top" width="25">L</td>        <td valign="top" width="120">Low</td>        <td valign="top" width="25">&#160;</td>        <td valign="top" width="120">&#160;</td>     </tr>   </tbody></table>  <p>In a few cases, the table shows a number rather than D or E or P; below the table is a description of each such entry.</p>  <p>At the very bottom of this post I've included the settings from the privacy tab, too.</p>  <p>Note: these settings reflect those for Internet Explorer 7 on Vista SP1. Please see the MDSN link above for differences between IE 6 and IE 7.</p>  <p>&#160;</p>  <p><strong>.NET Framework</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Loose XAML</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">XAML browser applications</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">XPS documents</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>.NET Framework-reliant components</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Permissions for components with manifests</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>     </tr>      <tr>       <td valign="top" width="325">Run components not signed with Authenticode</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Run components signed with Authenticode</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = High safety</p>  <p><strong>ActiveX controls and plug-ins</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Allow previously unused ActiveX controls to run without prompt</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow scriptlets</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Automatic prompting for ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Binary and script behaviors</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Display video and animation on a Web page that doesn't use an external media player</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Download signed ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Download unsigned ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Initialize and script ActiveX controls not marked as safe for scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Run ActiveX controls and plug-ins</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Script ActiveX controls marked as safe for scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Downloads</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Automatic prompting for file downloads</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">File download</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Font download</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Enable .NET Framework setup</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Enable .NET Framework setup</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Miscellaneous</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Access data sources across domains</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25">P</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>     </tr>      <tr>       <td valign="top" width="325">Allow META REFRESH</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow scripting of Internet Explorer Web browser control</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"><strong></strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow script-initiated windows without size or position constraints</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow web pages to use restricted protocols for active content</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow web sites to open windows without address or status bars</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Display mixed content</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Don't prompt for client certificate selection when no certificates or only one certificate exists</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Drag and drop or copy and paste files</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Include local directory path when uploading files to a server</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Installation of desktop items</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Launching applications and unsafe files</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Launching programs and files in an IFRAME</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Navigate sub-frames across different domains</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Open files based on content, not file extension</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Software channel permissions</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">3</td>     </tr>      <tr>       <td valign="top" width="325">Submit non-encrypted form data</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Use phishing filter</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Use pop-up blocker</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Userdata persistence</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Web sites in less privileged content zone can navigate into this zone</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = Prohibit downloads from software update channels    <br />&#160;&#160;&#160;&#160; 2 = Cache content downloaded from software update channels     <br />&#160;&#160;&#160;&#160; 3 = Automatically install software updates</p>  <p><strong>Scripting</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Active scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow programmatic clipboard access</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow status bar updates via script</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow Web sites to prompt for information using scripted windows</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Scripting of Java applets</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>User authentication</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Logon</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">3</td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = Prompt the user for name and password    <br />&#160;&#160;&#160;&#160; 2 = Automatic logon only in intranet zone     <br />&#160;&#160;&#160;&#160; 3 = Automatic logon with current user name and password</p>  <p>&#160;</p>  <p><strong>Privacy settings (on the &quot;Privacy&quot; tab)</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Allow persistent cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow per-session cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow third-party persistent cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow third-party session cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table><img src="http://blogs.technet.com/aggbug.aspx?PostID=3124973" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 20:19:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/script behaviors">script behaviors</category>
      <category domain="http://securityratty.com/tag/script">script</category>
      <category domain="http://securityratty.com/tag/script activex controls">script activex controls</category>
      <category domain="http://securityratty.com/tag/activex controls">activex controls</category>
      <category domain="http://securityratty.com/tag/net framework">net framework</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/zone">zone</category>
      <category domain="http://securityratty.com/tag/content zone">content zone</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/16/internet-explorer-security-levels-compared.aspx">Internet Explorer security levels compared</source>
    </item>
    <item>
      <title><![CDATA[When turning updates off really doesnt]]></title>
      <link>http://securityratty.com/article/ad6bfd3501bc1cd24c641aab64e8f592</link>
      <guid>http://securityratty.com/article/ad6bfd3501bc1cd24c641aab64e8f592</guid>
      <description><![CDATA[In any business dealings, if you cant trust the company to do what they say they will do, You go elsewhere right? Its your decision. Not in this instance folks


clipped from windowssecrets.com

Youll...]]></description>
      <content:encoded><![CDATA[<div > In any business dealings, if you cant trust the company to do what they say they will do,<br/>You go elsewhere right?<br/>Its your decision. Not in this instance folks. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/9d9b6101-4fcd-4b38-800c-4f4f98154898/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://windowssecrets.com/comp/080814" href="http://windowssecrets.com/comp/080814" style="font-size: 11px;">windowssecrets.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><B><br />
You&#8217;ll get a new Windows Update, like it or not<br />
</B></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
This time, Microsoft is being more up-front about its forthcoming<br />
refresh of Windows Update. For example, product manager Michelle Haven described in a<br />
<A href="http://WindowsSecrets.com/links/$P20d/fee5a4h/?url=blogs.technet.com%2Fmu%2Farchive%2F2008%2F07%2F03%2Fupcoming-update-to-windows-update.aspx" class="nwindow" target="_blank">blog post</A> on July 3 some new features that the upgrade will add.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
The new version will reportedly reduce the time WU takes to scan for and send out new updates. In addition, if you use the online version of WU, and you click an update for more information, the new version will offer you more links with additional details.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
But the Redmond company hasn&#8217;t changed the wording of the Control Panel settings that appear to prevent Windows Update from performing silent downloads — but don&#8217;t.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
In light of these potentially misleading controls, a few tricks on managing Windows Update are just what the doctor ordered.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:31:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/prevent windows">prevent windows</category>
      <category domain="http://securityratty.com/tag/online version">online version</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/redmond company">redmond company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/product manager michelle">product manager michelle</category>
      <category domain="http://securityratty.com/tag/control panel settings">control panel settings</category>
      <category domain="http://securityratty.com/tag/additional details">additional details</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=559">When turning updates off really doesnt</source>
    </item>
    <item>
      <title><![CDATA[Times Up IPv6 OMB Mandate]]></title>
      <link>http://securityratty.com/article/cc832c2648fa421babda1922e9cba906</link>
      <guid>http://securityratty.com/article/cc832c2648fa421babda1922e9cba906</guid>
      <description><![CDATA[Three years ago, the OMB set a June 2008 deadline by which all agencies infrastructure (network backbones) must be using IPv6 and agency networks must interface with this infrastructure
Agencies are...]]></description>
      <content:encoded><![CDATA[<p>Three years ago, the OMB set a June 2008 deadline “by which all agencies’ infrastructure (network backbones) <a href="http://www.whitehouse.gov/omb/memoranda/fy2005/m05-22.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.whitehouse.gov');" target="_blank">must be using IPv6 and agency networks must interface with this infrastructure</a>.”
