<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: secondary]]></title>
    <link>http://securityratty.com/tag/secondary</link>
    <description></description>
    <pubDate>Tue, 22 Jul 2008 18:24:22 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[XRumer Spambot Cracks Captchas]]></title>
      <link>http://securityratty.com/article/8e16e4882509e89db49f04e7c4d2deb7</link>
      <guid>http://securityratty.com/article/8e16e4882509e89db49f04e7c4d2deb7</guid>
      <description><![CDATA[Weve known CAPTCHAs are insecure for some time, but now even the CAPTCHA-alternatives (often based on identifying cats from dogs or other animals) have proven insecure. Gmail, Windows Live hotmail and...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;ve known CAPTCHAs are insecure for some time, but now even the CAPTCHA-alternatives (often based on identifying cats from dogs or other animals) have proven insecure. Gmail, Windows Live hotmail and other popular sites were hacked as early as <a rel="nofollow" target="_blank" href="http://http://arstechnica.com/news.ars/post/20080415-gone-in-60-seconds-spambot-cracks-livehotmail-captcha.html">February</a>. Recently another defeat has come in the form of <a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Xrumer">XRumer,</a> a <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081002-right-back-at-ya-captcha-bad-guys-crack-gmail-hotmail.html">spam bot</a> that posts messages on blogs and through email in order to boost search engine rankings.</p>
<p>What&#8217;s the solution? Ars Technica suggests there might not be a good one, in part because malware distributors can go so far as to hire real people to do their dirty work:</p>
<blockquote><p>Instead of trying to build better CAPTCHA-cracking programs, the malware industry went out and got itself some humans of its own. This effectively bypasses the primary security strength of the CAPTCHA system and leaves it entirely dependent on what we&#8217;ll call secondary security characteristics. CAPTCHAs are often complex (particularly these days), which does increase the chance that they&#8217;ll be misread (and returned incorrectly), while the font and display of the characters themselves are at least somewhat unfamiliar to the CAPTCHA crackers sitting on the other side of the world.</p></blockquote>
<p>Sometimes those captcha phrases are pretty incoherent to me too. When I post over at Craigslist sometimes it says I&#8217;ve gotten its Captcha wrong, and I end up wondering if secretly I&#8217;m a bot?? Apparently not a very smart one either.</p>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:40:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/captchas">captchas</category>
      <category domain="http://securityratty.com/tag/bot">bot</category>
      <category domain="http://securityratty.com/tag/primary security strength">primary security strength</category>
      <category domain="http://securityratty.com/tag/windows live hotmail">windows live hotmail</category>
      <category domain="http://securityratty.com/tag/spam bot">spam bot</category>
      <category domain="http://securityratty.com/tag/ars technica suggests">ars technica suggests</category>
      <category domain="http://securityratty.com/tag/hire real people">hire real people</category>
      <category domain="http://securityratty.com/tag/popular sites">popular sites</category>
      <category domain="http://securityratty.com/tag/xrumer">xrumer</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/410515365/">XRumer Spambot Cracks Captchas</source>
    </item>
    <item>
      <title><![CDATA[CCTV Firm Threatens The Researcher Who Found Vulnerable Products That Reveal Cam Images Without Authentication]]></title>
      <link>http://securityratty.com/article/004b60ada89c39b7a3f4bb4d0ecf0735</link>
      <guid>http://securityratty.com/article/004b60ada89c39b7a3f4bb4d0ecf0735</guid>
      <description><![CDATA[A flaw discovered by security researcher Mike Stephens, affects The LookC 44 server and Pro IX server, which allows anyone to view static images from any camera connected to its servers. This product...]]></description>
      <content:encoded><![CDATA[A flaw discovered by security researcher Mike Stephens, affects The LookC 4&#215;4 server and Pro IX server, which allows anyone to view static images from any camera connected to its servers. This product is installed in some primary and secondary schools. The flaw requires no authentication to exploit and vulnerable servers might be found via [...]]]></content:encoded>
      <pubDate>Sat, 20 Sep 2008 04:22:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flaw requires">flaw requires</category>
      <category domain="http://securityratty.com/tag/vulnerable servers">vulnerable servers</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/view static images">view static images</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <category domain="http://securityratty.com/tag/secondary schools">secondary schools</category>
      <category domain="http://securityratty.com/tag/authentication">authentication</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/pro">pro</category>
      <source url="http://cyberinsecure.com/cctv-firm-threatens-the-researcher-who-found-vulnerable-products/">CCTV Firm Threatens The Researcher Who Found Vulnerable Products That Reveal Cam Images Without Authentication</source>
    </item>
    <item>
      <title><![CDATA[Identity Farming]]></title>
      <link>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</link>
      <guid>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up. </p>

