<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: silent]]></title>
    <link>http://securityratty.com/tag/silent</link>
    <description></description>
    <pubDate>Mon, 09 Jun 2008 07:34:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Silent Break-Ins: How Technology Compromises Physical Security Too]]></title>
      <link>http://securityratty.com/article/037bb160455e2a7c95f039f67e29cad0</link>
      <guid>http://securityratty.com/article/037bb160455e2a7c95f039f67e29cad0</guid>
      <description><![CDATA[I could have used this technique last night I got home to my apartment in Oakland at 11:30, only to realize Id left my keys in Sacramento. Two hours later a locksmith finally came and charged me $100...]]></description>
      <content:encoded><![CDATA[<p>I could have used this technique last night &#8212; I got home to my apartment in Oakland at 11:30, only to realize I&#8217;d left my keys in Sacramento. Two hours later a locksmith finally came and charged me $100 to let me in my own apartment. Expensive? Maybe, but comparable to other services, and compared to the havoc that a lock-breaker could wreak if he was trying to use his talents for crime rather than service, it&#8217;s a small price.</p>
<p>It&#8217;s kind of frightening to see how quickly a skilled lock-picker can jimmy a lock and get in. But new technology makes it even simpler &#8212; apparently all you need is a good telephoto lens to break in to someone&#8217;s house &#8212; just wait till they leave their keys out on a table, snap a picture, and take it to an unethical key maker, and wha-la, a perfect replica:</p>
<blockquote><p><span id="intelliTXT"> &#8220;We built our key duplication <a rel="nofollow" class="iAs" style="border-bottom:0.075em solid darkgreen important;font-weight:normal;font-size:100%;text-decoration:underline;padding-bottom:1px;color:darkgreen important;background-color:transparent important;" target="_blank" href="http://www.physorg.com/news144519246.html#">software</a> system to show people that their keys are not inherently secret,&#8221; said Stefan Savage, the <a rel="nofollow" class="iAs" style="border-bottom:0.075em solid darkgreen important;font-weight:normal;font-size:100%;text-decoration:underline;padding-bottom:1px;color:darkgreen important;background-color:transparent important;" target="_blank" href="http://www.physorg.com/news144519246.html#">computer</a> science professor from UC San Diego&#8217;s Jacobs School of Engineering who led the student-run project. &#8220;Perhaps this was once a reasonable assumption, but advances in digital imaging and optics have made it easy to duplicate someone&#8217;s keys from a distance without them even noticing.&#8221;<br />
</span></p>
<p><span id="intelliTXT">Professor Savage presents this work on October 30 at ACM&#8217;s Conference on Communications and Computer Security (CCS) 2008, one of the premier academic computer security conferences. </span></p></blockquote>
<p><a rel="nofollow" target="_blank" href="http://www.secureconsulting.net/2008/11/remote_key_copying_eep.html">Read</a> the <a rel="nofollow" target="_blank" href="http://www.physorg.com/news144519246.html">full article</a> here.</p>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 12:17:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/someones keys">someones keys</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/lock">lock</category>
      <category domain="http://securityratty.com/tag/computer science professor">computer science professor</category>
      <category domain="http://securityratty.com/tag/unethical key maker">unethical key maker</category>
      <category domain="http://securityratty.com/tag/lock-picker">lock-picker</category>
      <category domain="http://securityratty.com/tag/lock-breaker">lock-breaker</category>
      <category domain="http://securityratty.com/tag/apartment">apartment</category>
      <category domain="http://securityratty.com/tag/reasonable assumption">reasonable assumption</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/450105958/">Silent Break-Ins: How Technology Compromises Physical Security Too</source>
    </item>
    <item>
      <title><![CDATA[Flash 10 Fixes Clickjacking Flaw]]></title>
      <link>http://securityratty.com/article/7466eca5f91107c96844d79b2e110ddd</link>
      <guid>http://securityratty.com/article/7466eca5f91107c96844d79b2e110ddd</guid>
      <description><![CDATA[Not long after &quot;clickjacking&quot; attacks appeared several weeks ago it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature....]]></description>
      <content:encoded><![CDATA[Not long after <a href="http://securitywatch.eweek.com/vulnerability_research/clickjacking_browser_attack_details_emerge.html">"clickjacking" attacks appeared several weeks ago</a> it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature. This feature has been modified in <a href="http://www.eweek.com/c/a/Application-Development/Adobe-Releases-Flash-Player-10/">the new Flash 10 player</a> to address the problem.