<p>Agencies are supposed to demonstrate that they can:
<ul>
<li>Transmit IPv6 traffic from the Internet and external peers, through the core (WAN), to the LAN.</li>
<li>Transmit IPv6 traffic from the LAN, through the core (WAN), out to the Internet and external peers.</li>
<li>Transmit IPv6 traffic from the LAN, through the core (WAN), to another LAN (or another node on the same LAN).</li>
</ul>
<p><em>(</em><a href="http://www.whitehouse.gov/omb/egov/documents/IPv6_FAQs.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.whitehouse.gov');" target="_blank"><em>Source: OMB IPv6 FAQs</em></a><em>)</em></p>
<p>One year ago, the OMB reviewed the Enterprise Architecture Assessment Framework results and found that six of the twenty-four agencies were on track to achieve the June deadline. Two months ago, there was a <a href="http://www.networkworld.com/news/2008/040208-ipv6-feds.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkworld.com');" target="_blank">good article by Carolyn Marsan Duffy about the status of compliance</a>. Take a look at this article because it seemed like there was a lot of backpedaling going on about meeting the date – using phrases like “we don’t like the term mandate” and “more of a recommendation than a mandate.” At the time, only three agencies were in compliance.
<p>Duffy just wrote an updated article, “<a href="http://www.networkworld.com/news/2008/062608-ipv6-federal-government.html?page=1" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkworld.com');" target="_blank">Feds say they have aced IPv6 deadline</a>”, and suddenly two months later, all lights seem green. As of June 24, ten of the twenty-four agencies sent emails to the OMB stating that “they have successfully transmitted IPv6 packets”. Fourteen still need to report in, but none have asked for an extension. And all of it was done through the regular tech refresh budget over the past three years. So if this is true, kudos to the feds!
<p>Right around the time of the first not-so-rosy article, we <a href="http://blog.sciencelogic.com/whats-in-a-number/04/2008"  target="_blank">ran a survey at FOSE</a>, the big federal government IT show. We asked attendees if their agencies would be ready by the deadline:
<ul>
<li>33% said they would be ready</li>
<li>6% said they were already there</li>
<li>33% said they would NOT be ready</li>
<li>About a quarter didn’t know</li>
</ul>
<p>What was really interesting is that we asked this same question in 2007, and the audience was equally split (yes/no) on whether or not their agencies would meet the mandate – 1 in 5 (2007) instead of 1 in 3 (2008).
<p>So what can explain these numbers? Surprisingly, out of the attendees we talked to, only 65% of them said that IPv6 is important to their operations, making it second to last on the list of IT priorities covered by the survey. Maybe the answer lies in the relative “unimportance” of the milestone – that just the network backbones (and the routers supporting them) be capable of passing IPv6 packets. The true test for government IT workers will be when actual IPv6 applications must be supported which will impact networks, systems, application and monitoring tools throughout the government.
<p>So was this a nice checklist item for the Bush administration? This initial deadline is the only one for IPv6 mandates from the current OMB incarnation. Actually running IPv6 applications, that’s a whole ‘nother story, apparently for a new administration.</p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Time%26rsquo%3Bs+Up+%26ndash%3B+IPv6+OMB+Mandate&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Ftimes-up-ipv6-omb-mandate%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 15:27:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/aced ipv6 deadline">aced ipv6 deadline</category>
      <category domain="http://securityratty.com/tag/ipv6 packets">ipv6 packets</category>
      <category domain="http://securityratty.com/tag/transmit ipv6 traffic">transmit ipv6 traffic</category>
      <category domain="http://securityratty.com/tag/omb">omb</category>
      <category domain="http://securityratty.com/tag/ipv6 applications">ipv6 applications</category>
      <category domain="http://securityratty.com/tag/actual ipv6 applications">actual ipv6 applications</category>
      <category domain="http://securityratty.com/tag/agencies">agencies</category>
      <category domain="http://securityratty.com/tag/twenty-four agencies">twenty-four agencies</category>
      <source url="http://blog.sciencelogic.com/times-up-ipv6-omb-mandate/06/2008">Times Up IPv6 OMB Mandate</source>
    </item>
    <item>
      <title><![CDATA[Evil BETAs Attack!]]></title>
      <link>http://securityratty.com/article/ecca2544900eaabcc0ae94312b97f973</link>
      <guid>http://securityratty.com/article/ecca2544900eaabcc0ae94312b97f973</guid>
      <description><![CDATA[Read this awesome &quot; The BETA Mindset: Public Enemy #1 &quot; piece from Mike R (BTW, it is a MUST-read ). The maybe refresh on what I said after reading &quot; Geekonomics .&quot; Then think

Yes, it is available...]]></description>
      <content:encoded><![CDATA[Read <a href="http://securityincite.com/blog/mike-rothman/the-beta-mindset-public-enemy-1">this awesome "</a><a href="http://securityincite.com/blog/mike-rothman/the-beta-mindset-public-enemy-1">The BETA Mindset: Public Enemy #1</a><a href="http://securityincite.com/blog/mike-rothman/the-beta-mindset-public-enemy-1">" piece </a>from Mike R (BTW, it is a <a href="http://securityincite.com/blog/mike-rothman/the-beta-mindset-public-enemy-1">MUST-read</a>). The maybe refresh on <a href="http://chuvakin.blogspot.com/2008/06/it-changed-my-life-my-review-of.html"><span style="text-decoration: underline;">what I said after reading</span></a> "<a href="http://geekonomicsbook.com/">Geekonomics</a>."  Then think!<br /><br />Yes, it is available today (as beta maybe - but then again "all software is beta").<br />Yes, it is free.<br />Yes, it works ... well, when it does.<br />Yes, you can trust, say, your email to it (who cares when it is made public, really! :-))<br /><br /><span style="font-style: italic;">And then the same programmer mindset trickles up to the software that controls your aircraft engine.</span><br /><br /><span style="font-weight: bold;">Boom!</span><br /><br />That <span style="font-style: italic;">WAS </span>you.<br /><br /><br /><br />The more I think about it, the more I like the idea of software manufacturers' liability (succinctly described in "<a href="http://www.amazon.com/Geekonomics-Real-Cost-Insecure-Software/dp/0321477898">Geekonomics</a>"); I suspect that everything bad that might come with it will probably still be better than what we have now (or will have soon...)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0wMFRI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0wMFRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=iU334I"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=iU334I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=qhQYrI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=qhQYrI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/323659738" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 13:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software manufacturers">software manufacturers</category>
      <category domain="http://securityratty.com/tag/beta">beta</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/beta mindset">beta mindset</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/public enemy">public enemy</category>
