<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: stop]]></title>
    <link>http://securityratty.com/tag/stop</link>
    <description></description>
    <pubDate>Tue, 18 Nov 2008 06:55:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Online safety is a science, dont get infected!]]></title>
      <link>http://securityratty.com/article/9405d60bd657bf8eba366596bc66d353</link>
      <guid>http://securityratty.com/article/9405d60bd657bf8eba366596bc66d353</guid>
      <description><![CDATA[Ran across this great article, its written with a touch of science applied to the threats that are out there online. A must read


clipped from www.sciencenewslive.com

Antispyware Software Helps Stop...]]></description>
      <content:encoded><![CDATA[<div > Ran across this great article, its written with a touch of science applied to the threats that are out there online.<br/>A must read. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/1E8E190C-F727-4594-82C9-A2DBB94AC92D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/3a8e25c6-edbe-4c36-80f5-38c87c227892/1E8E190C-F727-4594-82C9-A2DBB94AC92D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.sciencenewslive.com/technology/1223-antispyware-software-helps-stop-cyber-intruders.php" href="http://www.sciencenewslive.com/technology/1223-antispyware-software-helps-stop-cyber-intruders.php" style="font-size: 11px;">www.sciencenewslive.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.sciencenewslive.com/technology/1223-antispyware-software-helps-stop-cyber-intruders.php -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Antispyware Software Helps Stop Cyber Intruders</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.sciencenewslive.com/technology/1223-antispyware-software-helps-stop-cyber-intruders.php --><P> One of the key weapons effective in fighting the battle against these despicable internet threat security trends that are so widespread these days is to have a robust and dependable <A href="#" class="kLink" target="undefined" id="KonaLink10"><FONT color="blue"><SPAN class="kLink">antispyware</SPAN></FONT></A> software package installed on your system. But, it must be noted that installing internet <A href="#" class="kLink" target="undefined" id="KonaLink11"><FONT color="blue"><SPAN class="kLink">security </SPAN><SPAN class="kLink">software</SPAN></FONT></A> is simply the first step, since it must be actively used and continually updated.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/1E8E190C-F727-4594-82C9-A2DBB94AC92D/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_021208041711"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021208041711&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021208041711&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=021208041711&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_021208041711" /></a></P>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 13:17:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/key weapons effective">key weapons effective</category>
      <category domain="http://securityratty.com/tag/internet security software">internet security software</category>
      <category domain="http://securityratty.com/tag/science">science</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/battle">battle</category>
      <category domain="http://securityratty.com/tag/noted">noted</category>
      <category domain="http://securityratty.com/tag/actively">actively</category>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=667">Online safety is a science, dont get infected!</source>
    </item>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/mybank">mybank</category>
      <category domain="http://securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Communications During Terrorist Attacks are Not Bad]]></title>
      <link>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</link>
      <guid>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</guid>
      <description><![CDATA[Twitter was a vital source of information in Mumbai: News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the...]]></description>
      <content:encoded><![CDATA[<p>Twitter was a vital <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5245059.ece">source of information</a> in Mumbai:</p>

<blockquote>News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the carnage. 

<p>The website has a stream of comments on the attacks which is being updated by the second, often by eye-witnesses and people in the city. Although the chatter cannot be verified immediately and often reflects the chaos on the streets, it is becoming the fastest source of information for those seeking unfiltered news from the scene.</blockquote></p>

<p>But we simply have to be smarter than this:</p>

<blockquote>In the past hour, people using Twitter reported that bombings and attacks were continuing, but none of these could be confirmed. Others gave details on different locations in which hostages were being held. 

<p>And this morning, Twitter users said that Indian authorities was asking users to stop updating the site for security reasons.</p>

<p>One person wrote: "Police reckon tweeters giving away strategic info to terrorists via Twitter".</blockquote></p>

<p><a href="http://stephensonstrategies.com/2008/11/26/us-officials-must-monitor-learn-from-use-of-web-20-in-mumbai/">Another link</a>:</p>

<blockquote>I can't stress enough: people can and will use these devices and apps in a terrorist attack, so it is imperative that officials start telling us what kind of information would be relevant from Twitter, Flickr, etc. (and, BTW, what shouldn't be spread: one Twitter user in Mumbai tweeted me that people were sending the exact location of people still in the hotels, and could tip off the terrorists) and that they begin to monitor these networks in disasters, terrorist attacks, etc.</blockquote>

<p>This fear is exactly backwards.  During a terrorist attack -- during any crisis situation, actually -- the one thing people can do is exchange information.  It helps people, calms people, and actually reduces the thing the terrorists are trying to achieve: terror.  Yes, there are specific movie-plot scenarios where certain public pronouncements might help the terrorists, but those are rare.  I would much rather err on the side of more information, more openness, and more communication.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=slTEO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=slTEO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BvXZO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BvXZO" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 09:02:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/calms people">calms people</category>
      <category domain="http://securityratty.com/tag/twitter user">twitter user</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/helps people">helps people</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/exchange information">exchange information</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/communications.html">Communications During Terrorist Attacks are Not Bad</source>
    </item>
    <item>
      <title><![CDATA[Lessons from Mumbai]]></title>
      <link>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</link>
      <guid>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</guid>
      <description><![CDATA[I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details. What we know is horrific, and my sympathy goes out to the survivors of the...]]></description>
      <content:encoded><![CDATA[<p>I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details.  What we know is horrific, and my sympathy goes out to the survivors of the dead (and the injured, who often seem to get ignored as people focus on death tolls).  Without discounting the awfulness of the events, I have some initial observations:</p>

<ul><li>Low-tech is very effective.  <a href="http://www.schneier.com/essay-087.html">Movie-plot threats</a> -- terrorists with crop dusters, terrorists with biological agents, terrorists targeting our water supplies -- might be what people worry about, but a bunch of trained (we don't really know yet what sort of training they had, but it's clear that they <a href="http://www.news.com.au/couriermail/story/0,23739,24726093-954,00.html">had some</a>) men with guns and grenades is all they needed.

<p><li>At the same time, the attacks were surprisingly ineffective.  I can't find exact numbers, but it seems there were about 18 terrorists.  The latest toll is 195 dead, 235 wounded.  That's 11 dead, 13 wounded, per terrorist.  As horrible as the reality is, that's much less than you might have thought if you imagined the movie in your head.  Reality is <a href="http://www.pebbleandavalanche.com/weblog/2008/11/30/blog-20081130T1857">different</a> from the movies.</p>

<p><li>Even so, terrorism is rare.  If a bunch of men with guns and grenades is all they really need, then why isn't this sort of terrorism more common?  Why not in the U.S., where it's easy to get hold of weapons?  It's because terrorism is very, very rare.</p>

<p><li>Specific countermeasures don't help against these attacks.  None of the high-priced countermeasures that defend against specific tactics and specific targets made, or would have made, any difference: photo ID checks, confiscating liquids at airports, fingerprinting foreigners at the border, bag screening on public transportation, anything.  Even<a href="http://www.upi.com/Top_News/2008/11/29/Executive_says_Taj_hotel_warned_of_attack/UPI-97361228007685/">metal detectors and threat warnings</a> didn't do any good:</p>

<blockquote>"If I look at what we had, which all of us complained about, it could not have stopped what took place," he told CNN. "It's ironic that we did have such a warning, and we did have some measures."

