<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: s-job]]></title>
    <link>http://securityratty.com/tag/s-job</link>
    <description></description>
    <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Researchers Use Facebook App to Create Zombie Army]]></title>
      <link>http://securityratty.com/article/798bedf8348492e0aef129ad7d4e6c9f</link>
      <guid>http://securityratty.com/article/798bedf8348492e0aef129ad7d4e6c9f</guid>
      <description><![CDATA[Facebook users who choose to install the wrong third party application could find themselves inducted into a robot computer army controlled by a hacker. At least, that's what a team of Greek computer...]]></description>
      <content:encoded><![CDATA[Facebook users who choose to install the wrong third party application could find themselves inducted into a robot computer army controlled by a hacker. At least, that's what a team of Greek computer researchers proved with their rogue Photo of the Day application.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d96ef0eaa374f413ab2871474815c4b3" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d96ef0eaa374f413ab2871474815c4b3" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=08kpL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=08kpL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=doKPl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=doKPl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2Cawl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2Cawl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=MzruL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=MzruL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=NYCRL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=NYCRL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=SF5Fl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=SF5Fl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=0asul"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0asul" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=EoS1L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=EoS1L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/384545347" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/384545349" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 15:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/greek computer researchers">greek computer researchers</category>
      <category domain="http://securityratty.com/tag/robot computer army">robot computer army</category>
      <category domain="http://securityratty.com/tag/day application">day application</category>
      <category domain="http://securityratty.com/tag/party application">party application</category>
      <category domain="http://securityratty.com/tag/rogue photo">rogue photo</category>
      <category domain="http://securityratty.com/tag/facebook users">facebook users</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/384545349/researchers-use.html">Researchers Use Facebook App to Create Zombie Army</source>
    </item>
    <item>
      <title><![CDATA[The Analyzer Is Among The Suspects In $1.8 Million Theft From A Canadian Company]]></title>
      <link>http://securityratty.com/article/1a3f2a8d883dec31c59c3fe3a24e0d4d</link>
      <guid>http://securityratty.com/article/1a3f2a8d883dec31c59c3fe3a24e0d4d</guid>
      <description><![CDATA[Ehud Tenenbaum, a 29-Israeli known online as the Analyzer and living in Montreal, was arrested after investigators spent nine months and found out that him and three other suspects allegedly stole...]]></description>
      <content:encoded><![CDATA[Ehud Tenenbaum, a 29-Israeli known online as &#8220;the Analyzer&#8221; and living in Montreal, was arrested after investigators spent nine months and found out that him and three other suspects allegedly stole $1.8 million from a Calgary company. The operation involved the U.S. Secret Service and municipal police in Calgary and Vancouver - as well as [...]]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 13:42:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/calgary company">calgary company</category>
      <category domain="http://securityratty.com/tag/calgary">calgary</category>
      <category domain="http://securityratty.com/tag/municipal police">municipal police</category>
      <category domain="http://securityratty.com/tag/secret service">secret service</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/ehud tenenbaum">ehud tenenbaum</category>
      <category domain="http://securityratty.com/tag/suspects allegedly">suspects allegedly</category>
      <category domain="http://securityratty.com/tag/analyzer">analyzer</category>
      <category domain="http://securityratty.com/tag/montreal">montreal</category>
      <source url="http://cyberinsecure.com/the-analyzer-is-among-the-suspects-in-theft-from-canadian-company/">The Analyzer Is Among The Suspects In $1.8 Million Theft From A Canadian Company</source>
    </item>
    <item>
      <title><![CDATA[Friday Squid Blogging: Colossal Squid was a Lethargic Blob]]></title>
      <link>http://securityratty.com/article/6d4f80e8d3fa802ab13aac07fe66d4c9</link>
      <guid>http://securityratty.com/article/6d4f80e8d3fa802ab13aac07fe66d4c9</guid>
      <description><![CDATA[Fierce deep-sea predator? Not so much : &quot;We are looking at something verging on the incredibly bizarre. As she got older she got shorter and broader and was reduced to a giant gelatinous blob,...]]></description>
      <content:encoded><![CDATA[<p>Fierce deep-sea predator?  <a href="http://www.abc.net.au/science/articles/2008/08/22/2343461.htm">Not so much</a>:</p>

<blockquote>"We are looking at something verging on the incredibly bizarre. As she got older she got shorter and broader and was reduced to a giant gelatinous blob, carrying many thousands of eggs," he says.

