<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: test]]></title>
    <link>http://securityratty.com/tag/test</link>
    <description></description>
    <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ISP's secret opt-in advertising test draws the UK's ire]]></title>
      <link>http://securityratty.com/article/e6a0ea63c7bd059a41314bb9abb6373f</link>
      <guid>http://securityratty.com/article/e6a0ea63c7bd059a41314bb9abb6373f</guid>
      <description><![CDATA[It's no surprise that ISPs are aggressively pursuing new revenue streams, but UK ISP BT may have crossed the line. Two years ago it retained search records and information on some 18,000 users,...]]></description>
      <content:encoded><![CDATA[It's no surprise that ISPs are aggressively pursuing new revenue streams, but UK ISP BT may have crossed the line. Two years ago it retained search records and information on some 18,000 users, without informing them first.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/X8HjqfRhxO4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 15:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/revenue streams">revenue streams</category>
      <category domain="http://securityratty.com/tag/isp">isp</category>
      <category domain="http://securityratty.com/tag/isps">isps</category>
      <category domain="http://securityratty.com/tag/records">records</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/surprise">surprise</category>
      <category domain="http://securityratty.com/tag/aggressively">aggressively</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/X8HjqfRhxO4/ISP_s_secret_opt_in_advertising_test_draws_the_UK_s_ire_2">ISP's secret opt-in advertising test draws the UK's ire</source>
    </item>
    <item>
      <title><![CDATA[Manage and test firewall changes]]></title>
      <link>http://securityratty.com/article/84538b01c1d530bd4ed4a768a968f728</link>
      <guid>http://securityratty.com/article/84538b01c1d530bd4ed4a768a968f728</guid>
      <description><![CDATA[Regardless of how you approach firewall management, manage. Configuration changes which appear to work properly can easily produce unwanted results. Only a formalized change and testing process based...]]></description>
      <content:encoded><![CDATA[Regardless of how you approach firewall management, manage.  Configuration changes which appear to work properly can easily produce unwanted results.  Only a formalized change and testing process based on clear strategic objectives can prevent growing cracks in the wall.]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/approach firewall management">approach firewall management</category>
      <category domain="http://securityratty.com/tag/easily produce">easily produce</category>
      <category domain="http://securityratty.com/tag/process based">process based</category>
      <category domain="http://securityratty.com/tag/strategic objectives">strategic objectives</category>
      <category domain="http://securityratty.com/tag/manage">manage</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/wall">wall</category>
      <category domain="http://securityratty.com/tag/cracks">cracks</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/manage-and-test-firewall-changes-28567">Manage and test firewall changes</source>
    </item>
    <item>
      <title><![CDATA[Blurring the Lines Between Managed Service Provider and Cloud Computing]]></title>
      <link>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</link>
      <guid>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</guid>
      <description><![CDATA[VMware made big announcements at their VMworld conference back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the...]]></description>
      <content:encoded><![CDATA[<p>VMware made big announcements at their <a href="http://www.vmworld.com/index.jspa" target="_blank">VMworld conference</a> back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the “cloud” with vCloud services. Like most people, I had a lot of skepticism about what vCloud really meant; was this just more hype trying to take advantage of the cloud computing buzz? Certainly CEO Paul Maritz came from this world and virtualization itself (and especially vMotion) is an enabling technology for cloud computing. But how ready were VMware and its ecosystem of partner vendors to actually fulfill on the promise?</p>
<p>So I was very interested when I heard that <a href="http://opusinteractive.com/" target="_blank">Opus Interactive</a>, a customer of ours, had “joined the VMware vCloud initiative as a <a href="http://www.opusinteractive.com/news_detail.asp?item=40" target="_blank">VMware Service Provider</a>”. I talked to Eric Hulbert, CTO of Opus Interactive, to get some details directly from the source.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0025.jpg" border="0" alt="clip_image002" width="202" height="74" align="left" /></p>
<p>Eric shared our own caution about making “cloud-ready” announcements. There have simply been too many companies talking about cloud solutions that lack any substance – usually based on definitions of cloud computing that are hazy or just too broad. The backlash against the cloud hype is often quite justified. But in Opus’ case, there are real components that if they don’t add up to a “full” cloud computing solution just yet, are well on their way – and enabled by <a href="http://www.vmware.com/partners/vip/service-providers/" target="_blank">VMware’s program for service providers</a> (VSPP).</p>
<p>Opus Interactive is <a href="http://www.viddler.com/explore/sciencelogic/videos/3" target="_blank">serious about virtualization</a>, which is an indispensable tool in their stated goal of creating a high-density micro-data center with the smallest footprint possible. They are 100% wind-powered and have already virtualized much of their data center, reducing the amount of hardware necessary to run the business and driving down costs to produce even more competitive advantage in a crowded marketplace.</p>
