<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: solutions]]></title>
    <link>http://securityratty.com/tag/solutions</link>
    <description></description>
    <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Cisco 7600 OSR Backbone Router]]></title>
      <link>http://securityratty.com/article/a447dc34e61d2770ab6d723a54abcb31</link>
      <guid>http://securityratty.com/article/a447dc34e61d2770ab6d723a54abcb31</guid>
      <description><![CDATA[For our confused CEO blogger over at StreamBase, who thinks an Internetbackbone router is the small $30 device he set up in his home office, here is a photo of a the Cisco 7600 OSR which of course...]]></description>
      <content:encoded><![CDATA[<p style="text-align: left;">For our confused CEO blogger over at StreamBase, who thinks an Internet backbone router is the small $30 device he set up in his home office, here is a photo of a the <a href="http://newsroom.cisco.com/dlls/prod_022001b.html" target="_blank">Cisco 7600 OSR</a> which of course runs <a href="http://www.cisco.com/en/US/products/sw/iosswrel/products_ios_cisco_ios_software_category_home.html" target="_blank">CISCO IOS</a>.</p>
<p style="text-align: center;"><img style="vertical-align: middle;" src="http://newsroom.cisco.com/ts_images/Cisco-7600-OSR-high.jpg" alt="Cisco 7600 OSR" height="600" /></p>
<p style="text-align: left;">The Cisco 7600 OSR consists of a 256 Gbps switching fabric and a 30 million packets per second (mpps) forwarding engine. Its breadth of IP services comes from Cisco IOS, which provides features such as security, enhanced QoS, and destination sensitive services. In addition, the Cisco 7600 OSR allows the migration of existing port adapters from Cisco 7500 series routers, via the Cisco FlexWAN module, giving service providers one the industry&#8217;s widest array of interface options in any single platform. This provides service providers great flexibility in deploying the Cisco 7600 OSR for a variety of applications, protects their investment in existing systems, and gives them a practical migration path to the New World Optical Internet.</p>
<h3>A Revolutionary Platform For Evolving Networks</h3>
<p>The Cisco 7600 OSR helps service providers break through service and bandwidth barriers today, while designing networks to scale for future growth. The Cisco 7600 OSR achieves this through &#8220;adaptive network processing,&#8221; or the ability to evolve the platform for new IP services without hardware upgrades. Unlike fixed, ASIC-based platforms, which are hardware encoded, the Cisco 7600 OSR relies on the highly flexible Parallel eXpress Forwarding (PXF) technology for scalable performance of services. PXF is a patented, Cisco-developed network processor capable of line-rate IP services delivery that can support new IP services through periodic software upgrades. Each OSM has two PXF processors capable of 12 mpps of IP services delivery per interface card.</p>
<p>&#8220;IP+Optical combines the dynamism of the Internet world with the foundation of the transport world, creating an infrastructure that can deliver the services that service providers need,&#8221; said Lele Nardin, vice president of the Internet Systems Business Unit at Cisco. &#8220;Cisco will continue to add innovative solutions on top of this solid foundation to make service providers better equipped to meet the constantly escalating and changing customer demands for new networking services.&#8221;</p>
<h3>Pricing and Availability</h3>
<p>The base Cisco 7600 OSR system is list priced at $73,000 and the entry level system, with interfaces, start at $100,000. The interfaces modules are priced between $27,000 to $180,000. The Cisco 7600 OSR is available now worldwide.</p>
]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 07:25:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/cisco flexwan module">cisco flexwan module</category>
      <category domain="http://securityratty.com/tag/osr">osr</category>
      <category domain="http://securityratty.com/tag/runs cisco ios">runs cisco ios</category>
      <category domain="http://securityratty.com/tag/base cisco">base cisco</category>
      <category domain="http://securityratty.com/tag/cisco ios">cisco ios</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/destination sensitive services">destination sensitive services</category>
      <category domain="http://securityratty.com/tag/osr system">osr system</category>
      <source url="http://www.thecepblog.com/2008/09/06/cisco-7600-osr-backbone-router/">Cisco 7600 OSR Backbone Router</source>
    </item>
    <item>
      <title><![CDATA[Customers Being Heard Dell OEM Customer Advisory Council]]></title>
      <link>http://securityratty.com/article/b5bf6c31cfb46c51caf3436e68450bcd</link>
      <guid>http://securityratty.com/article/b5bf6c31cfb46c51caf3436e68450bcd</guid>
