<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: stats]]></title>
    <link>http://securityratty.com/tag/stats</link>
    <description></description>
    <pubDate>Fri, 13 Jun 2008 00:27:25 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Awesome Apple Utility Apps for Your Battery and Wifi Security]]></title>
      <link>http://securityratty.com/article/7132d8b85ba0bb368b13068dfa062d48</link>
      <guid>http://securityratty.com/article/7132d8b85ba0bb368b13068dfa062d48</guid>
      <description><![CDATA[I found a few awesome apps this morning for my Macbook Pro that I want to share with you, courtesy of Coconut-Flavour.com
coconutBattery This little app tells you more info about your batterys quality...]]></description>
      <content:encoded><![CDATA[<p>I found a few awesome apps this morning for my Macbook Pro that I want to share with you, courtesy of <a rel="nofollow" target="_blank" href="http://www.coconut-flavour.com/">Coconut-Flavour.com</a>.</p>
<p>coconutBattery &#8212; This little app tells you more info about your battery&#8217;s quality of life. Namely, I&#8217;ve been having a frustrating problem &#8212; my laptop acts like it&#8217;s at 0% and shuts down, even when the power meter reads upwards of 10-30%&#8230; According to coconutBattery, my battery&#8217;s only operating about 80% of its original capacity. Maybe that&#8217;s my problem&#8230; It also allows you to save its stats so you can monitor your battery over time.</p>
<p>coconutWifi &#8212; Many Mac controls are easier to use than Windows &#8212; but the Airport card isn&#8217;t always one of them. Unlike on a Windows machine, it doesn&#8217;t tell you which networks in the area are encrypted. This little app changes that with a handy icon telling you how many open networks are available, and not only that &#8212; it also lets you know what channels they&#8217;re all using. Now I can easily increase the range of my network by setting it to an unused channel.</p>
<p>Excuse me, I have to go play with my new utility toys&#8230;</p>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 10:24:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/batterys">batterys</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows machine">windows machine</category>
      <category domain="http://securityratty.com/tag/app">app</category>
      <category domain="http://securityratty.com/tag/batterys quality">batterys quality</category>
      <category domain="http://securityratty.com/tag/app tells">app tells</category>
      <category domain="http://securityratty.com/tag/awesome apps">awesome apps</category>
      <category domain="http://securityratty.com/tag/handy icon">handy icon</category>
      <category domain="http://securityratty.com/tag/coconutbattery">coconutbattery</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/362357138/">Awesome Apple Utility Apps for Your Battery and Wifi Security</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Dont become a statistic says Sophos]]></title>
      <link>http://securityratty.com/article/e3e77f1b401935dc5ace8457fe03a4fd</link>
      <guid>http://securityratty.com/article/e3e77f1b401935dc5ace8457fe03a4fd</guid>
      <description><![CDATA[Alot of numbers and stats, but a must read for those who want to take no changes while online


clipped from www.istockanalyst.com

Hackers Attack Businesses, Blogs and Web 2.0 Sites, Sophos Security...]]></description>
      <content:encoded><![CDATA[<div > Alot of numbers and stats, but a must read for those who want to take no changes while online. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/678C0240-BB90-40E3-8292-98F75AF03ECA/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/8c805b24-d9c8-498d-87d1-a3181f501ee1/678C0240-BB90-40E3-8292-98F75AF03ECA/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.istockanalyst.com/article/viewiStockNews+articleid_2429351&#038;title=Hackers_Attack.html" href="http://www.istockanalyst.com/article/viewiStockNews+articleid_2429351&#038;title=Hackers_Attack.html" style="font-size: 11px;">www.istockanalyst.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.istockanalyst.com/article/viewiStockNews+articleid_2429351&#038;title=Hackers_Attack.html --><DIV class="presstitle">Hackers Attack Businesses, Blogs and Web 2.0 Sites, Sophos Security Threat Report Reveals</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.istockanalyst.com/article/viewiStockNews+articleid_2429351&#038;title=Hackers_Attack.html --><P> Sophos, the largest privately held vendor in the secure content and threat management market today published new research into the first six months of cybercrime in 2008. The Sophos Security Threat Report examines existing and emerging security trends and has identified that criminals are increasingly using creative, new techniques in their attempt to make money out of internet users.   </P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/678C0240-BB90-40E3-8292-98F75AF03ECA/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 14:56:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hackers attack businesses">hackers attack businesses</category>
      <category domain="http://securityratty.com/tag/privately held vendor">privately held vendor</category>
      <category domain="http://securityratty.com/tag/threat management market">threat management market</category>
      <category domain="http://securityratty.com/tag/sophos">sophos</category>
      <category domain="http://securityratty.com/tag/internet users">internet users</category>
      <category domain="http://securityratty.com/tag/security trends">security trends</category>
      <category domain="http://securityratty.com/tag/secure content">secure content</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=511">Dont become a statistic says Sophos</source>
    </item>
    <item>
      <title><![CDATA[Don't use Clickcaster for podcast hosting]]></title>
      <link>http://securityratty.com/article/01df752e16a09e2ea33357c64a9d883e</link>
      <guid>http://securityratty.com/article/01df752e16a09e2ea33357c64a9d883e</guid>
      <description><![CDATA[Image via Wikipedia
When I find a new product or service that I think is good I am only too happy to let the world know it on my blog. For the past almost 2 years in the notes of every episode of our...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><div class="zemanta-img" style="margin: 1em; float: right; display: block;"><a href="http://en.wikipedia.org/wiki/Image:Clickcasterlogo.png"><img alt="ClickCaster" src="http://upload.wikimedia.org/wikipedia/en/thumb/4/4e/Clickcasterlogo.png/202px-Clickcasterlogo.png" style="border: medium none ; display: block;" /></a><p class="zemanta-img-attribution">Image via <a href="http://en.wikipedia.org/wiki/Image:Clickcasterlogo.png">Wikipedia</a></p></div>

