<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: technorati]]></title>
    <link>http://securityratty.com/tag/technorati</link>
    <description></description>
    <pubDate>Fri, 18 Jul 2008 05:18:07 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Monthly Blog Round-Up October 2008]]></title>
      <link>http://securityratty.com/article/425e8bb2014656857a1c215075620790</link>
      <guid>http://securityratty.com/article/425e8bb2014656857a1c215075620790</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>OF COURSE, the news of my “transition” is the item #1, by far. “<a href="http://chuvakin.blogspot.com/2008/10/change.html">Change!!!</a>” and “<a href="http://www.qualys.com/solutions/pci_compliance/">Qualys</a>” posts rule the list.</li>    <li>Last month I posted a bunch of my presentations on logs, security, etc on the blog.&#160; “<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Presentation from GOVCERT.NL 2008: Log Forensics</a>” takes one of the tops spots; and so do “<a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Presentation on Application Logging, Done Wrong or Very Wrong</a>” and “<a href="http://www.slideshare.net/anton_chuvakin/logs-vs-insiders-presentation">Presentation on Optimizing Your Logging for Insider Attack Tracking</a>.”&#160; BTW, all the presentations are <a href="http://chuvakin.blogspot.com/search/label/presentation">here</a>.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists.</li>    <li>SIEM bashing reached a new high (eh…“low”? :-)), now that Richard is <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">helping too</a>;&#160; my “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a> and <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">here</a>.)</li>    <li>Somewhat predictably, PCI compliance is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list.</li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in November.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bZriN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bZriN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=8jskN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=8jskN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=haLRN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=haLRN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/448986147" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 13:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/monthly top5 list">monthly top5 list</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/448986147/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up October 2008</source>
    </item>
    <item>
      <title><![CDATA[Three years of Blue Box podcasts....]]></title>
      <link>http://securityratty.com/article/cc61b7549892d897fdca3fb3d3366a42</link>
      <guid>http://securityratty.com/article/cc61b7549892d897fdca3fb3d3366a42</guid>
      <description><![CDATA[Today is a special day for me. It was three years ago on October 24, 2005, that Blue Box Podcast #1 was uploaded . It was an 11-minute episode where I talked about... Skype security, SIP security,...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml">Today is a special day for me.  It was three years ago on October 24, 2005, that <a href="http://www.blueboxpodcast.com/2005/10/blue_box_podcas.html">Blue Box Podcast #1 was uploaded</a>.  It was an 11-minute episode where I talked about... Skype security, SIP security, IETF, VOIPSA and some other VoIP security news.....   (Hmmm... sounds  lot like our <em>recent</em> shows, too, eh?)

<p>Jonathan Zar joined me a week later on <a href="http://www.blueboxpodcast.com/2005/11/blue_box_podcas.html">Blue Box Podcast #2</a> and we've been going ever since.  We've now produced over 112 episodes, had close to 245,000 downloads of our various shows, met some amazing people, learned a lot along the way... and hopefully helped you all learn a lot out there as well.

<p>Thank you to all of you who have joined with us on this journey... whether you've listened to our show from the very beginning (and we know of a couple of you who have) or have only recently joined in... <em>thank you</em>!