<p>He said people were told to park away from the entrance and had to go through a metal detector. But he said the attackers came through a back entrance.</p>

<p>"They knew what they were doing, and they did not go through the front. All of our arrangements are in the front," he said.</blockquote></ul></p>

<p>If there's any lesson in these attacks, it's not to focus too much on the specifics of the attacks.  Of course, that's not the way we're programmed to think.  We <a href="http://www.schneier.com/essay-171.html">respond to stories</a> and not analysis.  I don't mean to be sympathetic; this tendency is human and these deaths are really tragic.  But eighteen armed people intent on killing lots of innocents will be able to do just that, and last-line-of-defense countermeasures won't be able to stop them.  Intelligence, investigation, and emergency response.  We have to find and stop the terrorists before they attack, and deal with the aftermath of the attacks we don't stop.  There really is no other way, and I hope that we don't let the tragedy lead us into unwise decisions about how to deal with terrorism.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=4dGOO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=4dGOO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qnl9O"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qnl9O" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 05:03:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mumbai terrorist attacks">mumbai terrorist attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/armed people intent">armed people intent</category>
      <category domain="http://securityratty.com/tag/people focus">people focus</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/lessons_from_mu.html">Lessons from Mumbai</source>
    </item>
    <item>
      <title><![CDATA[Chairman Tata Surprised by Tricky Terrorists]]></title>
      <link>http://securityratty.com/article/7b4520b092d5aedad18be187c5cd3069</link>
      <guid>http://securityratty.com/article/7b4520b092d5aedad18be187c5cd3069</guid>
      <description><![CDATA[Chairman Rata Tata, whose company owns the Taj hotel in Mumbai, gave a frank and honest interview to CNN. I would imagine that the Tata Group's PR people and General Counsel are scrambling at the...]]></description>
      <content:encoded><![CDATA[Chairman Rata Tata, whose company owns the Taj hotel in Mumbai, gave a frank and honest interview to CNN.  I would imagine that the Tata Group's PR people and General Counsel are scrambling at the moment trying to do as much damage control as possible. <br /><span id="fullpost"><br />The sad part of this unfolding story is the feeling one gets that the terrible loss of life at the hotel may have been prevented or at least mitigated had proper security measures been implemented and if the security that had been in place prior to the attack had not been removed.  <br /></span><br />One eye witness who stayed at the hotel a week before the terrorist assault spoke about metal detectors and baggage being checked.  The same witness then went on to say that those security measures had been removed within the last week, allowing people to enter without being checked.<br /><br />The most surprising news to surface must be the Chairman's comments regarding the terrible event. Unbelievably, he actually said; "They knew what they were doing and they did not go through the front.  All of our arrangements were on the front entrance".<br /><br />Who is Tata's security advisor, a kitchen worker?  Actually, he might have been better off if that were the case since the terrorists entered the hotel through the rear kitchen door.  ANNOUNCEMENT TO ALL CHAIRMEN AND CEO's; Terrorists are Tricky.  That is their job.  They are watching your businesses and will do the opposite to what you expect.  <br /><br />In the case of the TAJ HOTEL, you made it easy for them.  Did nobody in Mumbai ever stop to think that a bad person can go through the back door?  It is one thing for a cafe in a pedestrian area to be attacked as anyone can walk right by or walk through the front and open fire, but how can a major landmark that attracts Western vistors drop their security measures AFTER they have received terrorist alert warnings that the hotel may be the target of terrorsit attacks?  <br /><br />I don't know if it was the case with the Taj Hotel, but cutting corners where security is concerned is common place in corporate culture.  Security is often seen as a necessary evil and usually the first department to experience budgetary cutbacks.  It is very difficult to convince some clients that nothing happening is really a good thing and that by cutting out security may open the door to evil.<br /><br />This appears to have been the case with the Taj.  There is no doubt that the terrorists had conducted hundreds of hours of surveillance in and around Mumbai.  Was it a coincidence that the attack occurred the week after security measures had been removed?  What might have been the result if security had remained tight (if you could call watching the front entrance and disregarding the back as "tight security")?  Maybe the terrorists would have held back another month or two...maybe in that time they would have been detected...<br /><br />One thing is for certain, places like the Taj Hotel have to get serious about security.  Mr. Tata's claim that; "If I look at what we had...it could not have stopped what took place", must be replaced by more progressive, proactive thinking.  If the Tata Group had spent an adequate amount of funding on ensuring that a strict security policy was in force - if only for the period in question - then they might not now be facing a 5 Billion Rupee reconstruction bill.  Who knows how high the civil suits against the Taj will run when compensation and punitive costs are calculated.         <br /><br />Kudos though to Chairman Tata for at least recognizing that the Indian authorities may not be able to handle the situation on their own.  "These attacks underscore the need for Law Enforcement to seek outside expertise for training, equipment and strategic operations", he said.<br /><br />We agree Mr. Tata.  We also hope that you will recognize the need for the Tata Group to seek similar outside expertise to assist you with your security planning and training.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 22:29:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/proper security measures">proper security measures</category>
      <category domain="http://securityratty.com/tag/tata">tata</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security advisor">security advisor</category>
      <category domain="http://securityratty.com/tag/chairman tata">chairman tata</category>
      <category domain="http://securityratty.com/tag/chairman rata tata">chairman rata tata</category>
      <category domain="http://securityratty.com/tag/taj">taj</category>
      <category domain="http://securityratty.com/tag/taj hotel">taj hotel</category>
      <source url="http://www.thebulletproofblog.com/2008/11/chairman-tata-surprised-by-tricky.html">Chairman Tata Surprised by Tricky Terrorists</source>
    </item>
    <item>
      <title><![CDATA[A Review of EM7]]></title>
      <link>http://securityratty.com/article/7c2d378fa923b40a0fe3059fab4258a1</link>
      <guid>http://securityratty.com/article/7c2d378fa923b40a0fe3059fab4258a1</guid>
      <description><![CDATA[Were very happy to have had EM7 reviewed by The Tech Stop . We originally met Fr. Robert Ballecer SJ at Interop Las Vegas 2008. Padre (as everyone knows him) was one of the networking team leads at...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;re very happy to have had EM7 reviewed by <a href="http://www.thetechstop.net/?page_id=975" target="_blank">The Tech Stop</a>.  We originally met Fr. Robert Ballecer SJ at Interop Las Vegas 2008.  Padre (as everyone knows him) was one of the networking team leads at Interop and got hands on experience with EM7 in the NOC at the show.  As far as we&#8217;re concerned Interop was the best way to review EM7.  While working with a product in a lab gets you a reasonable idea of how it works, using the product in a high pressure, real world environment like Interop, really shows you what a product can do.  We&#8217;d like to thank Padre for taking the time to do such a complete review of EM7 and look forward to hopefully working with him again during Interop 2009.</p>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 14:39:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/review em7">review em7</category>
      <category domain="http://securityratty.com/tag/real world environment">real world environment</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/complete review">complete review</category>
      <category domain="http://securityratty.com/tag/robert ballecer">robert ballecer</category>
      <category domain="http://securityratty.com/tag/reasonable idea">reasonable idea</category>
      <source url="http://blog.sciencelogic.com/a-review-of-em7/11/2008">A Review of EM7</source>
    </item>
    <item>
      <title><![CDATA[The Economics of Finding and Fixing Vulnerabilities in Distributed Systems ]]></title>
      <link>http://securityratty.com/article/8a34266a61546df04c75d0de7416a33d</link>
      <guid>http://securityratty.com/article/8a34266a61546df04c75d0de7416a33d</guid>
      <description><![CDATA[The Economics of Finding and Fixing Vulnerabilities in Distributed Systems
Quality of Protection Keynote
Alexandria, VA
October 27. 2008