<p>When I find a new product or service that I think is good I am only too happy to let the world know it on my blog. For the past almost 2 years in the notes of every episode of our podcast, I mention and thank <a class="zem_slink" rel="homepage" title="ClickCaster" href="http://www.clickcaster.com/">ClickCaster</a> for hosting our podcast.</p>

<p>I originally was turned on to ClickCaster by Scott Converse out in <a class="zem_slink" rel="geolocation" title="Boulder, Colorado" href="http://maps.google.com/maps?ll=40.0194444444,-105.292777778&amp;spn=0.1,0.1&amp;q=40.0194444444,-105.292777778&amp;t=h">Boulder, Co</a> who was the founder of ClickCaster.&nbsp; When Scott realized that a free model was not going to pay the bills, he instituted a pay model for podcast hosting. I was only too happy to pay for the great service and stats I was receiving. Well a few months ago Scott and team sold ClickCaster to focus on their new project, <a href="http://medioh.com/">Medioh!</a>.</p>

<p>The new owners, nexplore promised no changes and same great service.&nbsp; Since then the stats stopped working, it became harder and harder to post new content and the site was down more than it was up.&nbsp; Finally after getting no satisfaction from ClickCaster I had no choice but to look for another host.&nbsp; Mitchell and I have chosen <a href="http://ashimmy.podomatic.com">Pod-o-matic</a> to host the podcast going forward. </p>

<p>Of course we don't have all of the episodes moved over yet because ClickCaster isn't even up enough for us to grab all the episodes.&nbsp; But most of them are up at pod-o-matic and we have already repointed the feedburner/iTunes feed.&nbsp; So from here on you can hear us at pod-o-matic.&nbsp; </p>

<p>If you are looking to host your podcast, you don't have to use pod-o-matic, but don't use ClickCaster!</p>

<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/1dd3a9ac-5070-4f6a-8def-08ed180dfb1e/" class="zemanta-pixie-a"><img alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=1dd3a9ac-5070-4f6a-8def-08ed180dfb1e" class="zemanta-pixie-img" style="border: medium none ; float: right;" /></a></div>
</div>
]]></content:encoded>
      <pubDate>Mon, 07 Jul 2008 10:41:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/clickcaster">clickcaster</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/scott converse">scott converse</category>
      <category domain="http://securityratty.com/tag/scott">scott</category>
      <category domain="http://securityratty.com/tag/months ago scott">months ago scott</category>
      <category domain="http://securityratty.com/tag/pod-o-matic">pod-o-matic</category>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/episodes moved">episodes moved</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/dont-use-clickc.html">Don't use Clickcaster for podcast hosting</source>
    </item>
    <item>
      <title><![CDATA[Don't use Clickcaster for podcast hosting]]></title>
      <link>http://securityratty.com/article/6e9b2a97cf6cb7fe0a1941ffa2979e13</link>
      <guid>http://securityratty.com/article/6e9b2a97cf6cb7fe0a1941ffa2979e13</guid>
      <description><![CDATA[Image via Wikipedia
When I find a new product or service that I think is good I am only too happy to let the world know it on my blog. For the past almost 2 years in the notes of every episode of our...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><div class="zemanta-img" style="margin: 1em; float: right; display: block;"><a href="http://en.wikipedia.org/wiki/Image:Clickcasterlogo.png"><img alt="ClickCaster" src="http://upload.wikimedia.org/wikipedia/en/thumb/4/4e/Clickcasterlogo.png/202px-Clickcasterlogo.png" style="border: medium none ; display: block;" /></a><p class="zemanta-img-attribution">Image via <a href="http://en.wikipedia.org/wiki/Image:Clickcasterlogo.png">Wikipedia</a></p></div>