<p>And now... on to the next three years...  :-)


<!-- Technorati Tags Start -->
<p>Technorati Tags:
<a href="http://technorati.com/tag/blue%20box" rel="tag">blue box</a>, <a href="http://technorati.com/tag/bluebox" rel="tag">bluebox</a>, <a href="http://technorati.com/tag/dan%20york" rel="tag">dan york</a>, <a href="http://technorati.com/tag/danyork" rel="tag">danyork</a>, <a href="http://technorati.com/tag/jonathan%20zar" rel="tag">jonathan zar</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/voipsa" rel="tag">voipsa</a>
</p>
<!-- Technorati Tags End --></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=OCOyT6"><img src="http://feeds.feedburner.com/~a/BlueBox?i=OCOyT6" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=I5uhM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=I5uhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=f4w9M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=f4w9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Nsx0M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Nsx0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=FD20M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=FD20M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=PfrRm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=PfrRm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=lfcHM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lfcHM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/431331276" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 17:35:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/sip security">sip security</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/blue box podcast">blue box podcast</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/jonathan zar">jonathan zar</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/431331276/three-years-of-blue-box-podcasts.html">Three years of Blue Box podcasts....</source>
    </item>
    <item>
      <title><![CDATA[Blue Box's 3-year anniversary coming up on Friday... ]]></title>
      <link>http://securityratty.com/article/a116eaf0133996627443234f07d74420</link>
      <guid>http://securityratty.com/article/a116eaf0133996627443234f07d74420</guid>
      <description><![CDATA[It was three years ago Friday, on October 24, 2005, that I uploaded Blue Box Podcast #1 , an 11-minute show where I introduced the show, talked about VoIP security news (To no surprise, I was talking...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml">It was three years ago Friday, on October 24, 2005, that I uploaded <a href="http://www.blueboxpodcast.com/2005/10/blue_box_podcas.html">Blue Box Podcast #1</a>, an 11-minute show where I introduced the show, talked about VoIP security news (To no surprise, I was talking about Skype security!), some projects of VOIPSA and some other podcasts people might find interesting. A week later, on Halloween 2005, Jonathan joined me in <a href="http://www.blueboxpodcast.com/2005/11/blue_box_podcas.html">Blue Box Podcast #2</a> and we were off and running...

<p>Three years later... 84 main Blue Box episodes (with one more recorded) .... 26 Special Editions (with about 10 in the queue)... almost <em>250,000</em> downloads... we're still here and, with an admitted bit of a rough patch this summer, are still going along creating shows and enjoying what we do.

<p>Jonathan and I are planning to record a 3-year show on this coming Friday, October 24th, and if you have any comments you would like us to include in that show, please do get them to us by the end of the day on Thursday, October 23rd.  You can send them to us via:
<ul>
<li>Email to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>
<li>Phone to +1-415-830-5439
<li>Phone via SIP to <a href="sip:bluebox@voipuser.org">sip:bluebox@voipuser.org</a>
</ul>
<p>The show started out 3 years ago as really an experiment in seeing whether or not podcasting could be used to reach out to very specific audiences... and it's been both fun, amazing and interesting to see how well it's done.
<p>Thank you to all of you who have continued to listen and contribute over the years!


<!-- Technorati Tags Start -->
<p>Technorati Tags:
<a href="http://technorati.com/tag/blue%20box" rel="tag">blue box</a>, <a href="http://technorati.com/tag/bluebox" rel="tag">bluebox</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/dan%20york" rel="tag">dan york</a>, <a href="http://technorati.com/tag/jonathan%20zar" rel="tag">jonathan zar</a>, <a href="http://technorati.com/tag/voipsa" rel="tag">voipsa</a>
</p>
<!-- Technorati Tags End --></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=rawl4P"><img src="http://feeds.feedburner.com/~a/BlueBox?i=rawl4P" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=pWXDM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pWXDM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=eOTOM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=eOTOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=IXAsM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=IXAsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=4qxNM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=4qxNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=58c0m"><img src="http://feeds.feedburner.com/~f/BlueBox?i=58c0m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uhaaM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uhaaM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/426937191" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 15:22:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/blue box podcast">blue box podcast</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/october 24th">october 24th</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/426937191/blue-boxs-3-yea.html">Blue Box's 3-year anniversary coming up on Friday... </source>