Gunnar Peterson
Managing Principal, Arctec Group
Blog:...]]></description>
      <content:encoded><![CDATA[<div>The Economics of Finding and Fixing Vulnerabilities in Distributed Systems&#0160;</div><div><a href="http://qop-workshop.org/Program.htm">Quality of Protection Keynote</a></div><div>Alexandria, VA</div><div>October 27. 2008</div><br /><div>Gunnar Peterson</div><div>Managing Principal, Arctec Group</div><div>Blog: http://1raindrop.typepad.com</div><br /><div>When Andy Ozment asked me over the summer to do this talk at QoP, I knew back in August that the topic I wanted to address was security and economics. So to that end I would like to start by thanking all of our friends on Wall Street and here in Washington DC for providing such a rich tapestry of recent events that I can speak to.</div><br /><div>Like many people in this industry, my focus on security was fundamentally altered by Dan Geer&#39;s speech &quot;Risk Management is Where the Money Is&quot;[1], there are not many people who can call a ten year shot in the technology business, but Dan Geer did. The talk revolutionized the security industry. Since that speech, the security market, the vendors, consultants, and everyone else has realized that security is really about risk management.</div><br /><div>Of course, saying that you are managing risk and actually managing risk are two different things. Warren Buffett started off his 2007 shareholder letter [2] talking about financial institutions&#39; ability to deal with the subprime mess in the housing market saying, &quot;You don&#39;t know who is swimming naked until the tide goes out.&quot; In our world, we don&#39;t know whose systems are running naked, with no controls, until they are attacked. Of course, by then it is too late.</div><br /><div>So the security industry understands enough about risk management that the language of risk has permeated almost every product, presentation, and security project for the last ten years. However, a friend of mine who works at a bank recently attended a workshop on security metrics, and came away with the following observation - &quot;All these people are talking about risk, but they don&#39;t have any assets.&quot; You can&#39;t do risk management if you don&#39;t know your assets.</div><br /><div>Risk management requires that you know your assets, that on some level you understand the vulnerabilities surrounding your assets, the threats against those, and efficacy of the countermeasures you would like to use to separate the threat from the asset. But it starts with assets. Unfortunately, in the digital world these turn out to be devilishly hard to identify and value.</div><br /><div>Recent events have taught us again, that in the financial world, Warren Buffett has few peers as a risk manager. I would like to take the first two parts of this talk looking at his career as a way to understand risk management and what we can infer for our digital assets.</div><br /><div>Warren Buffett&#39;s evolution as an investor can be broken up into two parts. He began his career very much influenced by Ben Graham, who sought to buy &quot;cheap stocks&quot;, comparing the price of the stock to value of the company&#39;s assets, and placing many, diversified bets on companies whose share price was below the total assets. Note that the businesses may have been of unremarkable quality, but when the price was right Graham would buy in, wait for it to rise and then sell. This was the dawn of value investing.</div><br /><div>Buffett&#39;s later career departed from Graham&#39;s strict, statistical measures, where he sought to buy into companies that were selling at a fair price, but were also high quality businesses. We will examine high quality in Part 2 of this talk, but first we go to Part 1 which is asset value.</div><br /><div>Why does a talk on finding and fixing vulnerabilities start with valuing assets? The reason is that vulnerabilities are everywhere, we are literally marinating in them. Interesting vulnerabilities are attached to high value assets. In a world that quite literally presents us with too much information, we need screens to sift out what is worth paying attention to. &#0160;You can run your vulnerability assessment tool of choice on your system, and come back with hundreds or thousands of vulnerabilities, but which ones should you pay attention to and act on? The first part of answering this question is asset value.</div><br /><div>When Warren Buffett was 19 years old studying at the University of Nebraska, he read Ben Graham&#39;s book &quot;The Intelligent Investor&quot;, Buffett said he thought it was the best book on investing he has ever read and still feels that way today. In the Intelligent Investor Graham lays out the framework of value investing. Specifically, Graham talks about three concepts - Mr. Market, a stock is a piece of a business, and Margin of Safety.</div><br /><div>Mr. Market is a fictional, teaching device invented by Graham. You imagine that you have a somewhat manic depressive business partner called Mr. Market. Every day, Mr. Market comes into the office and offers you quotes on companies, some days he is in a good mood and the prices are high, other days he is gloomy and prices are low. The market is a quote machine, for quoting prices, not a value assessment machine. Your job is to wait for the right price, and you are free to take as many passes and be as patient as you would like, Mr. Market will just show up the next day and throw out a new price.&#0160;</div><br /><div>Graham used Mr. Market to teach us the separation between a price of a stock, and the value of a company. The second big concept from Intelligent Investor is that buying a stock is buying a small piece of the underlying business. You are not buying a roulette chip, or a number that fluctuates in the newspaper every day, rather you are buying a piece of the company&#39;s existing and future cash flow. What the stock market says General Electric is worth yesterday, today or tomorrow is separate from GE&#39;s actual ability to generate cash flow.</div><br /><div>The last big concept in &quot;The Intelligent Investor&quot; and the one seemingly most applicable to information security is the Margin of Safety. Graham&#39;s margin of safety involved calculating the intrinsic value of a business and then buying stock where the market cap of a company is less than its intrinsic value. So if a company has $100 million in assets and a market capitalization of $75 million, then an investor would get a 25% margin of safety. Ideally, Graham wanted to buy stocks that were selling for one half of their book value, i.e. with a 50% margin of safety. Graham said that buying stocks without a margin of safety, above their book value, speculation, not investing.</div><br /><div>So price is readily available, but how do we calculate intrinsic value so that we can ascertain the margin of safety? Graham used quantitative statistical measures, relying heavily on the company&#39;s book value, like its hard assets. What would it take for a competitor to reproduce the company&#39;s assets - its factories, distribution system, and so on. The difference between the book value of the assets and market cap is the margin of safety.</div><br /><div>What can we learn in information security from this quantitative approach? Where price and value are readily ascertainable we should build countermeasures and eliminate on vulnerabilities that give our assets a wide margin of safety. Since budgets are not unlimited we should prefer vulnerabilities that are cheap to find, cheap to fix.</div><br /><div>First to the asset question, information security budgets like all IT budgets are crufty, they are not a reflection of today&#39;s top issues and priorities so much as an accumulating snowball of decisions, legacy contracts, and solution attempts to yesteryear&#39;s problems. Today the normal Information Security budget is just a legacy artifact from bygone years when the network was the purported greatest vulnerability. If you were around in 1995, you remember the great gnashing of gears as the enterprises opened up their networks, connected their back ends to the Web and began to transact business in the giant virtual space.</div><br /><div>The security people huffed and puffed that it was dangerous but there was simply too much money to be made, so businesses went ahead. The security people would not go down without a fight and insisted on countermeasures. They got two - the network firewall and SSL. The firewall was used to separate the average Fortune 500s network of hundreds of thousands of machines, employees, consultants, and partners from the web at large. SSL was used to protect the network channel between the web server and the client browser. so the network firewall separated the network segments, and SSL in effect encrypted the last mile of many million complex transactions and computations.