<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sets]]></title>
    <link>http://securityratty.com/tag/sets</link>
    <description></description>
    <pubDate>Mon, 29 Sep 2008 16:42:29 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[AlgoSec upgrades analysis platform to paint big picture of firewall protection ]]></title>
      <link>http://securityratty.com/article/34eb189192e927ac319c0c067dfb68d6</link>
      <guid>http://securityratty.com/article/34eb189192e927ac319c0c067dfb68d6</guid>
      <description><![CDATA[AlgoSec is releasing new software that enables its Firewall Analyzer to simulate the effect multiple firewalls have on traffic, making simpler to determine the net effect of the firewalls and to...]]></description>
      <content:encoded><![CDATA[AlgoSec is releasing new software that enables its Firewall Analyzer to simulate the effect multiple firewalls have on traffic, making simpler to determine the net effect of the firewalls and to streamline their rule sets.]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firewalls">firewalls</category>
      <category domain="http://securityratty.com/tag/effect multiple firewalls">effect multiple firewalls</category>
      <category domain="http://securityratty.com/tag/rule sets">rule sets</category>
      <category domain="http://securityratty.com/tag/net effect">net effect</category>
      <category domain="http://securityratty.com/tag/algosec">algosec</category>
      <category domain="http://securityratty.com/tag/firewall analyzer">firewall analyzer</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/enables">enables</category>
      <category domain="http://securityratty.com/tag/streamline">streamline</category>
      <source url="http://www.networkworld.com/news/2008/112408-algosec.html?fsrc=rss-security">AlgoSec upgrades analysis platform to paint big picture of firewall protection </source>
    </item>
    <item>
      <title><![CDATA[Mamma.com: Insider trading and XSS]]></title>
      <link>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</link>
      <guid>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</guid>
      <description><![CDATA[Mamma.com 's got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked 4064 on Alexa as of today
I won't profess to following...]]></description>
      <content:encoded><![CDATA[<a href="http://mamma.com/" target="_blank">Mamma.com</a>'s got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked <a href="http://www.alexa.com/search?q=mamma.com" target="_blank">4064</a> on <a href="http://www.alexa.com" target="_blank">Alexa</a> as of today.<br />I won't profess to following Mr. Cuban's public life and the occasional antics. Obviously, he's a colorful and popular figure; certainly in Dallas, if not nationally. <br />What follows is not a judgment of Mr. Cuban or his pending legal challenges. I'm sure the process will play itself out accordingly.<br />A quick summary and some reference material:<br />The SEC has <a href="http://www.businessweek.com/the_thread/blogspotting/archives/2008/11/sec_hits_mark_c.html?chan=technology_technology+index+page_top+stories" target="_blank">filed</a> insider trading charges against Mr. Cuban. "According to the SEC, Cuban dumped 600,000 shares, or all of his 6.3% stake, in the search engine Mamma.com (The Mother of All Search Engines), in June 2004 after learning about private financing that the company was proposing. By selling, he avoided losing $750,000, the SEC alleges."<br />The whole issue for Mr. Cuban was <a href="http://blogmaverick.com/2008/11/17/the-sec/" target="_blank">PIPE</a> financing because it's "dilutive to existing shareholders’ stakes."<br />That's the long and the short of the current issue, and again, not my real interest here, with the exception of the bet I made with myself regarding the probable web application security posture of mamma.com. <br />All this talk about a popular site immediately sets off the little bell in my head (I hear it a lot). <span style="font-weight:bold;"><br />"What's wrong with the site?" is always the first question I ask myself.</span> <br /><br />I was not disappointed. <br /><br />Mamma.com exhibits the following issues:<br />1) XSS vulnerability in the <span style="font-style:italic;">utfout<span style="font-weight:bold;"><span style="font-style:italic;"></span></span></span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s1600-h/mamma1.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s320/mamma1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129685521075730" /></a><br /><br />2) XSS vulnerability in the <span style="font-style:italic;">qtype</span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s1600-h/mamma2.