    </item>
    <item>
      <title><![CDATA[Change!!!]]></title>
      <link>http://securityratty.com/article/5b3cb2048a4ff388096e282abddd6870</link>
      <guid>http://securityratty.com/article/5b3cb2048a4ff388096e282abddd6870</guid>
      <description><![CDATA[No, this is not about a certain populist US politician :-) It is about a much graver subject indeed
As of today, the only Chief Logging Evangelist in the world is no more. I have resigned from my...]]></description>
      <content:encoded><![CDATA[<p>No, this is not about a certain populist US politician :-) It is about a much graver subject indeed.</p><p>As of today, the only <strong><a href="http://www.chuvakin.org/">Chief Logging Evangelist</a></strong> in the world is no more. I have resigned from my position at <a href="http://www.loglogic.com/">LogLogic</a>, effective October 9, 2008, which is <strong>today</strong>. Please don't contact me at the company email; use <a href="http://www.chuvakin.org/">my personal email</a> instead. My <a href="http://www.linkedin.com/in/chuvakin">LinkedIn profile</a> has been updated accordingly.</p><p>If you are curious, I still love logs. I really do. Logs are cute :-) You should love them too. And, it goes without saying, I will always remember that title, <strong>Chief Logging Evangelist</strong>, that I have created for myself. <a href="http://chuvakin.blogspot.com/2008/02/new-morning-new-logs-life-goes-on.html">People did say</a> that "Anton wakes up and thinks 'what else he can do today to make the world love logs?'" - it was pretty much like this. In fact, I think <em>world does love logs</em> a tiny bit more now and thus my mission of a logging evangelist has not been in vain.</p><p>I will be offline for the entire next week ("OMG, no blogging?" - "Nope, no blogging!") and you, my dear reader, will have to wait until October 20th to hear the news about ...</p><p><span style="font-size:6;"><strong>... where Anton is NOW!!!???</strong></span></p><p>Yes, where is he? :-) </p><p>Talk to ya October 20th! The end always brings the new beginning ...</p><p>P.S. Please don't tell me that I have a <em>penchant</em> for dramatic. I know :-)</p><div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:b5cda46e-0cce-4b5e-b2b4-63d17d62b3f7" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px">Technorati Tags: <a href="http://technorati.com/tags/chuvakin" rel="tag">chuvakin</a></div><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OCHwM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OCHwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=BgT7M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=BgT7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=lXFCM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=lXFCM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/416274862" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 13:17:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world love logs">world love logs</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/love logs">love logs</category>
      <category domain="http://securityratty.com/tag/love">love</category>
      <category domain="http://securityratty.com/tag/october 20th">october 20th</category>
      <category domain="http://securityratty.com/tag/anton">anton</category>
      <category domain="http://securityratty.com/tag/anton wakes">anton wakes</category>
      <category domain="http://securityratty.com/tag/evangelist">evangelist</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/416274862/change.html">Change!!!</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - September 2008]]></title>
      <link>http://securityratty.com/article/7bcc00d7fa1280bf6a276c7c821e4445</link>
      <guid>http://securityratty.com/article/7bcc00d7fa1280bf6a276c7c821e4445</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>. </li>    <li><a href="http://chuvakin.blogspot.com/search/label/ROI">Security ROI</a> - and its parent topic &quot;security metrics&quot;/&quot;measuring security&quot; - is definitely an ongoing <strong>HOT</strong> debate. Indeed, the old post <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">&quot;</a><a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">Security ROI Pile-Up!</a><a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">&quot;</a> takes the #2 spot this month, possibly propelled by a more recent post &quot;<a href="http://chuvakin.blogspot.com/2008/09/second-roi-war.html">Second ROI War</a>.&quot;</li>    <li>Some say that &quot;short blog posts rule&quot;, but, in reality, good, fun content is the best. Here is an example:&#160; &quot;<a href="http://chuvakin.blogspot.com/2008/09/dumb-luck-is-strategy.html">Dumb Luck IS a Strategy!