The problem is clipboard access. By default, Flash 9 allowed a Flash program to read and write to the clipboard. "Clickjacking" attacks took advantage of this to persistently stuff a value. usually a malicious URL, into the clipboard, in the hope the user would visit it. The attack is as cross-platform as Flash, working on Macs as well as Windows.

In Flash 10 the clipboard methods will only work when called through ActionScript which originates with a user action, like pressing a button. No longer will a silent Flash app be able to hijack the clipboard completely without the user noticing.

This change was just one of <a href="http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html">many security changes in the Flash 10 player</a>. Changes in how Flash handles policy files means that developers will have to address their use of them. Errors on socket connect() calls will be handled differently. And much in the same philosophy as with clipboards, file uploads and downloads may only occur in script that begins with a user action. There are other changes as well.

The flip side of this fix is that it is not implemented in Flash 9. This means that the only way to escape clickjacking attacks is to upgrade to Flash 10.
<p><a href="http://feedads.googleadservices.com/~a/FtymtK-1YQe4YgTHIvGH8JR05Ck/a"><img src="http://feedads.googleadservices.com/~a/FtymtK-1YQe4YgTHIvGH8JR05Ck/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/58cVGsWzlbk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 10:07:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/silent flash app">silent flash app</category>
      <category domain="http://securityratty.com/tag/flash program">flash program</category>
      <category domain="http://securityratty.com/tag/clipboard">clipboard</category>
      <category domain="http://securityratty.com/tag/clipboard methods">clipboard methods</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/user action">user action</category>
      <category domain="http://securityratty.com/tag/clipboard access">clipboard access</category>
      <category domain="http://securityratty.com/tag/clipboard completely">clipboard completely</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/58cVGsWzlbk/flash_10_fixes_clickjacking_flaw.html">Flash 10 Fixes Clickjacking Flaw</source>
    </item>
    <item>
      <title><![CDATA[Disk Containing Data on 17 Million T-Mobile Customers Missing, The Data Is For Sale]]></title>
      <link>http://securityratty.com/article/b7d7d76e0604b84cbe7c11b2c852ec6f</link>
      <guid>http://securityratty.com/article/b7d7d76e0604b84cbe7c11b2c852ec6f</guid>
      <description><![CDATA[In 2006, 17 million German customer records were stolen from T-Mobile, a mobile network operator headquartered in Bonn, Germany. T-Mobile has admitted the incident where stolen customer records...]]></description>
      <content:encoded><![CDATA[In 2006, 17 million German customer records were stolen from T-Mobile, a mobile network operator headquartered in Bonn, Germany. T-Mobile has admitted the incident where stolen customer records included names, addresses, phone numbers, dates of birth and email addresses.
Silent about the data loss for more than two years, the company published its version of events [...]]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 07:44:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/t-mobile">t-mobile</category>
      <category domain="http://securityratty.com/tag/email addresses">email addresses</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/mobile network operator">mobile network operator</category>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/customer records">customer records</category>
      <category domain="http://securityratty.com/tag/birth">birth</category>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <source url="http://cyberinsecure.com/disk-containing-data-on-17-million-t-mobile-customers-missing-the-data-is-for-sale/">Disk Containing Data on 17 Million T-Mobile Customers Missing, The Data Is For Sale</source>
    </item>
    <item>
      <title><![CDATA[All Quiet on the CA Front]]></title>
      <link>http://securityratty.com/article/a644ba10404315a6034969475c3def4a</link>
      <guid>http://securityratty.com/article/a644ba10404315a6034969475c3def4a</guid>
      <description><![CDATA[If youve read the blog, you know that we follow the Perils of CA with much amusement. Honestly, you couldnt make up the stuff that Sanjay Kumar et al were and apparently are still making headlines...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px; border-right-width: 0px" height="113" alt="sanjay kumar" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/sanjay-kumar.jpg" width="240" align="left" border="0" /> If you&#8217;ve read the blog, you know that we follow the Perils of CA with much amusement. Honestly, you couldn&#8217;t make up the stuff that <a href="http://java.sys-con.com/node/666065" target="_blank">Sanjay Kumar</a> et al were and apparently are still making headlines with <a href="http://digitaldaily.allthingsd.com/20080904/sanjay-kumar-goes-to-white-castle-prison/" target="_blank">&#8220;35-day months&#8221;</a>, accusations that founder Charles Wang knew and was part of the whole mess, a former US senator involved too, Sanjay&#8217;s unbelievable <a href="http://www.networkworld.com/news/2007/041307-cas-kumar-ordered-to-pay.html" target="_blank">$1 billion in restitution</a>&#8230;and <a href="http://channelmarker.blogs.techtarget.com/2008/09/03/kumar-accuses-damato-ranieri-in-ca-coverup/" target="_blank">the list goes on</a>. (<a href="http://www.nytimes.com/2006/04/25/technology/25fraud.html" target="_blank"><em>img from NYTimes.com</em></a>)</p>