<p>Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities. </p>

<p>Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them. </p>

<p>There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop. </p>

<p>You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work. </p>

<p>Here's the real question: Do you actually have to show up for any part of your life? </p>

<p>Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China. </p>

<p>Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. Iâm told this is a common idea in Highlander fan fiction. </p>

<p>The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.schneier.com/essay-219.html">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.) </p>

<p>It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary. </p>

<p>Our data shadows can live a perfectly normal life without us.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/09/securitymatters_0904">previously appeared<a> on Wired.com.</p>

<p>EDITED TO ADD (9/9): Interesting <a href="http://www.examiner.com/x-536-Civil-Liberties-Examiner~y2008m9d4-Im-not-myself-today-or-manufacturing-a-new-you">commentary</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YzkGL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YzkGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JDMVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JDMVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 01:42:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <category domain="http://securityratty.com/tag/photo ids">photo ids</category>
      <category domain="http://securityratty.com/tag/identity databases">identity databases</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/identity_farmin.html">Identity Farming</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: How to Create the Perfect Fake Identity]]></title>
      <link>http://securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</link>
      <guid>http://securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up.
</p>

<p>
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities.
</p>

<p>
Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them.
</p>

<p>
There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop.
</p>

<p>
You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work.  
</p>

<p>
Here's the real question: Do you actually have to show up for any part of your life?
</p>

<p>
Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China.
</p>

<p>
Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. I’m told this is a common idea in <a href="http://www.highlander.org/"><cite>Highlander</cite></a> fan fiction.
</p>

<p>
The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/securitymatters_0515">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.)
</p>

<p>
It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary.
</p>

<p>
Our data shadows can live a perfectly normal life without us.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8c450d9a9d0030ff631259b1803cae6a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8c450d9a9d0030ff631259b1803cae6a" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=snUd9L"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=snUd9L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=uzqRkl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=uzqRkl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zVASIl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zVASIl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=itvpML"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=itvpML" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=XRzLgL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XRzLgL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=hSbcKl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=hSbcKl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Rk785l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Rk785l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qjRx3L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qjRx3L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/382935195" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/382935196" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/social security card">social security card</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/382935196/securitymatters_0904">Security Matters: How to Create the Perfect Fake Identity</source>
    </item>
    <item>
      <title><![CDATA[My LA Times Op Ed on Photo ID Checks at Airport]]></title>
      <link>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</link>
      <guid>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</guid>
      <description><![CDATA[Opinion
The TSA's useless photo ID rules
No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work
By Bruce Schneier
August 28, 2008
The...]]></description>
      <content:encoded><![CDATA[<p>Opinion</p>

<p><a href="http://www.latimes.com/news/opinion/la-oe-schneier28-2008aug28,0,3099808.story">The TSA's useless photo ID rules</a></p>

<p>No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work.</p>

<p>By Bruce Schneier </p>

<p>August 28, 2008</p>

<p>The TSA is tightening its photo ID rules at airport security. Previously, people with expired IDs or who claimed to have lost their IDs were subjected to secondary screening. Then the Transportation Security Administration realized that meant someone on the government's no-fly list -- the list that is supposed to keep our planes safe from terrorists -- could just fly with no ID. </p>

<p>Now, people without ID must also answer personal questions from their credit history to ascertain their identity. The TSA will keep records of who those ID-less people are, too, in case they're trying to probe the system.</p>