<p>"Her shape was likely to have affected her behaviour and ability to hunt. I can't imagine her jetting herself around in the water at any great speed, and she was too gelatinous to have been a fighting machine.</p>

<p>"It's likely she was just blobbing around the seabed carrying her brood of eggs, living on dead fish, while her mate was off hunting."</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gWpmL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gWpmL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ir4dL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ir4dL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 12:36:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gelatinous">gelatinous</category>
      <category domain="http://securityratty.com/tag/giant gelatinous blob">giant gelatinous blob</category>
      <category domain="http://securityratty.com/tag/fierce deep-sea predator">fierce deep-sea predator</category>
      <category domain="http://securityratty.com/tag/dead fish">dead fish</category>
      <category domain="http://securityratty.com/tag/eggs">eggs</category>
      <category domain="http://securityratty.com/tag/incredibly bizarre">incredibly bizarre</category>
      <category domain="http://securityratty.com/tag/broader">broader</category>
      <category domain="http://securityratty.com/tag/thousands">thousands</category>
      <category domain="http://securityratty.com/tag/shorter">shorter</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/friday_squid_bl_138.html">Friday Squid Blogging: Colossal Squid was a Lethargic Blob</source>
    </item>
    <item>
      <title><![CDATA[Premature Update on Philadelphia Wi-Fi]]></title>
      <link>http://securityratty.com/article/95922e41bb691a60a525baab81a41942</link>
      <guid>http://securityratty.com/article/95922e41bb691a60a525baab81a41942</guid>
      <description><![CDATA[I'm not sure why this article was written, as there appears to be nothing particularly newsworthy in it: The News.com reporter Marguerite Reardon has covered muni-Fi for as long as I have, and after...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><a href="http://news.cnet.com/8301-1035_3-10033386-94.html"><strong>I'm not sure why this article was written, as there appears to be nothing particularly newsworthy in it:</strong></a> The News.com reporter Marguerite Reardon has covered muni-Fi for as long as I have, and after reading this in-depth piece, I'm left wondering whether it was assigned far too early, and she was meeting an editorial desk requirement instead of feeling like the story was ready to "print." The article looks at Network Acquisition Corp. (NAC), the allegedly interim name for the group that's taken over Phila-Fi. </p>

<p>One source at the Knight Center for Digital Excellence notes, "The new network owners are supposed to have a much more sustainable business model." <em>Supposed to.</em> Later, "Network Acquisition Company, which acquired the network, hasn't talked publicly about the details of its new plan, but it has hinted that its strategy will differ from EarthLink's." <em>Hasn't talked publicly.</em> Then, "[NAC and Tropos] spokespeople said the companies would talk more about the network later this month when details of the new business plan are ready." Huh.</p>

<p>Reardon explains digital divide issues and looks into what Wireless Philadelphia has been up to, although doesn't note that delays in EarthLink's deployment and other factors have led to just a few hundred individuals that have been assisted by the non-profit; numbers may have changed, but that was as of a few months ago. Still, Wireless Philadelphia has apparently diversified its funding sources--Reardon cites 30 now.</p>