</div><br /><div>In 1995, this seemed like a good security architecture. When we built out these security architectures, the eCommerce market was derided as a toy. Amazon famously lost money for years - losing a little on every transaction but making it up in volume. When the market is nascent, a quaint security architecture offers cost effective protection. But what about 2008? Those cute little eCommerce buggers have grown they even make profits now - market caps measured in the tens of billions, accumulating large cash hordes, no debt, and the largest ones are in better financial shape than the financial services players that kicked sand in their face in the dotcom era.&#0160;</div><br /><div>And its not just eCommerce, the &quot;real&quot; economy Fortune 500 types are all connected as well. Directly and indirectly the Web is seeping into all businesses. Major changes from when the security architecture of the web was built out. But has the security architecture changed to reflect these new business realities? Not a bit of it!</div><br /><div>We can use the book value of the IT budget investments and the book value of the Information Security investments to see what kind of Margins of Safety Information Security groups are engineering.</div><br /><div>Let&#39;s look at some market data, Gary McGraw reviewed the numbers [2] in software security for 2007, breaking down software security sectors like tools and services. Here is a summary of his findings on software security tools:</div><br /><div>&quot;One of the most important developments in the software security market can be seen in the tools space which, combined, almost doubled to $150-180 million. Top of list are two major acquisitions that closed in 2007: Watchfire&#39;s purchase by IBM (somewhere in the range of $120-150 million on 2006 revenue of $26 million) and SPI Dynamics&#39;s purchase by HP (for around $100 million on 2006 revenue of $21.2 million).</div><br /><div>...</div><br /><div>The black box space was flat in 2007, with IBM/Watchfire checking in at $24.1 million and HP/SPI Dynamics earning $22.3 million. Smaller companies in the space, including Cenzic, Codenomicon, WhiteHat and the like had combined revenues around $12.5 million (a growth of 25%, though Cenzic grew 16% and WhiteHat 52%). Most of the growth &quot;hiccup&quot; in the black box market can be attributed to the serious challenges posed by any acquisition. So far 2008 looks to be back on track from a growth perspective in the black box testing space. The global reach that IBM and HP offer are already making a big difference.</div><br /><br /><div>On a more positive note, static analysis tools for code review grew at a healthy clip in 2007 into a $91.9 million dollar market. Fortify was up 83% to $29.2 million. Klocwork grew over 60% to $26 million. Coverity grew over 50% to $27.2 million. Ounce Labs tripled their revenue to $9.5 million.&quot;</div><br /><div>These are very nice growth numbers, what company doesn&#39;t want 83% growth? However, the let&#39;s look at the total picture and compare the software security countermeasures against other security mechanisms. Gary McGraw&#39;s estimate shows the software security space coming in at $150 Million total, yet we see a company like Checkpoint that won the network security war in 1995 with earnings of around $900 Million! One single network security vendor is 6 times bigger than the entire software security space, in what alternate universe does this make sense?</div><br /><div>This is where we begin to see that decisions in the People&#39;s Republic of Information Security have no real risk management thinking, they truly are swimming naked and hoping the tide doesn&#39;t go out.</div><br /><div>Let&#39;s look at network assets. Obviously Cisco is the biggest, they earned $39.5 Billion last year. Pretty stellar. So spending $900 Million (Checkpoint) to defined $39.5 Billion seems like a pretty good deal.</div><br /><div>Except, let&#39;s compare software security spending - last year Microsoft earned $60 Billion, SAP $16 billion, and Oracle $22 Billion. So that is about $98 Billion in just three vendors and you are going to &quot;defend&quot; that with allocating $150 Million worth of software security tools?</div><br /><div>On the network side we are buying $900 million of security countermeasures (Checkpoint firewalls) to protect $39.5 billion worth of Cisco gear, about 2.3% of the network investment goes to security.</div><br /><div>On the software side, we are buying $150 million of security countermeasures (like static analysis and black box scanners) to protect $98 billion of software (you know the stuff that runs the whole business), roughly coming to about 0.2% of the software budget goes to security.</div><br /><div>This is very disturbing. From a prioritization standpoint The People&#39;s Republic of Information Security is misaligned by an order of magnitude at least. Next time you read about a data breach, or see an auditor&#39;s report with thousands of findings you won&#39;t have to wonder how it happened. It happened because Information Security doesn&#39;t have its eye on the ball, it invests in network security not because those controls have greater efficacy (the whole point of networks is they are dumb), no, they invest in network firewalls because they bought a bunch in 1995, some more in 1998, and heck they just kept buying them, the Checkpoint rep kept showing up and taking CISOs out to play golf, contracts got renewed, and poof - there goes the security budget.</div><br /><div>Consider that software security tools could grow 50% a year for five years and still be half of where Checkpoint is today.</div><br /><div>The optimistic way of looking at all this data is that there is major room for growth for software security, if you take network security as a target for a mature industry and assume that 2.3% is a reasonable margin of safety, then the software security space should evolve to around 2% of the software space meaning that it should evolve into a $2 billion space around fifteen times larger than it is today. Unprotected assets will either be protected or will cease to be assets, VCs get your check books ready.</div><br /><div>My friend Brian Chess has a nice way of looking at this he says 2007 was the turning point - &quot;the first year there was a bigger market for products that help you get code right than there was for products that help you demonstrate a problem exists.&quot;</div><br /><div>Now I am not suggesting that Information Security budgets have to be aligned with IT budget one for one, but I do think that looking at the overall IT budget is the starting point. If Information Security has a more cost effective security mechanism they should deploy it, but the starting point should be aligned to the business. Businesses spend most of their money on software, and there are very good reasons - competitive advantage, increased revenues and lower costs. Information Security spends most of its money on network security, and there is no good reason why, except that it was a seemingly good idea in 1995. You really don&#39;t have to go beyond the book value of IT investment as a whole versus Information Security to see a stunning disparity. Information Security&#39;s job is to deliver a Margin of Safety to the business, but they are not.&#0160;</div><br /><div>To deliver a real Margin of Safety to the business, I propose the following based on a defense in depth mindset. Break the IT budget into the following categories:</div><br /><div>- Network: all the resources invested in Cisco, network admins, etc.</div><div>- Host: all the resources invested in Unix, Windows, sys admins, etc.</div><div>- Applications: all the resources invested in developers, CRM, ERP, etc.</div><div>- Data: all the resources invested in databases, DBAs, etc.</div><br /><div>Tally up each layer. If you are like most business you will probably find that you spend most on Applications, then Data, then Host, then Network.</div><br /><div>Then do the same exercise for the Information Security budget:</div><br /><div>- Network: all the resources invested in network firewalls, firewall admins, etc.</div><div>- Host: all the resources invested in Vulnerability management, patching, etc.</div><div>- Applications: all the resources invested in static analysis, black box scanning etc.</div><div>- Data: all the resources invested in database encryption, database monitoring, etc.