<p>But I am reminded that it&#8217;s not just the titillating stuff that&#8217;s of interest. CA is still one of the Big 4 and up until a couple of years ago making headlines with some major and strategic purchases in our space &#8211; such as buying <a href="http://news.cnet.com/CA-to-buy-Concord-Communications/2100-1014_3-5658423.html" target="_blank">Concord for its e-Health software</a> in 2005 and <a href="http://www.itnewsonline.com/showstory.php?storyid=2339&amp;scatid=1&amp;contid=3" target="_blank">Wily Technology</a> in 2006.</p>
<p>I recently ran across a <a href="http://blogs.the451group.com/techdeals/" target="_blank">451 Group report</a>, &#8220;<a href="http://blogs.the451group.com/techdeals/investment-banking/ca-ghosts-of-deals-past/" target="_blank">CA: ghosts of deals past</a>&#8221; by Brenon Daly (if you haven&#8217;t read one of his takes on the M&amp;A market, you don&#8217;t know what you&#8217;re missing) that showed quantitatively just how much the acquisitions had slowed down.</p>
<p>2003 &#8211; 4</p>
<p>2004 &#8211; 3</p>
<p>2005 &#8211; 6</p>
<p>2006 &#8211; 6</p>
<p>2007 &#8211; 0</p>
<p>2008 &#8211; 0 (so far)</p>
<p>Two or three years ago (I still have the slide in our presentations), it seemed like you couldn&#8217;t go a month or two without hearing about the latest acquisition by the Big 4 &#8211; to either fill gaps in their monolithic portfolios or <a href="http://www.networkworld.com/newsletters/nsm/2008/092908nsm2.html?nladname=100108networksystemsmanagemental&amp;code=nlnsm162167" target="_blank">take out a growing threat</a>, which had built some good technology. This should sound very familiar to anyone (like me) who rubbed up against WorldCom. Growth (in revenue and technology) by acquisition. Buy your own revenue and don&#8217;t worry about the niggling details like integration.</p>
<p>But we&#8217;ve certainly seen the acquisition trend slow across the board. HP, after its mega-purchase of <a href="http://www.networkworld.com/weblogs/management/012012.html" target="_blank">Mercury Interactive in 2005 for $4.5 billion</a>, for example, went relatively silent on the acquisition front in our space. Perhaps, as it turns out, because they were too busy preparing for the even bigger <a href="http://bigtech.blogs.fortune.cnn.com/2008/05/12/why-hp-is-smart-to-gamble-on-eds/" target="_blank">purchase of EDS for $13.9 billion</a> (and <a href="http://www.networkworld.com/news/2008/091508-hp-announces-24600-layoffs-in.html?hpg1=bn" target="_blank">the layoffs, 24,600 and counting</a>, which in this worsening economy are probably just starting).</p>
]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 11:31:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/acquisition">acquisition</category>
      <category domain="http://securityratty.com/tag/acquisition front">acquisition front</category>
      <category domain="http://securityratty.com/tag/acquisition trend slow">acquisition trend slow</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wily technology">wily technology</category>
      <category domain="http://securityratty.com/tag/founder charles wang">founder charles wang</category>
      <category domain="http://securityratty.com/tag/billion">billion</category>
      <category domain="http://securityratty.com/tag/strategic purchases">strategic purchases</category>
      <category domain="http://securityratty.com/tag/brenon daly">brenon daly</category>
      <source url="http://blog.sciencelogic.com/all-quiet-on-the-ca-front/10/2008">All Quiet on the CA Front</source>
    </item>
    <item>
      <title><![CDATA[It Was Sposed to Be So Eaaasy]]></title>
      <link>http://securityratty.com/article/5714e6ea5723d4a1d18b692711ca3452</link>
      <guid>http://securityratty.com/article/5714e6ea5723d4a1d18b692711ca3452</guid>
      <description><![CDATA[Earlier this year, I gave a talk with on Breaking Web Services with Brian Chess at RSA. We pointed out that adding security into Web services is an exercise left to the implementer, the standards...]]></description>
      <content:encoded><![CDATA[<p>Earlier this year, I gave a <a href="http://1raindrop.typepad.com/1_raindrop/2008/04/rsa-debrief-p-1.html">talk</a> with on Breaking Web Services with Brian Chess at RSA. We pointed out that adding security into Web services is an exercise left to the implementer, the standards bodies and vendors give you some primitives, but it is still up to you to figure out all of the items on the <a href="http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf">Web services security checklist</a>&#160;should work together in a cohesive system. Needless to say, there are many ways to shoot yourself in the foot.</p><br /><div>So during our talk, someone from Oracle stands up and says, &quot;hey, you guys are making this stuff sound hard. Its not hard we support WS-Security...