<p>This may seem like an improvement, except that the photo ID requirement is a joke. Anyone on the no-fly list can easily fly whenever he wants. Even worse, the whole concept of matching passenger names against a list of bad guys has negligible security value.</p>

<p>How to fly, even if you are on the no-fly list: Buy a ticket in some innocent person's name. At home, before your flight, check in online and print out your boarding pass. Then, save that web page as a PDF and use Adobe Acrobat to change the name on the boarding pass to your own. Print it again. At the airport, use the fake boarding pass and your valid ID to get through security. At the gate, use the real boarding pass in the fake name to board your flight.</p>

<p>The problem is that it is unverified passenger names that get checked against the no-fly list. At security checkpoints, the TSA just matches IDs to whatever is printed on the boarding passes. The airline checks boarding passes against tickets when people board the plane. But because no one checks ticketed names against IDs, the security breaks down.</p>

<p>This vulnerability isn't new. It isn't even subtle. I first wrote about it in 2006. I asked Kip Hawley, who runs the TSA, about it in 2007. Today, any terrorist smart enough to Google "print your own boarding pass" can bypass the no-fly list.</p>

<p>This gaping security hole would bother me more if the very idea of a no-fly list weren't so ineffective. The system is based on the faulty notion that the feds have this master list of terrorists, and all we have to do is keep the people on the list off the planes. </p>

<p>That's just not true. The no-fly list -- a list of people so dangerous they are not allowed to fly yet so innocent we can't arrest them -- and the less dangerous "watch list" contain a combined 1 million names representing the identities and aliases of an estimated 400,000 people. There aren't that many terrorists out there; if there were, we would be feeling their effects. </p>

<p>Almost all of the people stopped by the no-fly list are false positives. It catches innocents such as Ted Kennedy, whose name is similar to someone's on the list, and Islam Yusuf (formerly Cat Stevens), who was on the list but no one knew why.</p>

<p>The no-fly list is a Kafkaesque nightmare for the thousands of innocent Americans who are harassed and detained every time they fly. Put on the list by unidentified government officials, they can't get off. They can't challenge the TSA about their status or prove their innocence. (The U.S. 9th Circuit Court of Appeals decided this month that no-fly passengers can sue the FBI, but that strategy hasn't been tried yet.) </p>

<p>But even if these lists were complete and accurate, they wouldn't work. Timothy McVeigh, the Unabomber, the D.C. snipers, the London subway bombers and most of the 9/11 terrorists weren't on any list before they committed their terrorist acts. And if a terrorist wants to know if he's on a list, the TSA has approved a convenient, $100 service that allows him to figure it out: the Clear program, which issues IDs to "trusted travelers" to speed them through security lines. Just apply for a Clear card; if you get one, you're not on the list.</p>

<p>In the end, the photo ID requirement is based on the myth that we can somehow correlate identity with intent. We can't. And instead of wasting money trying, we would be far safer as a nation if we invested in intelligence, investigation and emergency response -- security measures that aren't based on a guess about a terrorist target or tactic.</p>