<p>When I find a new product or service that I think is good I am only too happy to let the world know it on my blog. For the past almost 2 years in the notes of every episode of our podcast, I mention and thank <a class="zem_slink" rel="homepage" title="ClickCaster" href="http://www.clickcaster.com/">ClickCaster</a> for hosting our podcast.</p>

<p>I originally was turned on to ClickCaster by Scott Converse out in <a class="zem_slink" rel="geolocation" title="Boulder, Colorado" href="http://maps.google.com/maps?ll=40.0194444444,-105.292777778&amp;spn=0.1,0.1&amp;q=40.0194444444,-105.292777778&amp;t=h">Boulder, Co</a> who was the founder of ClickCaster.&nbsp; When Scott realized that a free model was not going to pay the bills, he instituted a pay model for podcast hosting. I was only too happy to pay for the great service and stats I was receiving. Well a few months ago Scott and team sold ClickCaster to focus on their new project, <a href="http://medioh.com/">Medioh!</a>.</p>

<p>The new owners, nexplore promised no changes and same great service.&nbsp; Since then the stats stopped working, it became harder and harder to post new content and the site was down more than it was up.&nbsp; Finally after getting no satisfaction from ClickCaster I had no choice but to look for another host.&nbsp; Mitchell and I have chosen <a href="http://ashimmy.podomatic.com">Pod-o-matic</a> to host the podcast going forward. </p>

<p>Of course we don't have all of the episodes moved over yet because ClickCaster isn't even up enough for us to grab all the episodes.&nbsp; But most of them are up at pod-o-matic and we have already repointed the feedburner/iTunes feed.&nbsp; So from here on you can hear us at pod-o-matic.&nbsp; </p>

<p>If you are looking to host your podcast, you don't have to use pod-o-matic, but don't use ClickCaster!</p>