&quot; etc. Again, the whole point of our presentation was *not* that there are not very interesting general purpose security capabilities in Web services, our point was that you need to figure out the architecture yourself, and then bend the tools to your will. Oh, and deliver on time.</div><br /><div>So imagine my surprise, when I read this article <a href="http://www.ddj.com/database/209400693">&quot;Digitally Signing and Verifying Messages in Web Services&quot;&#160;</a>which talks about using Oracle&#39;s WSM tools to sign Web service messages and verify signatures in Web service messages, but only addresses integrity - absolutely nowt on authenticity! Integrity is important, but there are lots of times when it is not enough. Many times your service needs to be concerned with replay attacks, authentication policies and so on. To deal with those things, we would typically add policies and capabilities for timestamps, nonces and other primitives into the signature block, but the article is silent on those things. (Rad Mark O&#39;Neill&#39;s <a href="http://xmlnetworking.blogspot.com/2008/08/digitally-signing-and-verifying.html">post</a> on this as well)</div><br /><div>Its not about _can_ the standards do something or other, I mean given the right resources the standards can put a monkey on the moon, its about what use cases have they engineered in and what is supported in the tools today. I firmly believe SAML has such great adoption across the industry because they have a use case centric view and so gave the vendors something to engineer and optimize for. I think we&#39;ll still get there in WS-Security and other areas as well, but the use cases are not built into the spec (as with SAML) and so its taking longer.</div><br /><div>One of our points in the talk was - we want you vendors to do your job better and instead of shipping a box Legos, ship a Lego gas station, a Lego airport, and so on. Connect some dots for your customers.&#160;</div><br /><div>What I see in <a href="http://arctecgroup.net/training.htm">training</a> on this topic, is sort of the following - 1) Do I need Web service security? 2) Oh ok, well can I get by with SSL? 3) Oh wait that doesn&#39;t actually protect my assets, can I just use WS-Security? 4) Oh wait, WS-Security isn&#39;t just a checkbox for security, I need to figure out timestamps, nonces, signatures, encryption policies and so on.&#160;And finally 5) How do I accomplish this?</div><br /><div>Once we get to step 5 then the real work can begin. Its not easy to get a lot of developers through all of this, and again this is before the real work begins. Even once the lead developers and architects figure this out, there is still the little matter of transitioning it to the rest of the team.</div><br /><div>I remember I was working with an enterprise architect several years ago, and he bought a Web service XML gateway like <a href="http://www.vordel.com/">Vordel</a> to add WS-Security support into his Web services apps, but he didn&#39;t even buy it as a runtime tool, he bought it as Security API, the runtime enforcement in his opinion was a bonus! He said in effect, well I know I need to do this, but I can&#39;t expose all these security primitives directly to my developers.</div><br /><div>So yeah, I wish it was easier, but in my experience its not right now. Its not about raw capabilities its about use case realization. I think learning from what has worked well is the way to go. SAML&#39;s use case centric approach is one that has.</div><br />]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 03:12:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ws-security">ws-security</category>
      <category domain="http://securityratty.com/tag/support ws-security">support ws-security</category>
      <category domain="http://securityratty.com/tag/web service security">web service security</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/primitives">primitives</category>
      <category domain="http://securityratty.com/tag/security primitives directly">security primitives directly</category>
      <category domain="http://securityratty.com/tag/ws-security support">ws-security support</category>
      <category domain="http://securityratty.com/tag/security api">security api</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/it-was-sposed-to-be-so-eaaasy.html">It Was Sposed to Be So Eaaasy</source>
    </item>
    <item>
      <title><![CDATA[When turning updates off really doesnt]]></title>
      <link>http://securityratty.com/article/ad6bfd3501bc1cd24c641aab64e8f592</link>
      <guid>http://securityratty.com/article/ad6bfd3501bc1cd24c641aab64e8f592</guid>
      <description><![CDATA[In any business dealings, if you cant trust the company to do what they say they will do, You go elsewhere right? Its your decision. Not in this instance folks


clipped from windowssecrets.com

Youll...]]></description>
      <content:encoded><![CDATA[<div > In any business dealings, if you cant trust the company to do what they say they will do,<br/>You go elsewhere right?<br/>Its your decision. Not in this instance folks. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/9d9b6101-4fcd-4b38-800c-4f4f98154898/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://windowssecrets.com/comp/080814" href="http://windowssecrets.com/comp/080814" style="font-size: 11px;">windowssecrets.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><B><br />