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 201px;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s320/mamma2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129978766677474" /></a><br /><br />3) XSS vulnerability in their Mammajobs site at the <span style="font-style:italic;">pid</span> variable. This one's weirder still; if you drop an IFRAME in, it simply redirects to any URL you include in the IFRAME string.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s1600-h/mamma3.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 99px;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s320/mamma3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270130171179660098" /></a><br /><br />4) The prospect of CSRF (rather pointless here given that its just a search engine, but but still defies best practices) appears likely given that mamma.com blindly accepts updates via GET and POST with no sign of a formkey (canary) in sight.<br /><br />I figured it best to stop there, and have submitted all these to Copernic (the Momma parent company). <br />I am however truly disappointed that an enterprise as ambitious and motivated as Momma/Copernic seems to have thrown the baby out with the bath water when it comes to web application security.<br />With regard to Mark Cuban dumping his shares: maybe he was afraid of getting pwned. ;-) All kidding aside, it's a shame that the whimsical and pessimistic thoughts regarding web site security that bounce around in my head inevitably bear themselves out.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html&title=Mamma.com:%20Insider%20trading%20and%20XSS " title="Mamma.com: Insider trading and XSS ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html" title="Mamma.com: Insider trading and XSS ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 06:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mamma">mamma</category>
      <category domain="http://securityratty.com/tag/mark cuban">mark cuban</category>
      <category domain="http://securityratty.com/tag/cuban">cuban</category>
      <category domain="http://securityratty.com/tag/engine">engine</category>
      <category domain="http://securityratty.com/tag/engine mamma">engine mamma</category>
      <category domain="http://securityratty.com/tag/xss vulnerability">xss vulnerability</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/insider">insider</category>
      <category domain="http://securityratty.com/tag/web site security">web site security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Mamma.com: Insider trading and XSS</source>
    </item>
    <item>
      <title><![CDATA[Anti-malware group sets product testing guidelines]]></title>
      <link>http://securityratty.com/article/b16f78c6d466664814bc6b2fea497a69</link>
      <guid>http://securityratty.com/article/b16f78c6d466664814bc6b2fea497a69</guid>
      <description><![CDATA[The Anti-Malware Testing Standards Organization said Monday that its membership had agreed on guidelines and principles for testing anti-malware...]]></description>
      <content:encoded><![CDATA[The Anti-Malware Testing Standards Organization said Monday that its membership had agreed on guidelines and principles for testing anti-malware products.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:14b8752435c450095ed9ce87a25f6df5:QOoDyf94Js0HONWTZL9%2FMVAsmozwp8sIibz4z9unTFOUG%2Fb8nKIYvPaCrDuWYx0nyhpo3WHy%2BNg2'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:06b43279b2e5fe0c5b9e35dd1281cc6d:VkvEyIQ9cHh%2BhtTfwMi6SQ8VRxaxM2qTqATviQ97zhfZYRZZaQoUrUlEs3YkfFyga1SeUSeSyESK4A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5c5b28622019f3a4f2c00ae221757016:NR5TQ4x7AuiFRJAFPZygHVsoDIoe7gMyKcdFo2lHHhEcb203VXtt2nNwmyKJzL1YFEBeLgJ0FuMSUg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bfb08470e5ed3ee3d57c44412ceb7d67:Yw9DGdIS76mggJ1WiBBpHjtE5C%2Fp%2FaKj5XYhowtBf8pfm6PL9gvVvP8g6ZkPaGAQ%2Bl6KqsFBg0zA3g%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=1afe730cdc84fd6038771a04ff241911" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=1afe730cdc84fd6038771a04ff241911" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/anti-malware">anti-malware</category>
      <category domain="http://securityratty.com/tag/anti-malware products">anti-malware products</category>
      <category domain="http://securityratty.com/tag/guidelines">guidelines</category>
      <category domain="http://securityratty.com/tag/standards organization">standards organization</category>
      <category domain="http://securityratty.com/tag/principles">principles</category>
      <category domain="http://securityratty.com/tag/membership">membership</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=1afe730cdc84fd6038771a04ff241911">Anti-malware group sets product testing guidelines</source>
    </item>
    <item>