<p>I think we're still coming off the doldrums of August.</p>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:23:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network acquisition company">network acquisition company</category>
      <category domain="http://securityratty.com/tag/network acquisition corp">network acquisition corp</category>
      <category domain="http://securityratty.com/tag/network owners">network owners</category>
      <category domain="http://securityratty.com/tag/wireless philadelphia">wireless philadelphia</category>
      <category domain="http://securityratty.com/tag/sustainable business model">sustainable business model</category>
      <category domain="http://securityratty.com/tag/editorial desk requirement">editorial desk requirement</category>
      <category domain="http://securityratty.com/tag/plan">plan</category>
      <category domain="http://securityratty.com/tag/digital excellence notes">digital excellence notes</category>
      <source url="http://wifinetnews.com/archives/008431.html">Premature Update on Philadelphia Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[FAQ: Is your county posting your Social Security number online?]]></title>
      <link>http://securityratty.com/article/b908d17bbb107bca3a45c5bab64b3086</link>
      <guid>http://securityratty.com/article/b908d17bbb107bca3a45c5bab64b3086</guid>
      <description><![CDATA[County and state Web sites may harbor Social Security numbers and other personal data in broadly accessible public records. Here's what you should...]]></description>
      <content:encoded><![CDATA[County and state Web sites may harbor Social Security numbers and other personal data in broadly accessible public records. Here's what you should know.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:d0dd9a35cd2608e4f6335e3b30fc6f3c:5qzalZ0Z6OhI1%2BBYIXtkSGn9Hkxkbz403lJYWtQ2qjt6%2BwSqQWvd7O7C97lQf%2BfWCcvxWldFWxhiGv9iJDYnRLVAlEhYGqLYSsUvcZ6SZVs%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ad85aeb6b8ba02c54ff4984adabcc8a7:miAydBhVIU%2B%2F5Fcfb5dljSU0FXnhcnmz3ZItb80hBMSURysBXj%2FX210vjI1dmlZgHVk%2BAzGIaale9mAwSTZD8%2BHzubzatca8C0tGlAs%2BTyg%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:750070f286298d730e4280ff7ee8cf7d:uWW5i7kDsYQdDSoE0MyO8QCJrWe%2FbXYoZ119LXK8DlyNfaWiYjq58V1eVDfKns0He9Hpst9PBEPXEZapEdPXyRDN%2B%2Bi3KK6fkEg5WjgZ2Vw%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:cc721c56aeb97a089720dd496074ac56:GR%2FImFfoVRWGXmjiosz1ApKmtX4wK0g6tPm53PSGxMmGJIH8OXzAqhdmirRF6c6O5r98LhY58JpkEsKcPAJeREOJZPv2JR2AhVdGTs%2FPYOw%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a815cf9261dd5e28ab3b4bd6bf71d6b2" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a815cf9261dd5e28ab3b4bd6bf71d6b2" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/harbor social security">harbor social security</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a815cf9261dd5e28ab3b4bd6bf71d6b2">FAQ: Is your county posting your Social Security number online?</source>
    </item>
    <item>
      <title><![CDATA[Contest: Cory Doctorow's Cipher Wheel Rings]]></title>
      <link>http://securityratty.com/article/5bf9715088e83f021dd3a8a86d47bb52</link>
      <guid>http://securityratty.com/article/5bf9715088e83f021dd3a8a86d47bb52</guid>
      <description><![CDATA[Cory Doctorow wanted a secret decoder wedding ring, and he asked me to help design it. I wanted something more than the standard secret decoder ring , so this is what I asked for: &quot;I want each wheel...]]></description>
      <content:encoded><![CDATA[<p>Cory Doctorow wanted a secret decoder wedding ring, and he asked me to help design it.  I wanted something more than the standard <a href="http://en.wikipedia.org/wiki/Secret_decoder_ring">secret decoder ring</a>, so this is what I asked for: "I want each wheel to be the alphabet, with each letter having either a dot above, a dot below, or no dot at all.  The first wheel should have alternating above, none, below.  The second wheel should be the repeating sequence of above, above, none, none, below, below.  The third wheel should be the repeating sequence of above, above, above, none, none, none, below, below, below."  (I know it sounds confusing, but <a href="http://www.flickr.com/photos/doctorow/2816467273/">here's</a> a chart.)</p>