</a>&quot; post makes the top list. In it, I try to explore why people still ignore security concerns even if stare people in the face...</li>    <li>Discussion on what you can do to soften the impact of &quot;getting 0wned&quot; ( &quot;<a href="http://chuvakin.blogspot.com/2008/09/what-can-you-do.html">What CAN You Do?</a>&quot;) made the top list. Good!</li>    <li>As before, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in October.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IIM1M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IIM1M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bxJsM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bxJsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fBKoM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fBKoM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408700309" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 12:19:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security roi pile-up">security roi pile-up</category>
      <category domain="http://securityratty.com/tag/security roi">security roi</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ignore security concerns">ignore security concerns</category>
      <category domain="http://securityratty.com/tag/security metrics">security metrics</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408700309/monthly-blog-round-up-september-2008.html">Monthly Blog Round-Up - September 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - August 2008]]></title>
      <link>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</link>
      <guid>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>In a bizarre twist of fate (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my latest poll</a>), the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post in August.&#160; The analysis of said <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">log security poll</a> is coming up tomorrow. BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>:&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a> and a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually review and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>. </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li>    <li>Somewhat predictably, PCI compliance is all the rage again with <a href="http://chuvakin.blogspot.com/2008/08/run-through-pci-dss-12-changes.html">1.2 coming out soon</a>. So, <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. It discusses the fact that there is no &quot;easy list&quot; of what you MUST do to comply.</li>    <li>Finally, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>)</li> </ol>  <p>See you in September,&#160; when .... ah, come on! I will tell you later :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uVPfyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uVPfyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NrADzL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NrADzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=njcwZL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=njcwZL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/383511875" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 08:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log security poll">log security poll</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/popular post">popular post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/383511875/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</source>
    </item>
    <item>
      <title><![CDATA[Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis]]></title>
      <link>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</link>
      <guid>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</guid>
      <description><![CDATA[Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned here , here ; SANS jumped in as well ), I decided to follow along and join the initiative. One of the bloggers called it...]]></description>
      <content:encoded><![CDATA[<p>Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/08/pay_it_forward__1.html">here</a>, <a href="http://mcwresearch.com/archives/265">here </a>; <a href="http://isc.sans.org/diary.php?storyid=1530&amp;rss">SANS jumped in as well</a>), I decided to follow along and join the initiative. One of the bloggers called it <a href="http://mcwresearch.com/archives/255">&quot;pay it forward</a>&quot; to the community.</p>  <p>So, Anton Security Tip of the Day #16: <strong>Virtually Screwed - Journey Into VMWare ESX Log Analysis</strong></p>  <p>CISecurty guide for VMWare (<u><a href="http://www.cisecurity.org/bench_vm.html">here</a></u>) and DISA STIG for virtual machines (<u><a href="http://iase.disa.mil/stigs/stig/index.html">here</a></u>) both mandate collection and analysis of VM platform logs; none goes into enough details on what to look for in logs. Let's try to shed some light on security-focused log analysis of VMWare ESX v. 3.x logs. </p>  <p>First, at least until ESXi becomes the default choice, one needs to keep in mind that ESX as &quot;Linux-inside&quot; and thus diving into <em>/var/log</em> will not reveal any &quot;alien technology&quot; (well, not much :-)). However, one of the most useful logs is <em>/var/log/hostd.N </em>which is not a descendant of Linux standard logs. Extensive VM event records are written into this file. </p>  <p>Let's focus on various types of logins to the ESX platform and identify logs that indicate a successful and failed attempts to log in. Here are a few useful examples to analyze:</p>  <p><strong>Successful logins:</strong></p>  <ul>   <li><em>May 30 09:20:42 esx2 su(pam_unix)[9405]: session opened for user root by jhonny(uid=1626)</em> </li> </ul>  <p>This is a classic Linux root login message; you can watch for these by searching VMWare ESX logs for &quot;session AND opened AND user AND root.