      <description><![CDATA[It was a surprise and a great honor when Dell asked us to participate on their Industry Solutions Group (ISG) OEM Customer Advisory Council even more so when I met some of the other members from...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" height="234" alt="dell" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/dell.jpg" width="240" align="left" border="0"> It was a surprise and a great honor when Dell asked us to participate on their <a href="http://www.dell.com/content/topics/global.aspx/sitelets/solutions/industry_application/oem_solutions/oem_industry_solutions_group?c=us&amp;cs=555&amp;l=en&amp;s=biz&amp;redirect=1" target="_blank">Industry Solutions Group (ISG) OEM Customer Advisory Council</a> – even more so when I met some of the other members from companies like Google, Teradata, Siemens Medical and Cisco. Not so shabby.</p>
<p>I arrived in Austin Sunday night to get ready for a factory tour on Monday, a kickoff dinner and then two days of briefings from Dell executives, including Michael Dell himself! Dell’s ISG business is growing at a very fast pace and continues to build momentum and focus within the broader organization.</p>
<p>We had a nice <a href="http://www.lockergnome.com/blade/2008/08/02/microsoft-has-oems-adding-defender-one-care-to-pcs/" target="_blank">overview of the product roadmap</a>, including some of the exciting enhancements Dell is making to their <a href="http://gigaom.com/2008/09/04/pc-makers-give-storage-startups-a-boost/" target="_blank">storage products</a> <a href="http://blogs.smugmug.com/don/2007/10/01/dell-md3000-great-das-db-storage/" target="_blank">such as the MD3000</a> and the new <a href="http://jpowell.blogs.com/jason_powell_church_it/2008/04/equallogic-app.html" target="_blank">EqualLogic PS5000 series iSCSI</a> solutions.</p>
<p>I really enjoyed the Council meeting and it reminds me all over again; what I admire about Dell is the way they and Michael Dell himself stay close to the customer. The entire purpose of this event is to “get it right” and determine meaningful ways to embrace change (including change in the manufacturing process) in order to make their customers more successful. Ah shucks, you may say that all companies behave this way… well I must tell you that is not true and at times, I find it difficult as we continue to grow to stay as close as I would like to all of our customers varying needs and directions.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="228" alt="Ideastorm" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/ideastorm1.jpg" width="456" border="0"> </p>
<p>This concept of <a href="http://www.briansolis.com/2008/07/comcast-cares-and-why-your-business.html" target="_blank">gathering, internalizing and embracing customer feedback is a simple principle</a> of Business Success stories. <a href="http://www.beingpeterkim.com/2008/09/ive-been-thinki.html" target="_blank">Always trying to improve</a> the pace of change and build meaningful sticky relationships with customers. Dell’s very successful <a href="http://www.dellideastorm.com/" target="_blank">Ideastorm</a> site where customers post <a href="http://www.pronetadvertising.com/articles/how-richard-binhammer-is-changing-the-face-of-dell-online34379.html" target="_blank">product feedback and are active participants</a> in the Dell community is a <a href="http://www.bloggingstocks.com/2008/07/07/how-dell-can-leap-ahead-in-consumer-laptop-sales/" target="_blank">great example of how to do this right</a>. No other hardware vendor that we have worked with or attempted to work with has ever gone to the extent of embracing change that Dell has during our 5-year relationship.</p>
<p>From the custom factory integration services to the attention to detail in the order and manufacturing, and logistics processes, Dell helps us execute for our customers and I must admit that we could not have built the business as quickly or efficiently without Dell!</p>
<p>So thank you Michael Dell for building a business that embraces change and is focused on helping your ISG customers succeed.</p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 11:54:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/michael dell">michael dell</category>
      <category domain="http://securityratty.com/tag/dells isg business">dells isg business</category>
      <category domain="http://securityratty.com/tag/isg">isg</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/dell community">dell community</category>
      <category domain="http://securityratty.com/tag/dell helps">dell helps</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/dell executives">dell executives</category>
      <source url="http://blog.sciencelogic.com/customers-being-heard-dell-oem-customer-advisory-council/09/2008">Customers Being Heard Dell OEM Customer Advisory Council</source>
    </item>
    <item>
      <title><![CDATA[Should You Install Messaging Security Software on Your Exchange Server?]]></title>
      <link>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</link>
      <guid>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</guid>
      <description><![CDATA[Source: Sunbelt Software) Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions. Read this white paper to help...]]></description>
