<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: vulnerabilities]]></title>
    <link>http://securityratty.com/tag/vulnerabilities</link>
    <description></description>
    <pubDate>Tue, 26 Aug 2008 16:16:43 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for August]]></title>
      <link>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</link>
      <guid>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</guid>
      <description><![CDATA[Here's a concise summary of all of my posts at Zero Day for August. If interested, consider going through July's summary , subscribe yourself to my personal feed , or Zero Day's main feed , and stay...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/GbK1dWvgJFs/s1600-h/zeroday_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/5TbgDFTdET4/s200-R/zeroday_august.png" /></a>Here's a concise summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a> for August. If interested, consider going through <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summary</a>, subscribe yourself to <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal feed</a>, or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a>, and stay informed.<br />
<br />
Some of the notable articles are - <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a> ; <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a> and <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1620">Cuil's stance on privacy - "We have no idea who you are"</a><br />
<b>02. </b><a href="http://blogs.zdnet.com/security/?p=1641">Phishers increasingly scamming other phishers</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1655">Consumer Reports urges Mac users to dump Safari, cites lack of phishing protection</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1657">Fake CNN news items malware campaign spreading rapidly</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1664">CNET's Clientside developer blog serving Adobe Flash exploits</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1712">Researcher discovers Nokia S40 security vulnerabilities, demands 20,000 euros to release details</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1717">Intel proactively fixes security flaws in its chips</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1723">1.5m spam emails sent from compromised University accounts</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1741">Fortune 500 companies use of email spoofing countermeasures declining</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1743">China busts hacking ring, managed to penetrate 10 gov't databases</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1750">Scammers caught backdooring chip and PIN terminals</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1754">SpamZa - opt in spamming service fighting to remain online</a><br />
<b>15.</b> <a href="http://blogs.zdnet.com/security/?p=1765">FEMA's PBX network hacked, over 400 calls made to the Middle East</a><br />
<b>16.</b> <a href="http://blogs.zdnet.com/security/?p=1782">Typosquatting the U.S presidential election - a security risk?</a><br />
<b>17.</b> <a href="http://blogs.zdnet.com/security/?p=1788">Hundreds of Dutch web sites hacked by Islamic hackers</a><br />
<b>18.</b> <a href="http://blogs.zdnet.com/security/?p=1796">Twitter's "me too" anti-spam strategy</a><br />
<b>19.</b> <a href="http://blogs.zdnet.com/security/?p=1806">Malware detected at the International Space Station</a><br />
<b>20.</b> <a href="http://blogs.zdnet.com/security/?p=1814">Taiwan busts hacking ring, 50 million personal records compromised</a><br />
<b>21.</b> <a href="http://blogs.zdnet.com/security/?p=1815">MSN Norway serving Flash exploits through malvertising</a><br />
<b>22.</b> <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q40d6L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q40d6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7EXTjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7EXTjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E4X5Il"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E4X5Il" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZxvQTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZxvQTl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8PfjsL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8PfjsL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bOWuvL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bOWuvL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RGgc1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RGgc1l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/383219682" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 03:40:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/adobe flash exploits">adobe flash exploits</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/flash exploits">flash exploits</category>
      <category domain="http://securityratty.com/tag/undetectable malware">undetectable malware</category>
      <category domain="http://securityratty.com/tag/inside india">inside india</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/million personal records">million personal records</category>
      <category domain="http://securityratty.com/tag/clientside developer blog">clientside developer blog</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/383219682/summarizing-zero-days-posts-for-august.html">Summarizing Zero Day's Posts for August</source>
    </item>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[Early security issues tarnish Google's Chrome]]></title>
      <link>http://securityratty.com/article/166e66e7741fa7e8bd10cfb10008983e</link>
      <guid>http://securityratty.com/article/166e66e7741fa7e8bd10cfb10008983e</guid>
      <description><![CDATA[Security researchers have reported finding vulnerabilities in Google's new Web browser a day after it was released in...]]></description>
      <content:encoded><![CDATA[Security researchers have reported finding vulnerabilities in Google's new Web browser a day after it was released in beta.]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/web browser">web browser</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/beta">beta</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://www.networkworld.com/news/2008/090308-early-security-issues-tarnish-googles.html?fsrc=rss-security">Early security issues tarnish Google's Chrome</source>
    </item>
    <item>
      <title><![CDATA[Carpet-bombing Vulnerability In Google Chrome New Browser]]></title>
      <link>http://securityratty.com/article/22a4a4e82415f10d35fa517933dd4473</link>
      <guid>http://securityratty.com/article/22a4a4e82415f10d35fa517933dd4473</guid>
      <description><![CDATA[Hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities, a flaw in Apple Safari (WebKit) and a Java bug discussed at this years Black Hat...]]></description>
      <content:encoded><![CDATA[Hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities, a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference, to trick users into launching executables directly from the browser window.