<p>VSPP for vCloud provides a rental model of VMware licenses – e.g., for Enterprise ESX or VDI. VMware Service Providers report on their customers’ virtual machines (vm) and pay only for what is actually used. This model lets Opus Interactive quickly spin up a vm to get a new customer up and running in about an hour and stay very cost competitive at the same time; Opus offers their <a href="http://opusinteractive.com/vClustr.asp" target="_blank">vClustr entry-level virtual server</a> for only $99.</p>
<p>Cost-effective, rapidly scalable computing “on-demand” based on shared resources, managed by “expert” third-parties, enabled by virtualization technology and pay-per-use vm licenses. Cloud computing? Instead of thinking about a single definition of cloud computing, perhaps it’s more relevant as the market matures to think about a continuum of cloud computing. And by that definition, Opus Interactive is providing cloud services, enabled by VMware’s VSP program. Next on the schedule, automated provisioning and perhaps in the future, API’s that make it even easier for application developers to test and deploy apps on Opus Interactive’s cloud platform – which, by the way, uses <a href="http://www.sciencelogic.com/products.htm" target="_blank">EM7</a> for its core management solution.</p>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 11:20:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud hype">cloud hype</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/cloud-ready announcements">cloud-ready announcements</category>
      <category domain="http://securityratty.com/tag/cloud solutions">cloud solutions</category>
      <category domain="http://securityratty.com/tag/announcements">announcements</category>
      <category domain="http://securityratty.com/tag/vmware vcloud initiative">vmware vcloud initiative</category>
      <category domain="http://securityratty.com/tag/ready">ready</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <source url="http://blog.sciencelogic.com/blurring-the-lines-between-managed-service-provider-and-cloud-computing/11/2008">Blurring the Lines Between Managed Service Provider and Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Bush's exit to put new e-records system to the test]]></title>
      <link>http://securityratty.com/article/5136882ab474438d37a3010c7c02b7cb</link>
      <guid>http://securityratty.com/article/5136882ab474438d37a3010c7c02b7cb</guid>
      <description><![CDATA[The National Archives received only 32 million e-mails from the Clinton administration eight years ago, but in a few months, it expects to get hit with 50 times that from the Bush administration,...]]></description>
      <content:encoded><![CDATA[The National Archives received only 32 million e-mails from the Clinton administration eight years ago, but in a few months, it expects to get hit with 50 times that from the Bush administration, which has exacerbated the problem by dragging its feet in supplying the data.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e889bfb861b0728bfef7d260f090a058:diBBHUUrFFyErrj%2B%2BKgX1ahwdVzU4L3H6hB2XrUTFg680kI%2FEeBFtIPW7%2FsmXk6TnXG0Jcl19YIp'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6dc5566a1b9d46a6a42c1890a26ab6f9:lqkR6JP7fpNff1d3fHteBbf0KLF%2F8LrAyaCArSXp1eDqQAZydSSqtdqW0snQg%2Bog7uJkQpstzyDw0A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:dfa5facdde0aecd816123a7300487a3d:Zgucha0u0JmZ3UA7kY6%2B6%2BlAxyvCphjii5cIhjz3KZN31yEk7VQenZe5I%2B5I1GHGerp1IES1LJL5PA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:51286a4f343898890678765c7028ca67:Rw58e65mDSHXMIyCwPCibMX3mCCvq6OZltcMj2VvY6ip%2BQs8wbwXyfEgckk6zFuw0wIJ4YpbFyGCdQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=e7b60bc98cf75a8107026f8126bdf79b&amp;p=1"><img style="border:0;" src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=e7b60bc98cf75a8107026f8126bdf79b&amp;p=1" border="0" /></a>
]]></content:encoded>
      <pubDate>Fri, 21 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bush administration">bush administration</category>
      <category domain="http://securityratty.com/tag/national archives">national archives</category>
      <category domain="http://securityratty.com/tag/million e-mails">million e-mails</category>
      <category domain="http://securityratty.com/tag/clinton administration">clinton administration</category>
      <category domain="http://securityratty.com/tag/feet">feet</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/hit">hit</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/expects">expects</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e7b60bc98cf75a8107026f8126bdf79b">Bush's exit to put new e-records system to the test</source>
    </item>
    <item>
      <title><![CDATA[Skein and SHA-3 News]]></title>
      <link>http://securityratty.com/article/cc81d2d4853466933826ebdeeef07d52</link>
      <guid>http://securityratty.com/article/cc81d2d4853466933826ebdeeef07d52</guid>
      <description><![CDATA[There are two bugs in the Skein code. They are subtle and esoteric, but they're there. We have revised both the reference and optimized code -- and provided new test vectors -- on the Skein website ....]]></description>
      <content:encoded><![CDATA[<p>There are two bugs in the Skein code.  They are subtle and esoteric, but they're there.  We have revised both the reference and optimized code -- and provided new test vectors -- on the <a href="http://www.schneier.com/skein.html">Skein website</a>.  A <a href="http://www.schneier.com/skein.pdf">revision of the paper</a> -- Version 1.1 -- has new IVs, new test vectors, and also fixes a few typos in the paper.</p>