<p>That's the TSA: Not doing the right things. Not even doing right the things it does.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=0Nd83L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=0Nd83L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uz4JRL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uz4JRL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 01:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/no-fly list">no-fly list</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/transportation security administration">transportation security administration</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/ids">ids</category>
      <category domain="http://securityratty.com/tag/matches ids">matches ids</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/my_la_times_op.html">My LA Times Op Ed on Photo ID Checks at Airport</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Heuristics for De-identifying Health Data]]></title>
      <link>http://securityratty.com/article/3e946b95fd3cf25d9c1712fcd1e819ac</link>
      <guid>http://securityratty.com/article/3e946b95fd3cf25d9c1712fcd1e819ac</guid>
      <description><![CDATA[Before releasing personal health information for secondary uses, such as research or public health monitoring, organizations must de-identify the data they've collected. Several common heuristics are...]]></description>
      <content:encoded><![CDATA[Before releasing personal health information for secondary uses, such as research or public health monitoring, organizations must de-identify the data they've collected. Several common heuristics are useful for this purpose, but they also have limitations.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=7907cb7fe7a10b2be37a9fd9ce3e85ed" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=7907cb7fe7a10b2be37a9fd9ce3e85ed" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 09:30:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal health information">personal health information</category>
      <category domain="http://securityratty.com/tag/common heuristics">common heuristics</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/public health">public health</category>
      <category domain="http://securityratty.com/tag/limitations">limitations</category>
      <category domain="http://securityratty.com/tag/purpose">purpose</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/secondary">secondary</category>
      <source url="http://www.pheedo.com/click.phdo?i=7907cb7fe7a10b2be37a9fd9ce3e85ed">Heuristics for De-identifying Health Data</source>
    </item>
    <item>
      <title><![CDATA[CISA and CISSP Preparation]]></title>
      <link>http://securityratty.com/article/4990229406d5e949151cc28d8d8799b9</link>
      <guid>http://securityratty.com/article/4990229406d5e949151cc28d8d8799b9</guid>
      <description><![CDATA[Recently I have received a number of questions seeking preparation tips and insights for the CISA and CISSP certifications. I hold both of these certifications, and passed them both on the first...]]></description>
      <content:encoded><![CDATA[<p>Recently I have received a number of questions seeking preparation tips and insights for the CISA and CISSP certifications. I hold both of these certifications, and passed them both on the first attempt using very different preparation approaches. I took the CISA first, and based on a few lessons learned, I radically changed my preparation plan for the CISSP.<br />
<br />
FYI, the official preparation information, qualification requirements, exam requirements, etc. can be found at:</p>
<ul>
<li>Certified Information Systems Auditor (CISA) : <a href="http://www.isaca.org/cisa/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.isaca.org/cisa/');" target="_blank">http://www.isaca.org/cisa/</a></li>
<li>Certified Information Systems Security Professional : <a href="https://www.isc2.org/cissp" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://www.isc2.org/cissp');">https://www.isc2.org/cissp</a></li>
</ul>
<p><strong>Are You Ready ?</strong><br />
A few basic questions to ask yourself to gauge how ready you are:</p>
<ul>
<li>Do I meet the spirit, and not just the letter, of the experience requirements ?</li>
<li>Has there been sufficient diversity in my experience ?</li>
</ul>
<p></p>
<div>Both of these exams cover a very broad spectrum of subjects. It is my personal belief that the experience requirements exist as an aid to whittle test takers down to candidates who have the professional experiences required to be successful, and to discourage people from taking the exams before they are ready. If you truly meet the background requirements, then you should have had some contact with many of the core topic areas for the exam.</div>
<p></p>
<div>If you are looking at the core content of the examination, and do not believe that you really have the breadth of exposure to be able to describe and discuss each domain at a high level, then you may be better served by delaying the exam in favor of working with your management to gain broader professional experience.</div>
<p><strong>Five Step Approach to CISA or CISSP Exam Preparation</strong></p>
<ol>
<li>Perform an initial benchmark and assessment of your readiness</li>