You&#8217;ll get a new Windows Update, like it or not<br />
</B></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
This time, Microsoft is being more up-front about its forthcoming<br />
refresh of Windows Update. For example, product manager Michelle Haven described in a<br />
<A href="http://WindowsSecrets.com/links/$P20d/fee5a4h/?url=blogs.technet.com%2Fmu%2Farchive%2F2008%2F07%2F03%2Fupcoming-update-to-windows-update.aspx" class="nwindow" target="_blank">blog post</A> on July 3 some new features that the upgrade will add.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
The new version will reportedly reduce the time WU takes to scan for and send out new updates. In addition, if you use the online version of WU, and you click an update for more information, the new version will offer you more links with additional details.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
But the Redmond company hasn&#8217;t changed the wording of the Control Panel settings that appear to prevent Windows Update from performing silent downloads — but don&#8217;t.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
In light of these potentially misleading controls, a few tricks on managing Windows Update are just what the doctor ordered.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:31:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/prevent windows">prevent windows</category>
      <category domain="http://securityratty.com/tag/online version">online version</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/redmond company">redmond company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/product manager michelle">product manager michelle</category>
      <category domain="http://securityratty.com/tag/control panel settings">control panel settings</category>
      <category domain="http://securityratty.com/tag/additional details">additional details</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=559">When turning updates off really doesnt</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[On Government Employees, Culture, and Survivability]]></title>
      <link>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</link>
      <guid>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</guid>
      <description><![CDATA[A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert. One thing he said still sticks in my mind...]]></description>
      <content:encoded><![CDATA[<p>A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert.  One thing he said still sticks in my mind (obviously paraphrased):</p>
<blockquote><p>&#8220;The Afghanis, they live in mud huts, they don&#8217;t have electricity, they are stick-people weighing 85 lbs, and to say that we could bomb them into the stone age would be an advancement in their technology level.  But never underestimate these people, they&#8217;re survivors.  They&#8217;ve survived 35 years of warfare, starting with the Soviets, then they fought a civil war before we arrived on the scene.  Never underestimate their ability to survive, and have respect for them because of who they are.&#8221;</p></blockquote>
<p>Today, I feel the same way about government employees, even more so because it&#8217;s an election year:  they&#8217;re survivors.</p>
<p>Now time for what I see is the &#8220;real&#8221; reason why the government is doing badly (if that&#8217;s what you believe&#8211;opinions differ) at security: it&#8217;s all an issue of culture. I have a friend who converted a year ago to a GS-scale employee and took a class on what motivates government employees. Some of these are obvious:</p>
<ul>
<li>Pride at making a difference</li>
<li>Helping people</li>
<li>Supporting a cause</li>
<li>Gaining unique experience on a global-class scope</li>
<li>Job stability</li>
<li>Retirement benefits</li>
</ul>
<p>And one thing is noticeably absent: better pay and personal recognition.  Hey, sounds like me in the army.</p>
<p style="text-align: center;"><em><img src="http://farm2.static.flickr.com/1348/1470902823_4a5145322e.jpg?v=0" alt="The Companion Family Plan to Survival at Home" width="362" height="500" /></em></p>
<p style="text-align: center;"><em>The Companion Family Plan for Survival at Home photo by <a href="http://www.flickr.com/photos/jikan/" target="_blank">Uh &#8230; Bob</a>.</em></p>
<p>Now I&#8217;m not trying to stereotype, but you need to know the organizational behavior pieces to understand how government security works. And in this case, the typical government employee is about as survival-aware as their Afghani counterpart.</p>
<p>Best advice I ever heard from a public policy wonk: the key to survival in this town is to influence everything you can get your hands on and never have your name actually written on anything.</p>
<p>In other words, don&#8217;t criticize, be nice to everybody even though you think they are a jerk, and avoid saying anything at all because you never know when it will be contrary to the political scene.  The Government culture is a silent culture. That&#8217;s why every day amazing things happen to promote security in the Government and you&#8217;ll never hear about it on the outside.</p>