      <category domain="http://securityratty.com/tag/programmer mindset trickles">programmer mindset trickles</category>
      <category domain="http://securityratty.com/tag/geekonomics">geekonomics</category>
      <category domain="http://securityratty.com/tag/aircraft engine">aircraft engine</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/323659738/evil-betas-attack.html">Evil BETAs Attack!</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Geoff Horne of InteropNet]]></title>
      <link>http://securityratty.com/article/1df6186569af24703e097f5ae4445c8e</link>
      <guid>http://securityratty.com/article/1df6186569af24703e097f5ae4445c8e</guid>
      <description><![CDATA[Earlier this week I had the chance to sit down with Geoff Horne , Chief Architect for InteropNet , and discuss how he thought things went at Interop Vegas 2008 and how he thinks the lessons learned...]]></description>
      <content:encoded><![CDATA[<p class="MsoNormal"><!--[if gte mso 9]><xml> <w:WordDocument> <w:View>Normal</w:View> <w:Zoom>0</w:Zoom> <w:TrackMoves /> <w:TrackFormatting /> <w:PunctuationKerning /> <w:ValidateAgainstSchemas /> <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid> <w:IgnoreMixedContent>false</w:IgnoreMixedContent> <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText> <w:DoNotPromoteQF /> <w:LidThemeOther>EN-US</w:LidThemeOther> <w:LidThemeAsian>X-NONE</w:LidThemeAsian> <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript> <w:Compatibility> <w:BreakWrappedTables /> <w:SnapToGridInCell /> <w:WrapTextWithPunct /> <w:UseAsianBreakRules /> <w:DontGrowAutofit /> <w:SplitPgBreakAndParaMark /> <w:DontVertAlignCellWithSp /> <w:DontBreakConstrainedForcedTables /> <w:DontVertAlignInTxbx /> <w:Word11KerningPairs /> <w:CachedColBalance /> </w:Compatibility> <m:mathPr> <m:mathFont m:val="Cambria Math" /> <m:brkBin m:val="before" /> <m:brkBinSub m:val="&#45;-" /> <m:smallFrac m:val="off" /> <m:dispDef /> <m:lMargin m:val="0" /> <m:rMargin m:val="0" /> <m:defJc m:val="centerGroup" /> <m:wrapIndent m:val="1440" /> <m:intLim m:val="subSup" /> <m:naryLim m:val="undOvr" /> </m:mathPr></w:WordDocument> </xml><![endif]--><!--[if gte mso 9]><xml> <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"   DefSemiHidden="true" DefQFormat="false" DefPriority="99"   LatentStyleCount="267"> <w:LsdException Locked="false" Priority="0" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Normal" /> <w:LsdException Locked="false" Priority="9" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="heading 1" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9" /> <w:LsdException Locked="false" Priority="39" Name="toc 1" /> <w:LsdException Locked="false" Priority="39" Name="toc 2" /> <w:LsdException Locked="false" Priority="39" Name="toc 3" /> <w:LsdException Locked="false" Priority="39" Name="toc 4" /> <w:LsdException Locked="false" Priority="39" Name="toc 5" /> <w:LsdException Locked="false" Priority="39" Name="toc 6" /> <w:LsdException Locked="false" Priority="39" Name="toc 7" /> <w:LsdException Locked="false" Priority="39" Name="toc 8" /> <w:LsdException Locked="false" Priority="39" Name="toc 9" /> <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption" /> <w:LsdException Locked="false" Priority="10" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Title" /> <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font" /> <w:LsdException Locked="false" Priority="11" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtitle" /> <w:LsdException Locked="false" Priority="22" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Strong" /> <w:LsdException Locked="false" Priority="20" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Emphasis" /> <w:LsdException Locked="false" Priority="59" SemiHidden="false"    UnhideWhenUsed="false" Name="Table Grid" /> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text" /> <w:LsdException Locked="false" Priority="1" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="No Spacing" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 1" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 1" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 1" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 1" /> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision" /> <w:LsdException Locked="false" Priority="34" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="List Paragraph" /> <w:LsdException Locked="false" Priority="29" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Quote" /> <w:LsdException Locked="false" Priority="30" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Quote" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 1" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 1" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 1" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 1" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 1" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 2" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 2" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 2" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 2" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 2" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 2" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 2" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 2" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 2" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 3" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 3" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 3" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 3" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 3" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 3" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 3" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 3" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 3" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 4" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 4" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 4" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 4" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 4" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 4" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 4" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 4" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 4" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 5" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 5" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 5" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 5" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 5" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 5" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 5" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 5" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 5" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 6" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 6" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 6" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 6" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 6" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 6" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 6" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 6" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 6" /> <w:LsdException Locked="false" Priority="19" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis" /> <w:LsdException