</div><br /><div>Again, tally each up layer. If you are like most business you will find that you spend most on Network, then Host, then Applications, then Data. Congratulations, Information Security, you are diametrically opposed to the business!</div><br /><div>Its not just about alignment for alignment&#39;s sake, its about applying controls as a way to have a Margin of Safety properly placed so that when not if there is a failure on a higher value asset you are relatively better positioned to deal with it.&#0160;</div><br /><div>The pure statistical approach can only take us so far. Buffett said he would be a lot poorer if all he did was listen to Ben Graham. Book value is great to see the diametric opposition mentioned above, but it doesn&#39;t really tell us much about the efficacy of the security mechanisms.</div><br /><div>What we do get out of this statistical approach is a screen. The asset value screen filters out subjective opinion and narrows the field for where we need to dig in to do the high value, time consuming analytical work.</div><br /><div>The second part of Warren Buffett&#39;s career and the second part of this talk leave behind pure statistical measures. In Warren Buffett&#39;s case he was joined by a guy named Charlie Munger who talked him out of the pure Ben Graham approach. Charlie Munger has a saying - &quot;a great business at a fair price beats a fair business at a great price.&quot; Where Graham was focused on price and margin of safety, Munger wants a fair price but also a high quality business. This lead to Warren Buffett&#39;s company Berkshire Hathaway investing in companies like Coca Cola, Wells Fargo, and American Express, where the prices were far from dirt cheap (as Graham would have wanted), but the long term returns were outstanding.</div><br /><div>In our world of Information Security, we start by aligning our priorities with the business using the thumbnail defense in depth approach, but then we would like to invest in high quality, effective controls.</div><br /><div>To get at the notion of control quality and effectiveness, I am going to start part 2 of this talk with a brief history of software. The first web software was just static HTML, but web software really got interesting when developers started creating dynamic websites using CGI an PERL.</div><br /><div>Once websites were hooked up to company databases and were not just serving static content, the security people realized they needed a security architecture, and they sprung into action. What they came up was was model that divided the world into &quot;good stuff&quot; which was comprised of all their networks, systems, and data; and then there was everything else the &quot;bad stuff&quot; on the Internet. So job one of the early days Internet security architecture was to separate all your good stuff (i.e. your network) for the bad stuff (the Internet). To do this the security people used a sophisticated tool called Visio to draw a flaming brick wall on the network diagram, and this flaming brick wall was supposed to keep the good stuff and the bad stuff separate.</div><br /><div>The security people also realized that the data and session tokens that they served up from their Web server would have to traverse the &quot;bad&quot; neighborhood called the Internet, so they added one more security mechanism to secure the last mile of the transaction - SSL between the browser and the Web server.</div><br /><div>And this was the state of the art security architecture used circa 1995 to protect the earliest dynamic web applications.</div><br /><div>What happened next was that the dotcom boom started to happen and businesses realized they could make some real money on the Web, the web apps started to get more sophisticated, more personalization, richer session experiences and so on. This led the Java people to create JSP and the Microsoft people to create ASP, and of course the PERL people to create even greasier PERL scripts, all of this in the effort to pooling resources and sessions on the Web server. The security people defended this new application programming model with network firewall and SSL.</div><br /><div>Around 1998, developers began building out more distributed N tier or 3 tier applications that separated the business logic layer, the presentation layer and the data access layer. Among other things, your web application could seamlessly integrate data from multiple back ends systems. Let&#39;s say you have pricing data in Oracle, order data in SAP, and customer data in a Mainframe. You write separate data access objects, apply business logic in the middle tier and then you tie it all together in a friendly user interface. At this point the web applications are beginning to integrate across departments and geographic boundaries, huge critical chunks of the business are now connected to the web. How did the security people defend this part of the business? They applied the same 1995 security architecture - network firewall and SSL.</div><br /><div>Around 1999-2000 timeframe businesses relied on web applications for major parts of the revenue, and the apps were built in different technologies like Java and Microsoft technologies, but the customer didn&#39;t care (still doesn&#39;t), the customer wanted (and still wants) data access and functionality. So to integrate the disparate technologies, SOAP and XML were deployed so that Microsoft could talk to Java and so Websphere could talk to Weblogic and so on. And, oh yes, SOAP and XML were used to connect B2B networks so partners in a supply chain and business process can exchange data and interoperate. &#0160;SOAP and XML present a fundamentally new programming model based on a message document style integration, where XML is used to mesh together data and functionality across platforms. SOAP and XML have no security model by default for authentication, authorization, and confidentiality. How did the security people deal with this? They kept the security architecture the same as they had in 1995 - network firewalls and SSL.</div><br /><div>The software world did not stop innovating in 2000 of course, in the last few years we have seen Web services and XML form the basis of baroque and powerful SOAs and simple REST applications. We have seen Web 2.0 come on the scene, and entirely new networked applications built on top of that.</div><br /><div>What we have not seen, is a single meaningful change in security architecture in 13 years. Developers have evolved, businesses have increasingly bet their entire business models on the web and they have increased security budgets. But what has the security architecture as its deployed in the field got to show for all of this? More firewalls and more SSL connections.</div><br /><div>Since Information Security has proven incapable of evolving, it is time to learn from a discipline that has mastered innovation - software development, and yes, I will step back in case the lightning bolts hits.</div><br /><div>What does software development focus on these days? Well, let&#39;s look at Service Oriented Architecture (SOA), all hype aside I look at SOA as a set of technologies that delivers three things:</div><br /><div>Virtualization: we want Beijing, Bangalore and Boston to communicate.</div><br /><div>Interoperability: we want our .Net stuff to talk to our java stuff.</div><br /><div>Reusability: how many order/claim/pricing/customer systems does one company need?</div><br /><div>To build out their SOA, developers separated the application interface from its implementation. So you can host the interface in a variety of locations, but its separate from the application logic and data.</div><br /><div>This is also a useful trick for putting services like SOAP through the firewall. SOAP was designed as a firewall friendly protocol. When SOAP first came out, Bruce Schneier said calling SOAP a firewall friendly protocol is like having a skull friendly bullet. Which is a great line and explains why his books fly off the shelves, it does not explain, why security people think an architecture designed in 1995 is the one we should be using today. Maybe the problem is not that the developers figured out how to go through the firewall to get the data their customers want, maybe the problem is that the firewall is the sum total of the security architecture, and it never adapted.</div><br /><div>A big part of this problem is that we have left Newton&#39;s world behind and entered Einstein&#39;s universe. Mainframes are Newton’s world, we have THE computer, THE price, THE record and so on.