<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/1dd3a9ac-5070-4f6a-8def-08ed180dfb1e/" class="zemanta-pixie-a"><img alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=1dd3a9ac-5070-4f6a-8def-08ed180dfb1e" class="zemanta-pixie-img" style="border: medium none ; float: right;" /></a></div>
</div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=Nq8Nig"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=Nq8Nig" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=GR9FnJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=GR9FnJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TtpyRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TtpyRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=llQa4J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=llQa4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wobUzJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wobUzJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=l4vNrj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=l4vNrj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Wq4vAj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Wq4vAj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/329099360" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 07 Jul 2008 09:41:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/clickcaster">clickcaster</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/scott converse">scott converse</category>
      <category domain="http://securityratty.com/tag/scott">scott</category>
      <category domain="http://securityratty.com/tag/months ago scott">months ago scott</category>
      <category domain="http://securityratty.com/tag/pod-o-matic">pod-o-matic</category>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/episodes moved">episodes moved</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/329099360/dont-use-clickc.html">Don't use Clickcaster for podcast hosting</source>
    </item>
    <item>
      <title><![CDATA[Data breaches and gas prices..]]></title>
      <link>http://securityratty.com/article/f4007a9f9c0266aa582601c225f05b0e</link>
      <guid>http://securityratty.com/article/f4007a9f9c0266aa582601c225f05b0e</guid>
      <description><![CDATA[Seems like the growth rate is the same - IRTC (Identity Theft Resource Center ) just released some interesting stats . Apparently number of breaches in the first half of 2008 have risen 69% over the...]]></description>
      <content:encoded><![CDATA[Seems like the growth rate is the same - <a href="http://idtheftcenter.org/">IRTC (Identity Theft Resource Center</a>) just released some<a href="http://newsblaze.com/story/2008063005530600002.pnw/topstory.html"> interesting stats</a>. Apparently number of breaches in the first half of 2008 have risen 69% over the same period in 2007. Maybe gas prices have increased a bit more, but not by much...<br /><br />Also other interesting nuggets -<br /><ul><li>Almost 40% have not disclosed the number of records breached.</li><li>Theft, either internal or external, have been the primary reason for the breach. </li></ul>Wonder why we are not hearing this on the presidential campaign? A unified and national policy approach to this epidemic would be welcome (as would lower gas prices!)<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=quoGWI"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=quoGWI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=F9GSLi"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=F9GSLi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=cCqt0I"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=cCqt0I" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/323392425" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 13:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gas prices">gas prices</category>
      <category domain="http://securityratty.com/tag/lower gas prices">lower gas prices</category>
      <category domain="http://securityratty.com/tag/national policy approach">national policy approach</category>
      <category domain="http://securityratty.com/tag/breaches">breaches</category>
      <category domain="http://securityratty.com/tag/primary reason">primary reason</category>
      <category domain="http://securityratty.com/tag/presidential campaign">presidential campaign</category>
      <category domain="http://securityratty.com/tag/nuggets">nuggets</category>
      <category domain="http://securityratty.com/tag/half">half</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/323392425/data-breaches-and-gas-prices.html">Data breaches and gas prices..</source>
    </item>
    <item>
      <title><![CDATA[Links List 6.27.08]]></title>
      <link>http://securityratty.com/article/8d5a94cb377694fae8da52b080f88521</link>
      <guid>http://securityratty.com/article/8d5a94cb377694fae8da52b080f88521</guid>
      <description><![CDATA[Peanut butter and chocolate. Beavis and Butthead. Social networking and CMDB? Heres a great blog post on the recently released myCMDB from Managed Objects . The IT Skeptic is as funny as ever
We heard...]]></description>
      <content:encoded><![CDATA[<p>Peanut butter and chocolate. Beavis and Butthead. Social networking and CMDB? Here’s a great blog post on the recently released <a href="http://www.itskeptic.org/node/644" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.itskeptic.org');" target="_blank">myCMDB from Managed Objects</a>. The IT Skeptic is as funny as ever.
<p>We heard a lot about cloud computing at the Gartner show this week. You can read a bit about their take on it <a href="http://blog.sciencelogic.com/a-hot-cloudless-computing-day-in-florida/06/2008"  target="_blank">here</a>. While we’ve been musing on the different ways we monitor cloud computing resources, <a href="http://www.webware.com/8301-1_109-9975354-2.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.webware.com');" target="_blank">Hyperic is already announcing their solution to monitor Amazon’s cloud computing availability</a>. <a href="http://www.informationweek.com/news/hardware/utility_ondemand/showArticle.jhtml?articleID=208800360" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.informationweek.com');" target="_blank">Hyperic believes</a> that “making use of cloud resources would be more popular if the customers had an independent means to monitor cloud services.” They plan to offer the monitoring service to other cloud companies this year. However, <a href="http://www.johnmwillis.com/amazon/taking-the-hype-out-of-hyperics-new-cloudstatus/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.johnmwillis.com');" target="_blank">John Willis questions the hype of Hyperic</a>.