<p>So that's what he asked for, and that's what <a href="http://www.flickr.com/photos/doctorow/2817314740/">he got</a>.  And now it's time to create some cryptographic applications for the rings.  Cory and I are holding an open contest for the cleverest application.</p>

<p>I don't think we can invent any encryption algorithms that will survive computer analysis -- there's just not enough entropy in the system -- but we can come up with some clever pencil-and-paper ciphers that will serve them well if they're ever stuck back in time.  And there are certainly other  cryptographic uses for the rings.</p>

<p>Here's a way to use the rings as a password mnemonic:  First, choose a two-letter key.  Align the three wheels according to the key.  For example, if the key is "EB" for eBay, align the three wheels AEB.  Take the common password "PASSWORD" and encrypt it.  For each letter, find it on the top wheel.  Count one letter to the left if there is a dot over the letter, and one letter to the right if there is a dot under it.  Take that new letter and look at the letter below it (in the middle wheel).  Count two letters to the left if there is a dot over it, and two letters to the right if there is a dot under it.  Take that new letter (in the middle wheel), and look at the letter below it (in the lower wheel).  Count three letters to the left if there is a dot over it, and three letters to the right if there is a dot under it.  That's your encrypted letter.  Do that with every letter to get your password.</p>

<p>"PASSWORD" and the key "EB" becomes "NXPPVVOF."</p>

<p>It's not very good; can anyone see why?  (Ignore for now whether or not publishing this on a blog makes it no longer secure.)</p>

<p>How can I do that better?  What else can we do with the rings?  Can we incorporate other elements -- a deck of playing cards as in <a href="http://www.schneier.com/solitaire.html">Solitaire</a>, different-sized coins to make the system more secure?</p>

<p>Post your contest entries as comments to <a href="http://www.boingboing.net/2008/09/05/help_design_a_cipher.html">Cory's blog post</a> -- you can post them here, but they're not going to count as contest submissions --  or send them to <a href="mailto:cryptocontest@craphound.com">cryptocontest@craphound.com</a>.  Deadline is October 1st.  </p>

<p>Good luck, and have fun with this. </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XHAZL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XHAZL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=vFg0L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=vFg0L" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 08:01:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wheel">wheel</category>
      <category domain="http://securityratty.com/tag/letter">letter</category>
      <category domain="http://securityratty.com/tag/two-letter key">two-letter key</category>
      <category domain="http://securityratty.com/tag/middle wheel">middle wheel</category>
      <category domain="http://securityratty.com/tag/dot">dot</category>
      <category domain="http://securityratty.com/tag/cory doctorow">cory doctorow</category>
      <category domain="http://securityratty.com/tag/cory">cory</category>
      <category domain="http://securityratty.com/tag/rings">rings</category>
      <category domain="http://securityratty.com/tag/top wheel">top wheel</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/contest_cory_do.html">Contest: Cory Doctorow's Cipher Wheel Rings</source>
    </item>
    <item>
      <title><![CDATA[Your Companies Biggest Security Hole - What is the BGP-style Vuln Lurking in Software Security?]]></title>
      <link>http://securityratty.com/article/95b08326dc660fff6cb1103621e8f2f3</link>
      <guid>http://securityratty.com/article/95b08326dc660fff6cb1103621e8f2f3</guid>
      <description><![CDATA[My vote is MQ Series and other enterprise messaging systems. Schneier's succinct summary of BGP