<p>One of the reasons that I started blogging was to counter the naysayers who say that FISMA is failing and that the Government would succeed if they would just buy their product for technical policy compliance or end-to-end encryption.  Sadly, the true heroes in Government, the people who just do their job every day and try to survive a hostile political environment, are giving credit to the critics because of their silence.</p>
<p>Which brings me to my point:</p>
<p>Yes, my name is Rybolov and I&#8217;m a heretic, but this is the secret to security in the Government:  it&#8217;s cultural at all layers of the personnel stack.  Security (and innovation, now that I think about it) needs a culture of openness where it&#8217;s allowable to make mistakes and/or criticize.  Doesn&#8217;t sound like any government&#8211;local, state, or federal&#8211;that I&#8217;ve ever seen.  However, if you fix the culture, you fix the security.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" alt="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to digg" alt="Add 'On Government Employees, Culture, and Survivability' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to reddit" alt="Add 'On Government Employees, Culture, and Survivability' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=On+Government+Employees%2C+Culture%2C+and+Survivability&amp;url=http://www.guerilla-ciso.com/archives/298&amp;version=0.7" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" alt="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Technorati" alt="Add 'On Government Employees, Culture, and Survivability' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/298&amp;t=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" alt="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" alt="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" alt="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo" alt="Add 'On Government Employees, Culture, and Survivability' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines" alt="Add 'On Government Employees, Culture, and Survivability' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=KQw1LJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=KQw1LJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=8UDDwj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=8UDDwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/341552257" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 09:46:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/government employees">government employees</category>
      <category domain="http://securityratty.com/tag/government security">government security</category>
      <category domain="http://securityratty.com/tag/culture">culture</category>
      <category domain="http://securityratty.com/tag/government culture">government culture</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/typical government employee">typical government employee</category>
      <category domain="http://securityratty.com/tag/promote security">promote security</category>
      <category domain="http://securityratty.com/tag/silent culture">silent culture</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/341552257/298">On Government Employees, Culture, and Survivability</source>
    </item>
    <item>
      <title><![CDATA[Waukesha County job applicant data exposed in mailing]]></title>
      <link>http://securityratty.com/article/6efea251f53508bced1039830009ef31</link>
      <guid>http://securityratty.com/article/6efea251f53508bced1039830009ef31</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/13/08

Organization
Waukesha County, Wisconsin

Contractor/Consultant/Branch
Crivello Carlson, S.C

Victims
Job applicants from the year 2006

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/waukesha.jpg" width="149" align="right" height="200"><font size="2"><b>Date Reported: </b><br>7/13/08<br><br><b>Organization: </b><br><a href="http://www.waukeshacounty.gov/">Waukesha County, Wisconsin</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.milwlaw.com/index.aspx">Crivello Carlson, S.C.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Job applicants from the year 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 130"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Job applications including, names, addresses, job and education history, salary, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"More than 130 people who applied for a job with Waukesha County in 2006 had their Social Security numbers, employment and salary information, addresses and phone numbers and other personal information released to one of the women who applied for the job. "<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.jsonline.com/story/index.aspx?id=772046">Milwaukee Journal Sentinel</a> <br><a href="http://www.newrichmond-news.com/articles/index.cfm?id=87905&amp;section=Wisconsin%20News&amp;property_id=19">New Richmond News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Raquel Rutledge, Milwaukee Journal Sentinel<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Taunya Thomas was horrified when she got a call from a stranger who knew almost everything about her.<br><br>The woman on the phone told Thomas she knew her Social Security number, where she lived and worked, how much money she made and where she went to high school and college. She rattled them off, not missing a single digit or fact.<br><br>She promised she wasn't going to use the information.<br><span style="font-style: italic;">[Evan] Yeah.