<p>Here are some interesting <a href="http://networkinstruments.wordpress.com/2008/06/20/most-companies-fail-to-use-netflow/" onclick="javascript:pageTracker._trackPageview('/outbound/article/networkinstruments.wordpress.com');" target="_blank">NetFlow use stats</a> from our friends at Network Instruments. In a survey they did a few months ago, only 23% of respondents used NetFlow to monitor network performance; 60% didn’t use flow tech and 17% weren’t sure they had anything for it. I have to say we are asked at every Interop show we do if we support NetFlow so the numbers are slightly surprising but useful.
<p>Kuala Lumpur is bullish on <a href="http://www.bladewatch.com/2008/06/23/talking-about-sun-and-virtualization/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.bladewatch.com');" target="_blank">Sun’s virtualization strategy</a>.
<p>Just like at the Gartner show, one of the tracks at the Burton Group’s conference this week is on virtualization. This post on the Data Center Strategies blog covers Day 1 with some interesting notes on <a href="http://dcsblog.burtongroup.com/data_center_strategies/2008/06/catalyst-day-1.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/dcsblog.burtongroup.com');" target="_blank">where virtualization needs to go</a>, from clarity around software licensing and support to the use of raw storage (connecting VMs directly to LUNs) to improve VM performance, provide better integration with storage and data management solutions, and prevent vendor lock-in.</p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+6.27.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-62708%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 16:02:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monitor cloud services">monitor cloud services</category>
      <category domain="http://securityratty.com/tag/monitor cloud">monitor cloud</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud resources">cloud resources</category>
      <category domain="http://securityratty.com/tag/monitor amazons cloud">monitor amazons cloud</category>
      <category domain="http://securityratty.com/tag/cloud companies">cloud companies</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/support netflow">support netflow</category>
      <category domain="http://securityratty.com/tag/suns virtualization strategy">suns virtualization strategy</category>
      <source url="http://blog.sciencelogic.com/links-list-62708/06/2008">Links List 6.27.08</source>
    </item>
    <item>
      <title><![CDATA[Links List 6.13.08]]></title>
      <link>http://securityratty.com/article/0b0ff8a848238747fbf053dae5ed4898</link>
      <guid>http://securityratty.com/article/0b0ff8a848238747fbf053dae5ed4898</guid>
      <description><![CDATA[Nothing to do with monitoring, but completely funny. I have not been following the Broadcom ex-CEO Henry Nicholas exploits , and now I think I should have been. Not only did this bad boy add a...]]></description>
      <content:encoded><![CDATA[<p>Nothing to do with monitoring, but completely funny. I have not been following the <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/06/geek_week_broad.html" target="_blank">Broadcom ex-CEO Henry Nicholas&#8217; exploits</a>, and now I think I should have been. Not only did this bad boy add a<b> </b><a href="http://www.infoworld.com/article/08/06/05/Broadcom-co-founder-drugged-drinks-indictment-says_1.html" target="_blank">fictional $2.2 billion</a> worth of revenue to his company&#8217;s bottom line, a second indictment also charges him with a slew of stuff including &#8220;spiking customer and employee drinks with ecstasy and other drug-related charges&#8221;. The best one: during a trip to Vegas on his private plane, Nicholas and others smoked so much pot that the pilot had to put on an oxygen mask. </p>
<p>Sevcik and Wetzel have a consistently interesting column on Application Performance Management at NetworkWorld. This week, they unveiled the results of a benchmarking survey that tells them <a href="http://www.networkworld.com/community/node/28639" target="_blank">mid-sized enterprises have it harder</a> when it comes to deploying such solutions.</p>
<p>We agree; it&#8217;s why we exist. Mid-sized enterprises have the same IT problems but not nearly the same amount of resources as the really big guys to throw against solving them.</p>
<p>VMWare&#8217;s acquisition of B-hive continues to generate buzz for <a href="http://servervirtualization.blogs.techtarget.com/2008/06/10/performance-management%e2%80%99s-next-frontier/" target="_blank">performance management and virtualization</a>. I love this quote from the CEO of Aternity, &#8220;The next big frontier is the ability to transform huge amounts of data into actionable business intelligence that correlates across platforms.&#8221; Um, we&#8217;re already doing this. What would be the purpose of collecting hundreds of millions of data points if you couldn&#8217;t actually present the data in a meaningful way? Maybe his comment was taken out of context and it&#8217;s more about the fact that it&#8217;s often difficult to get consistent and accurate info on virtualization resource utilization stats in particular. That we totally agree with. Another take on the B-hive acquisition: <a href="http://blogs.vmware.com/vmtn/2008/06/what-does-b-hiv.html" target="_blank">VMTN blog gives a quick overview</a> of what it means for infrastructure groups and virtual environments.</p>