      <content:encoded><![CDATA[<b>(Source:  Sunbelt Software)</b> Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions.  Read this white paper to help you understand the latest Exchange security risks and also learn about reasons why an installed security solution may be the best option for you in countering those challenges.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:4c2325713dd32016c18954ac278d0864:NFQXxHFMI5joATi8rb9XqG1wphiNoRddmISCypgry8gEDx2Kenb%2BwST2VWrGNREyFwdH5a2LrernMF3UzVyemXdU3bxFrh23RewQbJvsbuU%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ae8b7af0edbdcbad40287f4417dc000e:fzsuOnQABO%2F8zb5KR73dVE95rbdex%2BnHTgnrI25OHes0WbXZDNfE9nFNPIILxlOYupKK7IkQgzmbRxlSncXrguiZ7MZAsL4%2FH5S1pQG82Pw%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9c187aa78b037950ceedc32de289ca2a:oM6A8Agm%2F3STbmMJgABVmGsiNFyFOaEhlsz8Si9HGzhxFAyAewDxbjLhdwiEQuD0ypx4eY%2BBm21mHRQFzIJF9g8%2FNKkoh0hbbKprpRjTCWY%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:be6d95967a93a89dc81e7f6b60ac6416:ibgVPVeXQV%2FqsmmMgf4t8i5bA1sbwSydZxlubOrocwKd3AketgClxa1YazuQW6MMa1W2lTZwLFa1Y8zrp1bym0dpybbsmX4n87C8piBSqHs%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=27986667fa8fa86c25fb326572f03aad" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=27986667fa8fa86c25fb326572f03aad" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email security solutions">email security solutions</category>
      <category domain="http://securityratty.com/tag/exchange security risks">exchange security risks</category>
      <category domain="http://securityratty.com/tag/white paper">white paper</category>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/security solution">security solution</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/dispel">dispel</category>
      <source url="http://www.pheedo.com/click.phdo?i=27986667fa8fa86c25fb326572f03aad">Should You Install Messaging Security Software on Your Exchange Server?</source>
    </item>
    <item>
      <title><![CDATA[Safely providing anywhere, anytime network access]]></title>
      <link>http://securityratty.com/article/171ed5feba667c18affc04e17cf43723</link>
      <guid>http://securityratty.com/article/171ed5feba667c18affc04e17cf43723</guid>
      <description><![CDATA[Today's business user often needs remote access to email, documents, or other business information, even when a business supplied laptop or desktop is available. This need for secure anytime, anywhere...]]></description>
      <content:encoded><![CDATA[Today's business user often needs remote access to email, documents, or other business information, even when a business supplied laptop or desktop is available.  This need for secure anytime, anywhere access to business information comes with its own complete set of challenges.  But reasonably priced and user-friendly solutions are emerging.]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 01:26:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business information">business information</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/business user">business user</category>
      <category domain="http://securityratty.com/tag/remote access">remote access</category>
      <category domain="http://securityratty.com/tag/complete set">complete set</category>
      <category domain="http://securityratty.com/tag/user-friendly solutions">user-friendly solutions</category>
      <category domain="http://securityratty.com/tag/secure anytime">secure anytime</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/safely-providing-anywhere-anytime-network-access-26949">Safely providing anywhere, anytime network access</source>
    </item>
    <item>
      <title><![CDATA[Thieves Target Homeowners and Builders]]></title>
      <link>http://securityratty.com/article/67d7747ad19221ce58f6109953ee7bee</link>
      <guid>http://securityratty.com/article/67d7747ad19221ce58f6109953ee7bee</guid>
      <description><![CDATA[We have written about thefts of copper wire and even street manhole covers in the past. It appears that new homes and those being foreclosed upon are ripe targets for unscrupulous thieves

Thankfully,...]]></description>
      <content:encoded><![CDATA[We have written about thefts of copper wire and even street manhole covers in the past.  It appears that <a href="http://www.nytimes.com/2008/08/28/garden/28theft.html?_r=1&oref=slogin">new homes and those being foreclosed upon </a>are ripe targets for unscrupulous thieves.  <br /><span id="fullpost"><br />Thankfully, there are many more solutions than in days past.  Global Positioning Systems can now be hidden in materials and the thieves can be tracked in real time and the Police notified by the security consultant who has been hired to monitor their movements.<br /><br />The highlighted link from "The New York Times", tells the sad story of a young couple and their 7 month old child who had to live onsite at their new house for many months in order to deter thieves.<br /><br />We have spoken with home builders in the past regarding supplying security officers to monitor unfinished homes.  One of the hurdles has been the cost of security. The escalating cost of these thefts may now make Home Builders think twice though.  <br /><br />The National Association of Home Builders claims that $5 BILLION a year is being stolen nationally by theives from homes under construction.  That would purchase a lot of security services.  Not to mention the cost of labor to replace that missing copper wire, plumbing fittings, doors & windows, etc. <br /><br />Like we always say, thieves are opportunists.  If you give them an opportunity such as leaving valuable building supplies unprotected, they will take them.  On the other hand, if you put an obstacle in their path such as a site that is monitored by security cameras (with somebody on the other end of the camera - you'd be surprised how many businesses put in cameras but have nobody to monitor them)or a roving security vehicle, they will move along and ply their trade elsewhere.<br /><br />That is called "target hardening".  Quite literally, you make yourself (or your property) a harder, more difficult target.  They then move along to some other target.  Bad for someone else, but good for you.     <br /></span><div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 15:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/thieves">thieves</category>
      <category domain="http://securityratty.com/tag/security cameras">security cameras</category>
      <category domain="http://securityratty.com/tag/security vehicle">security vehicle</category>
      <category domain="http://securityratty.com/tag/target">target</category>
      <category domain="http://securityratty.com/tag/security consultant">security consultant</category>
      <category domain="http://securityratty.com/tag/home builders">home builders</category>
      <category domain="http://securityratty.com/tag/home builders claims">home builders claims</category>
      <category domain="http://securityratty.com/tag/deter thieves">deter thieves</category>
      <source url="http://www.thebulletproofblog.com/2008/08/thieves-target-homeowners-and-builders.html">Thieves Target Homeowners and Builders</source>
    </item>
    <item>
      <title><![CDATA[Magic Quadrant for Application Delivery Controllers]]></title>
      <link>http://securityratty.com/article/224089e5d76323e4bbe5b8297445e9f4</link>
      <guid>http://securityratty.com/article/224089e5d76323e4bbe5b8297445e9f4</guid>
      <description><![CDATA[Source: Citrix) Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across...]]></description>
      <content:encoded><![CDATA[<b>(Source: Citrix)</b> Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors.  Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=71TQZs"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=71TQZs" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/378143212" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application delivery controllers">application delivery controllers</category>
      <category domain="http://securityratty.com/tag/magic quadrant">magic quadrant</category>
      <category domain="http://securityratty.com/tag/citrix">citrix</category>
      <category domain="http://securityratty.com/tag/citrix netscaler">citrix netscaler</category>
      <category domain="http://securityratty.com/tag/gartner">gartner</category>
      <category domain="http://securityratty.com/tag/quick comparison">quick comparison</category>
      <category domain="http://securityratty.com/tag/all-in-one device">all-in-one device</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/378143212/whitepapers.do">Magic Quadrant for Application Delivery Controllers</source>
    </item>
    <item>
      <title><![CDATA[How do you Manage Virtualization if you cant see Performance?]]></title>
      <link>http://securityratty.com/article/ed2ef4931f690c62b02f28e517c0aa0d</link>
      <guid>http://securityratty.com/article/ed2ef4931f690c62b02f28e517c0aa0d</guid>
      <description><![CDATA[NetIQ, which seemed to drop off the planet not long after being bought by Attachmate , is back with the results of a very interesting virtualization survey . Now, you know that you need to take all...]]></description>
      <content:encoded><![CDATA[<p>NetIQ, which seemed to drop off the planet not long after being <a href="http://www.itjungle.com/tfh/tfh071706-story08.html">bought by Attachmate</a>, is back with the results of a very interesting <a href="http://tarrysingh.blogspot.com/2008/08/netiq-survery-virtualization-initiative.html">virtualization survey</a>. Now, you know that you need to take all surveys with a big grain of salt (e.g., the majority of respondents to this one were less than 10% virtualized), but it&#8217;s still good to take temperatures whenever possible. </p>
<p>The numbers we found interesting: </p>
<p>- only 21% currently deploying virtualization have any kind of systems management solutions for their virtual infrastructure </p>
<p>- about 27% are managing performance/ability of virtual systems with same tools they use for physical servers (Nothing wrong with that as long as they&#8217;re seeing what they need to see but&#8230;)</p>