</div><br /><div>As Pat Helland explained [4,5], Mainframes are Newron&#39;s world, but Distributed computing is Einstein’s world. More specifically in the Einstein world of distributed computing - &quot;Computers don’t make decisions, computers try &#0160;to make decisions.&quot; Our computers don&#39;t really make a decision, they say you can buy this book from Amazon at this price, we have it in stock and will deliver on such and such a date. But the warehouse runs out, the pallet gets dropped in the warehouse, your boo is crushed, and the package is stolen off your front step. The computer confirmed your transaction, but the real world intervened.</div><br /><div>So we don&#39;t have iron clad decisions, instead its all about Memories (last time I checked your book was in stock), Guesses (we should be able to ship on this date) and Apologies (sorry the forklift ran over your book)</div><br /><div>Translating this into security, security mechanisms don’t make policy-based decisions, security mechanisms try to make policy-based decisions</div><br /><div>Some examples of memories, guesses and apologies in security</div><br /><div>Memories</div><div>Security Policies - for example Triple A policy</div><div>Triple A policies can memorize a map of subjects, objects, and roles. They can even replicate these memories and play them back at runtime to try to make policy enforcement decisions.</div><br /><div>Guesses</div><div>Security Policy Enforcement Decision</div><div>Unfortunately, while the policy enforcement decisions can be based on memorized logic, the decision itself is still a guess, even in the case of Triple A. Any guesses why? Because, the authentication process itself is a guess. It happens to be a guess that you then bind to a principal so it looks very official once you bind your guess to a Kerberos ticket or SAML assertion, but it still a guess.</div><br /><div>Apologies</div><div>Giant Global Bank is sorry your account was compromised!</div><div>And this leads to lots and lots of apologies by companies with poor access control models.</div><br /><div>Some additional examples of information security memories, guesses and apologies.</div><br /><div>Example Memories - Triple A Security Policies, Audit logs, User account information , Authorization Logic - concrete mapping Subject, Resource, Condition, Action</div><br /><div>Example Guesses - Security Policy Enforcement Decision Points, Authentication Logic, Monitoring, detection, fraud response</div><br /><div>Example Apologies - Identity Management tools - provisioning, deprovisioning, Reimburse customer for fraud losses, Compensating Transaction - Giant Global Bank is still sorry your account was compromised!</div><br /><div>The point of this is that security memories, guesses and apologies utilize different processes, different people, and different capabilities to be effective.</div><br /><div>What trends can we identify to lead us toward better qualitative analysis based on the best practices of virtualization, interoperability and reusability.</div><br /><div>Virtualization</div><div>Finding Vulnerabilities in a Virtualized World is a problem because applications are more configured than coded. Runtime behavior and structure not apparent due to weak typing and inversion of control.</div><br /><div>Result - finding bugs becomes harder. Action - use screens to target finding time and resources</div><br /><div>Fixing Vulnerabilities in a Virtualized World is a problem because how do I locate the controls when interfaces run in Beijing, Bangalore and Boston?</div><br /><div>Result - synchronization and/or replication of security policy is problematic. Action - decentralized policy enforcement points and policy decision points. &#0160;</div><br /><div>Interoperability</div><div>Finding interoperable vulnerabilities</div><div>XSS - Javascript is an equal opportunity offender - interoperability for developers and attackers alike.</div><br /><div>Fixing interoperable vulnerabilities</div><div>App servers, ESBs, and services are the attacker’s red carpet to your enterprise, right into your book of business. Interoperable access control can be leveraged across the enterprise.</div><br /><div>Use XML signature for authentication and integrity&#0160;</div><br /><div>&lt;SOAP:Envelope&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;SOAP:Header&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>&lt;WSSE:Security&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">			</span>&lt;ds:Signature&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">				</span>&lt;ds:Reference URI=‘#body’&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>&lt;/WSSE:Security&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;/SOAP:Header&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;SOAP:Body wsu:Id=‘body’&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>…</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;/SOAP:Body&gt;</div><div>&lt;SOAP:Envelope&gt;</div><br /><div>Use XML encryption to protect sensitive data, don&#39;t pass sensitive data in the clear</div><br /><div>&lt;?xml version=&#39;1.0&#39; encoding=&#39;UTF-8&#39;?&gt;</div><div>&lt;soapenv:Envelope xmlns:soapenv=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot;&gt;</div><br /><div>&lt;soapenv:Body&gt;&lt;ns1:echo xmlns:ns1=&quot;http://sample01.samples.rampart.apache.org&quot;&gt;</div><br /><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;param0&gt;My Credit Card Number&lt;/param0&gt;</div><div>&lt;/ns1:echo&gt;</div><div>&lt;/soapenv:Body&gt;</div><div>&lt;/soapenv:Envelope&gt;</div><br /><div>Encrypt the data</div><br /><div>&#0160;&lt;wsse:Security xmlns:wsse=&quot;http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd&quot; soapenv:mustUnderstand=&quot;1&quot;&gt;…</div><div>&#0160;&#0160; &#0160; &#0160; &#0160; &#0160; &#0160;&lt;xenc:EncryptedKey Id=&quot;EncKeyId-3020592&quot;&gt;</div><div>&#0160;&#0160; &#0160; &#0160; &#0160; &#0160; &#0160; &#0160; &lt;xenc:EncryptionMethod Algorithm=&quot;http://www.w3.org/2001/04/xmlenc#rsa-1_5&quot; /&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span> &lt;xenc:CipherValue&gt;</div><div>XNQ0a4legiie5mWFxO6CQkk2hhldYNnKroObue/LXS/VYtvaTgMbCujhGExDi+vlkU//Qc2/T6mx0WVTmBMT3z8rogha8jD+nS9Zr2Bc3CwoTh2lh8wL3D0DEu91iwJT9JByLGXvt7v9lyuxK0ooDOYEClsH974CPmTs3tBC+GQ=</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>&lt;/xenc:CipherValue&gt; &#0160; &#0160; &#0160; &#0160; &#0160; &#0160; &#0160;&#0160;</div><div>&lt;/xenc:CipherData&gt;</div><br /><div>To ensure that these controls are applied use automated tools like static analysis to scan for security mechanism use and coverage.</div><br /><div>In terms of reusability findings and fixes consider two bug findings</div><br /><div>Session management bug: session state is passed around to every component, service and user. Makes for many high priority findings in audit report, also the fix is required on virtually every program</div><br /><div>Data validation bug: Data access object (DAO) has a SQL injection hole. One major high priority finding in report. DAO used by many business logic classes, one fix location serves many classes&#0160;</div><br /><div>To bring these factors together, I generally use a scorecard index [6], so you can measure such things as transport security, message security, threat protection and so on. The hard work in developing the index is developing a useful scale. A scale for XML tokens could use the following</div><br /><div>0: no token</div><div>1: hashed token</div><div>2: hashed and signed token</div><div>3: hashed and signed token from standard authoritative source</div><br /><div>An example scale for XML validation could use:</div><br /><div>0: no validation</div><div>1: schema validation</div><div>2: schema validation against hardened schema</div><div>3: schema validation against standard, hardened schema</div><br /><div>These indexed scales are used to show maturity across the factors in the scorecard. The first part of the talk described value, the value assessment is used to focus time and effort on high value assets. The value assessment can be determined quantitatively. There is hard analytical work to qualitatively determine the scorecard, index, and scales, the quantitative value assessment is used to screen out high value targets for these endeavors. The scoring index is used to track progress and improve quality over time. In the best case scenario, automated tools are used to perform the checks described in the index, and once security is automated just like software developers we may see security innovation make progress in years not decades.</div><br /><div>Thank you for your time.