<li>Read a &#8220;survey&#8221; level preparation guide cover to cover</li>
<li>Perform a secondary benchmark, and compare your readiness</li>
<li>Review official, or &#8220;deep dive&#8221;, preparation materials on areas identified as your weaknesses</li>
<li>Re-benchmark, and repeat targeted reviews until ready</li>
</ol>
<p></p>
<div>For the first certification that I prepared for, I did not perform the first three steps outlined above. I went directly to the official source materials and began trying to review them cover to cover. I passed the exam, but I also spent a lot of time &amp; energy reviewing things that I already knew &#8220;well enough&#8221;, and was burned out when reviewing the areas which could have been richer learning opportunities. No matter what your professional background, no one knows-it-all or does-it-all, so there is always  an opportunity to learn new things while you are preparing for the certification exam. The goal of this five step approach is to focus your time where you have the greatest learning opportunities. Hopefully this focuses your time and energy in the most rewarding way.</div>
<p></p>
<div><strong>Performing the Benchmarks</strong></div>
<div>For the Benchmarks, I like to complete a timed half-length or full-length examination.</div>
<p></p>
<div>It is my feeling that a half-length exam is long enough that fatigue, maintaining focus, and pace are all stressed, as they will be on examination day. This of course requires access to a large set of test questions or sample tests, preferably with explanations of incorrect answers. In addition to commercial third-party test preparation tools, there are good (and free) test preparation quizzes available from <a href="http://www.cccure.org/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.cccure.org/');">www.cccure.org</a>.</div>
<p></p>
<div><strong>Survey Materials</strong></div>
<div>I find the &#8220;Exam Cram&#8221; series to be very useful survey literature. I purchase books from this series when I want a high-level and quick handling of an entire subject matter area. As a result, I own survey books from the series in topic areas which I have no intention of pursuing certification for. Obviously the books I recommend for these certifications are:</div>
<p><a href="http://www.amazon.com/gp/product/078973446X?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=078973446X" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/078973446X?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=078973446X');"><img src="http://artofinfosec.com/wp-content/uploads/cissp_exam_cram.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=078973446X" border="0" alt="" width="1" height="1" /> <a href="http://www.amazon.com/gp/product/0789732726?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0789732726" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/0789732726?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0789732726');"><img src="http://artofinfosec.com/wp-content/uploads/cisa_exam_cram.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=0789732726" border="0" alt="" width="1" height="1" /></p>
<div><strong>Deep Dive Materials</strong></div>
<div>There are exam preparation materials available from a variety of sources that fit the bill in this area. What we are looking for are books that contain solid coverage of the areas where benchmarking has shown the most significant need for improvement. In addition to the materials from (ISC)2 and ISACA that I list below, consult your local library - often they will have books that fit the bill. (And, of course, consider arranging a donation of good materials if they do not.)</div>
<p><a href="http://www.amazon.com/gp/product/0849382319?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0849382319" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/0849382319?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0849382319');"><img src="http://artofinfosec.com/wp-content/uploads/official_cissp.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=0849382319" border="0" alt="" width="1" height="1" /> <a href="http://www.amazon.com/gp/product/1933284935?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1933284935" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/1933284935?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1933284935');"><img src="http://artofinfosec.com/wp-content/uploads/cisa_review_2008.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=1933284935" border="0" alt="" width="1" height="1" /></p>
<div><strong>Final Thoughts</strong></div>
<div>Good luck on your journey toward Information Security or Audit certification. One word of caution: Make sure that you have realistic expectations about what actually being certified will mean. Although I do think being certified helps a person establish credibility more quickly, and is helpful when searching for new employment, often people are underwhelmed by the &#8220;Congratulations, that&#8217;s nice&#8221; from their current employer. If your expectation is that a big raise, bonus, promotion, etc. is hinging on your being certified, then I would strongly encourage you to reality-check that with peers in your organization.</div>
<p></p>
<div>Cheers, Erik</div>
<p></p>