Locked="false" Priority="21" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis" /> <w:LsdException Locked="false" Priority="31" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference" /> <w:LsdException Locked="false" Priority="32" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Reference" /> <w:LsdException Locked="false" Priority="33" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Book Title" /> <w:LsdException Locked="false" Priority="37" Name="Bibliography" /> <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading" /> </w:LatentStyles> </xml><![endif]--> <a href="http://blog.sciencelogic.com/wp-content/uploads/2008/06/geoff.jpg" ><img style="border-right: 0px; border-top: 0px; margin: 5px 15px 15px 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/06/geoff-thumb.jpg" border="0" alt="geoff" width="244" height="184" align="left" /></a> Earlier this week I had the chance to sit down with <a href="http://www.linkedin.com/in/slchorne" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.linkedin.com');" target="_blank">Geoff Horne</a>, <a href="http://www.interop.com/blog/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.interop.com');" target="_blank">Chief Architect for InteropNet</a>, and discuss how he thought things went at Interop Vegas 2008 and how he thinks the lessons learned apply to enterprises.</p>
<p class="MsoNormal"><em>(<a href="http://m.thetechstop.net/blog08/184.jpg" onclick="javascript:pageTracker._trackPageview('/outbound/article/m.thetechstop.net');" target="_blank">Photo credit: The Tech Stop</a>)</em></p>
<p class="MsoNormal"><strong>ScienceLogic: </strong>How long have you been involved with Interop?</p>
<p class="MsoNormal"><strong>Geoff Horne:</strong> Since about 1996.<span> </span></p>
<p class="MsoNormal"><strong>ScienceLogic: </strong><a href="http://www.thevarguy.com/2006/09/19/interop-2006-vs-interop/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.thevarguy.com');" target="_blank">How has it been changing</a>?<span> </span>Does the show get more complex with new technologies or because of the constantly changing size of the show?</p>
<p class="MsoNormal"><strong>Geoff Horne: </strong>The technologies have changed.<span> </span>Every year there’s a different market environment.<span> </span>Since we build on customer needs, things change every year. Things like ScienceLogic for Network Monitoring, for how long have Network Management tools been completely web based?<span> </span>In general, it doesn’t really get any better or worse because every year we’re building it again.<span> </span>You don’t get the stability of a standard environment.<span> </span>The upside is that we’re always doing a full upgrade, a full technology refresh and not using old code.<span> </span></p>
<p class="MsoNormal"><strong>ScienceLogic: </strong>Do those kinds of changes influence the types of <a href="http://interop.com/newyork/event-highlights/interopnet/sponsors.php" onclick="javascript:pageTracker._trackPageview('/outbound/article/interop.com');" target="_blank">vendors</a> you look for for InteropNet?</p>
<p class="MsoNormal"><strong>Geoff Horne: </strong>The base categories don’t change.<span> </span>You always need to forward packets.<span> </span>You always need switches, you always need routers.<span> </span>We’ve tried to open it up to everyone that has products involved with networks to see if we have the time or space for it.</p>
<p class="MsoNormal"><strong>ScienceLogic: </strong>The kind of cooperation that you get between the vendors is what seems to be an unachievable nirvana for Enterprises.<span> </span>What’s the secret to getting 17 vendors to work together in such a short time?<span> </span>Enterprises would kill for that.</p>
<p class="MsoNormal"><strong>Geoff Horne: </strong>The honest answer is don’t trust the vendors.<span> </span>If they try and build something the way they want to, its not going to interoperate.<span> </span>You have to pull them out of their safety zone, make them do things that you think the product can/should do to ensure interoperability.</p>
<p class="MsoNormal"><strong>ScienceLogic:</strong> In a <a href="http://www.interop.com/blog/?p=378" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.interop.com');" target="_blank">blog post</a> prior to Interop Vegas 2008 you stated three major goals for InteropNet.<span> They were Education, Monitoring and  Statistics.  How did you do against these goals?</span><strong><span><br />
</span></strong></p>
<p class="MsoNormal"><strong>Geoff Horne:</strong> I think we did pretty well.<span> </span>They’re 3 things we really didn’t have before.<span> </span>They’re things that just weren’t focused on the right way.<span> </span>For the first round of changing the focus, changing the way people look at the network (statistics rather than packets), it worked quite well, it gave people a much better idea as to what’s going on.</p>
<p class="MsoNormal"><strong>ScienceLogic: </strong>If we look at NY as take two for Interop 2008, are there things you are going to do differently based on lessons learned in Vegas?</p>
<p class="MsoNormal"><strong>Geoff Horne:</strong> We’re building more physical redundancy in the core network, geographic distribution of the infrastructure within the show.<span> </span>This will allow us to bring up chunks of the network independently.<span> </span>It isn’t something that we really thought of before.<span> </span>This helps us take the single point of failure (<a href="http://www.flickr.com/photos/adunne/sets/72157605022232170/show/with/2487945036/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.flickr.com');" target="_blank">the NOC</a>) out of the equation.</p>
<p class="MsoNormal"><strong>ScienceLogic: </strong>Are there any lessons learned from Interop that you think would help enterprises?</p>
<p class="MsoNormal"><strong>Geoff Horne:</strong> Visibility is key.<span> </span>Your network is significantly more functional when more people can see what’s going on.<span> </span>If the only guy that can see what’s going on is the guy with his fingers on the terminal, no one can make good decisions.<span> </span>You have to make people loosen up their control so that everyone can see and therefore make educated decisions.</p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26%23038%3BA+with+Geoff+Horne+of+InteropNet&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-geoff-horne-of-interopnet%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 12:20:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/geoff horne">geoff horne</category>
      <category domain="http://securityratty.com/tag/network independently">network independently</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/core network">core network</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/vegas">vegas</category>
      <category domain="http://securityratty.com/tag/interop vegas">interop vegas</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <source url="http://blog.sciencelogic.com/qa-with-geoff-horne-of-interopnet/06/2008">Q&amp;A with Geoff Horne of InteropNet</source>
    </item>
    <item>
      <title><![CDATA[So, CAN We Have DLP?]]></title>
      <link>http://securityratty.com/article/55f6fc8e7adf0a9b91953af0b69289cf</link>
      <guid>http://securityratty.com/article/55f6fc8e7adf0a9b91953af0b69289cf</guid>
      <description><![CDATA[Can we have DLP - data leak prevention
Well, can we have IDS? How about IPS? Can we really &quot;prevent intrusions?&quot; Can we really &quot;control access to our networks