      <title><![CDATA[Antimalware group sets product testing guidelines ]]></title>
      <link>http://securityratty.com/article/dabf5354869a2312cc6f5c298441d758</link>
      <guid>http://securityratty.com/article/dabf5354869a2312cc6f5c298441d758</guid>
      <description><![CDATA[The Anti-Malware Testing Standards Organization yesterday announced its members, which include more than 15 security firms specializing in combating malicious code, have adopted test principles and...]]></description>
      <content:encoded><![CDATA[The Anti-Malware Testing Standards Organization yesterday announced its members, which include more than 15 security firms specializing in combating malicious code, have adopted test principles and best practices they hope will eventually help unify the industry in the sphere of malware-code testing and reporting.]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/standards organization yesterday">standards organization yesterday</category>
      <category domain="http://securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://securityratty.com/tag/security firms">security firms</category>
      <category domain="http://securityratty.com/tag/test principles">test principles</category>
      <category domain="http://securityratty.com/tag/anti-malware">anti-malware</category>
      <category domain="http://securityratty.com/tag/sphere">sphere</category>
      <category domain="http://securityratty.com/tag/include">include</category>
      <category domain="http://securityratty.com/tag/hope">hope</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <source url="http://www.networkworld.com/news/2008/111108-antimalware-guidelines.html?fsrc=rss-security">Antimalware group sets product testing guidelines </source>
    </item>
    <item>
      <title><![CDATA[Links List 11.7.08]]></title>
      <link>http://securityratty.com/article/005aeccf95461397bcc44aae9976e6f2</link>
      <guid>http://securityratty.com/article/005aeccf95461397bcc44aae9976e6f2</guid>
      <description><![CDATA[Government contractors spill their thoughts about how Obamas historic win will affect the industry. A majority of those questioned agreed to the fact that nothing will change overnight and everything...]]></description>
      <content:encoded><![CDATA[<p>Government <a href="http://www.bisnow.com/washington_dc_tech_news_story.php?p=1744">contractors spill their thoughts</a> about how Obama’s historic win will affect the industry. A majority of those questioned agreed to the fact that nothing will change overnight and everything will occur within 2-3 years. Others expressed thoughts on who will lead procurement and acquisition policy at GSA and OMB, as well as a possible hiring freeze for the government workforce. We’re also waiting to see what will happen to <a href="http://blog.sciencelogic.com/government-sent-home-with-a-c-on-fisma-report-card/08/2008">FISMA</a> and<a href="http://blog.sciencelogic.com/times-up-ipv6-omb-mandate/06/2008"> IPv6</a> compliance going forward as a new administration and new OMB management sets their own agendas and mandates.<strong></strong></p>
<p>Due to the slow economy, most tech companies are being cautious and ratcheting back sales forecasts for software and hardware. <a href="http://blogs.wsj.com/biztech/2008/10/31/how-to-survive-the-downturn-sell-tech-to-bankruptcy-lawyers/?mod=djemTECH">The exception: Infra-Strategy</a>, a company that operates a group of Web sites that help people find a lawyer and info to deal with bankruptcies, divorces and DUI cases. Visits to the sites are booming – with visits to <a href="http://www.totaldivorce.com/">totaldivorce.com</a>, for example, up 112% in October 2008 (I found the picture on the website particularly compelling). Apparently, in bad times, divorce rates go up. Who knew?</p>
<p>Is it always a recession when it comes to IT Operations? <a href="http://blogs.forrester.com/it_infrastructure/2008/10/how-is-the-econ.html">Companies are constantly trying to find ways to do more with less in IT – reducing costs but keeping the same or even adding functionality</a> – deploying technologies that drive IT consolidation such as mobile and remote access, unified communications and virtualization. Chris Silva of The Forrester Blog for IT Infrastructure &amp; Operations Professionals is looking for a research panel to find out what fellow IT companies are doing to keep their IT budgets in check. To join the research panel visit: <a href="http://itpanel.forrester.com/">http://itpanel.forrester.com/</a>.</p>