&quot;&#160; Notice the user name of the user who switched to root.</p>  <ul>   <li><em>May 30 09:20:34 esx2 sshd(pam_unix)[9364]: session opened for user jhonny by (uid=0)</em> </li> </ul>  <p>This is also a classic Linux message for a normal (non-root) user login.</p>  <ul>   <li><em>[2008-05-25 06:57:48.774 'ha-eventmgr' 111639472 info] Event 40645 : User jhonny@1.1.1.1 logged in</em> </li> </ul>  <p>This is a VMWare -specific application login to ESX. You can track such events by username, by event ID or by keywords &quot;event AND logged AND user&quot; (if you are using search)</p>  <p><strong>Failed logins:</strong></p>  <ul>   <li><em>May 30 09:20:31 esx2 sshd[9356]: Failed password for jhonny from 1.1.1.1 port 54773 ssh2</em> </li> </ul>  <p>Another classic Linux message from the ESX system; a failure to login due to incorrect password. </p>  <ul>   <li><em>May 27 12:06:59 esx2 sshd[4756]: Failed password for illegal user jonny from 1.1.1.1 port 30594 ssh2</em> </li> </ul>  <p>A message indicating a failure to login due to incorrect username (note a typo). </p>  <ul>   <li><em>May 25 07:03:48 esx1 sudo:&#160;&#160;&#160;&#160; jhonny : 3 incorrect password attempts ; TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/bin/bash</em> </li> </ul>  <p>This ESX Linux platform message should also be familiar to Linux/Unix admins: it indicates multiple sudo password failures; look for such messages in the logs.</p>  <p>BTW, do you <a href="http://chuvakin.blogspot.com/2006/09/anton-security-tip-of-day-3-watch-for.html">need to be reminded</a> to track NOT only failed, but also successful login events?!</p>  <p>Overall, you must prepare for the future by learning to analyze&#160; VMWare logs, just like you handled &quot;legacy OS&quot;, such as Linux/Unix and Windows.</p>  <p>As I said before, I am tagging all the tips on <a href="http://del.icio.us/anton18">my del.icio.us feed</a>; here is the link: <a href="http://del.icio.us/anton18/security+tips">All Security Tips of the Day</a>.</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:54499c21-dd11-4ff7-9221-4cf2ec0c95fe" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/tips" rel="tag">tips</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a></div> <script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");<br />document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var pageTracker = _gat._getTracker("UA-101395-5");<br />pageTracker._initData();<br />pageTracker._trackPageview();</script>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fhl1bK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fhl1bK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xW7PtK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xW7PtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=qHcDbK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=qHcDbK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/374532539" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware esx">vmware esx</category>
      <category domain="http://securityratty.com/tag/analyze vmware logs">analyze vmware logs</category>
      <category domain="http://securityratty.com/tag/analyze">analyze</category>
      <category domain="http://securityratty.com/tag/vmware esx logs">vmware esx logs</category>
      <category domain="http://securityratty.com/tag/esx">esx</category>
      <category domain="http://securityratty.com/tag/security tip">security tip</category>
      <category domain="http://securityratty.com/tag/anton security tip">anton security tip</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/374532539/anton-security-tip-of-day-16-virtually.html">Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - July 2008]]></title>
      <link>http://securityratty.com/article/ad180724e0eff95212e4a6b6f36f73c1</link>
      <guid>http://securityratty.com/article/ad180724e0eff95212e4a6b6f36f73c1</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>As you can easily, easily guess, the&#160; #1 spot this month is taken by my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot;</li>    <li>Obviously, my earlier post/rant called &quot;<a href="http://chuvakin.blogspot.com/2008/06/you-are-security-idiot-if.html">You Are &quot;A Security Idiot&quot; If ...</a>&quot; takes the #2 spot. Yes, we all like to point out other people's problems, especially when they are epically huge :-)</li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) </li>    <li>Also popular is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>.</li>    <li>Finally, again this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took the #1 spot!