A harmless proof-of-concept demo of the attack is available. In the [...]]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 18:41:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google chrome">google chrome</category>
      <category domain="http://securityratty.com/tag/researcher aviv raff">researcher aviv raff</category>
      <category domain="http://securityratty.com/tag/black hat conference">black hat conference</category>
      <category domain="http://securityratty.com/tag/java bug">java bug</category>
      <category domain="http://securityratty.com/tag/apple safari">apple safari</category>
      <category domain="http://securityratty.com/tag/trick users">trick users</category>
      <category domain="http://securityratty.com/tag/browser window">browser window</category>
      <category domain="http://securityratty.com/tag/executables directly">executables directly</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://cyberinsecure.com/carpet-bombing-vulnerability-in-google-chrome-new-browser/">Carpet-bombing Vulnerability In Google Chrome New Browser</source>
    </item>
    <item>
      <title><![CDATA[McIrony: An unexpected response from McAfee]]></title>
      <link>http://securityratty.com/article/b7777c8973f62604f441965769aa7200</link>
      <guid>http://securityratty.com/article/b7777c8973f62604f441965769aa7200</guid>
      <description><![CDATA[Irony: incongruity between what might be expected and what actually occurs

Right before Black Hat, I put together what I believed was a pretty strong arguement against McAfee Secure - Hacker Safe, at...]]></description>
      <content:encoded><![CDATA[Irony: incongruity between what might be expected and what actually occurs.<br /><br />Right before Black Hat, I put together what I believed was a pretty strong  arguement against McAfee Secure - Hacker Safe, at a level heretofore unexplored. I believe it was more damaging than anything I've said to date, and as such, presented potential risk for me. So I ran it by some friends before publishing it. Then a most extraordinary thing happened. I had a long chat with <a href="http://blogs.zdnet.com/security/?p=1668" target="_blank">Nate McFeters</a>, who described an awakening he'd recently experienced. He shared with me the belief that a better approach to potentially negative security research might be to try to create a positive outcome, and worry less about press cycles or exposure, the 15 minutes of fame if you will. He pointed to people like <a href="http://blogs.zdnet.com/security/?p=1030" target="_blank">Mark Dowd</a> as an example of people who conduct crushingly good research, and steer clear of the petty, ego driven  bulls**t. <br />There I sat, repose like the thinking <a href="http://www.downshoredrift.com/photos/uncategorized/thinking_man.gif" target="_blank">man</a>, frozen for minutes. "Nate", I said, "I think you're right." <br />What do I aspire to as an information security professional; more readership or street cred than the next guy, or the respect of my peers for contributing to the greater <a href="http://holisticinfosec.org/content/view/21/31/" target="_blank">good</a>? Attention, press cycles, 15 minutes...it all has its allure, trust me on this. <br />But at the end of the day, I really do want to contribute to the greater good.<br />So I did something different. I sent my findings to McAfee and offered them an opportunity to respond, rather than publish first, ask questions later. <br />Here's the real kicker. <br />They responded.<br />I had a three hour lunch this past Thursday with two gentlemen from McAfee, who flew up from the Bay Area to Seattle to have a face to face with me. This, all by itself, speaks volumes to me. In addition to meeting with Kirk Lawrence, the new Director of Product Management for McAfee Secure, there I sat with, of all people, Joe Pierini, the very guy who has suffered more than his share of abuse, up to and including the <a href="http://pwnie-awards.org/2008/awards.html">Pwnie</a>.  As I have been a direct contributor and participant in heckling Joe, you can imagine our meeting could have been uncomfortable. It was not. <br />I have had expectations of McAfee and Scan Alert that to date have not been met, or my (your) perception has been that they have not been met.<br />This meeting was designed as an opportunity to voice some of these expectations, and see if McAfee, in turn, believed there was any merit to them.<br />Surprisingly, at least as spoken, we weren't all that far apart.<br />While, as a naive idealist, I believe that security should come before conversions, I am also grounded enough of a realize that the most attainable goal can be a marriage of both. This premise frames my expectations of McAfee. <br />Can they not be more of a "thought leader" for all the Ma & Pa websites who rely on McAfee Secure, first for a higher conversion rate, then security?<br />Can they not hold merchants to a higher standard, without alienating them and losing business?<br />Can they not embrace the security research community in a fashion that McAfee, the security community, the merchants, and consumers can all benefit from?<br />Can they not be more transparent in their approach, providing more details and feedback about their methods, their findings, and their vision?<br />I know McAfee Secure - Hacker Safe scans can find vulnerabilities.<br />I know they report the vulnerabilities to merchants.<br />What happens thereafter is where things begin to break down. <br />Can the scan engine be improved to find more vulns? Sure. That's really not that big a deal; technology can always be improved.