&nbsp; The government body that exposed the information made the promise that "your Social Security number will remain confidential".&nbsp; So much for promises</span>.<br><br>She was calling, she said, because she wanted Thomas and others to know where she had gotten it.<br><br>She hadn't stolen it. <br><br>Waukesha County sent it to her in the mail, along with the same personal information for more than 130 other people who had all applied for a job with the county in 2006.<br><span style="font-style: italic;">[Evan] What's with Wisconsin and mailing confidential information (in error)?&nbsp; This is the third mailing error reported on The Breach Blog coming out of Wisconsin this year.</span><br><br>The woman on the phone, Bernadine Matthews, too had applied for the position as an economic support specialist.<br><br><img src="http://images.quickblogcast.com/95781-88451/matthews.jpg" width="324" border="0"><br><font size="1">This is Matthews displayed holding the applications.&nbsp; Source: Milwaukee Journal Sentinel</font><br><br>When she didn't get it, she filed a complaint with the Equal Employment Opportunity Commission.<br><br>As part of the complaint and the investigation, the EEOC requested copies of all the applications.<br><br>The law firm representing the county, Crivello Carlson, sent the applications to Matthews.<br><span style="font-style: italic;">[Evan] Really?&nbsp; Any second thoughts about the fact that this may put innocent people at risk?</span><br><br>Waukesha County tried to reclaim the documents sent to Matthews, threatening to get a search warrant and send a lawyer to her house, Matthews said.<br><br>When Matthews refused, they insisted she bring the documents to the law firm so they could white-out the private information in the applications.<br><br>Again, Matthews refused.<br><span style="font-style: italic;">[Evan] At what point does Matthews cross a line.&nbsp; The confidential information on those job applications does NOT belong to her.&nbsp; In my opinion, she has no right to maintain possession of the information.&nbsp; For Matthews to knowingly maintain information that does not belong to her almost seems criminal to me.</span><br><br>The applications would be critical to her discrimination suit, she thought.<br><span style="font-style: italic;">[Evan] So risk the disclosure of senstive information belonging to 130 people for your own benefit?&nbsp; If not criminal, it is certainly selfish.</span><br><br>She quickly hired an attorney, copied the documents and sent a set back to the county. She keeps her copies in an oversize safe-deposit box at her bank, she said.<br><span style="font-style: italic;">[Evan] Who authorized her to make copies?&nbsp; The data owners (victims) certainly did not.</span><br><br>"I'm not going to be like the county," Matthews said. "I'm going to protect the privacy of the information in this box. Obviously they didn't give a darn about the applicants' privacy."<br><br>The Waukesha County employment application specifically states it will protect Social Security numbers.<br><br>"Your Social Security Number will remain confidential and will not be copied or released but is required for applicant tracking purposes," the application reads.<br><br><a href="http://www.milwlaw.com/ourpeople/profile.aspx?id=285&amp;name=Raymond%20J.%20Pollen">Ray Pollen</a>, an attorney with Crivello Carlson, at first said it was no mistake that Matthews received the uncensored applications.<br><span style="font-style: italic;">[Evan] So Mr. Pollen sent the information on purpose.&nbsp; Did he stop to think that there might be a problem here?&nbsp; Did it occur to anyone that they should redact the most sensitive information such as Social Security numbers, or names?</span><br><br>He said it was required under federal law that all parties in an EEOC discrimination complaint receive copies of information requested by the agency investigating. He couldn't point to the specific provision.<br><span style="font-style: italic;">[Evan] Does a specific provision exist?&nbsp; I cannot think of a single purpose that a Social Security number would serve in this case.</span><br><br>Several days later, Pollen said the EEOC had no such requirement.<br><br>"The EEOC is silent on the issue," he said.<br><br>Instead it's the state's Equal Rights Division that requires all parties be copied on information requested by the division but even that provision doesn't mandate that attachments - such as the applications - be included. And, Matthew's case was not filed with the state.<br><br>"We followed the state's protocol," Pollen said.<br><br>P.I. asked: So anyone who applies for a job with Waukesha County could have their private information disclosed to a non-governmental third-party?<br>&nbsp;<br>Pollen answered: "We responded to a federal agency's request for information. . . . In my opinion there was no violation of any law or procedure."<br><span style="font-style: italic;">[Evan] Let's give Mr. Pollen the benefit of the doubt.&nbsp; Let's say that there was no violation of any law or procedure here.&nbsp; There certainly seems to be a violation of trust, a violation of good judgment, and a violation of privacy.&nbsp; The "if the law don't state it, then I must be able to do it" mentality is one of the reasons we have so many laws.