The answer to &quot;can we have DLP?&quot; is...]]></description>
      <content:encoded><![CDATA[<p>Can we have <a href="http://chuvakin.blogspot.com/2008/05/in-passing-on-dlp.html">DLP</a> - data leak prevention? </p> <p>Well, can we have IDS? How about IPS? Can we really "prevent intrusions?" Can we really "control access to our networks?"</p> <p>The answer to "can we have DLP?" is actually pretty simple: if you think "DLP = box that prevents all data leaks" (and you also think that deploying IPS will "prevent intrusions"), then we can't. Forget it.</p> <p>But blame the idiots who called it "leak <strong>prevention</strong>" - if you think that "DLP will prevent all leaks" - sorry, but you are one of them! :-) If you treat "L" not as "leak" but as "loss" and hope that "DLP will prevent all data loss, whether intentional or not," you are an even BIGGER one.</p> <p>So rambling about <a href="http://www.networkworld.com/community/node/28864">"Can DLP Really Stop All Leaks"</a> is pretty silly. No, it can't. Pondering "<a href="http://www.computerweekly.com/blogs/stuart_king/2008/06/is-data-loss-prevention-really.html">Is DLP Possible</a>"&nbsp; is just as silly. No, complete prevention of all leaks is impossible, with OR without DLP technology. <a href="http://securityincite.com/TDI-2008-06-17#TSN1">Go read Mike R instead</a> :-)</p> <p>Why seemingly smart people behave in such childish manner? I dunno. Scratch all that. Instead ask:</p> <p><strong>Is today's <a href="http://www.nextiernetworks.com/">cutting-edge DLP technologies</a> USEFUL? </strong></p> <p>And the answer is "<strong>Hell yeah!"</strong></p> <p>If you see how much "fun" sensitive content goes over email (corp and personal web-based), gets uploaded to forums, channeled over IM file transfers, FTP'ed somewhere, you'd scream for one of these boxes. Accidental leaks, email address typos, non-malicious leaks, blatant disregard of security policy for the sake of "productivity", even phishing, "wholesale data theft" and amateur "employee hackers" probably account for 10x (100x?)&nbsp; more damage (in direct losses, brand damage, embarrassment and - yes! - non-compliance fines AND loss frequency) than "uber-hackers" (who might indeed go thru your DLP box like hot knife thru butter.) And if <a href="http://www.nextiernetworks.com/">an advanced DLP box</a> does one day stop some determined insider theft, that's just icing on the cake.</p> <p>That is why <a href="http://www.securosis.com">smart people</a> don't call it "DLP" - they call it "content monitoring and filtering." This sounds much less sexy, but much more useful. The boxes that will show up on your doorstep will still have "DLP" labels, but what they will do for you is really content monitoring and filtering.&nbsp; And even though it will not stop all data theft, DLP box will likely prove useful more than once...</p> <p>Finally, all rants about any preventative AND monitoring technologies should really end the same: <strong>go refresh your incident response plans. </strong></p> <p><strong>Possibly related posts:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/05/in-passing-on-dlp.html">"In Passing on DLP"</a></li></ul> <p>&nbsp;</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:b2cc045f-700a-482b-a6ec-0cf1615903c3" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/DLP" rel="tag">DLP</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/data%20loss" rel="tag">data loss</a>, <a href="http://technorati.com/tags/data%20theft" rel="tag">data theft</a>, <a href="http://technorati.com/tags/data%20protection" rel="tag">data protection</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=co9oII"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=co9oII" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AgRzgI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AgRzgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pkXrlI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pkXrlI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/316563485" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 12:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/cutting-edge dlp technologies">cutting-edge dlp technologies</category>
      <category domain="http://securityratty.com/tag/dlp technology">dlp technology</category>
      <category domain="http://securityratty.com/tag/dlp box">dlp box</category>
      <category domain="http://securityratty.com/tag/leak prevention">leak prevention</category>
      <category domain="http://securityratty.com/tag/leak">leak</category>
      <category domain="http://securityratty.com/tag/non-malicious leaks">non-malicious leaks</category>
      <category domain="http://securityratty.com/tag/leaks">leaks</category>
      <category domain="http://securityratty.com/tag/loss">loss</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/316563485/so-can-we-have-dlp.html">So, CAN We Have DLP?</source>
    </item>
    <item>
      <title><![CDATA[Payment Card Industry Mandate Stresses Importance of Web Application Security: Recommended Becomes Required]]></title>
      <link>http://securityratty.com/article/f0a627cb5699aef47964db3dc7dd3fb6</link>
      <guid>http://securityratty.com/article/f0a627cb5699aef47964db3dc7dd3fb6</guid>
      <description><![CDATA[On June 30, another refresh of the Payment Card Industry (PCI) Data Security Standards (PCI DSS) will upgrade Web application security testing from a best practice to a mandatory practice. The...]]></description>
      <content:encoded><![CDATA[On June 30, another refresh of the Payment Card Industry (PCI) Data Security Standards (PCI DSS) will upgrade Web application security testing from a best practice to a mandatory practice. The deadlin...]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 17:36:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payment card industry">payment card industry</category>
      <category domain="http://securityratty.com/tag/data security standards">data security standards</category>
      <category domain="http://securityratty.com/tag/practice">practice</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/mandatory practice">mandatory practice</category>
      <category domain="http://securityratty.com/tag/refresh">refresh</category>
      <category domain="http://securityratty.com/tag/june">june</category>
      <category domain="http://securityratty.com/tag/deadlin">deadlin</category>
      <source url="http://www.net-security.org/article.php?id=1143">Payment Card Industry Mandate Stresses Importance of Web Application Security: Recommended Becomes Required</source>
    </item>
    <item>
      <title><![CDATA[The DDoS Attack Against CNN.com]]></title>
      <link>http://securityratty.com/article/0c99ce385868ceb40b1baaf43aadeaf8</link>
      <guid>http://securityratty.com/article/0c99ce385868ceb40b1baaf43aadeaf8</guid>
      <description><![CDATA[The DDoS attack against CNN.com, whether successful or not in terms of the perspective of complete knock-out, which didn't happen, is a perfect and perhaps the most recent example of a full scale...]]></description>