<blockquote>Errata: Version 1.1 of the paper, reference, and optimized code corrects an error in which the length of the configuration string was passed in as the size of the internal block (256 bits for Skein-256, 512 for Skein-512, and 1024 for Skein-1024), instead of a constant 256 bits for all three sizes.  This error has no cryptographic significance, but affected the test vectors and the initialization values.  The revised code also fixes a bug in the MAC mode key processing.  This bug does not affect the NIST submission in any way.</blockquote>

<p><a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html">NIST has received</a> 64 submissions.  (<a href="http://www.cio.com/article/461164/Amateurs_and_Pros_Vie_to_Build_New_Crypto_Standard">This article</a> interviews one of the submitters, who is fifteen.)  Of those, <a href="http://ehash.iaik.tugraz.at/wiki/The_SHA-3_Zoo">28 are public</a> and six have been broken.  NIST is going through the submissions right now, making sure they are complete and proper.  Their goal is to publish the accepted submissions by the end of the month, in advance of the <a href="http://csrc.nist.gov/groups/ST/hash/timeline.html">Third Cryptographic Hash Workshop</a> to be held in Belgium right after <a href="https://www.cosic.esat.kuleuven.be/fse2009/index.shtml">FSE</a> in February.  They expect to quickly make a first cut of algorithms -- hopefully to about a dozen -- and then give the community about a year of cryptanalysis before making a second cut in 2010.</p>

<p>Lastly, <a href="http://www.darkreading.com/blog/archives/2008/11/bending_skein_c.html">this</a> is a really nice article on Skein.</p>

<blockquote>These submissions make some accommodation to the Core 2 processor. They operate in "<a href="http://en.wikipedia.org/wiki/Little_endian" target="new">little-endian</a>" mode (a quirk of the <a href="http://en.wikipedia.org/wiki/X86" target="new">Intel-like processors</a> that reads some bytes in reverse order). They also allow a large file to be broken into chunks to split the work across multiple processors.