<p>The Cloud Computing Monopoly debate continues. O’Reilly Media founder Tim O’Reilly and technology writer Nicholas Carr (of <a href="http://www.computerworld.com/managementtopics/roi/story/0,10801,81045,00.html">“IT Doesn’t Matter”</a> fame/infamy) have been <a href="http://www.informationweek.com/blog/main/archives/2008/11/the_cloud_compu.html?cid=RSSfeed_IWK_ALL">discussing the ‘potential for a single company to achieve monopoly control of the world of cloud computing</a>.’ But what’s even more interesting is the “who will make a lot of money” in cloud computing question.</p>
]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 19:49:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/research panel visit">research panel visit</category>
      <category domain="http://securityratty.com/tag/research panel">research panel</category>
      <category domain="http://securityratty.com/tag/monopoly">monopoly</category>
      <category domain="http://securityratty.com/tag/achieve monopoly control">achieve monopoly control</category>
      <category domain="http://securityratty.com/tag/tech companies">tech companies</category>
      <category domain="http://securityratty.com/tag/omb management sets">omb management sets</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/omb">omb</category>
      <category domain="http://securityratty.com/tag/forrester">forrester</category>
      <source url="http://blog.sciencelogic.com/links-list-11708/11/2008">Links List 11.7.08</source>
    </item>
    <item>
      <title><![CDATA[Quality Assurance in Malware Attacks - Part Two]]></title>
      <link>http://securityratty.com/article/e553d3dda55ead2f3b81e5c89625e5d9</link>
      <guid>http://securityratty.com/article/e553d3dda55ead2f3b81e5c89625e5d9</guid>
      <description><![CDATA[Surprisingly, while opportunistic cybercriminals have long embraced the malware as a service model , and are offering managed lower detection rate services for a customer's malware, or DIY ones where...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPRhE15p3EI/AAAAAAAACRo/-Sf5Kru9mE4/s1600-h/multiple_offline_av_scanners.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPRhE15p3EI/AAAAAAAACRo/L091hcqbjI8/s200-R/multiple_offline_av_scanners.bmp" /></a>Surprisingly, while opportunistic cybercriminals have long embraced the <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">malware as a service model</a>, and are offering managed lower detection rate services for a customer's malware, or DIY ones where the customer can take advantage of <a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">popular tools ported to the Web</a>, others are still trying to innovate at a faddish market niche - <a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">multiple offline AV scanners tools</a> aiming to ensure that their malware doesn't end up in the hands of vendors/researchers.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SPSHXY5GLGI/AAAAAAAACR4/ABWYWxPvTA4/s1600-h/malware_scanning_private.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SPSHXY5GLGI/AAAAAAAACR4/WY7deAhtx_o/s200-R/malware_scanning_private.JPG" /></a>Multiple offline AV scanning tools like this very latest release, naturally using pirated copies of popular antivirus software, are faddish, due to the fact that during the last two years, the underground has been busy working on several paid web based services, that not only make sure vendors and researchers never get the chance to obtain the samples, but also, are already offering scheduled scanning of malware and automatic ICQ/Jabber notifications for QA of the campaign, next to the rest of unique features disintermediating legitimate multiple AV scanning services.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SPSHpQzSpoI/AAAAAAAACSA/XtA3IYSNBAw/s1600-h/AV_scan_paid11.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SPSHpQzSpoI/AAAAAAAACSA/ybwLLGXpNDk/s200-R/AV_scan_paid11.JPG" /></a>Certain features within such services clearly speak for the intentions of the people behind the service. For instance, among one of these features is the ability to fetch a binary from a set of given dropper URLs like malwaredomain.com/binary.exe, the result of the scan can then alert the malware campaigner about the current state of detection.<br />
<br />
What's on these proprietary multiple AV scanning service's to-do list? Let's say anything that a legitimate multiple AV scanning service would never offer, like the following according to one of the services in question : <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SPSICzrSNuI/AAAAAAAACSI/NjGeKZhhV6w/s1600-h/AV_scan_paid22.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SPSICzrSNuI/AAAAAAAACSI/r-v6YSjtC58/s200-R/AV_scan_paid22.JPG" /></a>- DIY heuristic scanning level settings for each of the software in place<br />
- upcoming sets of anti spyware and personal firewalls with detailed statistics of the sandboxing<br />
- behavior-based detection results <br />
<br />