</div><br /><div>1 &quot;Risk Management is where the Money Is&quot; by Dan Geer,&#0160;<a href="http://catless.ncl.ac.uk/Risks/20.06.html">http://catless.ncl.ac.uk/Risks/20.06.html</a></div><br /><div>2 Berkshire Hathaway 2007 Shareholder Letter by Warren Buffett, <a href="http://www.berkshirehathaway.com/letters/2007ltr.pdf">http://www.berkshirehathaway.com/letters/2007ltr.pdf</a></div><br /><div>3 &quot;Software [In]security: Software Security Demand Rising, by Gary McGraw</div><div><a href="http://www.informit.com/articles/article.aspx?p=1237978">http://www.informit.com/articles/article.aspx?p=1237978</a></div><br /><div>4 &quot;SOA and Newton&#39;s Universe&quot; by Pat Helland, <a href="http://blogs.msdn.com/pathelland/archive/2007/05/20/soa-and-newton-s-universe.aspx">http://blogs.msdn.com/pathelland/archive/2007/05/20/soa-and-newton-s-universe.aspx</a></div><br /><div>5 &quot;Memories, Guesses and Apologies&quot; by Pat Helland, <a href="http://blogs.msdn.com/pathelland/archive/2007/05/15/memories-guesses-and-apologies.aspx">http://blogs.msdn.com/pathelland/archive/2007/05/15/memories-guesses-and-apologies.aspx</a></div><br /><div>6 &quot;Web Servicres Security Checklist&quot; by Gunnar Peterson, <a href="http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf">http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf</a></div>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 19:47:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security spends">information security spends</category>
      <category domain="http://securityratty.com/tag/safety information security">safety information security</category>
      <category domain="http://securityratty.com/tag/versus information security">versus information security</category>
      <category domain="http://securityratty.com/tag/information security budgets">information security budgets</category>
      <category domain="http://securityratty.com/tag/information security budget">information security budget</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/software security space">software security space</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/the-economics-of-finding-and-fixing-vulnerabilities-in-distributed-systems-.html">The Economics of Finding and Fixing Vulnerabilities in Distributed Systems </source>
    </item>
    <item>
      <title><![CDATA[National Security Perspectives A Post-Election Insider View]]></title>
      <link>http://securityratty.com/article/caa8257ee971993e58e1b834379f8c71</link>
      <guid>http://securityratty.com/article/caa8257ee971993e58e1b834379f8c71</guid>
      <description><![CDATA[Recently I participated in an event entitled National Security Perspectives held at the famous Congressional Country Club in Maryland . The featured panelists had impressive credentials from the NSA ,...]]></description>
      <content:encoded><![CDATA[<p>Recently I participated in an event entitled National Security Perspectives held at the famous <a href="http://www.ccclub.org/" target="_blank">Congressional Country Club in Maryland</a>. The featured panelists had impressive credentials from the <a href="http://www.nsa.gov/" target="_blank">NSA</a>, <a href="http://www.dhs.gov/" target="_blank">DHS</a> and the <a href="https://www.cia.gov/" target="_blank">CIA</a>. The topics of discussion ranged from Current Geopolitical Threats and Evolving Technology Demands to predictions about the New Administrations Intelligence, Defense and Homeland Security focus.</p>
<p>The panelists were:<br />
<a href="http://en.wikipedia.org/wiki/National_Security_Agency" target="_blank">William P. Crowell</a> – former Deputy Director of the National Security Agency<br />
<a href="http://www.whitehouse.gov/government/m_jackson-bio.html" target="_blank">Michael P. Jackson</a> – Deputy Secretary, Department of Homeland Security<br />
<a href="http://en.wikipedia.org/wiki/Jose_Rodriguez_(intelligence)" target="_blank">Jose A. Rodriguez, Jr</a>. – former Director CIA, National Clandestine Service &amp; CIA, DCI Counterterrorist Center</p>
<p>Overall, it was a very nicely arranged event on a brisk fall evening with about 100 CXO attendees; mostly large but some small government contractors and a few product companies like ScienceLogic that conduct business with military, intelligence and the public sector.</p>
<p>No surprise, given the financial crisis the economy is suffering from that the panelists said we also have a <a href="http://obsidianwings.blogs.com/obsidian_wings/2008/11/defictits-actua.html" target="_blank">crisis coming on the Federal budget front</a>. This will put enormous pressure on the way Administration thinks, and how and where to spend the $$.</p>
<p>Obama’s tone regarding the issues he will be confronting in the world during the election was encouraging. Make the world more non-partisan and take on the threats that we have in front of us head-on!</p>
<p>The panel was very upfront about current threats. William Crowell said,</p>
<blockquote><p>“It is highly imprudent to believe that there will not be another 9-11. We have to fund and support the work to stop other attacks. We can only mitigate risk but we can’t eliminate risk. We have to try to absorb the sense of urgency and wake up every day looking at the intelligence screens as if 9-11 happened within the last couple of months.”</p></blockquote>
<p>He added,</p>
<blockquote><p>“They (the intelligence community) need the innovation, sense of commitment and urgency that comes from the private sector – a sense of mutual commitment to that mission.”</p></blockquote>
<p>Predicted Priorities for investment for DHS:</p>
<ol>
<li>Cyber attack as the top issue</li>
<li>Nuclear threats including dirty bomb</li>
<li>Chemical and biological attacks</li>
<li>Explosive attacks against critical infrastructure with maximum # of lives and or financial disruption / loss.</li>
<li>Large scale natural disasters – hurricane + earthquakes</li>
<li>Border penetration - identity management and border management issues</li>
</ol>
<p>An <a href="http://www.barackobama.com/index.php" target="_blank">Obama administration</a> will spend dollars around these threat vectors. They will want to spend $$ to help state and local governments. Grants to state and local governments should significantly increase with the Obama administration, so think about how you will increase your focus on the state and local government spending initiatives.</p>
<p><a href="http://lawprofessors.typepad.com/immigration/2008/11/pressure-on-oba.html" target="_blank">Secure border investments</a> – the panelists believe that the new administration will feel compelled to invest here. Michael P. Jackson bluntly said, “You have to make investments in border tools to get meaningful immigration reform.”</p>
<p>Panelists agreed that the 1<sup>st</sup> year will be an intense period of scrutiny about fundamental directions. We can’t afford it all at DHS; it is dramatically under budgeted. At TSA/DOT and then at DHS, we spent about $4 Billion on technology investments since 9-11; those investments are now reaching the end of the original service life.</p>
<p>One gripe from the panel that I found humorous: “We don’t have a group of people who think like entrepreneurs.” It is insane how long things last when you buy things in the government. As an example, we are still replacing vacuum tubes in some of the very old FAA gear… this is well beyond what any reasonable person would think these initial investments should/would last.</p>
<p>Final Thoughts:<br />
I actually think that the Obama Administration will be quite favorable to COTS software products, SaaS offerings, and creative financing initiatives from the private sector. The government just won’t have the capital budget to do everything it wants to accomplish. I would say if you look at how intelligently and aggressively <a href="http://www.concurringopinions.com/archives/2008/11/obama_and_techn.html" target="_blank">Obama used technology</a> to assist his campaign, the odds are good that this new breed of IT talent (which is already really comfortable with SaaS products, blogs, wiki’s, hosted/outsourced Cloud solutions… this team really understands the latest technology trends) will quickly work to bring these new IT paradigms to the Federal marketplace. Clearly the private sector can help the Government achieve more with lower capital budgets – beginning to provide services rather than transaction-based selling. Another clear idea is to think about leasing as a better way to work with the government which going forward will have increased budgets restrictions.</p>