<p>However, virtually all of the contest submissions share the performance problem mentioned above. The logic they use won't optimally fit within the constraints of a Intel Core 2 processor. Most will perform as bad or worse than the existing SHA-1 algorithm.</p>

<p>One exception to this is <a href="http://www.schneier.com/skein.html" target="new">Skein</a>, created by several well-known cryptographers and noted pundit <a href="http://www.schneier.com/" target="new">Bruce Schneier</a>. It was designed specifically to exploit all three of the Core 2 execution units and to run at a full 64-bits. This gives it roughly four to 10 times the logic density of competing submissions.</p>

<p>This is what I meant by the <i><a href="http://www.imdb.com/title/tt0133093/" target="new">Matrix</a></i> quote above. They didn't bend the spoon; they bent the crypto algorithm. They moved the logic operations around in a way that wouldn't weaken the crypto, but would strengthen its speed on the Intel Core 2.</p>

<p>In their <a href="http://www.schneier.com/skein.pdf" target="new">paper</a> (PDF), the authors of Skein express surprise that a custom silicon <a href="http://en.wikipedia.org/wiki/Application-specific_integrated_circuit" target="new">ASIC</a> implementation is not any faster than the software implementation. They shouldn't be surprised. Every time you can redefine a problem to run optimally in software, you will reach the same speeds you get with optimized ASIC hardware. The reason software has a reputation of being slow is because people don't redefine the original problem.</blockquote></p>

<p>That's exactly what we were trying to do.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=98JTN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=98JTN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=diffN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=diffN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 03:14:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skein">skein</category>
      <category domain="http://securityratty.com/tag/skein-1024">skein-1024</category>
      <category domain="http://securityratty.com/tag/skein-512">skein-512</category>
      <category domain="http://securityratty.com/tag/skein express surprise">skein express surprise</category>
      <category domain="http://securityratty.com/tag/skein website">skein website</category>
      <category domain="http://securityratty.com/tag/skein code">skein code</category>
      <category domain="http://securityratty.com/tag/submissions share">submissions share</category>
      <category domain="http://securityratty.com/tag/submissions">submissions</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/skein_and_sha-3.html">Skein and SHA-3 News</source>
    </item>
    <item>
      <title><![CDATA[High-Tech Team Helps Cheaters Take Immigration Test]]></title>
      <link>http://securityratty.com/article/4f7d3d0e127ef651a28ab721297280ff</link>
      <guid>http://securityratty.com/article/4f7d3d0e127ef651a28ab721297280ff</guid>
      <description><![CDATA[Two test-takers each wore a buttonhole camera and a hidden earpiece while taking the immigration test in London, while the inventive masterminds read the test and fed them answers from a car...]]></description>
      <content:encoded><![CDATA[Two test-takers each wore a buttonhole camera and a hidden earpiece while taking the immigration test in London, while the inventive masterminds read the test and fed them answers from a car outside.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=76e7b8744f4b86595c75e622e7d55b4c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=76e7b8744f4b86595c75e622e7d55b4c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=MXrNN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=MXrNN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7Wh1n"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7Wh1n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=GfGkn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=GfGkn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=nWN5N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=nWN5N" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=Lb2NN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Lb2NN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=MPwrn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=MPwrn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=B9r7n"><img src="http://feeds.wired.com/~f/wired/politics/security?i=B9r7n" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Cw3nN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Cw3nN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/456575755" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/456575756" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 20:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/immigration test">immigration test</category>
      <category domain="http://securityratty.com/tag/test-takers">test-takers</category>
      <category domain="http://securityratty.com/tag/inventive masterminds">inventive masterminds</category>
      <category domain="http://securityratty.com/tag/buttonhole camera">buttonhole camera</category>
      <category domain="http://securityratty.com/tag/earpiece">earpiece</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/fed">fed</category>
      <category domain="http://securityratty.com/tag/london">london</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/456575756/high-tech-team.html">High-Tech Team Helps Cheaters Take Immigration Test</source>
    </item>
    <item>
      <title><![CDATA[Old scam, with a new twist.]]></title>
      <link>http://securityratty.com/article/a725c48b128f79db0e6a06f8eed9917e</link>
      <guid>http://securityratty.com/article/a725c48b128f79db0e6a06f8eed9917e</guid>
      <description><![CDATA[Please dont fall for this