&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a>. Other popular polls include a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Strangely, a lot of people wanted to &quot;<a href="http://chuvakin.blogspot.com/2008/07/which-blogs-do-i-read.html">Which Blogs Do I Read?</a>&quot; - so my brief post on that made it to the top.</li> </ol>  <p>See you in August, unless you are all on vacations, that is :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a></li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dP6djK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dP6djK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ZJx4wK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ZJx4wK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Avu9xK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Avu9xK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/353106236" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/353106236/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</source>
    </item>
    <item>
      <title><![CDATA[Backup tape is stolen from Bristol-Myers Squibb]]></title>
      <link>http://securityratty.com/article/911478f22f756b8e8513c59d7f720d18</link>
      <guid>http://securityratty.com/article/911478f22f756b8e8513c59d7f720d18</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/17/08

Organization
Bristol-Myers Squibb Co. (&quot;BMS

Contractor/Consultant/Branch
Unknown

Victims
Current and former employees and some dependants
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/bms.jpg" width="198" align="right" height="160"><font size="2"><b>Date Reported: </b><br>7/17/08<br><br><b>Organization: </b><br><a href="http://www.bms.com/landing/data/index.html">Bristol-Myers Squibb Co. ("BMS")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Unknown<br><br><span style="font-weight: bold;">Victims:</span><br>Current and former employees and some dependants<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*Bristol-Myers Squibb had "about 42,000 employees as of Dec. 31, the last date for which work force figures were available in regulatory filings.", Source: <a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200807171514DOWJONESDJONLINE000844_FORTUNE5.htm">CNN Money</a></font> <br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, marital status, gender, salary, hire date, termination date, retirement date, and, in some instances bank account information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"On June 4, 2008, Bristol-Myers Squibb Company ("BMS") learned that a back-up data tape containing BMS-related data was stolen while it was being transported for storage.&nbsp; Through subsequent forensic work, it was determined that the data tape included personal information of current and former BMS employees"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.pharmalot.com/wp-content/uploads/2008/07/bms_letter.pdf">Pharmalot (copy of notification letter)</a> <br><a href="http://www.pharmalot.com/2008/07/bristol-myers-security-breach-hits-untold-thousands/">Pharmalot</a> <br><a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200807171514DOWJONESDJONLINE000844_FORTUNE5.htm">CNNMoney</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Ed Silverman, Pharmalot<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The drugmaker sent letters over the past week saying a data tape containing reams of personal information was stolen several weeks ago<br><br>On June 4, 2008, Bristol-Myers Squibb Company ("BMS") learned that a back-up data tape containing BMS-related data was stolen while it was being transported for storage. <br><span style="font-style: italic;">[Evan] This statement prompted me to list the contractor as "unknown" instead of "none".&nbsp; I presume that the data tape was being transported by a third-party vendor when it was stolen.&nbsp; I am looking for more information on this.</span><br><br>Through subsequent forensic work, it was determined that the data tape included personal information of current and former BMS employees, such as name, address, date of birth, Social Security number, marital status, gender, salary, hire date, termination date, retirement date, and, in some instances, bank account information.<br><span style="font-style: italic;">[Evan] Ugh, this looks like very sensitive HR and benefits data.</span><br><br>The names, addresses, and Social Security numbers of some employee dependents also were included on the tape.<br><br>an untold number of current and former employees - and their dependents - could be affected<br><br>BMS has initiated an investigation of this incident.<br><br>To date, BMS has no reason to believe that any of your personal information has been inappropriately accessed from the data tape by an unauthorized party, or that any identity theft, fraud or misuse of your personal information has occurred.<br><span style="font-style: italic;">[Evan] I agree with most of this statement except for the "misuse" part.&nbsp; There may be no evidence of misuse post stolen tape, but there may be an argument for misuse by BMS themselves.&nbsp; BMS is the data custodian in this scenario, not the data owner.&nbsp; If a data custodian does not care for the owner's information in a manner that is expected or communicated, does it constitute misuse?