<p><a href="http://sharethis.com/item?&wp=2.3.3&amp;publisher=f8a81d13-50d0-4a5c-833d-8e5f2341e305&amp;title=Links+List+6.13.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-61308%2F06%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 09:01:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application performance management">application performance management</category>
      <category domain="http://securityratty.com/tag/performance management">performance management</category>
      <category domain="http://securityratty.com/tag/actionable business intelligence">actionable business intelligence</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/transform huge amounts">transform huge amounts</category>
      <category domain="http://securityratty.com/tag/companys bottom line">companys bottom line</category>
      <category domain="http://securityratty.com/tag/quick overview">quick overview</category>
      <category domain="http://securityratty.com/tag/vmtn blog">vmtn blog</category>
      <category domain="http://securityratty.com/tag/agree">agree</category>
      <source url="http://blog.sciencelogic.com/links-list-61308/06/2008">Links List 6.13.08</source>
    </item>
    <item>
      <title><![CDATA[Interop Vegas 2008 - A Tale of User Error]]></title>
      <link>http://securityratty.com/article/8e867fbc22a8ff47f1801ea868d92135</link>
      <guid>http://securityratty.com/article/8e867fbc22a8ff47f1801ea868d92135</guid>
      <description><![CDATA[When I think of Interop, I tend to think of pretty technical vendors all gathered together in Vegas for 3 days of geeking out. Whats interesting, is an analysis of the trouble tickets that were opened...]]></description>
      <content:encoded><![CDATA[<p>When I think of Interop, I tend to think of pretty technical vendors all gathered together in Vegas for 3 days of <a href="http://www.interop.com/blog/?p=408" target="_blank">geeking</a> out.  What&#8217;s interesting, is an analysis of the trouble tickets that were opened in EM7 for Interop Vegas 2008, doesn&#8217;t necessarily play that story out.  If the types of problems that exhibitors experienced are indicative of the staff in the booth, it seems like it was largely marketing people, and not <a href="http://farm4.static.flickr.com/3009/2454750176_812e3a5522_o.jpg" target="_blank">engineers</a> at all.  Let&#8217;s take a brief look at the ticketing numbers:</p>
<p>A total of 155 trouble tickets were opened in the four days that the help desk was operational.  Of these tickets:</p>
<ul>
<li>91 were opened by exhibitors, these were opened by 75 different booths (of about 500).
<ul>
<li>28 were to report slow or no connections.  Of these only 6 were related to the network (all before the show opened), usually they were things like patch cables not pushed all the way in.  The remaining 22 were <a href="http://www.pioneer.net/~mchumor/computer_error1_bframe.html" target="_blank">user error</a>.  Another interesting stat is that four of the tickets came from the same networking vendor and in each case it was their own gear that was misconfigured.  I guess as users we shouldn&#8217;t feel bad when we have trouble getting configs right.</li>
<li>The other 63 were change requests with the most common being a request to move an internet drop from one location in a booth to another.</li>
</ul>
</li>
<li>Two tickets were proactively opened by the InteropNet NOC team to notify/warn a vendor that a machine in their booth was infected and performing malicious scans of the network, in order to try and spread the infection.  Without naming names here, it&#8217;s interesting that one of the companies was a security company and the other a very large software company.</li>
<li>The remaining tickets were largely opened to track that activities of the NOC and InteropNet deployment teams as they <a href="http://www.interop.com/blog/?p=405" target="_blank">deployed</a>, tuned and maintained the network over the course of the show.</li>
</ul>
<p>So what does this mean?  It means that less about 15% of the exhibitors ran in to something that <a href="http://www.bomgar.com/blog/justinbrock/incident-resolution-on-site-vs-remote" target="_blank">required them to open a ticket with the help desk</a> and that in reality only 21% of those tickets were for valid issue, meaning only about 3% of the exhibitors actually had any issues.  Further analysis shows that for the tickets where there actually was an issue, the issue was resolved in an average of 50 minutes, with the quickest in 11m and the longest at 2hr 39m.  Finally, not a single valid exhibitor ticket was open during show floor hours.  All issues occurred before the show began during the set-up phase.</p>
<p>Overall I think that these stats point to an <a href="http://farm4.static.flickr.com/3014/2453932927_f7dc79be00_o.jpg" target="_blank">efficient help desk</a> and <a href="http://farm4.static.flickr.com/3077/2454752662_5601c4c094_o.jpg" target="_blank">trouble shooting</a> process that was facilitated by the link between the EM7 Trouble Ticketing system and Network Monitoring components that allowed <a href="http://searchdatacenter.techtarget.com/news/article/0,289142,sid80_gci1315261,00.html" target="_blank">quick validation of tickets</a> so that the right teams could be dispatched.</p>
<p><a href="http://sharethis.com/item?&wp=2.3.3&amp;publisher=f8a81d13-50d0-4a5c-833d-8e5f2341e305&amp;title=Interop+Vegas+2008+-+A+Tale+of+User+Error&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Finterop-vegas-2008-a-tale-of-user-error%2F06%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 00:27:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tickets">tickets</category>
      <category domain="http://securityratty.com/tag/trouble tickets">trouble tickets</category>
      <category domain="http://securityratty.com/tag/trouble">trouble</category>
      <category domain="http://securityratty.com/tag/vegas">vegas</category>
      <category domain="http://securityratty.com/tag/interop vegas">interop vegas</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 trouble">em7 trouble</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <source url="http://blog.sciencelogic.com/interop-vegas-2008-a-tale-of-user-error/06/2008">Interop Vegas 2008 - A Tale of User Error</source>
    </item>
  </channel>
</rss>