clipped from it.toolbox.com

Mystery Shoppers testing out Money Gram Services Scam



With a new spin on an old scam, mystery shoppers are being recruited to test money...]]></description>
      <content:encoded><![CDATA[<div > Please dont fall for this! </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/7BD92628-49D8-455A-8851-38E0BBCC5A40/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/97ae93d9-d8a9-466a-9c4c-a97e0c8baf41/7BD92628-49D8-455A-8851-38E0BBCC5A40/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257" href="http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257" style="font-size: 11px;">it.toolbox.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
		Mystery Shoppers testing out Money Gram Services Scam
	</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257 --><DIV><br />
		With a new spin on an old scam, mystery shoppers are being recruited to test money gram systems, by sending your money to the scammer.<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/7BD92628-49D8-455A-8851-38E0BBCC5A40/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_141108042528"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=141108042528&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=141108042528&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=141108042528&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_141108042528" /></a></P>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 13:25:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mystery shoppers">mystery shoppers</category>
      <category domain="http://securityratty.com/tag/scam">scam</category>
      <category domain="http://securityratty.com/tag/spin">spin</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/scammer">scammer</category>
      <category domain="http://securityratty.com/tag/toolbox">toolbox</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=658">Old scam, with a new twist.</source>
    </item>
    <item>
      <title><![CDATA[MSDN Security Issue Articles]]></title>
      <link>http://securityratty.com/article/1074b3008b822d4dbf799e92676f81a1</link>
      <guid>http://securityratty.com/article/1074b3008b822d4dbf799e92676f81a1</guid>
      <description><![CDATA[Bryan here. The SDL team is well represented in the annual security issue of MSDN magazine we have three articles that might be interesting to you, given that you read the SDL Blog
First up is a code...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Bryan here. The SDL team is well represented in the annual security issue of MSDN magazine – we have three articles that might be interesting to you, given that you read the SDL Blog!</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>First up is a code review quiz, “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/cc982154.aspx"><FONT face=Calibri size=3>Test Your Security IQ</FONT></A><FONT face=Calibri size=3>”. Put your C/C++/C# security skills to the challenge by reviewing ten tricky code snippets that Michael and I devised. As an added incentive, I’ll post public congratulations here in the SDL blog to the first person who reverses the insecure hash found somewhere in the exam (not to give too much of a hint).</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Next up, we have “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/dd153756.aspx"><FONT face=Calibri size=3>Agile SDL: Streamline Security Practices for Agile Development</FONT></A><FONT face=Calibri size=3>”. I’ve been talking about web application security issues in the SDL blog (and in the </FONT><A href="http://msdn.microsoft.com/en-us/magazine/cc794277.aspx"><FONT face=Calibri size=3>September</FONT></A><FONT face=Calibri size=3> issue of MSDN magazine, if you missed it). However, while it’s essential to make sure that web-specific issues are covered in the SDL, it’s equally important to make sure that web development teams – and other Agile development teams – can use the SDL effectively, and the classic, phased SDL approach is not always a good fit for these teams. This MSDN article is the first public look at the new SDL/Agile methodology that we’ve been working on for the last year. This process is currently in beta with some internal Microsoft product teams and online services. We’d love to get some external feedback on it before we release it to the entire company, so please send us your thoughts.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Finally, be sure to check out Michael’s Security Briefs column “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/dd148644.aspx"><FONT face=Calibri size=3>Threat Models Improve Your Security Process</FONT></A><FONT face=Calibri size=3>”. Regular readers of this blog know how important threat modeling is to secure development. This article describes methods of using threat modeling not just to identify security vulnerabilities outright, but how to use it to make other SDL activities such as fuzzing and reducing attack surface more effective.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Three articles are more than enough for one team for one month! But be on the lookout for more articles from the usual SDL suspects in the near future. As always, keep watching this space for details.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9067921" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 20:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/usual sdl suspects">usual sdl suspects</category>
      <category domain="http://securityratty.com/tag/sdl approach">sdl approach</category>
      <category domain="http://securityratty.com/tag/annual security issue">annual security issue</category>
      <category domain="http://securityratty.com/tag/agile sdl">agile sdl</category>
      <category domain="http://securityratty.com/tag/sdl activities">sdl activities</category>
      <category domain="http://securityratty.com/tag/security process">security process</category>
      <category domain="http://securityratty.com/tag/sdl team">sdl team</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/11/13/msdn-security-issue-articles.aspx">MSDN Security Issue Articles</source>
    </item>
    <item>
      <title><![CDATA[Kaspersky remains in the best category]]></title>
      <link>http://securityratty.com/article/f2f0eb2d0d03629917ccf3b3653a6d07</link>
      <guid>http://securityratty.com/article/f2f0eb2d0d03629917ccf3b3653a6d07</guid>
      <description><![CDATA[Ive always been a fan of the Kaspersky products


clipped from www.kaspersky.com

Kaspersky Anti-Virus 2009 receives the Gold Malware Treatment Award from Anti-Malware Test Lab