<p><a href="http://artofinfosec.com/60/cisa-and-cissp-preparation/" >CISA and CISSP Preparation</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/351541992" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 09:14:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/exam">exam</category>
      <category domain="http://securityratty.com/tag/exam requirements">exam requirements</category>
      <category domain="http://securityratty.com/tag/cissp exam preparation">cissp exam preparation</category>
      <category domain="http://securityratty.com/tag/half-length exam">half-length exam</category>
      <category domain="http://securityratty.com/tag/exam cram series">exam cram series</category>
      <category domain="http://securityratty.com/tag/certification exam">certification exam</category>
      <category domain="http://securityratty.com/tag/exam preparation materials">exam preparation materials</category>
      <category domain="http://securityratty.com/tag/preparation materials">preparation materials</category>
      <category domain="http://securityratty.com/tag/cissp">cissp</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/351541992/">CISA and CISSP Preparation</source>
    </item>
    <item>
      <title><![CDATA[The Not-So-Sweet Life of Supplicants]]></title>
      <link>http://securityratty.com/article/a7513e6c4a71a61081c2aa1aef143439</link>
      <guid>http://securityratty.com/article/a7513e6c4a71a61081c2aa1aef143439</guid>
      <description><![CDATA[There are plenty of integration and configuration challenges when we look at 802.1X , but one of the most notable issues is choosing the right supplicant to best serve your end users
Some of the major...]]></description>
      <content:encoded><![CDATA[<P>There are plenty of integration and configuration challenges when we look at <A title="802.1X Primer" href="http://securityuncorked.squarespace.com/security-uncorked/2008/4/2/what-is-8021x-heres-a-technology-primer-for-you.html">802.1X</A>, but one of the most notable issues is <strong>choosing the right <A title="What is a supplicant?" href="http://securityuncorked.squarespace.com/security-uncorked/2008/6/5/know-the-difference-between-a-nac-client-and-a-1x-supplicant.html">supplicant</A> to best serve your end users</strong>. </P>
<P>Some of the major obstacles we face with 802.1X center around creating a smooth end user experience.&nbsp; We, as integrators, have the distinct ability to make &#8216;whatever&#8217; work- we find a way. But, what I hear most from my customers is &#8220;<em>it has to be easy for the end user.&#8221;</em>&nbsp; (Sometimes they go on a little further, but I&#8217;ll leave it at that.)</P>
<P><strong>Why does it matter?</strong> </P>
<P>Wireless, wireless, wireless. Although&nbsp;wired 1X is&nbsp;popular&nbsp;with our customer-base, the world isn&#8217;t quite flocking to it yet. However, 802.1X is certainly the best way to increase security and ease management of wireless networks. It&#8217;s standard, it&#8217;s flexible, it&#8217;s widely-supported by devices and endpoints and it eliminates the need for pre-shared keys or secondary passwords. It&#8217;s what most enterprises, government&nbsp;and educational organizations are implementing now, so it&#8217;s important. </P>
<P><strong>What are some of the problems?</strong> </P>
<P>The end user will have some adjustments to make, and network admins and support desks aren&#8217;t always thrilled with the propect of re-training users for these expectations.</P><span>
<ul>
<li>First of all, the <span style="TEXT-DECORATION: underline">time to authenticate</span> and connect to the network is going to drastically increase. I say drastically- it&#8217;s only a few seconds- but I&#8217;m sure it feels like minutes to a new 1X end user. 
<li>In addition, we&#8217;re in a transition and growing period where we&#8217;re trying to integrate and authenticate multiple pieces- the machine and/or user as well as any other clients residing on the endpoint, so there can be <span style="TEXT-DECORATION: underline">single-sign-on issues</span>. Not SSO in the traditional sense, but single-1X-sign-on vs logging in to authenticate and open the port, logging in again to get to network resources (such as Novell). 
<li>There may also be issues supporting <span style="TEXT-DECORATION: underline">multiple profiles</span>, so end users may need to understand the concept of enabling 802.1X on an interface at their office, then disabling it when they go home. 
<li>Or perhaps, in a shared or lab-type environment, we may have multiple unique users logging in to the same endpoint device, so we have to make it easy for end users to <span style="TEXT-DECORATION: underline">log off so there&#8217;s a forced re-auth</span> for the next user. </li>
</ul>
<P>There are plenty more, but this hits on the major concerns of most organizations planning to implement 802.1X (wired or wireless).</span></P>
<P><strong>How do we address the issues?</strong></P>
<P>There are different ways to deal with the complexity of supplicant and end-user interactions. First and foremost, a good <span style="TEXT-DECORATION: underline">end user training</span> program will be needed. There&#8217;s a learning curve, but eventually end users will get it- we just have to make sure the transition for &#8216;now&#8217; to &#8216;got it&#8217; is smooth and doesn&#8217;t overwhelm help desk resources. </P>