It's a man-in-the-middle attack. &quot;The Internet's Biggest Security Hole&quot; has been that interior relays...]]></description>
      <content:encoded><![CDATA[<p>My vote is MQ Series and other enterprise messaging systems. Schneier&#39;s succinct <a href="http://www.schneier.com/blog/archives/2008/08/border_gateway.html">summary</a> of BGP:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">It&#39;s a man-in-the-middle attack. &quot;The Internet&#39;s Biggest Security Hole&quot; &#160;has been that interior relays have always been trusted even though they are not trustworthy.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br />That could apply word for word to how MQ Series and other enterprise messaging systems are deployed. Let&#39;s say you are a bank and have been happily running your business on a mainframe for decades. Life is good, come in at 9 leave at 5, count the cash. Then some dotcommer comes along and tells you that you need to get online. What are you gonna do? Rewrite your whole system from scratch? Hard to make that case.</span></p><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Nope what you&#39;ll do is build out a web farm to talk to the consumer, but then you will realize all of your business runs on the mainframe, and you need to connect to it. How exactly? Enter MQ Series and friends, they broker the communications to legacy backends for most major corporations, but there is one slight problem - they didn&#39;t even bother to support useful security protocols until very recently, and most of the time the security protocols are not even implemented.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Typical anti-patterns include:</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* no authentication, no authorization (just open up a queue) - run your whole book of business transaction backbone on anonymous ftp</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* authorization with no authentication (mq enforces authorization policy on unverifiable tokens) -&#160;run your whole book of business transaction backbone on anonymous ftp, but think that you have security</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">What is strange about the MQ Series, enterprise messaging vulns is that there is no need for them, there are no technical excuses to not add better tokens, message security, and encryption. People don&#39;t do it, because of poor tool support,</span><span style="font-family: Verdana; font-size: 12px; line-height: normal;">&#160;a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html">mainframe mindset</a><span style="font-family: Verdana; font-size: 12px; line-height: normal;">, silo projects, and a whole variety of reasons. But just because you choose to ignore a fact doesn&#39;t mean its not true. On the plus side, some of the open source ESBs are </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/04/cxf-axis2-and-e.html">adding support for message security</a><span style="font-family: Verdana; font-size: 12px; line-height: normal;">, so you can improve security and save your company money at the same time, what&#39;s not to like?</span></div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 04:31:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/security protocols">security protocols</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business runs">business runs</category>
      <category domain="http://securityratty.com/tag/business transaction backbone">business transaction backbone</category>
      <category domain="http://securityratty.com/tag/improve security">improve security</category>
      <category domain="http://securityratty.com/tag/message security">message security</category>
      <category domain="http://securityratty.com/tag/enforces authorization policy">enforces authorization policy</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/your-companies-biggest-security-hole---what-is-the-bgp-style-vuln-lurking-in-software-security.html">Your Companies Biggest Security Hole - What is the BGP-style Vuln Lurking in Software Security?</source>
    </item>
    <item>
      <title><![CDATA[More MMORPG Fakeouts]]></title>
      <link>http://securityratty.com/article/b648d83d66372f23dbf0ea3ee7b7deee</link>
      <guid>http://securityratty.com/article/b648d83d66372f23dbf0ea3ee7b7deee</guid>
      <description><![CDATA[Here's a few more sites presumably created by the maker of the fake Batman Online game