<p>They will likely be in confrontation with members of Congress that won’t change fast enough, however the future of our nation’s ability to fight terror lies in becoming more efficient and effective. It requires the government be flexible enough to figure out what <a href="http://blogs.techrepublic.com.com/hiner/?p=880" target="_blank">jobs and IT functions to outsource</a> in a nimble and smart way. My prediction: this is great news for Service Providers. Overall the next 4 years should be great for our business as well as the Managed Service Provider/SaaS industry!</p>
<p><em><span style="color: #333333;"> </span></em></p>
]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 11:13:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/secure border investments">secure border investments</category>
      <category domain="http://securityratty.com/tag/investments">investments</category>
      <category domain="http://securityratty.com/tag/government contractors">government contractors</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <category domain="http://securityratty.com/tag/government achieve">government achieve</category>
      <category domain="http://securityratty.com/tag/initial investments shouldwould">initial investments shouldwould</category>
      <category domain="http://securityratty.com/tag/obama administration">obama administration</category>
      <category domain="http://securityratty.com/tag/current threats">current threats</category>
      <source url="http://blog.sciencelogic.com/national-security-perspectives-a-post-election-insider-view/11/2008">National Security Perspectives A Post-Election Insider View</source>
    </item>
    <item>
      <title><![CDATA[Chinese pirates crack Blu-ray DRM, sell pirated HD discs]]></title>
      <link>http://securityratty.com/article/8528f4f8dea5555e92596e5c96e9e190</link>
      <guid>http://securityratty.com/article/8528f4f8dea5555e92596e5c96e9e190</guid>
      <description><![CDATA[A recent bust in China netted several hundred pirated HD discs ripped from Blu-ray masters. The discs were only 720p, not 1080p, but their mere existence shows that Blu-ray's amped-up DRM schemes,...]]></description>
      <content:encoded><![CDATA[A recent bust in China netted several hundred pirated HD discs ripped from Blu-ray masters. The discs were only 720p, not 1080p, but their mere existence shows that Blu-ray's amped-up DRM schemes, AACS and BD+, won't be enough to stop pirates.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/2HyPEbQC928" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 10:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blu-ray">blu-ray</category>
      <category domain="http://securityratty.com/tag/discs">discs</category>
      <category domain="http://securityratty.com/tag/amped-up drm schemes">amped-up drm schemes</category>
      <category domain="http://securityratty.com/tag/blu-ray masters">blu-ray masters</category>
      <category domain="http://securityratty.com/tag/recent bust">recent bust</category>
      <category domain="http://securityratty.com/tag/mere existence">mere existence</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/720p">720p</category>
      <category domain="http://securityratty.com/tag/1080p">1080p</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/2HyPEbQC928/Chinese_pirates_crack_Blu_ray_DRM_sell_pirated_HD_discs">Chinese pirates crack Blu-ray DRM, sell pirated HD discs</source>
    </item>
    <item>
      <title><![CDATA[Mamma.com: Insider trading and XSS]]></title>
      <link>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</link>
      <guid>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</guid>
      <description><![CDATA[Mamma.com 's got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked 4064 on Alexa as of today
I won't profess to following...]]></description>
      <content:encoded><![CDATA[<a href="http://mamma.com/" target="_blank">Mamma.com</a>'s got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked <a href="http://www.alexa.com/search?q=mamma.com" target="_blank">4064</a> on <a href="http://www.alexa.com" target="_blank">Alexa</a> as of today.<br />I won't profess to following Mr. Cuban's public life and the occasional antics. Obviously, he's a colorful and popular figure; certainly in Dallas, if not nationally. <br />What follows is not a judgment of Mr. Cuban or his pending legal challenges. I'm sure the process will play itself out accordingly.<br />A quick summary and some reference material:<br />The SEC has <a href="http://www.businessweek.com/the_thread/blogspotting/archives/2008/11/sec_hits_mark_c.html?chan=technology_technology+index+page_top+stories" target="_blank">filed</a> insider trading charges against Mr. Cuban. "According to the SEC, Cuban dumped 600,000 shares, or all of his 6.3% stake, in the search engine Mamma.com (The Mother of All Search Engines), in June 2004 after learning about private financing that the company was proposing. By selling, he avoided losing $750,000, the SEC alleges."<br />The whole issue for Mr. Cuban was <a href="http://blogmaverick.com/2008/11/17/the-sec/" target="_blank">PIPE</a> financing because it's "dilutive to existing shareholders’ stakes."<br />That's the long and the short of the current issue, and again, not my real interest here, with the exception of the bet I made with myself regarding the probable web application security posture of mamma.com. <br />All this talk about a popular site immediately sets off the little bell in my head (I hear it a lot). <span style="font-weight:bold;"><br />"What's wrong with the site?" is always the first question I ask myself.</span> <br /><br />I was not disappointed. <br /><br />Mamma.com exhibits the following issues:<br />1) XSS vulnerability in the <span style="font-style:italic;">utfout<span style="font-weight:bold;"><span style="font-style:italic;"></span></span></span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s1600-h/mamma1.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s320/mamma1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129685521075730" /></a><br /><br />2) XSS vulnerability in the <span style="font-style:italic;">qtype</span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s1600-h/mamma2.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 201px;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s320/mamma2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129978766677474" /></a><br /><br />3) XSS vulnerability in their Mammajobs site at the <span style="font-style:italic;">pid</span> variable. This one's weirder still; if you drop an IFRAME in, it simply redirects to any URL you include in the IFRAME string.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s1600-h/mamma3.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 99px;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s320/mamma3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270130171179660098" /></a><br /><br />4) The prospect of CSRF (rather pointless here given that its just a search engine, but but still defies best practices) appears likely given that mamma.com blindly accepts updates via GET and POST with no sign of a formkey (canary) in sight.<br /><br />I figured it best to stop there, and have submitted all these to Copernic (the Momma parent company). <br />I am however truly disappointed that an enterprise as ambitious and motivated as Momma/Copernic seems to have thrown the baby out with the bath water when it comes to web application security.<br />With regard to Mark Cuban dumping his shares: maybe he was afraid of getting pwned. ;-) All kidding aside, it's a shame that the whimsical and pessimistic thoughts regarding web site security that bounce around in my head inevitably bear themselves out.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html&title=Mamma.com:%20Insider%20trading%20and%20XSS " title="Mamma.com: Insider trading and XSS ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html" title="Mamma.com: Insider trading and XSS ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 06:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mamma">mamma</category>
      <category domain="http://securityratty.com/tag/mark cuban">mark cuban</category>
      <category domain="http://securityratty.com/tag/cuban">cuban</category>
      <category domain="http://securityratty.com/tag/engine">engine</category>
      <category domain="http://securityratty.com/tag/engine mamma">engine mamma</category>
      <category domain="http://securityratty.com/tag/xss vulnerability">xss vulnerability</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/insider">insider</category>
      <category domain="http://securityratty.com/tag/web site security">web site security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Mamma.com: Insider trading and XSS</source>
    </item>
  </channel>
</rss>