      <content:encoded><![CDATA[<div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SA5i69Dpi4I/AAAAAAAABnE/aygLnU_8-FQ/s1600-h/IFRAME_CNN_China_hacktivists.jpg"><img id="BLOGGER_PHOTO_ID_5192196185366563714" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SA5i69Dpi4I/AAAAAAAABnE/aygLnU_8-FQ/s200/IFRAME_CNN_China_hacktivists.jpg" border="0" /></a>The DDoS attack against CNN.com, whether successful or not in terms of the perspective of complete knock-out, which didn't happen, is a perfect and perhaps the most recent example of a full scale <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare in action</a>. Utilizing the bandwidth of the over 200 million nationalism minded Chinese Internet users, can greatly outpace any botnet's capacity if coordinated, or though the use of automated DIY tools, like the ones we've seen released for the purpose of attacking CNN.com<br /><br /><a href="http://news.netcraft.com/archives/2008/04/22/cnn_site_bears_the_brunt_of_chinese_attackers.html">CNN.com was indeed inacessible for a period of three hours according to NetCraft</a>, and literally any web site performance monitoring too with a historical perspective for a host can prove the same :<br /><br />"<span style="font-style: italic;">The CNN News website has twice been affected since an earlier distributed denial of service attack last Thursday. CNN fixed Thursday's attack by limiting the number of users who could access the site from specific geographical areas. Subsequently, an attack was purportedly organised to start on Saturday 19th April, but cancelled. However, our performance monitoring graph shows CNN's website s</span><span style="font-style: italic;">u</span><span style="font-style: italic;">ffered downtime within a 3 hour period on Sunday </span><span style="font-style: italic;">morning, followed by other anomalous activity on Monday morning, where response times were greatly inflated. Netcraft is continuing to monitor the CNN News website. Live uptime graphs can be viewed here.</span>"<br /><br /><a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Unrestricted warfare</a> is all about bypassing the most fortified engagement points, and achieving asymmetric dominance by excelling where there are no engagement points, in order for the attacker to enjoy the pioneer advantage. Now that CNN.com was indeed slowed down to a situation where it was unnacessible, what remains to be answered is how was CNN.com DDoS? Throught a botnet, or through <a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">the collective bandwidth of virtually recruited Chinese citizens</a>? Despite that the common wisdom in terms of botnets used speaks for itself, this is China hacktivism and therefore common wisdom does not apply in an unrestricted warfare situation, and best of all data speaks for itself.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SA56c9Dpi9I/AAAAAAAABno/M-GVLAfVMB0/s1600-h/super_ddos_chinese_hacktivists.JPG"><img id="BLOGGER_PHOTO_ID_5192222058249554898" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SA56c9Dpi9I/AAAAAAAABno/M-GVLAfVMB0/s200/super_ddos_chinese_hacktivists.JPG" border="0" /></a>- <span style="font-weight: bold;">Through the use of DIY DDoS Tools</span><br /><br />Besides <span style="font-weight: bold;"><a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">anticnn.exe</a> </span>which I assessed in a previous post, there's also the Supper DDoS tool that as it appears was also getting actively recommended for participating in the attack, courtsy of a Chinese script kiddies group. Some basic info :<br /><br />Scanners Result: 3<span id="porcentaje">/32 (9.38%)</span><br />DDoS.Win32.Sdattack.A; DDoS.Trojan<br />File size: 1510643 bytes<br />MD5...: ed25e7188e5aa17f6b35496a267be557<br />SHA1..: 71138f0c0556dde789854398c3c7cde29352662b<br /><br />For instance, Estonia's DDoS attacks were a combination of botnets and DIY attack tools released in the wild, whereas the attacks on CNN.com were primarily the effect of people's information warfare, a situation where people would on purposely infect themselves with malware released on behalf of Chinese hacktivists to automatically utilize their Internet bandwidth for the purpose of a coordinated attack against a particular site.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA54VNDpi8I/AAAAAAAABng/QHBuNCRD_3I/s1600-h/IFRAME_CNN_China_hacktivists_2.jpg"><img id="BLOGGER_PHOTO_ID_5192219726082313154" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SA54VNDpi8I/AAAAAAAABng/QHBuNCRD_3I/s200/IFRAME_CNN_China_hacktivists_2.jpg" border="0" /></a><br />- <span style="font-weight: bold;">Collectively building bandwidth capacity and mobilizing novice cyber warriors</span><br /><br />What if a simple script that is automatically refreshing CNN.com multiple times in several IFRAME windows, gets embedded at thousands of sites, and then promoted at hundreds of forums, with a single line stating that - "If you're a patriot, forward this to all your friends"? Now, what if this gets coordinate to happen at a particular moment in time? This is perhaps the most realistic scenario to what exactly happened with CNN.com, and data speaks for itself, in fact I can easily state that the bandwidth generated by this massive PSYOPs campaign is greater than the one used by a botnet that's also been DDoS-ing CNN.com. All of these sites are basically refreshing CNN.com every couple of seconds, thereby wasting the sites's bandwidth, the only flaw of this attack approach compared to a botnet, is that all the participating hosts are Chinese, and therefore as NetCraft pointed out, CNN blocked access to certain countries, take these countries as China for instance. If it were a botnet used, the diversity of the infected hosts would have required more efforts into dealing with the attack, then again from another perspective regular web traffic compared to network flood is sometimes harder to detect as a DDoS attack.<br /><br /><span style="font-weight: bold;">hackerhf.com/cnn.html</span> <span style="font-weight: bold;"><br />80aft.com/cnn.htm</span> <span style="font-weight: bold;"><br />tom765.cn/cnn.html</span> <span style="font-weight: bold;"><br />ah930.com/cnn.htm</span> <span style="font-weight: bold;"><br />0851qiche.cn/cnn.html</span><br /><span style="font-weight: bold;">xdadmin.com/cnn.html</span> <span style="font-weight: bold;"><br />ah930.com/cnn.html</span><br /><span style="font-weight: bold;">s234sdf3.cn.webz.datasir.com/cnn.asp</span><br /><span style="font-weight: bold;">bbscar.com.cn/cnn</span> <span style="font-weight: bold;"><br />120abc.cn/cn</span><span style="font-weight: bold;">n.html</span> <span style="font-weight: bold;"><br />hospltal.cn/cnn.html</span> <span style="font-weight: bold;"><br />bbs.cityzx.cn/cnn.htm</span> <span style="font-weight: bold;"><br />bestmf.cn/cnn.html</span> <span style="font-weight: bold;"><br />anlycloud.com/cnn/cnn</span> <span style="font-weight: bold;"><br />qibubbs.net/ddoscnn.htm</span> <span style="font-weight: bold;"><br />maje.cn/cnn.html</span> <span style="font-weight: bold;"><br />edu.sina.googlepages.com/FuckCNN.htm</span> <span style="font-weight: bold;"><br />urlonline.com.cn/kaocnn.html</span> <span style="font-weight: bold;"><br />lmpx.net/cnn.htm</span><br /><span style="font-weight: bold;">ily88.com/cn</span><span style="font-weight: bold;">n.html</span> <span style="font-weight: bold;"><br />zjipc.net/cnn</span> <span style="font-weight: bold;"><br />axlovechina.cn/<br />idernice.com/cnn.asp</span> <span style="font-weight: bold;"><br />conncn.com/cnn.html</span> <span style="font-weight: bold;"><br />xuanxuanmu.000webhost.com/cnn.html</span> <span style="font-weight: bold;"><br />jianw1.cn/cnn.htm</span> <span style="font-weight: bold;"><br />bjzs114.com/cnn.htm</span> <span style="font-weight: bold;"><br />0851qiche.cn/cnn.html</span><br /><span style="font-weight: bold;">yaanren.net/cnn.html</span> <span style="font-weight: bold;"><br />todayol.cn/cnn.html</span> <span style="font-weight: bold;"><br />17bnb.com/cn</span><span style="font-weight: bold;">n.htm</span> <span style="font-weight: bold;"><br />hackerhf.com/cnn.html</span> <span style="font-weight: bold;"><br />hnjdbbs.com/cnn.html</span> <span style="font-weight: bold;"><br />sql8.net/cnn</span> <span style="font-weight: bold;"><br />bh125.cn/cnn.html</span> <span style="font-weight: bold;"><br />razorcn.cn/cnn.html</span> <span style="font-weight: bold;"><br />93HR.com/cnn.html</span> <span style="font-weight: bold;"><br />tke08.com/cnn.htm<br />vipeee.com/cnn.htm</span><br /><br />This is also the statement made for the recruiting purpose across the forums, including remarks against France's policy against China :<br /><br /><span style="font-weight: bold;">Anti-CNN Plans v4.19</span><br /><br />"<span style="font-style: italic;">Revenge of the flame - we, as the publicity in the network of special groups, we notice as follows: We are still able to recall that the Sino-US hackers exciting war, and that war, what are the reasons? That have taken place in Indonesia because of the large-scale anti-Chinese, the majority of Chinese women were raped, killed, and we Chinese hackers predecessors such unbearable humiliation, and from the other side of the ocean in advance of the attack, losing their right to. " cn "for China's first website launched a large-scale attack, but at that time the Chinese network is not very developed, we use the most immature way to attack, but in any case, we all expressed their intention by everyone, although we on the network do not know each other, but we have a common motherland. </span><br /><br /><span style="font-style: italic;">We know that the 2008 Olympic Games will be held in our beloved motherland, which is the dream of the people look forward to for a long time, and we in the passing of the torch in the process of being repeatedly obstructed because we all know that, as an act of Tibetan independence elements each of us Mission hearts have a personal anger. Then we briefly look at the practice of France: France is now the largest in the protection of Tibetan independence, advocates in support of France is in support of splitting China, French President Sarkozy, the country is now the world just for a dare to openly resist Beijing Olympic Games President, the Chinese go-vern-ment has just come to an end with the French Airbus as much as billions of dollars in trade contracts. France on bad faith.</span><br /><br /><span style="font-style: italic;">Recently, the United States "cnn" Since, as we said a number of Chinese people can not accept things, is that we are willing to endure, willing to yield? We plan on taking the lead in the 2008.4.19 "cnn" Web site attacks, as a Chinese, please support us. </span><br /><span style="font-style: italic;"></span><br /><span style="font-style: italic;">Plot: </span><br /><span style="font-style: italic;">1, first of all, all the conditions for full, I expect four days later, in the - on April 19, 2008, 8:00 p.m., at www.cnn.com against a DDOS attack! More than three hours on the CNN Web site with the assistance of attacks, How DOS attack CNN website? If you are patriotic, please forward!<br /></span><br /><span style="font-style: italic;">iframe Id="cnn" width="100%" height="100"> <!-- iframe--></span><br /><span style="font-style: italic;">script> </span><br /><span style="font-style: italic;">Var e = document.getElementById ( 'cnn'); </span><br /><span style="font-style: italic;">SetInterval ( "e.src = 'http://www.cnn.com'", 3000); </span><br /><span style="font-style: italic;">/ / 1000 said that 1,000 ms, you can modify and transmit<br /> <!-- span script<--><br /><span style="font-style: italic;">You can also directly open qibubbs.net/ddoscnn.htm open on the trip, you do not affect anything. I have to, I have friends in all of it again, the strong support of friends, and their repercussions great, and to many people, have been transmitted in other friend, a classmate now has begun to link their Web sites the I believe that compatriots in China, in collaboration with CNN article seconds click rate in the second can at least 50 million times, if the 200 million Internet users click on, I believe CNN, will be suspended instantaneous, as our fellow countrymen will be more hackers the chance to win big, exciting good mood now, and looks forward to 8:00 after we are all fellow hackers smoothly, we will sincerely pray that China win. The great motherland is not to take advantage of the separatist elements, all anti-China reunification of the sophistry of speech are all in vain Revenge of the flame - we, as the publicity in the network of special groups, we notice as follows:</span><br /><br /><span style="font-style: italic;">We are still able to recall that the Sino-US hackers exciting war, and that war, what are the reasons? That have taken place in Indonesia because of the large-scale anti-Chinese, the majority of Chinese women were raped, killed, and we Chinese hackers predecessors such unbearable humiliation, and from the other side of the ocean in advance of the attack, losing their right to. " cn "for China's first website launched a large-scale attack, but at that time the Chinese network is not very developed, we use the most immature way to attack, but in any case, we all expressed their intention by everyone, although we on the network do not know each other, but we have a common motherland. </span>  <span style="font-style: italic;">We know that the 2008 Olympic Games will be held in our beloved motherland, which is the dream of the people look forward to for a long time, and we in the passing of the torch in the process of being repeatedly obstructed because we all know that, as an act of Tibetan independence elements each of us Mission hearts have a personal anger. </span>  <span style="font-style: italic;">Then we briefly look at the practice of France: France is now the largest in the protection of Tibetan independence, advocates in support of France is in support of splitting China, French President Sarkozy, the country is now the world just for a dare to openly resist Beijing Olympic Games President, the Chinese go-vern-ment has just come to an end with the French Airbus as much as billions of dollars in trade contracts.</span> "</span></div><br /><div><span style="font-style: italic;"><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5-4tDpi-I/AAAAAAAABnw/qzRVOFjSUm4/s1600-h/sina-anti-cnn.jpg"><img id="BLOGGER_PHOTO_ID_5192226933037435874" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5-4tDpi-I/AAAAAAAABnw/qzRVOFjSUm4/s200/sina-anti-cnn.jpg" border="0" /></a></span>This particular DDoS people's information warfare attack against CNN.com is also a great example of a psychological operations (PSYOPS) chain-letter. Given China's 3.0 state of social networking, messages forwarding people to sites that would automatically refresh their browsers with CNN.com were distributed at over 5000 web forums, with a bit of propanga taste enticing everyone to forward the message by telling them "If you're a patriot forward this attack link", so if you don't, it means you're not a patriot, another indication of China's understanding of the effectiveness of psychological operations (PSYOPS) online.