<br />But, regarding holding merchants to a higher standard; therein is the whole point of this debate. <br />Anyone can throw a badge on a site. <br />But what happens when the site proves vulnerable is the key. I'll be candid here: I don't give a damn about the merchant at that point; it's the consumer who is at risk and needs something better from McAfee and their peers.<br />So, here begins a different approach. I know that making changes at a company the size of McAfee can be likened to the three miles it takes to turn around an aircraft carrier. I'm willing to work with them, and allow for a positive outcome.<br />I have been told that, in two or three weeks, we can expect a published standard, that clearly defines exactly what the McAfee Secure product offering adheres to, inclusive of their expectations for merchant remediation timelines, potential badge downgrades for unresolved vulnerabilities, and hopefully even a more clear stance on XSS.<br />I have been told that I will have the opportunity to discuss this standard, and invite feedback. Any <a href="http://holisticinfosec.org/content/view/19/29/" target="_blank">standard</a> is better than no standard. <br />I have also been told that this is just the beginning of changes that will lead to more of what I have hoped for in my expectations, over the next 6 months or so.<br />I am hopeful that we can take McAfee at their word, and even if slowly, see a positive outcome.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/08/mcirony-unexpected-response-from-mcafee.html&title=McIrony:%20An%20unexpected%20response%20from%20McAfee " title="McIrony: An unexpected response from McAfee ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/08/mcirony-unexpected-response-from-mcafee.html" title="McIrony: An unexpected response from McAfee ">digg</a>]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 09:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/negative security research">negative security research</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/mcafee secure product">mcafee secure product</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security research community">security research community</category>
      <category domain="http://securityratty.com/tag/information security professional">information security professional</category>
      <category domain="http://securityratty.com/tag/positive outcome">positive outcome</category>
      <source url="http://holisticinfosec.blogspot.com/2008/08/mcirony-unexpected-response-from-mcafee.html">McIrony: An unexpected response from McAfee</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</link>
      <guid>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel?? to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</link>
      <guid>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel® to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=lWcQZE"><img src="http://feeds.feedburner.com/~a/BlueBox?i=lWcQZE" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=pYLEpK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pYLEpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=rcmyeK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=rcmyeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=FcteyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=FcteyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=g4KpjK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=g4KpjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=XvHGuk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=XvHGuk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=WQc3oK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=WQc3oK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/376657116" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 15:53:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/376657116/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[SDL and the XSS Filter]]></title>
      <link>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</link>
      <guid>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</guid>
      <description><![CDATA[Steve Lipner here. When the Internet Explorer team posted the announcement about the XSS Filter feature in IE8 I asked some other members of the SDL blog team why arent we talking about the new XSS...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Steve Lipner here.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>When the Internet Explorer team posted the announcement about the </FONT><A href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"><FONT face=Calibri color=#0000ff size=3>XSS Filter feature in IE8</FONT></A><FONT size=3><FONT face=Calibri> <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>I asked some other members of the SDL blog team “why aren’t we talking about the new XSS Filter feature on the SDL blog?” &nbsp;Bryan and Jeremy said something like “that’s a mitigation that only applies to specific clients and a subset of attacks”.&nbsp; So we didn’t cross-reference IE’s XSS Filter post on the SDL blog at the time.&nbsp; Instead, I agreed to write a subsequent post about the relationship of XSS Filter to the SDL and to the ways that our SDL and security science teams think about improving product security.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>For those of you who aren’t familiar with XSS Filter, a brief summary is that it is a client-side defense against reflected cross-site scripting (XSS) attacks.&nbsp; It works by recognizing that reflected XSS attacks inject script into the string that the browser sends to the targeted web server.&nbsp; If the server doesn’t neuter or strip out the injected script, it gets sent back to the browser and executed in the context of the target web page.