</span><br><br>In addition, there is no evidence that the data tape or the information contained on it was the target of the theft.<br><span style="font-style: italic;">[Evan] I am interested in knowing more about who was transporting the tape and whether or not other items were taken.</span><br><br>As a precaution, to help you detect any possible misuse of your data, BMS has arranged for you to enroll in credit monitoring for one full year, at no cost to you.<br><span style="font-style: italic;">[Evan] There is that "misuse" mention again.&nbsp; One year of free credit monitoring does nothing to protect a victim against fraud that occurs after one year, supposing the victim does not renew at his/her own expense.&nbsp; I wonder how many people renew on average.</span><br><br>If you have any questions, you may call the dedicated Privacy Help Line at 1-877-214-0689.&nbsp; Our representatives will be available to assist you Monday through Friday, between 8 a.m. and 5 p.m. ET.<br><br>the drugmaker is issuing this statement: "Bristol-Myers Squibb regrets that this incident occurred and is committed to providing appropriate assistance for affected individuals who had their personal information on the stolen data tape. We are committed to protecting the privacy and security of employee and dependent information. Maintaining the trust and confidence of our employees is paramount to Bristol-Myers Squibb."<br><br>Protecting the privacy and security of your information is extremely important to us.<br><br>In this regard, BMS wishes to reiterate that it does not have any evidence indicating that your personal information has been misused.<br><span style="font-style: italic;">[Evan] Another "misuse" mention.</span><br><br>the company is taking appropriate remedial steps, including enhancing security protocols regarding the handling of personal information and our back-up data tapes.<br><span style="font-style: italic;">[Evan] Like what? Encryption maybe?</span><br><br>On behalf of BMS, I apologize for any inconvenience or concern that this matter may cause for you.<br><br><span style="font-weight: bold;">Commentary:</span><br>I couldn't find any mention about encryption or whether or not police were called.&nbsp; You would think that a large, well-repected company like Bristol-Myers Squibb encrypts confidential data on tape, right? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/18/bms.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 07:26:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/back-up data tape">back-up data tape</category>
      <category domain="http://securityratty.com/tag/data tape">data tape</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/bristol-myers squibb">bristol-myers squibb</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/07/18/bms.aspx">Backup tape is stolen from Bristol-Myers Squibb</source>
    </item>
    <item>
      <title><![CDATA[Mailing error at the University of Maryland exposes student information]]></title>
      <link>http://securityratty.com/article/a51262d40f98a67474833c65ff29621e</link>
      <guid>http://securityratty.com/article/a51262d40f98a67474833c65ff29621e</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/17/08

Organization
University of Maryland

Contractor/Consultant/Branch
Department of Transportation Services

Victims
All students registered for...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/umd.jpg" width="88" align="right" height="83"><font size="2"><b>Date Reported: </b><br>7/17/08<br><br><b>Organization: </b><br><a href="http://www.umd.edu/">University of Maryland</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.transportation.umd.edu/index.html">Department of Transportation Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>All students registered for Fall 2008 classes<br><br><span style="font-weight: bold;">Number Affected:</span><br>23,727<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>On July 1st, 2008, the University of Maryland Department of Transportation Services mailed an </font><font size="2">on-campus parking </font><font size="2">brochure to all students </font><font size="2">registered for Fall 2008 classes</font><font size="2"> as of June 15, 2008.&nbsp; Recipient Social Security numbers were inadvertently exposed on the mailing labels.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.transportation.umd.edu/parkingmailer/">University of Maryland</a> <br><a href="http://www.wjla.com/news/stories/0708/536794.html">ABC Channel 7 News</a> <br><a href="http://www.wtop.com/?sid=1442585&amp;nid=25">WTOP FM 103.5 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of Maryland<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>On July 1st, 2008, the University of Maryland’s Department of Transportation Services sent all students registered at the time, by U.S. mail, a brochure with on-campus parking information.<br><br>On July 8, 2008, the University discovered that the labels on that mailing included the addressees’ Social Security numbers.<br><span style="font-style: italic;">[Evan] Sheesh, a fraudster doesn't even have to tamper with the mail if the Social Security number is on the label.</span><br><br>The error was discovered on the morning of July 8 when calls were made to the University.