<br /></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GPVfMGG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GPVfMGG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8JZLhbG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8JZLhbG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e5BEfGg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e5BEfGg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xOuYnag"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xOuYnag" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vzmsr4G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vzmsr4G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a7dJe5G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a7dJe5G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MVNOTRg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MVNOTRg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/275777656" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Apr 2008 15:30:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <category domain="http://securityratty.com/tag/ddos-ing cnn">ddos-ing cnn</category>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/ddos people">ddos people</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/information warfare attack">information warfare attack</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/chinese script kiddies">chinese script kiddies</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/275777656/ddos-attack-against-cnncom.html">The DDoS Attack Against CNN.com</source>
    </item>
    <item>
      <title><![CDATA[Audit/Monitor Controls or Audit/Monitor BEFORE Control?]]></title>
      <link>http://securityratty.com/article/9d4936fb0b15ffba77521833b9f38777</link>
      <guid>http://securityratty.com/article/9d4936fb0b15ffba77521833b9f38777</guid>
      <description><![CDATA[Back in 2004, Forrester paper called &quot; The Natural Order Of Security Yields The Greatest Benefits &quot; proclaimed that &quot;the adoption of security has a natural order: 1) authentication; 2) authorization;...]]></description>
      <content:encoded><![CDATA[<p>Back in 2004, <a href="http://www.forrester.com">Forrester</a> paper called "<a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,34777,00.html">The Natural Order Of Security Yields The Greatest Benefits</a>" proclaimed that "the adoption of security has a natural order: <strong>1) authentication; 2) authorization; 3) administration and <em>4) audit</em></strong>." Note that <strong><em>audit</em></strong> which, in this case, broadly includes audit, monitoring and detection, comes last. It seems to be fairly in line with common sense: you audit the controls after you put them in place; you monitor after you have <strong>authentication</strong> and <strong>authorization</strong> taken care of and you detect the violations after you organized your <strong>administration</strong>.</p> <p>The paper even had the following picture, which is presented here to illustrate the point:</p> <p><a href="http://lh5.google.com/anton.chuvakin/R8cNts_zltI/AAAAAAAADOo/qSCp6JFxIKY/forrnatural3"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="158" alt="forr-natural" src="http://lh3.google.com/anton.chuvakin/R8cNuM_zluI/AAAAAAAADOw/9tN14S4C66k/forrnatural_thumb1" width="244" border="0"></a>&nbsp;</p> <p>(source: <a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,34777,00.html">Forrester paper named above</a>)</p> <p>The <a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,34777,00.html">paper</a> clarifies: "With people and contexts defined, protective controls in place, and policies outlined, the<br>fourth set of questions [<em>i.e. regarding the audit</em>] includes: “<strong>What happened?</strong>”, “<strong>What is happening?”</strong> or, especially, “Is<br>it working?” </p> <p>However, is this really so? Or, is this always so? First, when reality collided with plans,&nbsp; many of the organizations that followed that wisdom got mired in one phase (e.g. in trying to get authentication under control) and ended up having no audit whatsoever: in other words, <strong>they are flying blind while implementing controls!</strong>&nbsp; Second, in some cases controls (authentication, authorization, administration) will actually be impossible to implement, while audit will be possible. Imagine retrofitting a legacy application for granular authorization? Third, in some cases implementing prevention/control will be much more complicated, compared to implementing audit: thus, people will face a choice between a half-baked control to a full-blown audit capability? An example will be managing which file each user can access vs monitoring/auditing which file each user have accessed. The latter is doable, while the former is next to impossible. Another way to phrase it is "reactive but possible" vs "proactive but impossible" (hint: pick the former :-))</p> <p>I think the idea of putting <strong>audit first</strong> in some cases is the way we'd need to progress. "Wow, what a blasphemy!", some might say ...&nbsp; After all, if you have not defined controls, what are you going to audit? But remember that audit is meant broadly in this context and thus the opposite question is very relevant: <strong>what are you going to control if you have no idea what is going on?</strong> People sometimes define a security policy based on how things should be (and then <a href="http://online.wsj.com/article/SB118539543272477927.html?mod=fpa_mostpop">WSJ happens</a> :-) - refresh your memory of the "WSJ saga" <a href="http://del.icio.us/anton18/awareness+security+stupidity">here</a>), but then spent years trying to bring policy and reality together (and end up with an environment which is "half-controlled") Won't it be better to audit first, then control? </p> <p>Obviously, "do IDS before IPS" falls under the same principle: monitor first, [<em>try to</em>] control second. Here is another example: implement <a href="http://www.loglogic.com">log management</a> before identity management. Looking at logs will tell you what privileges the users actually use for doing their daily jobs. Then you can mix it up with what the idea access policy will be. </p> <p>So, think about it! Questioning the common wisdom does often bring interesting insights.</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:f0c30498-9000-4222-bd71-c632a6daece6" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/security%20management" rel="tag">security management</a>, <a href="http://technorati.com/tags/audit" rel="tag">audit</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=VvvOHyE"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=VvvOHyE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=LY4pxsE"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=LY4pxsE" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/242895782" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Feb 2008 08:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/audit">audit</category>
      <category domain="http://securityratty.com/tag/broadly includes audit">broadly includes audit</category>
      <category domain="http://securityratty.com/tag/broadly">broadly</category>
      <category domain="http://securityratty.com/tag/includes">includes</category>
      <category domain="http://securityratty.com/tag/audit whatsoever">audit whatsoever</category>
      <category domain="http://securityratty.com/tag/full-blown audit capability">full-blown audit capability</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/paper clarifies">paper clarifies</category>
      <category domain="http://securityratty.com/tag/controls">controls</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/242895782/auditmonitor-controls-or-auditmonitor.html">Audit/Monitor Controls or Audit/Monitor BEFORE Control?</source>
    </item>
  </channel>
</rss>