Kaspersky Lab, a...]]></description>
      <content:encoded><![CDATA[<div > Ive always been a fan of the Kaspersky products. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/D2EAD4D2-0171-4400-A4F5-6CA112AA37D9/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e156200e-eb8e-440c-8ec0-000c9179c136/D2EAD4D2-0171-4400-A4F5-6CA112AA37D9/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.kaspersky.com/news?id=207575705" href="http://www.kaspersky.com/news?id=207575705" style="font-size: 11px;">www.kaspersky.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.kaspersky.com/news?id=207575705 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Kaspersky Anti-Virus 2009 receives the Gold Malware Treatment Award from Anti-Malware Test Lab</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.kaspersky.com/news?id=207575705 --><H3><IMG height="65" border="0" width="65" alt="Malware Treatment Gold: Anti-Malware.ru" src="http://images.kaspersky.com/en/awards/malware_treatment_gold.jpg" />Kaspersky Lab, a leading developer of secure content management solutions, announces that Kaspersky Anti-Virus 2009 has received the Gold Malware Treatment Award from respected security software test laboratory Anti-Malware Test Lab. </H3></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/D2EAD4D2-0171-4400-A4F5-6CA112AA37D9/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_131108050914"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=131108050914&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=131108050914&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=131108050914&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_131108050914" /></a></P>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 14:09:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kaspersky">kaspersky</category>
      <category domain="http://securityratty.com/tag/kaspersky lab">kaspersky lab</category>
      <category domain="http://securityratty.com/tag/kaspersky anti-virus">kaspersky anti-virus</category>
      <category domain="http://securityratty.com/tag/anti-malware test lab">anti-malware test lab</category>
      <category domain="http://securityratty.com/tag/kaspersky products">kaspersky products</category>
      <category domain="http://securityratty.com/tag/fan">fan</category>
      <category domain="http://securityratty.com/tag/receives">receives</category>
      <category domain="http://securityratty.com/tag/developer">developer</category>
      <category domain="http://securityratty.com/tag/announces">announces</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=656">Kaspersky remains in the best category</source>
    </item>
    <item>
      <title><![CDATA[Antimalware group sets product testing guidelines ]]></title>
      <link>http://securityratty.com/article/dabf5354869a2312cc6f5c298441d758</link>
      <guid>http://securityratty.com/article/dabf5354869a2312cc6f5c298441d758</guid>
      <description><![CDATA[The Anti-Malware Testing Standards Organization yesterday announced its members, which include more than 15 security firms specializing in combating malicious code, have adopted test principles and...]]></description>
      <content:encoded><![CDATA[The Anti-Malware Testing Standards Organization yesterday announced its members, which include more than 15 security firms specializing in combating malicious code, have adopted test principles and best practices they hope will eventually help unify the industry in the sphere of malware-code testing and reporting.]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/standards organization yesterday">standards organization yesterday</category>
      <category domain="http://securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://securityratty.com/tag/security firms">security firms</category>
      <category domain="http://securityratty.com/tag/test principles">test principles</category>
      <category domain="http://securityratty.com/tag/anti-malware">anti-malware</category>
      <category domain="http://securityratty.com/tag/sphere">sphere</category>
      <category domain="http://securityratty.com/tag/include">include</category>
      <category domain="http://securityratty.com/tag/hope">hope</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <source url="http://www.networkworld.com/news/2008/111108-antimalware-guidelines.html?fsrc=rss-security">Antimalware group sets product testing guidelines </source>
    </item>
  </channel>
</rss>