&nbsp; Maybe if we used a little more common sense.</span><br><br>Taunya Thomas called the release of her information to a stranger shocking. She said at a minimum the county should have notified her that her information had been compromised.<br><br>"I'm devastated that it's that easy for my information to be disclosed," she said. "For someone to call me and tell me where I worked, where I went to school, recite my Social Security number verbatim to me, that's scary."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very frustrating breach to read about.&nbsp; It is frustrating when someone knowingly discloses confidential information and then tries to justify it.&nbsp; Equally frustrating is when a person that has no right to the information refuses to part with it.&nbsp; In the middle of all of this are 130 innocent people.<br><br>I do not claim to know half as much about the law as Mr. Pollen does.&nbsp; His actions may be well within his legal rights for all I know. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/waukesha.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 04:07:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/waukesha county">waukesha county</category>
      <category domain="http://securityratty.com/tag/senstive information">senstive information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/salary information">salary information</category>
      <source url="http://breachblog.com/2008/07/15/waukesha.aspx">Waukesha County job applicant data exposed in mailing</source>
    </item>
    <item>
      <title><![CDATA[Stealing Password Hashes with Java and IE]]></title>
      <link>http://securityratty.com/article/8194d6ab09a249e970bed5125521056a</link>
      <guid>http://securityratty.com/article/8194d6ab09a249e970bed5125521056a</guid>
      <description><![CDATA[OK, I read a lot, I mean a lot on a regular basis. There is a lot of tripe floating about the tubes of the internet and Im always pleased to read a new posting from several folks who buck that trend....]]></description>
      <content:encoded><![CDATA[<p>OK, I read a lot, I mean <b>a lot</b> on a regular basis. There is a lot of tripe floating about the tubes of the internet and I&#8217;m always pleased to read a new posting from several folks who buck that trend. Among which I count John Heasman. He has a great new post on his site about stealing password hashes with Java and Internet Exploder.</p>
<p>From Aut Disce, Aut Discede:</p>
<blockquote><p>Consider for a moment the state of client-side bugs 5 or 6 years ago. Attacks such as this, a multi-stage miscellany of IE and Mediaplayer bugs that resulted in the &#8220;silent delivery and installation of an executable on the target computer, no client input other than viewing a web page&#8221; were reported with regularity. Gradually these type of attack gave way to exploitation of direct browser implementation flaws such as the IFRAME overflow and DHTML memory corruption flaws. So what has become of the multi-stage attacks - have they become redundant? The answer to this, which I&#8217;m sure you can guess, is a resounding &#8220;no&#8221; and will be emphatically demonstrated in my upcoming Black Hat talk &#8220;The Internet is Broken: Beyond Document.Cookie - Extreme Client Side Exploitation&#8221;, a joint double session presentation co-presented by Billy Rios, Nate McFeters and Rob Carter.</p>
<p>As a teaser for that, I&#8217;m going to revisit an old attack - pre-computed dictionary attacks on NTLM - and discuss how we can steal domain credentials from the Internet with a bit of help from Java. I&#8217;m going to split it into two posts. In this post we&#8217;ll apply the attack to Windows XP (a fully patched SP3 with IE7). In my next post we&#8217;ll consider its impact on Windows Vista.</p></blockquote>
<p>For the full article read on.</p>
<p>Why are you still here? Go read it. </p>
<p> <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://heasman.blogspot.com/2008/06/stealing-password-hashes-with-java-and.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=kFHS3D"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=kFHS3D" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=jii6HI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=jii6HI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=fcDSai"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=fcDSai" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=h9BNei"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=h9BNei" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=zcteYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=zcteYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=1UYjFi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=1UYjFi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/307957636" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 07:34:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/internet exploder">internet exploder</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/dictionary attacks">dictionary attacks</category>
      <category domain="http://securityratty.com/tag/password hashes">password hashes</category>
      <category domain="http://securityratty.com/tag/java">java</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/307957636/">Stealing Password Hashes with Java and IE</source>
    </item>
  </channel>
</rss>