The possibilities for integrating such proprietary multi AV scanning services within the QA process of a malware campaign are countless, and both, the customers and the sellers seem to have realized the potential of this ecosystem.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=y4fzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=y4fzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m4dJM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m4dJM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BysXm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BysXm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LvDTm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LvDTm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4HLmM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4HLmM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QZYsM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QZYsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=epZlm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=epZlm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/420491420" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 03:21:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/malware campaigner">malware campaigner</category>
      <category domain="http://securityratty.com/tag/web based services">web based services</category>
      <category domain="http://securityratty.com/tag/proprietary multiple">proprietary multiple</category>
      <category domain="http://securityratty.com/tag/multiple">multiple</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/multiple offline">multiple offline</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/420491420/quality-and-assurance-in-malware.html">Quality Assurance in Malware Attacks - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Cambridge lab sets quantum key world record]]></title>
      <link>http://securityratty.com/article/4e328e7a882b1e30f6e592c1535fca81</link>
      <guid>http://securityratty.com/article/4e328e7a882b1e30f6e592c1535fca81</guid>
      <description><![CDATA[The hugely promising security technology of Quantum Key Distribution (QKD) has moved an important step closer to commercialization with the announcement by U.K.-based researchers that they can now...]]></description>
      <content:encoded><![CDATA[The hugely promising security technology of Quantum Key Distribution (QKD) has moved an important step closer to commercialization with the announcement by U.K.-based researchers that they can now shift encryption keys around at speeds of 1Mbps.]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shift encryption keys">shift encryption keys</category>
      <category domain="http://securityratty.com/tag/quantum key distribution">quantum key distribution</category>
      <category domain="http://securityratty.com/tag/step closer">step closer</category>
      <category domain="http://securityratty.com/tag/security technology">security technology</category>
      <category domain="http://securityratty.com/tag/1mbps">1mbps</category>
      <category domain="http://securityratty.com/tag/moved">moved</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/speeds">speeds</category>
      <category domain="http://securityratty.com/tag/qkd">qkd</category>
      <source url="http://www.networkworld.com/news/2008/100808-cambridge-lab-sets-quantum-key.html?fsrc=rss-security">Cambridge lab sets quantum key world record</source>
    </item>
    <item>
      <title><![CDATA[University sets up a campus warning network for free ]]></title>
      <link>http://securityratty.com/article/532f402f74efb59fafb0b176f8e8a342</link>
      <guid>http://securityratty.com/article/532f402f74efb59fafb0b176f8e8a342</guid>
      <description><![CDATA[Elon University needed to come up with a campus-wide emergency notification system that integrated with all the possible warning-delivery systems already installed on campus, and managed to pull it...]]></description>
      <content:encoded><![CDATA[Elon University needed to come up with a campus-wide emergency notification system that integrated with all the possible warning-delivery systems already installed on campus, and managed to pull it off for free.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=44788?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=44788?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/campus">campus</category>
      <category domain="http://securityratty.com/tag/elon university">elon university</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/pull">pull</category>
      <source url="http://www.networkworld.com/news/2008/100708-campus-warning-network.html?fsrc=rss-security">University sets up a campus warning network for free </source>
    </item>