&nbsp; Bad things then happen.&nbsp; At a high level, XSS Filter remembers the string that the browser sent to the server, and looks at the server’s response to see if any of the script was actually in that string.&nbsp; If it was, then XSS Filter decides that it got there because it was injected by an XSS attack and blocks the script from executing.&nbsp; The rest of the web page renders as usual.&nbsp; This is a vastly oversimplified sketch of XSS Filter – for details, see the post by David Ross, inventor of XSS Filter on the </FONT><A href="http://blogs.technet.com/swi/archive/2008/08/19/ie-8-xss-filter-architecture-implementation.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>So what does XSS Filter have to do with the SDL?&nbsp; Well, for almost nine years, since XSS was first discovered at Microsoft, we’ve been trying to figure out effective ways to reduce vulnerability to XSS attacks.&nbsp; Our focus has been on improving the ways that web page developers code their pages, and we’ve developed a lot of tools and techniques for making web content safer from XSS attacks and for detecting XSS vulnerabilities in live pages.&nbsp; The SDL requires the use of many of these tools and techniques, and we’re sure we’ve prevented a lot of XSS vulnerabilities from being introduced into Microsoft web pages as a result.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>But while we identify (and the SDL requires) measures that allow developers to avoid classes of vulnerabilities, we also look to identify more sweeping solutions that can either 1) eliminate classes of vulnerabilities, 2) reduce their severity, or 3) reduce the likelihood of attacks being successful.&nbsp; The process usually starts from deep understanding of a class of vulnerabilities and attacks, and then we broaden defenses from there.&nbsp; In the case of XSS Filter, David’s years of work researching XSS led him to come up with an approach that blocks many of the most common vulnerabilities to reflected attacks found on the web today.&nbsp; The solution is compatible with existing web pages (doesn’t “break the web”) and thus we were able to enable it by default for users of Internet Explorer 8.&nbsp; Because it’s a client-side mitigation, it will help protect users from attacks even though the sites they visit may be vulnerable to XSS.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Our work on buffer overrun defenses follows a somewhat similar pattern – we started by prescribing coding techniques, banning the use of some APIs, and building tools that detect coding constructs that look like buffer overruns.&nbsp; As we gained a deeper understanding of how buffer overruns can be exploited, we enhanced the </FONT><A href="http://msdn.microsoft.com/en-us/library/8dbf701c(VS.80).aspx"><FONT face=Calibri size=3>/GS compiler flag</FONT></A><FONT face=Calibri size=3> and added </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2006/05/26/address-space-layout-randomization-in-windows-vista.aspx"><FONT face=Calibri color=#0000ff size=3>ASLR</FONT></A><FONT size=3><FONT face=Calibri> in a quest to cause classes of exploits to fail even if a buffer overrun remains.&nbsp; We’re not yet close to eliminating the SDL requirements for use of tools and coding techniques, but the SDL also requires the use of the mitigations to reduce the severity of vulnerabilities that slip past.&nbsp; Will we ever get to the point where the mitigating technologies are so strong that we can relax the coding requirements?&nbsp; Maybe not, but we will continue to introduce technologies that reduce the chances of a successful attack.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Similarly, in the case of XSS, even after IE8 ships, the SDL will continue to require the use of safe web site coding practices and tools such as the </FONT><A href="http://msdn.microsoft.com/en-us/library/aa973813.aspx"><FONT face=Calibri color=#0000ff size=3>Anti-XSS library</FONT></A><FONT size=3><FONT face=Calibri> both to protect users of browsers other than IE8 and to provide protection in recognition of the fact that XSS Filter is a mitigation or defense in depth rather than a complete solution.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>But we’ll also be keeping our eyes open (and doing active research) in the quest for an even more effective defense – whether client or server side – that eliminates XSS for good.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>This post is a little far afield from the normal content of the SDL blog, but I thought it was important to provide a picture of the role of security science and security research in defining SDL requirements and in making major improvements in software security.&nbsp; You can read more about our work in security science in the </FONT><A href="http://blogs.technet.com/swi/default.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.</FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8900490" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 11:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss filter">xss filter</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/xss led">xss led</category>
      <category domain="http://securityratty.com/tag/anti-xss library">anti-xss library</category>
      <category domain="http://securityratty.com/tag/xss attack">xss attack</category>
      <category domain="http://securityratty.com/tag/xss attacks">xss attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/xss filter remembers">xss filter remembers</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/08/27/sdl-and-the-xss-filter.aspx">SDL and the XSS Filter</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</link>