<P>As the operating systems and clients progress, we&#8217;re seeing <span style="TEXT-DECORATION: underline">more integration</span> and the ability to share 802.1X information between disparate pieces of the endpoint. </P>
<P>In the meantime, there are also <span style="TEXT-DECORATION: underline">3rd-party supplicants</span> that can ease several of the pains. <A class=offsite-link-inline title="Cisco SSC" href="http://www.cisco.com/en/US/products/ps7034/index.html" target=_blank>Cisco&#8217;s&nbsp;Secure Services&nbsp;Client</A>&nbsp; (acquired from Meetinghouse&#8217;s Aegis supplicant) and <A class=offsite-link-inline title="Juniper OAC" href="http://www.juniper.net/products_and_services/aaa_and_802_1x/odyssey/index.html" target=_blank>Juniper&#8217;s Odyssey Access Client</A>&nbsp; (acquired from Funk) both offer options and configurations not currently available in native OS supplicants. (For example, both offer the GINA shim for integrating Windows 1X login with Novell as well as multiple profile support.) Although I haven&#8217;t tried it, my understanding is you can still operate both of these clients independent of the controllers provided from the same vendor. </P>
<P><strong>Is it a deal-killer?</strong> </P>
<P>It can be. The struggle to provide a smooth transition for end users is often a deal-killer for organizations looking at deploying 802.1X. Although there are ways to combat most of these obstacles; often the time, planning and money required to&nbsp;proceed make it unattractive enough to abandon the project. In most cases, the more heterogeneous the endpoint environment is, the less attractive the solution becomes. In an all-Microsoft environment, you can have an 802.1X framework up in a matter of hours. With a mix of authentication directories, endpoint OSs and user expectations, you could spend weeks or&nbsp;months ironing out the details.</P>
<P><strong>The good news.</strong></P>
<P>Yes, there&#8217;s some good news here. The increased adoption of 802.1X is continually leading to increased integration of the software, operating systems and clients on endpoints. While 802.1X may never reach &#8216;plug-and-play&#8217; status, pretty soon the integration will reach a point where configuration is simplified enough for more wide-spread adoption, even in the most diverse environments. </P>
<P>Just hang tight, we&#8217;ll get there!</P>
<P># # #</P>
]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 11:23:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/end-user interactions">end-user interactions</category>
      <category domain="http://securityratty.com/tag/user experience">user experience</category>
      <category domain="http://securityratty.com/tag/machine andor user">machine andor user</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/multiple unique users">multiple unique users</category>
      <category domain="http://securityratty.com/tag/user expectations">user expectations</category>
      <category domain="http://securityratty.com/tag/endpoint">endpoint</category>
      <category domain="http://securityratty.com/tag/expectations">expectations</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/7/23/the-not-so-sweet-life-of-supplicants.html">The Not-So-Sweet Life of Supplicants</source>
    </item>
    <item>
      <title><![CDATA[Heinemann-Raintree Reports a Year And A Half Old Breach in Their E-commerce Website]]></title>
      <link>http://securityratty.com/article/55e4bea851701266a381a565c05309c4</link>
      <guid>http://securityratty.com/article/55e4bea851701266a381a565c05309c4</guid>
      <description><![CDATA[Heinemann-Raintree, publishers of PreK-Secondary nonfiction books for the library and classroom, maintains websites where customers can purchase products online. In January 2007, an unauthorized...]]></description>
      <content:encoded><![CDATA[Heinemann-Raintree, publishers of PreK-Secondary nonfiction books for the library and classroom, maintains websites where customers can purchase products online. In January 2007, an unauthorized person was able to obtain access to the database that contains the product information used by the Heunemann-Raintree websites. Heinemann-Raintree informed their customers about this breach in a letter sent in [...]]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 18:24:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/maintains websites">maintains websites</category>
      <category domain="http://securityratty.com/tag/prek-secondary nonfiction books">prek-secondary nonfiction books</category>
      <category domain="http://securityratty.com/tag/websites">websites</category>
      <category domain="http://securityratty.com/tag/purchase products online">purchase products online</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/obtain access">obtain access</category>
      <category domain="http://securityratty.com/tag/product information">product information</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/letter">letter</category>
      <source url="http://cyberinsecure.com/heinemann-raintree-reports-a-year-and-a-half-old-breach-in-their-e-commerce-website/">Heinemann-Raintree Reports a Year And A Half Old Breach in Their E-commerce Website</source>
    </item>
  </channel>
</rss>