    <item>
      <title><![CDATA[Credit-card security standard issued after much debate ]]></title>
      <link>http://securityratty.com/article/01216534647f9456d3a180c9517e56cb</link>
      <guid>http://securityratty.com/article/01216534647f9456d3a180c9517e56cb</guid>
      <description><![CDATA[The Payment Card Industry Security Standards Council, the organization that sets technical requirements for processing credit- and debit-cards, today issued revised security rules, while also...]]></description>
      <content:encoded><![CDATA[The Payment Card Industry Security Standards Council, the organization that sets technical requirements for processing credit- and debit-cards, today issued revised security rules, while also indicating next year it will focus on new guidelines for end-to-end encryption, payment machines and virtualization.]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sets technical requirements">sets technical requirements</category>
      <category domain="http://securityratty.com/tag/security rules">security rules</category>
      <category domain="http://securityratty.com/tag/payment machines">payment machines</category>
      <category domain="http://securityratty.com/tag/end-to-end encryption">end-to-end encryption</category>
      <category domain="http://securityratty.com/tag/credit-">credit-</category>
      <category domain="http://securityratty.com/tag/debit-cards">debit-cards</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/guidelines">guidelines</category>
      <source url="http://www.networkworld.com/news/2008/100108-pci-credit-card.html?fsrc=rss-security">Credit-card security standard issued after much debate </source>
    </item>
    <item>
      <title><![CDATA[Passgen tool from my book]]></title>
      <link>http://securityratty.com/article/10fd1ee17e5b6f22fc7c246edbe0163b</link>
      <guid>http://securityratty.com/article/10fd1ee17e5b6f22fc7c246edbe0163b</guid>
      <description><![CDATA[Way back in 2005, Jesper Johannson and I wrote Protect Your Windows Network . Its still available , and although its product set is now somewhat dated (Windows XP and Server 2003), much of the...]]></description>
      <content:encoded><![CDATA[<p>Way back in 2005, <a target="_blank" href="http://msinfluentials.com/blogs/jesper/">Jesper Johannson</a> and I wrote <em>Protect Your Windows Network</em>. It’s <a target="_blank" href="http://www.amazon.com/dp/0321336437">still available</a>, and although its product set is now somewhat dated (Windows XP and Server 2003), much of the practical advice about security policies, social engineering, security dependencies, and how to think about security remains relevant. That’s because we strove to write something more lasting than a simple configuration guide.</p>  <p>On the CD-ROM accompanying the book we included a tool called Passgen. In the book, we recommended that you maintain separate passwords on every local administrator and service account in your enterprise. This is, of course, almost impossible to manage without something to automate it for you. That’s what Passgen does. The tool generates unique passwords based on known input (an identifier and passphrase you define), sets those passwords remotely, and allows you to retrieve them later.</p>  <p>For a while Jesper maintained a web site for the book, running on a server in his house. His <a target="_blank" href="http://www.comcast.net/terms/subscriber/">ISP</a> changed <a target="_blank" href="http://www.comcast.net/terms/use/">policies</a> and made it impractical to continue running the site. But because the tool is still so useful, I’ve put a copy in my <a target="_blank" href="http://steveriley-ms.spaces.live.com/">SkyDrive</a>—look in the “<a target="_blank" href="http://cid-45497626ab321d20.skydrive.live.com/browse.aspx/Passgen">Passgen</a>” folder.</p>  <p>Also, note that I’ve put a new section in the right-side column, “Resources for you.” Here’s where I’ll keep links to bits and pieces that many of you will find relevant and interesting.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3130067" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 16:42:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/passwords remotely">passwords remotely</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/unique passwords based">unique passwords based</category>
      <category domain="http://securityratty.com/tag/relevant">relevant</category>
      <category domain="http://securityratty.com/tag/security remains relevant">security remains relevant</category>
      <category domain="http://securityratty.com/tag/windows network">windows network</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx">Passgen tool from my book</source>
    </item>
  </channel>
</rss>