      <guid>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3">Download the show here</a> (MP3, 19MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the hiatus</li>
	</ul>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/">Are your Skype username and password completely exposed if you use iSkoot?</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/chronology-of-the-blogosphere-and-iskoot-weekend-response-to-the-iskoot-security-issue/">Chronology</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/iskoot-disclosure-of-skype-credentials-resolved-new-version-by-wednesday/">iSkoot disclosure of Skype credentials resolved &#8211; new version by Wednesday</a></li>
<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a> &#8211; and Hannes Tschofenig points to <a href="http://www.emergency-services-coordination.info/esw4.html">4th Emergency Services Coordination Workshop</a> and <a href="http://www.tschofenig.priv.at/twiki/pub/EmergencyServices/EswAgenda2008/BT-ES_SDO_April_08.ppt">presentation about the UK</a></li>
<li>MarketingVOX: <a href="http://www.marketingvox.com/british-proposal-may-force-isps-to-fork-over-online-activity-emails-voip-calls-038702/">British Proposal May Force ISPs to Fork Over Online Activity, Emails, <span class="caps">VOIP </span>Calls</a> pointing to Reuters article: <a href="http://www.reuters.com/article/lifestyleMolt/idUSL2076461020080520">Britain mulls plan to store all email and calls</a></li>

<p><li>Enterprise VoIP Planet: <a href="http://www.voipplanet.com/solutions/article.php/3747161">VoIP Security: <span class="caps">SIP</span>-Versatile but Vulnerable</a></li><br />
		<li><span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/cip/?p=343">Pay Attention to VoIP Security Before The Storm</a></li></p>

<p><li>NetworkWorld: <a href="http://www.pcworld.com/businesscenter/article/145272/guide_to_voip_security.html">Business Guide to VoIP Security</a></li><br />
<li>Pocket-lint: <a href="http://www.pocket-lint.co.uk/news/news.phtml/14768/15792/Fraudsters-targeting-internet-phone-services.phtml">Fraudsters targeting VoIP Users</a> based on <a href="http://www.voip-news.co.uk/2008/05/21/newport-networks-highlights-voip-security/">report out of Newport Networks</a> (reported in VoIP News) &#8211; also covered at Fierce VoIP: <a href="http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18">Newport Networks riles up VoIP Security Fears</a> and Computeractive: <a href="http://www.computeractive.co.uk/personal-computer-world/news/2216851/phreak-voip">Phreak-out over VoIP</a> and <a href="http://www.thetechherald.com/article.php/200821/1017/Newport-Networks-raises-VoIP-identity-theft-concerns">TechHerald article</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2008/042808converge1.html">Security and management considerations when deploying <span class="caps">OCS</span></a></li><br />
<li>LXer: <a href="http://lxer.com/module/newswire/view/102328/">Secure Calling Initiative Reaches Second Milestone</a> pointing to <a href="http://www.gnutelephony.org/index.php/Secure_Call">Secure Calling Initiative</a></li><br />
	<br />
	<li>[H]Enthusiast: <a href="http://www.hardocp.com/news.html?news=MzI0NjMsLCxoZW50aHVzaWFzdCwsLDE">Mobile Phones, VoIP Not Secure, Experts Warn</a>=</li><br />
	<br />
	<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-privacy-042308/">The Essential Guide to VoIP Privacy</a></li><br />
	<br />
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/18/information-week-interviews-securelogix-about-voip-security/">Information Week interviews SecureLogix about VoIP security</a></li><br />
<li>eWeek: <a href="http://www.eweek.com/c/a/Knowledge-Center/VoIP-Security-through-Responsible-Software-Development/">VoIP Security through Responsible Software Development</a></li><br />
<li><a href="http://techdirt.com/articles/20080429/095514977.shtml">Microsoft gives back door keys to Vista to police</a></li><br />
<li>Comment (blog) from <a href="http://www.blueboxpodcast.com/2008/03/blue-box-77-sky.html#comment-108655562">Martyn Davies</a></li><br />
		<li>Comment (email) from Detlef</li><br />
		<li>Comment (email) from Dan McGinn-Combs</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>41:43 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=labVEA"><img src="http://feeds.feedburner.com/~a/BlueBox?i=labVEA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=PJqInK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=PJqInK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=DKnQRK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=DKnQRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=0ojlsK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=0ojlsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=zQkKxK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=zQkKxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=j1XWBk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=j1XWBk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=t89cyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=t89cyK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/375722849" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 16:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip users based">voip users based</category>
      <category domain="http://securityratty.com/tag/enterprise voip planet">enterprise voip planet</category>
      <category domain="http://securityratty.com/tag/voip calls">voip calls</category>
      <category domain="http://securityratty.com/tag/voip privacy">voip privacy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/375722849/blue-box-81-isk.html">Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more</source>
    </item>
  </channel>
</rss>