Step up, Dragonball Z



Click to Enlarge

To &quot;download&quot; this Dragonball Z MMORPG, you have to fill out a...]]></description>
      <content:encoded><![CDATA[
        Here's a few more sites presumably created by the maker of the <a href="http://blog.spywareguide.com/2008/09/zango-and-the-batman-online-vi.html">fake Batman Online game</a>. <br /><br />Step up, Dragonball Z:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbz1.html" onclick="window.open('http://blog.spywareguide.com/images/dbz1.html','popup','width=624,height=585,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbz1-thumb-324x303.gif" alt="dbz1.gif" class="mt-image-none" style="" height="303" width="324" /></a></span><br />Click to Enlarge<br /></div><br />To "download" this Dragonball Z MMORPG, you have to fill out a survey:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbz2.html" onclick="window.open('http://blog.spywareguide.com/images/dbz2.html','popup','width=672,height=530,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbz2-thumb-372x293.gif" alt="dbz2.gif" class="mt-image-none" style="" height="293" width="372" /></a></span>
<br />Click to Enlarge<br /></div><br />Once done, you'll be amazed(!) to find you're taken to....shockingly....the <i>official</i> Dragonball Z MMORPG game.<br /><br />The only problem? The website is in Japanese and the game <a href="http://en.wikipedia.org/wiki/Dragon_Ball_Online">hasn't been released yet</a>.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbz3.html" onclick="window.open('http://blog.spywareguide.com/images/dbz3.html','popup','width=815,height=592,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbz3-thumb-315x228.gif" alt="dbz3.gif" class="mt-image-none" style="" height="228" width="315" /></a></span><br />Click to Enlarge<br /></div><br />Forgive me for thinking this isn't the greatest deal I've ever been sold.<br /><br />Now it's Harry Potters turn:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hp1.html" onclick="window.open('http://blog.spywareguide.com/images/hp1.html','popup','width=565,height=580,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hp1-thumb-365x374.jpg" alt="hp1.jpg" class="mt-image-none" style="" height="374" width="365" /></a></span><br />Click to Enlarge<br /></div><br />Like the Batman site, you need to install Zango. Do so, and.....you're taken to the popular <a href="http://www.hogwartslive.com/">Hogwarts Live</a>, which you could have easily found and played yourself without installing Adware. As you probably guessed, the screenshot from the title graphic on the site is <i>not</i> part of the game you'll eventually play.<br /><br />The sites involved are<br /><br />onlinedbzgame.info<br /><br />and<br /><br />harrypottergame.info<br /><br />in case you want to add them to your blocklists.<br />
        
    ]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 12:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mmorpg">mmorpg</category>
      <category domain="http://securityratty.com/tag/mmorpg game">mmorpg game</category>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/official dragonball">official dragonball</category>
      <category domain="http://securityratty.com/tag/dragonball">dragonball</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/popular hogwarts live">popular hogwarts live</category>
      <category domain="http://securityratty.com/tag/batman site">batman site</category>
      <source url="http://blog.spywareguide.com/2008/09/more-mmorpg-fakeouts.html">More MMORPG Fakeouts</source>
    </item>
    <item>
      <title><![CDATA[Are you insecure about SOA security?]]></title>
      <link>http://securityratty.com/article/27dce3cb651490f3ea9a9c5b1a8fc278</link>
      <guid>http://securityratty.com/article/27dce3cb651490f3ea9a9c5b1a8fc278</guid>
      <description><![CDATA[SOA's strength in open standards is also its biggest drawback from a security perspective. Here are some tips for how to address the...]]></description>
      <content:encoded><![CDATA[SOA's strength in open standards is also its biggest drawback from a security perspective. Here are some tips for how to address the issue.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=kGXyFQ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=kGXyFQ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/383350346" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security perspective">security perspective</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/drawback">drawback</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <category domain="http://securityratty.com/tag/strength">strength</category>
      <category domain="http://securityratty.com/tag/tips">tips</category>
      <category domain="http://securityratty.com/tag/standards">standards</category>
      <category domain="http://securityratty.com/tag/address">address</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/383350346/article.do">Are you insecure about SOA security?</source>
    </item>
    <item>
      <title><![CDATA[Facebook tests New Jersey's icon for reporting predators, pornography]]></title>
      <link>http://securityratty.com/article/f9b4025d1e8bd046aee9568b5fc3fb56</link>
      <guid>http://securityratty.com/article/f9b4025d1e8bd046aee9568b5fc3fb56</guid>
      <description><![CDATA[Facebook Inc. is testing an icon created by the state of New Jersey to provide online users with a way to report predators and inappropriate content to law enforcement...]]></description>
      <content:encoded><![CDATA[Facebook Inc. is testing an icon created by the state of New Jersey to provide online users with a way to report predators and inappropriate content to law enforcement authorities.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=G66fwO"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=G66fwO" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/383372794" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/law enforcement authorities">law enforcement authorities</category>
      <category domain="http://securityratty.com/tag/provide online users">provide online users</category>
      <category domain="http://securityratty.com/tag/icon">icon</category>
      <category domain="http://securityratty.com/tag/report predators">report predators</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/383372794/article.do">Facebook tests New Jersey's icon for reporting predators, pornography</source>
    </item>
  </channel>
</rss>