<p>- 40 percent of those surveyed do not report the performance of their virtualized applications, hardware, <a href="http://virtualization.com/news/2008/08/26/netiq-survey-results-reflect-lack-of-virtualization-management-basics/">operating systems, or their virtual machines in any measureable</a> way (which rather undercuts the whole point)</p>
<p>Get the full results <a href="http://download.netiq.com/Library/Misc/VirtualizationSurveyAnalysis-Aug2008.pdf">here</a>.</p>
]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 21:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/systems management solutions">systems management solutions</category>
      <category domain="http://securityratty.com/tag/virtual systems">virtual systems</category>
      <category domain="http://securityratty.com/tag/virtualization survey">virtualization survey</category>
      <category domain="http://securityratty.com/tag/virtual machines">virtual machines</category>
      <category domain="http://securityratty.com/tag/physical servers">physical servers</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/performance">performance</category>
      <source url="http://blog.sciencelogic.com/how-do-you-manage-virtualization-if-you-cant-see-performance/08/2008">How do you Manage Virtualization if you cant see Performance?</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[Diebold Finally Admits its Voting Machines Drop Votes]]></title>
      <link>http://securityratty.com/article/9fd72b6a71080a7d237192b1aba53111</link>
      <guid>http://securityratty.com/article/9fd72b6a71080a7d237192b1aba53111</guid>
      <description><![CDATA[Premier Election Solutions, formerly called Diebold Election Systems, has finally admitted that a ten-year-old error has caused votes to be dropped
It's unclear if this error is random or systemic. If...]]></description>
      <content:encoded><![CDATA[<p>Premier Election Solutions, formerly called Diebold Election Systems, <a href="http://www.networkworld.com/news/2008/082208-e-voting-vendor-programming-errors-caused.html">has</a> <a href="http://www.theregister.co.uk/2008/08/26/decade_old_evoting_error/">finally</a> <a href="http://www.engadget.com/2008/08/23/diebold-comes-clean-admits-that-its-e-voting-machines-are-fault/">admitted</a> <a href="http://voices.washingtonpost.com/the-trail/2008/08/21/ohio_voting_machines_contained.html">that</a> a ten-year-old error has caused votes to be dropped.</p>

<p>It's unclear if this error is random or systemic.  If it's random -- a small percentage of all votes are dropped -- then it is highly unlikely that this affected the outcome of any election.  If it's systemic -- a small percentage of votes for a particular candidate are dropped -- then it is much more problematic.</p>

<p>Ohio is trying to <a href="http://www.mcclatchydc.com/election2008/story/48508.html">sue</a>:</p>

<blockquote>Ohio Secretary of State Jennifer Brunner is seeking to recover millions of dollars her state spent on the touch-screen machines and is urging the state legislature to require optical scanners statewide instead.

<p>In a lawsuit, Brunner charged on Aug. 6 that touch-screen machines made by the former Diebold Election Systems and bought by 11 Ohio counties "produce computer stoppages" or delays and are vulnerable to "hacking, tampering and other attacks." In all, 44 Ohio counties spent $83 million in 2006 on Diebold's touch screens.</blockquote></p>

<p>In other news, election officials sometimes <a href="http://thelede.blogs.nytimes.com/2008/08/19/mom-can-my-voting-machine-spend-the-night/index.html?hp">take voting machines home</a> for the night.</p>

<p>My 2004 essay: "<a href="http://www.schneier.com/crypto-gram-0411.html#1">Why Election Technology is Hard</a>."</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nF5edK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nF5edK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qE9h7K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qE9h7K" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 02:38:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/election">election</category>
      <category domain="http://securityratty.com/tag/diebold election systems">diebold election systems</category>
      <category domain="http://securityratty.com/tag/diebold">diebold</category>
      <category domain="http://securityratty.com/tag/machines">machines</category>
      <category domain="http://securityratty.com/tag/election technology">election technology</category>
      <category domain="http://securityratty.com/tag/ohio">ohio</category>
      <category domain="http://securityratty.com/tag/ohio secretary">ohio secretary</category>
      <category domain="http://securityratty.com/tag/election officials">election officials</category>
      <category domain="http://securityratty.com/tag/votes">votes</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/diebold_finally.html">Diebold Finally Admits its Voting Machines Drop Votes</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</link>
      <guid>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel?? to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
  </channel>
</rss>