<br><br>This parking mailer was sent to all individuals registered for Fall 2008 classes at the University of Maryland as of June 15, 2008.<br><br>The mailing list numbered 23,727 individuals.<br><br>In our annual effort to provide parking and transportation information to the University community, the names and addresses of all registered students was requested internally at the Department of Transportation Services for the purpose of creating mailing labels for a brochure.<br><br>This information was generated by a computer query and included names, addresses and what was believed to be University identification numbers (UIDs).<br><span style="font-style: italic;">[Evan] When writing and executing database queries, isn't it a good idea to check the results and see if the information displayed is the information you were looking for?&nbsp; I wonder if UIDs are also nine digits long like Social Security numbers are.</span><br><br>Our normal process is to remove the University ID numbers prior to mailing.<br><span style="font-style: italic;">[Evan] Is it safe to assume that "normal process" was not followed in this instance?&nbsp; If so, then why not?&nbsp; There is no mention in the school's response.</span><br><br>It was not apparent to departmental staff that these numbers not only still existed within the file, but were Social Security numbers, and not University ID numbers.<br><span style="font-style: italic;">[Evan] Not apparent?&nbsp; They were on the labels!</span><br><br>The numbers were not identified as Social Security numbers and did not show the normal spacing between digits.<br><span style="font-style: italic;">[Evan] So it would be xxxxxxxxx instead of xxx-xx-xxxx.&nbsp; What percentage of people would recognize the first set of nine digits as a SSN?</span><br><br>This mailer was sent using third class, bulk mail delivery and may not have been delivered to you yet.<br><br>Currently, there is no evidence that anyone's Social Security number has been misused.<br><br>The University apologizes and deeply regrets this unfortunate mistake.<br><br>We are initiating immediate action to ensure that this error does not recur.<br><span style="font-style: italic;">[Evan] Like what?&nbsp; Maybe train people to review their query results and follow "normal process"?</span><br><br>The University of Maryland values the critical importance of your personal information.<br><br>We strongly recommend that you take appropriate precautions to mask, black out or destroy this document after use.<br><br>In unfortunate situations like this, it is possible that dishonest people may contact you asking for personal information in the guise of offering assistance from the University.<br><span style="font-style: italic;">[Evan] Equally unfortunate is the fact that there are a lot of dishonest people.</span><br><br>Please note that the University WILL NOT contact you by phone, e-mail or in any other way requesting personal information regarding this incident.<br><br>Please do not release any personal information in response to contacts claiming to be from the University.<br><br>In response to this incident, the University, and specifically the Department of Transportation Services, has moved to severely restrict access to sensitive student and faculty/staff information; we believe the fewer individuals who have access to this data will only increase our ability to protect sensitive information.<br><br>If individuals feel that they would like to take extra steps beyond the fraud alert, the University has arranged with Equifax to make available, at no cost to them, a 12-month service that includes credit monitoring, customer care, fraud expense reimbursement insurance and access to their credit report.<br><br>If you have not received this mailer and are unsure if you are included in the affected group, please call toll-free 1(877) 935-2428, Monday - Friday, 8:30 a.m. - 5 p.m. EST.<br><br><span style="font-weight: bold;">You may contact us in one of the following ways:</span><br>By telephone: Toll-free 1(877) 935-2428, Monday-Friday, 8:30 a.m. - 5 p.m. EST<br>Via e-mail: parkingmailer@umd.edu<br>Mailing address: Regents Drive Garage, Building #202, College Park, MD 20742<br><br><span style="font-weight: bold;">Commentary:</span><br>The lack of attention to detail coupled with lack of control leads to an increase of risk of confidential information disclosure.&nbsp; Not all that uncommon. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/18/umd.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 05:18:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/maryland">maryland</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/university identification">university identification</category>
      <category domain="http://securityratty.com/tag/university community">university community</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/addressees social security">addressees social security</category>
      <category domain="http://securityratty.com/tag/recipient social security">recipient social security</category>
      <source url="http://breachblog.com/2008/07/18/umd.aspx">Mailing error at the University of Maryland exposes student information</source>
    </item>
  </channel>
</rss>
